Whisper Flow
whisperflow.aiWispr Flow is a voice-to-text dictation and AI meeting note-taking tool aimed at general consumers and professionals. Its consumer terms are broadly user-favorable on ownership (users retain input rights and own outputs) and provide a user-controlled toggle for model training, plus a stated 30-day deletion limit for data shared with third-party LLM providers (OpenAI/Anthropic). Key risks for professional use: broad sublicensable content licenses, mandatory arbitration and class-action waiver, extensive PII collection including meeting audio and other participants' data, third-party advertising partner sharing, and compliance badges (SOC 2, HIPAA) shown as images with no audit evidence in the text. Notetaker processing of meeting audio and third-party participant data raises consent and privacy risks that fall on the user.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
Users retain ownership of the content and inputs they submit; Wispr expressly disclaims ownership. However, users grant a broad, worldwide, sublicensable license to Wispr and third parties acting on its behalf to use content for providing, improving and protecting the Services.
Output Data Ownership
Wispr assigns all of its right, title and interest in AI-generated Outputs to the user, so users own the outputs they generate. Users are cautioned that outputs may not be unique and that outputs generated from third parties' inputs are not theirs.
Training Data Usage
Wispr may use Customer Content to train its AI models, but only if the user enables the 'Improve the model for everyone' / model training setting. Meeting audio is excluded from training unless separately enabled, and Google User Data is never used for training. The default state of the toggle is not stated in the supplied text, which leaves a residual risk.
Data Retention & Deletion
The policy describes retention as needs-based rather than with specific schedules for most data, and provides deletion via email request under GDPR. Third-party LLM providers delete shared data within 30 days, and Google data is deleted within a 'commercially reasonable period' after disconnection. The absence of concrete retention periods and deletion SLAs for most Personal Data is a moderate risk.
Third-Party Data Sharing
Wispr shares data with service providers (LLM providers, cloud, analytics, payment), affiliates, and — notably — advertising partners such as LinkedIn for its own advertising. It states it does not sell data. Sharing with LLM providers is integral to the service and is limited (no training, 30-day deletion), but the disclosed advertising-partner sharing beyond core function elevates this to moderate risk.
Opt-Out Rights
Users can disable model training via a setting, opt out of the Context Awareness feature, unsubscribe from marketing, and use NAI/DAA/Google opt-out mechanisms for advertising cookies. GDPR consent withdrawal and deletion requests are available. Meaningful opt-out mechanisms are explicitly provided.
Compliance & Certifications
The privacy policy addresses GDPR rights in detail and references a California/CCPA supplemental notice, showing awareness of applicable privacy laws. SOC 2 and HIPAA are displayed only as badge images with no audit report, certificate, or trust-center reference in the text — so these are asserted claims without third-party attestation evidence. No ISO, NIST, or EU AI Act frameworks are mentioned.
Model Explainability & Auditability
The consumer documents provide no transparency into model behavior, no explainability commitments, and no enterprise auditing rights. They disclose which third-party LLMs may be used but say nothing about how outputs are produced or how the service can be audited. Silence on this topic is itself a risk.
Security Practices & Breach History
The privacy policy states general technical, administrative and physical safeguards and mentions encrypted meeting audio storage, but provides no specifics on encryption at rest/in transit, penetration testing, access controls, or incident response, and no breach history. A SOC 2 badge image appears but no trust center or security page with detail is referenced. Disclosure is thin.
Enterprise vs. Consumer Risk Delta
The consumer documents mention Paid Services and reference that an employer/customer may provide access, but do not detail material data-handling differences between free and paid consumer tiers. The most meaningful differences appear in the separate enterprise MSA/DPA, not in these consumer terms. Silence on a consumer free-vs-paid delta lowers confidence.
Human Review of User Inputs
Wispr reserves the right to review user conduct and content for compliance with the Terms, and the Context Awareness feature may collect on-screen text. The documents do not clearly state whether staff read prompts/outputs routinely, but the reserved review right combined with human corrections used for training implies possible human access.
Regulatory & Litigation Exposure
The documents address law-enforcement and legal-process cooperation and government/regulatory requests, and disclose mandatory arbitration with a class-action waiver (with a 30-day opt-out). No pending litigation or specific government-request statistics are disclosed. The arbitration/class-waiver structure is vendor-favorable for disputes.
PII & SPI Data Inventory
Wispr collects significant PII (name, email, phone, IP, device identifiers, usage data) and processes potentially sensitive content: audio inputs, meeting audio/transcripts, communications content, and data about other meeting participants, plus Gmail/Calendar/Contacts data. Payment data is handled by Stripe. Collection is disclosed with purpose limitation and opt-outs, but the breadth of communications content and third-party participant data warrants elevated caution.
Policy–Product Currency
Both consumer documents are dated 'Last Updated: August 19, 2026', roughly two weeks before the analysis date, and they explicitly address AI/LLM processing, third-party model providers (OpenAI/Anthropic), model training controls, Notetaker meeting features, and integrations — matching the product surface (voice-to-text dictation and AI note-taking). The policy demonstrably covers the shipped AI capabilities.
Cross-Document Consistency
Two consumer documents (Terms of Service and Privacy Policy) were supplied and are internally consistent on ownership, the user-controlled model-training toggle, third-party LLM 30-day deletion, and no-training-on-Google-data. No material contradictions were identified between the two documents.
You've read all 15 risk ratings for Whisper Flow. Create a free account to see the exact policy wording behind each rating.