← Dragon WisprTermsPrivacyRefundsLegal noticeSecurity

Privacy Policy

Last updated: 4 October 2026

  • Your audio is processed transiently to produce your text. Our speech-to-text provider is configured for zero data retention and never trains on it. We never store audio or transcripts.
  • We store your email address, your plan, and usage metadata: how many seconds each dictation lasted, when, the mode, and the language detected. Per-dictation records are deleted after 13 months.
  • Payments are handled by Paddle. We never see your card details.
  • No advertising, no selling of data, no cookies on our website.
  • You can download or delete your data yourself in the desktop app, or email privacy@dragonwispr.com.

1. Who is responsible for your data

The controller of your personal data under the EU General Data Protection Regulation (GDPR) is:

[TailorUp legal name] (trading as TailorUp), [legal form]
[registered address, Greece]
ΓΕΜΗ (General Commercial Registry) no.: [ΓΕΜΗ number] · VAT: [VAT number, EL…]
Email: support@dragonwispr.com

For anything about privacy, write to privacy@dragonwispr.com. That address reaches the person responsible for data protection directly. We are not required to appoint a Data Protection Officer and have not done so.

This policy covers the Dragon Wispr website (https://dragonwispr.com), the desktop app, the online service behind them (together, the “Service”) and the beta waitlist.

2. What we process, why, and on what legal basis

PurposePersonal dataLegal basis (GDPR)
Turning your speech into text (and, once Dragon mode launches, translating it)The audio of each dictation and the text it becomes, processed transiently.Contract, Art. 6(1)(b)
Your account and sign-inEmail address, account ID, when you signed up and last signed in, app settings that sync with your account.Contract, Art. 6(1)(b)
Counting your monthly minutes and applying your planPer-dictation metadata (audio seconds as reported by our speech-to-text provider, time, mode, detected language) and monthly totals.Contract, Art. 6(1)(b)
Your subscription (once paid plans open)Plan, billing period, status, Paddle customer and subscription IDs, email address, country.Contract, Art. 6(1)(b)
Service emails (sign-in links and codes, a notice when you have used 80% of your minutes)Email address, plan and usage figures.Contract, Art. 6(1)(b)
Security, rate limiting and abuse preventionIP address, a keyed hash of it, account ID, browser or app version, sign-in sessions and audit log, technical logs.Legitimate interest in keeping the Service secure and available, Art. 6(1)(f)
The beta waitlist and launch emailsEmail address, where you signed up, interests you ticked, when you confirmed, a keyed hash of your IP address until you confirm.Consent, Art. 6(1)(a)
Answering you and handling legal claimsWhat you send us by email, and the related account records.Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c); legitimate interest in defending claims, Art. 6(1)(f)

Your dictations

Your audio is processed transiently to produce your text; our speech-to-text provider is configured for zero data retention and never trains on it; we never store audio or transcripts. Audio travels encrypted from your device to our API, which passes it to our speech-to-text provider and returns the text to your app. Once Dragon mode launches and you turn it on, the text is also sent to our translation provider, under the same rules. We never put your dictations in emails, logs or analytics, and we do not use them to train models.

Speech-to-text currently runs on Whisper large-v3 turbo, an open-weights model, hosted by Groq. Dragon mode will use Qwen3-32B, an open-weights model, hosted by DeepInfra. The results are produced automatically and can contain errors, so check the text before you rely on it.

Do you have to give us this data?

You need an email address to create an account, and the Service needs your audio to turn it into text: without them we cannot provide the Service. Joining the waitlist is entirely optional.

Data we receive from Paddle

Paddle (see section 5) sells our paid plans as Merchant of Record and collects your payment details directly. When you buy, Paddle shares with us your plan, subscription status, Paddle’s customer and subscription IDs, your email address and your country, so we can activate your plan, provide support and keep our records. We use this data on the basis of our contract with you (Art. 6(1)(b)) and keep it for as long as your account exists. We never receive your full card details. Paddle only sends you marketing if you agreed to it with Paddle.

No automated decision-making

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects (Art. 22 GDPR), and we do not profile you for advertising. Automatic checks such as your monthly allowance and rate limits only pause dictation for a while; you can always contact us about them.

