← Speech

Trust and security

Last updated: 4 September 2026

Speech hears what you say all day. This page says what we do with it, who can reach it, where it physically lives, and which of the things a security review usually asks for we have not built yet.

Your data stays in India

Servers, database and backups run in AWS Mumbai (ap-south-1).

Privacy Mode keeps nothing

A switch in Settings. Audio and transcripts are discarded the moment they are transcribed.

Nobody reads your words

Not even us, unless you turn it on for your own account. Off by default.

Delete means delete

One page in your account removes the account and everything stored for it.

What we hold, and for how long

Your choice, made in Settings, decides this.

Privacy ModeStandard
Your audioNever written to diskDeleted after 60 days
Your transcriptsNever written to diskKept, and may be used to improve Speech's own accuracy and models
Account and usage recordsKept while the account exists. Counts and timings, not content.
Pictures Agent Mode made for youOne year
Bug reports you sentOne year
Database backups60 days in S3, 14 most recent on the server

Your transcripts are never sold and never used to train anybody else's models. Full detail is in the privacy policy.

Who can see your dictations

By default, only you.

How it is protected

In transit

TLS 1.2 and 1.3 only, with HSTS, a strict Content Security Policy, and certificates renewed automatically. The apps talk to nothing but our API.

At rest

The database runs inside the private network and is not published to the internet; nothing outside the application container can connect to it. Nightly backups are uploaded to S3 with AES-256 server side encryption and expire on a lifecycle rule after 60 days. The upload identity can write backups and do nothing else.

Access

The admin console is separate from the product: an account with elevated dictation limits does not get it. The console is granted from a declared list on every boot, so a grant cannot exist that nobody remembers making, and every change and every content read is audited.

In the code

Every change is reviewed as a pull request with the full test suite, a dependency vulnerability scan of everything we ship, and a secret scan of the whole history before it can merge. Dependency updates arrive as pull requests weekly.

For companies

Where it runs

AWS ap-south-1 (Mumbai), India: the application, the database and the backups. Two of the model providers that transcribe or format a dictation run in the United States, so a request that takes those paths crosses a border for the seconds it takes to process. Nothing about it is stored there. The full list, with what each one receives, is on the subprocessors page.

Your rights, and how to use them

Found a security problem?

Please tell us before you tell anyone else: security@creativefuel.io. We will reply, keep you updated while we fix it, and will not pursue legal action against anybody who follows our disclosure policy.

What we do not have yet

Most pages like this one list only what a company has. Here is the other half, because you are going to ask and we would rather you heard it from us.

Privacy policy · Terms · Data Processing Addendum · Subprocessors

Speech by Creativefuel