Privacy
What we collect, where it goes, and how long we keep it.
Effective 31 July 2026
Whisperly turns what you say into clean text. To do that we handle a small amount of your data. This page explains what, why, and for how long. Whisperly is operated by Evgeny Alexeev, a sole proprietor registered in Uzbekistan. Questions: support@whisperly.io.
What we collect
- Your email address, so you can sign in with a one-time code and so we can reach you about your account.
- Your dictation audio, only while it is being turned into text (see “How a dictation works”).
- Basic usage records: how many words you dictated and when, so we can apply your plan's limits and bill correctly. These records do not contain the content of your dictations.
- Your subscription status, if you upgrade to Pro.
We do not ask for your name, your address, or anything we do not need.
How a dictation works
When you dictate, the audio is sent over an encrypted connection to our servers in the EU, and from there to a specialist speech-to-text provider that turns it into text. The text is then sent to a language provider that cleans it up and, if you asked, translates it. The result comes back to you.
Your audio is never written to a database or a file. Once your text has been produced, the audio is gone. We do not build a history of your dictations.
Where your data is processed
- Your account, email, and usage records are stored in the EU (Supabase, in Frankfurt).
- Turning speech into text and cleaning it up uses specialist providers, currently Fireworks, Groq, and OpenAI. Your audio and text are sent to them only to produce your result. Some of these providers operate outside the EU, so your audio and text may be processed outside the EU under those providers' data-protection terms. We may change providers and will keep this page current.
- Payments are handled by Paddle, acting as our Merchant of Record. Paddle collects and processes your payment details and handles any tax. We never see or store your card number.
- Product analytics is handled by PostHog, which we run in its EU region (Frankfurt). It receives the basic site-usage signals described under “Cookies and tracking” below, together with your account's signup, usage, and subscription records, so we can see how the product is used and improve it. PostHog processes this on our behalf in the EU and never receives your dictation audio or the text of what you say. During first-run setup, the Mac app also sends anonymous product-analytics events to PostHog: when it launches, onboarding progress, permission prompts, and sign-in steps. This shows us where new users get stuck. It stops automatically once you finish onboarding, so there is no ongoing collection, and there is no in-app switch for it. These app events carry no account identifier, email address, audio, transcript, or vocabulary.
We do not use your dictations to train any model, ours or anyone else's, and we choose providers that process your content only to return your result.
Why we are allowed to process your data
- Contract: turning your speech into text, running your account, and billing: we process this because you asked us to (it is the service).
- Legitimate interest: product analytics (with a working opt-out in the cookie preferences) and abuse prevention (the brief IP processing described below).
- Consent: advertising cookies (Google Ads), YouTube video playback, and the tawk.to live chat in the EU, EEA, and UK: off until you accept, changeable any time from the cookie preferences. Also the platform-waitlist notification described below: we store your email address only because you ticked the box asking us to, and you can ask us to delete it at any time.
Custom vocabulary
Custom vocabulary. The custom words you add are stored with your account on our servers (EU, Frankfurt) so they sync across your devices, and are used only to spell your terms correctly. They are deleted when you delete your account.
Platform waitlist
Whisperly runs on macOS today. If you use the form at /windows to ask us to tell you when it runs somewhere else, we store the following on our servers in the EU (Frankfurt):
- Your email address.
- One record per platform you ticked.
- The acquisition id and channel name from the first-party attribution cookie described under “Channel attribution” below, if you have one.
- The moment you ticked the consent box, and which version of this policy it referred to.
- The moment the record was created.
Nothing else: no name, no IP address. Your IP address is processed briefly, in memory, only to limit how often the form can be submitted, and is never stored with the record or written to a log.
You do not need an account for this and it does not create one. The email address is used for the one notification per platform you asked about, and for nothing else: no newsletter, no other list, never sold or shared. To be taken off the list, email support@whisperly.io and we will delete the records.
Cookies and tracking
The website uses only what it needs to keep you signed in. To understand how people find and use the site, we use PostHog, a product-analytics provider we run in its EU region (Frankfurt), under legitimate interest. It records basic signals: the pages you view, the download link you click, and the channel you came from. PostHog can also capture an anonymous session replay: a recording of how you move, click, and scroll on the page. Typed input is masked in your browser before it is ever sent, so a replay never includes the words you dictate. It runs without cookies and does not track you across other websites. You can switch analytics off at any time from the cookie preferences: the badge in the bottom-left corner of the site, or Manage cookies in the footer. Both open the same preferences panel.