3. On your device

  • Keyboard hotkey. To work in every app, Dragon Wispr installs a system-wide keyboard hook. It only acts on the hotkey you configured (by default Right Ctrl); while you hold it, the app only notes that another key was pressed (so a shortcut such as Ctrl+C is not mistaken for dictation), never which one. It never records, logs or transmits any other keystroke.
  • Microphone. To avoid cutting off your first word, the microphone stays open while the app runs and the app keeps a rolling buffer of the last ~2 seconds of audio in memory only, continuously overwritten and never written to disk. Nothing leaves your computer until you press the hotkey; then the app sends what you say while you hold (or have toggled) the key, plus about 300 milliseconds from just before you pressed it.
  • Clipboard. With auto-copy (on by default), your text is placed on the clipboard so you can paste it. By default the app marks that text so Windows keeps it out of clipboard history (Win+V), cloud clipboard sync and clipboard managers; you can change this with “Keep out of clipboard history” (Settings → Feedback). Text that auto-paste (off by default) places on the clipboard only for a moment is always marked this way. When you press the app’s explicit Copy button, the text is copied like anything else you copy, so clipboard history and sync, if you turned them on, may keep a copy on your computer or in your Microsoft account.
  • Diagnostic log. The app writes a small local log file to help fix problems. It contains metadata only (for example timings, error codes and app version), never what you dictated. It is rotated at 40 KB, stays on your computer, and is only sent to us if you choose to attach it to a support request.
  • Sign-in and settings. Your sign-in session is stored in the Windows Credential Manager and your settings in the app’s folder. Recent results are shown in the app from memory and are never written to disk.
  • No analytics yet. The app has no telemetry today. If we ever add crash reports or usage analytics, they will be off until you opt in.

4. Service providers that process data for us

These providers act as our processors: they may only use the data to provide their service to us, under a data processing agreement.

ProviderWhat it does for usData involvedWhere
Supabase
Supabase Pte. Ltd., Singapore
Sign-in and our database.Email address, account and subscription records, usage metadata, waitlist; when you sign in, your IP address and browser or app (user agent) in sign-in sessions and logs.Hosted in Frankfurt (EU). Support access from outside the EU.
Cloudflare
Cloudflare, Inc., USA
Hosts the website and the API (Cloudflare Workers); DDoS protection.Requests in transit, including audio on its way to speech-to-text; IP address; technical logs kept up to 7 days.Global network; our API is placed in Frankfurt (EU).
Groq
Groq, Inc., USA
Speech-to-text.The audio of each dictation, processed transiently with zero data retention and never used for training.USA
DeepInfraNot active yet
Deep Infra Inc., USA
Translation for Dragon mode only, when it launches.Transcript text, processed transiently, not stored and not used for training.USA
Resend
Plus Five Five, Inc., USA
Transactional email (sign-in links and codes, waitlist confirmation, usage notices).Email address and message content (never your dictations); delivery logs kept 30 days.Sent from Ireland (EU), stored in the USA.
Upstash
Upstash, Inc., USA
Rate limiting and abuse protection.Short-lived counters keyed by your account ID or a keyed hash of your IP address; they expire within 48 hours.Frankfurt (EU)

5. Other recipients

  • Paddle (Paddle.com Market Ltd, United Kingdom) is an independent controller. Merchant of Record: checkout, payment, tax and invoicing, under its own privacy notice. The UK has an EU adequacy decision.
  • GitHub (GitHub, Inc., USA (EU-US Data Privacy Framework)) is an independent controller. Only if app updates are downloaded from GitHub Releases: GitHub receives your IP address and user agent when the app or your browser downloads an update.

Paddle’s own privacy notice applies to the payment data it collects. We do not sell your personal data or share it for advertising. We may disclose data if the law requires it, or to a successor if our business is transferred, in which case this policy continues to protect it.

6. International transfers

Our database is in Frankfurt (EU) and our API runs in Frankfurt. Some providers process data outside the European Economic Area. For each of them we rely on the following safeguard:

  • Supabase (Hosted in Frankfurt (EU). Support access from outside the EU): EU Standard Contractual Clauses (SCCs) for access from outside the EU.
  • Cloudflare (Global network; our API is placed in Frankfurt (EU)): EU-US Data Privacy Framework + SCCs.
  • Groq (USA): SCCs.
  • DeepInfra (USA): SCCs (data processing agreement signed before Dragon mode launches).
  • Resend (Sent from Ireland (EU), stored in the USA): EU-US Data Privacy Framework + SCCs.
  • Upstash (Frankfurt (EU)): EU-US Data Privacy Framework + SCCs.
  • Paddle (United Kingdom): EU adequacy decision for the UK.

