How Dicta handles legal work.
The services involved, the information they receive, and the controls available to you.
Hosting and storage
Cloudflare hosts Dicta's application, Worker runtime, database and private source-audio storage. Production, preview and local environments use separate application bindings.
Accounts and billing
WorkOS handles sign-in and receives the account details needed to authenticate users. Stripe processes subscription and payment information; Dicta stores customer, subscription and plan references rather than full payment-card details.
Speech processing
Deepgram receives raw audio for live and final transcription. Dicta sends mip_opt_out=true to request exclusion from model-improvement processing. This control is not represented as a guarantee of zero operational retention.
Optional AI functions
OpenAI receives transcript text, not raw audio, when a user requests title, review or enabled document functions. Requests use store:false, which disables response storage for the request but is not described as a complete zero-retention guarantee.
Retention and deletion
Dicta schedules source audio, transcript text and transcript-linked documents for deletion within 30 days. A user can delete a transcript sooner. Account, billing, security and minimal operational records may follow different retention periods where necessary.
Exports and telemetry
Google or Microsoft receives a produced file only when the relevant export is enabled, connected and requested. Exported copies leave Dicta's deletion controls. PostHog receives anonymous product events; transcript content is not intentionally included in those events.
Access and output controls
Dicta uses authenticated accounts, sealed session cookies, origin and host checks, limited retention and review warnings to keep access scoped and output reviewable.
Customer responsibility
Customers decide whether a matter is appropriate for Dicta, establish recording authority, protect account access, review recipients before export and verify every transcript and document before use.