Channel attribution. If you arrive from one of the links we post (Reddit, Hacker News, Product Hunt, and similar), from a creator's link, or from another user's invite link, your first visit stores which channel you came from in a first-party cookie; a creator or invite link also stores who referred you, identified by their handle (for example, a YouTube or X username, or the invite handle we issued them). When you sign in for the first time, the Whisperly app opens a page on this site that reads that cookie and sends the channel name and, if present, the referrer handle, together with a short-lived opaque token that identifies your new account, to our own API, so we can tell which channel and which referrer brought a real signup. This is server-mediated and first-party: the cookie itself carries no personal data beyond the channel name and the referrer's handle, and nothing is sent to a third party. One exception: if you join the platform waitlist described above, the cookie's channel and its acquisition id are stored alongside your email address, so on that one path they are linked to you.
Advertising measurement. If you arrive from one of our ads, we use Google's advertising cookies to measure whether our Google Ads campaigns work (for example, that a click led to a download). In the EU, the EEA, and the UK these cookies stay off until you choose to accept them: we ask with a consent banner, and nothing advertising-related is stored on your device unless you press Accept. Elsewhere they are on by default. Google acts as our provider and processes this data outside the EU, in the United States. You can change or withdraw your choice at any time, wherever you are, from the cookie preferences: the badge in the bottom-left corner of the site, or the Manage cookies link in the footer. Both open the same panel.
Video playback. Some pages let you play a product-demo video. Nothing loads from YouTube until you click to watch one: the video then plays through youtube-nocookie.com, operated by Google Ireland Limited / YouTube LLC. Loading a video can set cookies and share your IP address and viewing activity with Google, partly outside the EU, in the United States. In the EU, the EEA, and the UK this is off until you accept, either the first time you click a video or from the cookie preferences. Elsewhere it is on by default. You can change your choice at any time from the cookie preferences: the badge in the bottom-left corner of the site, or the Manage cookies link in the footer.
Live chat. The site offers a live support chat operated by tawk.to Inc., a United States company. In the EU, the EEA, and the UK nothing loads from tawk.to until you open the chat: you see a plain chat button that we render ourselves, and only pressing it loads the widget. Once the chat loads, tawk.to sets its own cookies and processes, in the United States, your IP address, your device and browser details, the pages you view, and the messages and any details you choose to share in the chat. Elsewhere the chat loads with the page. You can switch it off at any time from the cookie preferences: the badge in the bottom-left corner of the site, or the Manage cookies link in the footer.
Keeping the service safe
We briefly process your IP address to stop abuse, such as spam sign-ups or automated overload. We do not store it to build a profile of you or to track you across the web.
When you download the app, our server also records an anonymous “download started” signal, so we can see how many downloads actually start. This has no cookie and no account attached: it notes only your browser's identifier and the page the request came from, and whether the download is a fresh install or an automatic update. It runs on our server, not in your browser, so it is not part of the analytics you can switch off from the cookie preferences described above.
We protect your data in transit and at rest, but no way of sending or storing data is 100% secure, so we cannot promise absolute security.
How long we keep things
- Account and usage records: while your account exists; anonymised when you delete your account.
- Audio: not kept at all.
- Session replay: kept for 30 days, then deleted automatically.
- Analytics events: kept for 12 months, then deleted automatically.
- Platform waitlist records: kept until we have sent you the notification for that platform, or until you ask us to remove you, whichever comes first. Nothing deletes these on a schedule, so email support@whisperly.io if you want out sooner.
- You can delete your account and your data at any time from the app (Settings → Account → Delete account), or by emailing support@whisperly.io. Deletion is immediate: we erase your personal data from our live systems straight away. Anonymised usage and billing records that can no longer be linked to you may remain, and we keep a one-way cryptographic hash of your email address only to stop repeated free-trial sign-ups. It cannot be turned back into your email and is never used to identify you.
Your rights
You can ask us to show you the data we hold about you, correct it, or delete it. Email support@whisperly.io and we will act on your request. This policy never takes away any rights you have under your local data-protection law.
We may ask you to confirm your identity before acting on a request, so nobody else can use your rights against your data. If you think we have handled your data wrongly, you also have the right to complain to a data-protection supervisory authority, for example the one in the EU or EEA country where you live or work.
Children
Whisperly is not directed at children. By using it you confirm that you are at least 16 years old, or at least the age at which your country lets you consent to digital services on your own if that is lower, and that if you are under 18 you have a parent's or guardian's permission. We do not knowingly collect data from children. If you believe a child has an account, email support@whisperly.io and we will delete it.
Changes
If we change this policy we will update this page and the date above.
Questions? Email support@whisperly.io.