Transcription and confidentiality — the questions worth asking
This guide is about how to think through the confidentiality of a recording before you transcribe it. It is not legal advice, and it deliberately avoids telling you what any particular rule requires — those differ by country, by regulator, by profession and by the contract you signed, and anyone who tells you otherwise on a website has not read your contract.
What it can do is set out what actually happens technically, and which questions are worth putting to whoever does advise you.
The upload is the event
The moment a file finishes uploading, a disclosure has occurred. Everything after that — the service’s retention policy, its encryption, its certifications, its promise to delete — is a promise about data it already has. Those promises may be excellent and honoured perfectly. But the decision point has passed.
This matters because in most professional contexts, the question you will be asked afterwards is not “was the vendor secure?” It is “who did you give this to, and were you permitted to?” A vendor’s security posture is an answer to a different question.
What you are actually agreeing to
Terms vary, and they are worth reading rather than assuming. Across transcription and note-taking services the recurring provisions to look for:
- Retention. How long is the audio kept, and is deleting a transcript from the interface the same as deleting the recording from their storage and their backups?
- Sub-processors. Many services do not run their own speech models — they call somebody else’s. Your file may pass through more organisations than the one you contracted with, and the sub-processor list is where you find out.
- Training use. Whether your audio may be used to improve their models. Consumer tiers and business tiers frequently differ here, and the default on a free tier is often not the one you would choose.
- Jurisdiction. Where the servers are and whose legal process can reach them.
- Human review. Whether any human ever listens for quality assurance.
None of these are scandalous — they are ordinary terms for a service that has to run somewhere. The point is that accepting them is a decision, and it is a decision people make by clicking “upload” without noticing they made it.
The categories where this gets serious
Research interviews. Consent forms routinely say the recording will be heard only by the research team. Ethics approval is usually granted on that basis. Uploading to a service is a third-party disclosure that most approvals did not contemplate, and it is exactly the question committees ask about now.
Clinical and counselling recordings. These describe named individuals’ health in detail. Every processor added is another contract to maintain, another retention period to track, another entry in a breach report. Institutions handle this with formal agreements; an individual clinician wanting a draft usually cannot.
Legal work. Privileged material handed to an outside vendor raises questions that vary by jurisdiction and by the terms in place. Firms have policies about this precisely because the answer is not obvious.
Workplace investigations. The recording names a complainant, a respondent and witnesses, and it may end up in a tribunal bundle. A copy outside the organisation’s control is a problem the process did not plan for.
Anything covering someone who was not asked. Voice notes, family recordings, a meeting where one participant recorded and the others did not know a transcription service would be involved.
Where local processing helps — precisely
Running the model in your browser changes exactly one thing, and it is worth stating narrowly so that nobody over-relies on it:
The recording is not transmitted, so no additional party gains access to it during transcription.
That is the whole claim. There is no upload endpoint, no queue, no account holding a copy, no sub-processor, no retention question and no jurisdiction question, because the file never moves. You can verify it rather than trusting it — see how to verify nothing is uploaded — and the offline test is the version that convinces people: disconnect from the internet and it still works.
Where it does not help at all
Being clear about this is more useful than the reassurance:
- It does not make a recording lawful. Whether you could record the conversation at all is a separate question, and consent rules genuinely differ — between US states, between countries, and between phone calls, meetings and hearings.
- It does not satisfy your obligations. Consent, storage, access control, retention, breach procedures and disclosure duties are unchanged. One step in your workflow got simpler; none of the rest went away.
- It does not secure your device. If the recording sits in a synced folder, gets backed up to a cloud drive or is indexed by desktop search, it has left your machine by a route that has nothing to do with transcription.
- A transcript spreads more easily than audio. Text is searchable, quotable, pasteable and forwardable. Producing one increases the number of places sensitive content can end up, which is useful when that is what you want and a risk otherwise.
- It is not a compliance certification. No tool is. Compliance is a property of a whole process, assessed by someone who knows your circumstances.
Questions worth asking, whichever route you take
Before uploading anything to any service:
- What did I promise the person being recorded, in writing or otherwise?
- Does my employer, institution or regulator have a policy that names approved vendors?
- Does this service use sub-processors, and can I see the list?
- Can my audio be used for training, and can I turn that off?
- How do I actually delete it, and does that include backups?
- If this recording appeared somewhere it should not, what would the consequence be?
If question 6 has a serious answer, the transcription step is worth doing somewhere the file does not move — and the rest of your handling deserves the same scrutiny.
A reasonable default
For public material — a published podcast, a conference talk, a marketing video — use whatever is fastest and best. Confidentiality is not the constraint; accuracy and convenience are, and a large cloud model will beat a browser one on hard audio.
For anything covering a person who has not agreed to it being processed elsewhere, keep it local, and treat the transcript with the same care as the recording. That is not a claim that this tool is compliant with anything. It is the observation that the safest disclosure is the one that never happens.