Built to run locally,with privacy in mind.
Dictate without your audio touching anyone's cloud, and run your meetings entirely on your own computer. If you want AI on your notes, you choose whose: ours, or your own keys.
Audio stays on the device.
Capture and transcription run locally. By default the audio is deleted once the notes are written; you can keep it longer, but that is your choice, on your disk.
On your disk, your notes are ordinary files.
Transcripts and notes are readable files under your own user profile: yours to open, back up or take with you, with no lock-in. At rest they are protected the way the rest of your documents are, by your operating system's disk encryption (FileVault on macOS, BitLocker on Windows), which your IT team can enforce fleet-wide.
Only text ever leaves, and only on your say-so.
With AI off, nothing is sent anywhere. With Softspoken AI on, the transcript text for the one step you asked for is processed on our servers in Australia and never stored. With your own keys, it goes straight to your own provider. Either way it is encrypted in transit, every time.
The MCP connector is local too.
The MCP connector on Pro, Perpetual and Business is a local process with read access to your meeting library plus a single write: marking an action item done. It listens on no network port and never exposes audio.
Credentials live in the operating system's secure store.
API keys and sign-in tokens are kept in the macOS Keychain or Windows Credential Manager. They are never written to disk in plain text and never passed on the command line.
Updates are signed and confirmed.
Update manifests are cryptographically signed, and the app installs a new version only when you tell it to.
The network surface fits in one sentence.
The app talks to the update server, to Softspoken AI only when you have signed in, to your own AI provider only if you configured one, to your own calendar provider only if you connect a calendar link for meeting reminders, and to a one-time model download the first time a speech model is needed. Your device fetches that calendar link directly from your calendar provider, the same way your calendar app does, and no meeting content is in that request. That is the whole list, and the app has no telemetry.
No administrator rights on Windows.
The installer is per-user. Nothing asks for an admin password, which also makes it easy to trial inside a managed environment.
We are aligned to ISO/IEC 27001 (information security) and ISO/IEC 42001 (AI management), and we conduct regular audits across our product and services. We also have a rigorous OWASP security audit with audit logs. Beyond that, the architecture does the heavy lifting: the sensitive thing, your audio, never reaches us at all, and the privacy notice is short enough to actually read. If your IT team has questions, or wants to see how we audit, write to hello@softspoken.io and you will get engineering answers. Security disclosures: security@softspoken.io. Read our network requirements here.
Rolling Softspoken out on managed Windows devices? See App approval on the network page.
Common questions covers the rest: IT review, offline use, consent.