Privacy
Your voice is the most personal data you produce. Dicta never sends it anywhere: not to us, not to a cloud, not to a model provider. Speech recognition, vocabulary correction and AI rewriting all run on your machine. This page explains that in plain language and covers the little that the website itself handles.
Who is responsible
The controller for this website and for the limited data described below is GetDicta UG (haftungsbeschraenkt), Johannisstr. 71, 50668 Koeln, Germany, represented by its Managing Director Birgit Herz. You can reach us at [email protected]. Company details are in the Imprint.
What never leaves your Mac
- Your dictated audio
- Your transcripts and dictation history
- Your personal dictionary ("My Words") and writing styles
The only network calls the app ever makes
Dictation itself needs none of these. You can verify it yourself: run Dicta with a firewall in block-all mode and dictation, corrections and the AI rewrite keep working.
- Model download
- Downloads the speech and rewrite model files from the model host (Hugging Face CDN) the first time you need them. Carries no audio or text.
- Update check
- Checks for a new app version (Sparkle). Carries no audio or text.
- License activate / refresh
- Sends a hashed license key and a device id, at most weekly, with a 30-day offline grace period. Never carries audio or text.
- Anonymous usage counters
- A separate, unauthenticated, pseudonymous call: a random install id plus minutes/words/version counters, no content, no key hash, no device id. On by default, off in Settings, and honored immediately.
The website: what we handle here
The site is hosted on Cloudflare. Like any web host, Cloudflare processes technical request data (such as your IP address and the page requested) to deliver pages and keep the service secure. We rely on our legitimate interest in a working, secure site for that (Art. 6(1)(f) GDPR), and this data is kept only briefly.
For visitor numbers we use Cloudflare Web Analytics: cookieless, no fingerprinting, no cross-site tracking. There is no Google Analytics, no advertising pixel, no third-party tag. Fonts are self-hosted, so your browser never calls a font CDN.
Cookies and consent
Today this site sets no tracking cookies. The only thing we store in your browser is your choice on the consent banner itself, which is strictly necessary so we do not ask you again. Visitors from the EU/EEA, Switzerland and the UK see that banner, with Accept and Reject offered equally. If you reject, or never decide, nothing beyond the strictly necessary runs. The banner is here so that if we ever add anything that would need cookies, it loads only after you say yes, and never before.
Waitlist
If you join the waitlist, we store your e-mail address and a record of your opt-in (a timestamp) so we can e-mail you about the launch, and for nothing else. The legal basis is your consent (Art. 6(1)(a) GDPR). This is kept in a Cloudflare D1 database hosted in the EU, for up to 730 days or until you unsubscribe, whichever comes first. Unsubscribing is a hard delete: we remove the record. There is no marketing automation and no sharing with third parties.
Buying at launch
There is no checkout yet, so no payment data is collected today. When purchasing goes live, payment, invoicing and tax will be handled by Stripe as our payment processor; card and billing details stay with Stripe, and on our side we keep only what licensing needs (a Stripe customer id, a hashed license key, device activations, and referral state) in the EU-hosted D1 database. Full detail will be added here before checkout opens.
Who we share data with
We keep the list of processors deliberately short: Cloudflare (website hosting, cookieless analytics, and the EU database), the model host (Hugging Face CDN, which serves model files to the app and receives no account data), and, once purchasing is live, Stripe (payments and invoicing). We do not sell data, and there are no advertising or tracking partners.
Where data is stored
The waitlist and licensing database runs in Cloudflare's EU jurisdiction. Model files are fetched from a content delivery network that may serve them from outside the EU; that download carries no account data. Where a transfer outside the EU happens, it is covered by the standard safeguards the provider offers.
Your rights
You have the usual GDPR rights over any personal data we hold:
- Access: a copy of what we hold about you.
- Rectification: fix anything inaccurate.
- Erasure: have your data deleted.
- Restriction and objection: limit or object to processing.
- Portability: get your data in a portable form.
- Withdraw consent: at any time, without affecting what happened before.
To exercise any of these, e-mail [email protected]. You also have the right to complain to a data protection authority, for example the one for our region, the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW).
GDPR-friendly by architecture
Dicta processes voice and text entirely on your device, under your control. That means no processor relationship with us for your dictation content, and nothing for us to disclose because we hold nothing. We phrase this as "GDPR-friendly by architecture", never as "GDPR certified", and this page is not legal advice.
This page describes the architecture as built. The final legal copy is pending a lawyer's review before launch; nothing above is legal advice.