Privacy notice
Effective 24 August 2026
How Dicta collects, uses, discloses, retains and deletes personal information.
§ 1Who is responsible
Dicta is responsible for the personal information described in this notice. Questions, access requests and deletion requests may be sent to info@dicta.io.
§ 2Scope and customer responsibilities
This notice applies to Dicta's website and transcription service. A customer controls why a recording is made and who participates. The customer must provide required notices, obtain lawful authority and any consent, and respond appropriately to participants whose information is recorded.
§ 3Information collected
Dicta may collect account identity and profile data; authentication and session data; billing references and subscription status; recordings; transcript text, timings, speaker labels, corrections and comments; generated documents and their provenance; cloud-export connection and file metadata; device, browser and network data; usage allowances; and diagnostic events. Dicta does not receive full payment-card details from Stripe.
§ 4How information is collected
Information is provided by users, created from authorised recordings, generated through use of the service, received from connected providers, or collected automatically through operational logs and anonymous product events.
§ 5Purposes
Dicta uses information to authenticate users, provide live and final transcription, support transcript review, generate requested titles or documents, produce exports, administer plans and billing, secure and troubleshoot the service, enforce limits, answer support requests and comply with law.
§ 6Processing grounds
Depending on the relationship and applicable law, Dicta processes information to perform its agreement with a customer, on the customer's instructions, with consent where required, for legitimate service-security and operational interests, or to comply with legal obligations. Customers remain responsible for establishing the lawful basis for recording other people.
§ 7Service providers
Cloudflare hosts the application and stores application data. WorkOS handles authentication. Deepgram receives raw audio for live and final transcription. OpenAI receives transcript text for requested title, review or document functions. Stripe handles billing and subscription data. PostHog receives anonymous product telemetry. Google or Microsoft receives a produced file only when a connected export is enabled and requested.
§ 8Speech and AI processing
Dicta sends audio to Deepgram with mip_opt_out=true. This requests exclusion from Deepgram model-improvement processing but is not a promise of zero operational retention. Requests to OpenAI use store:false. That setting disables response storage in the request, but Dicta does not present it as a complete zero-retention guarantee. OpenAI receives transcript text, not raw audio, for these optional functions.
§ 9Authentication and billing
WorkOS may process a user's name, email address, IP address, user-agent, authentication method and session information. Stripe processes the customer and subscription information needed to take payment, maintain plan status, issue billing records and provide the billing portal.
§ 10Product telemetry
PostHog receives anonymous product events used to understand whether product flows work and to investigate operational failures. Dicta also keeps infrastructure logs that may include request identifiers, timestamps, routes and technical error details. Dicta does not intentionally place recording or transcript content in anonymous product events.
§ 11Retention and deletion
Transcript text and private source audio are scheduled for deletion within 30 days and may be deleted sooner from the transcript page. Generated documents stored with a transcript inherit that maximum period. Some account, billing, security and minimal operational records may be kept longer where needed to run the account, resolve disputes, prevent abuse or meet legal obligations.
§ 12Exports
A file exported to a user's device, Google Drive or OneDrive becomes a separate copy controlled by the user and the relevant storage provider. Deleting the source transcript or disconnecting a provider does not delete those exported copies.
§ 13Improvement and evaluations
Dicta does not use ordinary customer recordings, transcripts or documents to improve models or evaluation sets. Dicta may use material only where the customer separately and explicitly opts in or deliberately submits it for evaluation. Evaluation material must be de-identified before it is added to an evaluation set, and the consent may be withdrawn for future use by contacting Dicta.
§ 14International processing
Dicta and its providers may process information in countries outside Australia. Privacy and government-access rules may differ in those countries. Provider locations and transfer safeguards depend on the relevant service and customer configuration.
§ 15Security
Dicta uses authenticated accounts, sealed session cookies, environment separation, access controls and limited retention to reduce risk. No internet service is completely secure. Customers should use appropriate devices, protect account access, review recipients before export and promptly report suspected compromise.
§ 16Access, correction and complaints
You may request access to or correction of personal information held by Dicta, or ask for deletion where applicable, by emailing info@dicta.io. Dicta may need to verify identity and may direct a recorded participant to the customer that controlled the recording. Australian privacy complaints may also be made to the Office of the Australian Information Commissioner.
§ 17Changes
Dicta may update this notice when its service or processing changes. The effective date above identifies the current version. Material changes will be communicated through the service or another reasonable channel.