Trust and security
Last updated: 4 September 2026
Speech hears what you say all day. This page says what we do with it, who can reach it, where it physically lives, and which of the things a security review usually asks for we have not built yet.
Your data stays in India
Servers, database and backups run in AWS Mumbai (ap-south-1).
Privacy Mode keeps nothing
A switch in Settings. Audio and transcripts are discarded the moment they are transcribed.
Nobody reads your words
Not even us, unless you turn it on for your own account. Off by default.
Delete means delete
One page in your account removes the account and everything stored for it.
What we hold, and for how long
Your choice, made in Settings, decides this.
| Privacy Mode | Standard | |
|---|---|---|
| Your audio | Never written to disk | Deleted after 60 days |
| Your transcripts | Never written to disk | Kept, and may be used to improve Speech's own accuracy and models |
| Account and usage records | Kept while the account exists. Counts and timings, not content. | |
| Pictures Agent Mode made for you | One year | |
| Bug reports you sent | One year | |
| Database backups | 60 days in S3, 14 most recent on the server | |
Your transcripts are never sold and never used to train anybody else's models. Full detail is in the privacy policy.
Who can see your dictations
By default, only you.
- An administrator at your company sees when you dictated, in which kind of app, for how long, how many words, and whether it worked. They cannot read the words or play the audio.
- They can read your words only if you switch that on from your own account page. Nobody can set that switch for you, and you can turn it off again at any time.
- Every time somebody at Creativefuel opens another person's transcript or plays their audio, that is written to an append-only audit log with who, whose, when and from where. Reads, not only changes.
- Our own admin console is limited to named accounts and takes a second factor from an authenticator app. The 7 day session your desktop app holds cannot open it.
How it is protected
In transit
TLS 1.2 and 1.3 only, with HSTS, a strict Content Security Policy, and certificates renewed automatically. The apps talk to nothing but our API.
At rest
The database runs inside the private network and is not published to the internet; nothing outside the application container can connect to it. Nightly backups are uploaded to S3 with AES-256 server side encryption and expire on a lifecycle rule after 60 days. The upload identity can write backups and do nothing else.
Access
The admin console is separate from the product: an account with elevated dictation limits does not get it. The console is granted from a declared list on every boot, so a grant cannot exist that nobody remembers making, and every change and every content read is audited.
In the code
Every change is reviewed as a pull request with the full test suite, a dependency vulnerability scan of everything we ship, and a secret scan of the whole history before it can merge. Dependency updates arrive as pull requests weekly.
For companies
- Sign in with Google, enforced. An organization can require that every address on its domains signs in through its own Google Workspace. Passwords and emailed codes stop working for them, so identity stays yours and suspending somebody in Workspace ends their access here.
- SCIM 2.0 provisioning. Connect Okta, Microsoft Entra ID, Google Workspace or JumpCloud and joiners get accounts and leavers get disabled without anybody remembering to. Deprovisioning disables an account; it never deletes one, because an identity provider mis-sync should not destroy somebody's work.
- Organization controls. Feature defaults, caps, the team board, a shared dictionary, and an audit feed scoped to your own people.
- A Data Processing Addendum is available at /dpa.html, with the subprocessor list at /subprocessors.html.
Where it runs
AWS ap-south-1 (Mumbai), India: the application, the database and the backups. Two of the model providers that transcribe or format a dictation run in the United States, so a request that takes those paths crosses a border for the seconds it takes to process. Nothing about it is stored there. The full list, with what each one receives, is on the subprocessors page.
Your rights, and how to use them
- Export or delete everything: the delete page in your account removes the account, the dictations, the audio, the images and the usage records.
- Under the Digital Personal Data Protection Act, 2023 we have a Grievance Officer, and we acknowledge a grievance within 72 hours and respond within 30 days. Contact details are in the privacy policy, section 10.
- Privacy questions: support@creativefuel.io, two working days.
Found a security problem?
Please tell us before you tell anyone else: security@creativefuel.io. We will reply, keep you updated while we fix it, and will not pursue legal action against anybody who follows our disclosure policy.
What we do not have yet
Most pages like this one list only what a company has. Here is the other half, because you are going to ask and we would rather you heard it from us.
- SOC 2 and ISO 27001: neither, yet. We are working towards ISO/IEC 27001:2022 first. We will not imply an attestation we do not hold.
- An independent penetration test: not yet commissioned. The code is reviewed and scanned on every change, which is not the same thing.
- SAML single sign-on for Okta, Entra ID and Ping: not built. Google Workspace enforcement and SCIM provisioning are, and cover the lifecycle half. Talk to us if SAML is what stands between us.
- A customer-facing audit log export: organization admins see an audit feed in the console; there is no export or SIEM stream yet.
- Data residency outside India: not offered.
Privacy policy · Terms · Data Processing Addendum · Subprocessors
Speech by Creativefuel