For providers in the USA we also rely on the measures above: audio and text are processed transiently and not stored, and they are not used for training. You can ask us for a copy of the relevant safeguards at privacy@dragonwispr.com.

7. How long we keep data

DataKept for
Audio, transcripts and translationsNot stored by us. Processed transiently, then discarded.
Account data (email, plan, settings, subscription records)Until you delete your account.
Usage events (per-dictation metadata: seconds, mode, detected language, time)13 months. After that we keep only the monthly usage totals, until you delete your account.
Unconfirmed waitlist sign-ups30 days.
Keyed hash of your IP address on a waitlist sign-upRemoved when you confirm, or after 30 days.
Confirmed waitlist sign-upsUntil you unsubscribe, or 6 months after the public launch, whichever comes first.
Sign-in audit log (time, IP address, browser or app)90 days.
Sign-in sessions (IP address, browser or app, refresh token)Until you sign out, and at most 90 days after the session was last used.
Supabase platform logs (API and sign-in requests, incl. IP address)Up to 7 days (set by the vendor's plan).
Hosting logs (Cloudflare Workers)Up to 7 days. Our own log lines only, never request bodies.
Email delivery logs (Resend)30 days (set by the vendor).
Rate-limit counters (Upstash)48 hours at most.
Desktop diagnostic log (on your computer)Rotated at 40 KB, so only the most recent entries exist. Metadata only, never dictation text.
Support, privacy and security emails you send us24 months after the last message, unless we need them for a legal claim.
Billing recordsKept by Paddle for as long as tax and accounting law requires.

A daily job deletes data when its period ends. When you delete your account, your data is deleted straight away; encrypted database backups roll over within 7 days. We keep limited records longer only where the law requires it.

8. Your rights, and how to use them

Under the GDPR you have the right to:

  • access the personal data we hold about you and get a copy of it;
  • have inaccurate data corrected;
  • have your data deleted;
  • restrict processing, or object to processing based on legitimate interests;
  • receive your data in a portable, machine-readable format;
  • withdraw consent at any time (for example to leave the waitlist), without affecting earlier processing.

How to use them:

  • Download my data: in the desktop app’s account settings. You get a JSON file with your account, settings, subscription records, monthly totals, per-dictation metadata and any waitlist entry.
  • Delete account: in the desktop app’s account settings. This deletes your account, your subscription records, your usage data, the waitlist entry for your email address, your sign-in sessions and your sign-in audit log entries straight away. If you have a paid subscription, cancel it first (see our Refund Policy); Paddle keeps its billing records as tax law requires.
  • Leave the waitlist: open the unsubscribe link in any waitlist email and press the button (or use your email app’s own “Unsubscribe”). Your address is deleted straight away.
  • Anything else: email privacy@dragonwispr.com from the address on your account. We may ask you to confirm it is you. We reply within one month.

You also have the right to lodge a complaint with a data protection authority, in particular in the EU country where you live or work. Our lead supervisory authority is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifisias 1-3, 115 23 Athens, Greece, www.dpa.gr.

9. Cookies and similar technologies

Our website sets no cookies and stores nothing on your device, and it loads no third-party trackers or fonts. If we ever add analytics or other non-essential cookies or storage, to the website or the app, we will ask for your consent first (opt-in) and update this policy.

10. Security

Data is encrypted in transit (HTTPS). Access to our database is restricted to the server and to people who need it; IP addresses used against abuse are stored only as keyed hashes; your sign-in session on your device is stored in the operating system’s credential store. No system is perfectly secure: if a personal data breach is likely to put your rights at risk, we notify the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα) within 72 hours and tell you without undue delay when the risk is high. To report a vulnerability, see our Security policy.

11. Children

The Service is not intended for anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes to this policy

If we make material changes, for example a new provider that processes your dictations, we will tell you by email or in the app before they take effect. The date at the top shows the latest version. See also our Terms of Service, Refund Policy and Legal notice.