Security and data handling
See which providers receive account, audio, transcript or export data, when they receive it and the controls that apply.
- Retention
- Source audio and transcript text are scheduled for deletion within 30 days.
- Speech processing
- Deepgram receives raw audio for live and final transcription.
- Requested AI functions
- OpenAI receives transcript text, not raw audio, when you request an enabled function.
| Service | Receives | When | Control |
|---|---|---|---|
| Cloudflare | Application data, transcript text and private source audio | While Dicta provides the service | Private storage, separate environment bindings and scheduled deletion |
| WorkOS | Account details needed for authentication | When you create an account or sign in | Authentication provider controls and sealed Dicta session cookies |
| Stripe | Subscription and payment information | When you use paid billing | Dicta stores customer, subscription and plan references, not full card details |
| Deepgram | Raw audio | During live and final transcription | Dicta sends mip_opt_out=true; this is not a guarantee of zero operational retention |
| OpenAI | Transcript text, not raw audio | When you request title, review or enabled document functions | Requests use store:false; this is not described as complete zero retention |
| Google / Microsoft | A produced file | Only when you connect and request an export | The exported copy leaves Dicta's deletion controls |
| PostHog | Anonymous product events | While you use product features | Dicta does not intentionally include transcript content in those events |
Your controls
Delete a transcript sooner, review every output before use, and choose whether to connect an export provider.
Your responsibilities
Decide whether a matter is appropriate for Dicta, establish recording authority, protect account access and check recipients before export.