Wispr Flow Published What Its Users Dictate. The Default Setting Is the Real Story.
A Wispr Flow employee posted word-frequency stats from user dictations on LinkedIn. Nothing was breached — and that is exactly the problem for anyone dictating client work.

Key Takeaways
- On August 10, 2026, a Wispr Flow team member published a LinkedIn chart comparing how often users in India and the U.S. say specific words — sourced, in the credit line, to "Wispr Flow voice dictation data"
- Nothing leaked and no policy was broken. The post was only possible because retention is the default: without Privacy Mode, Wispr's own docs say audio and transcription data may be used to evaluate, train and improve its models
- Superwhisper founder Neil Chudleigh put it on X on August 11 — "openly admitting they are retaining every word their users say" — and the post cleared 190,000 views inside a day
- The fix is not a better privacy policy, it is a different architecture: if transcription happens on your machine, there is no corpus to query, publish, or subpoena
This week a marketing chart did what no security researcher managed to do: it told several hundred thousand people exactly what happens to the words they dictate.
The chart came from inside Wispr Flow. It compared how often users in India and the United States say words like “incredible,” “awesome” and “fantastic,” and the credit line underneath said the source was Wispr Flow voice dictation data. It was posted to LinkedIn as light linguistic research. It landed as a confession — and by the next morning the founder of a competing dictation app had put it in front of 190,000 people on X.
Nothing was hacked. No policy was broken. That is the part worth your attention.
What Actually Happened
On August 10, a Wispr Flow team member published a post analysing word-frequency patterns across the company's user base. The framing was friendly and academic: “We looked at which filler words and phrases show up most across Wispr Flow users in India vs the U.S.”
The chart gave India-to-US usage ratios for a list of superlatives — “incredible” at 0.3×, “awesome” 0.4×, “fantastic” and “love” at 0.5×, “amazing” and “excellent” at 0.7×. An earlier post in the same series had run the deference terms: “kindly” at 5.6×, “sir” at 2.5×, “please” at 1.3×.
To be precise about what was and was not exposed: nobody's transcript was published. These are aggregate counts. But you cannot count how often Indian users say “kindly” unless you are holding a searchable body of what your users said, tagged by country, and can run a query against it. The chart is not the leak. The chart is the receipt.
Timeline
- Aug 10The LinkedIn post goes up, crediting “Wispr Flow voice dictation data”
- Aug 11Neil Chudleigh, founder of Superwhisper, screenshots it on X: “your daily dose of linkedin gore”
- Aug 11That post passes 190,000 views, 1,000+ likes and 350+ bookmarks within a day; the reply thread fills with lawyers, clinicians and consultants
- Aug 12The story trends on X as people go looking for their own Privacy Mode toggle
Chudleigh's framing — “openly admitting they are retaining every word their users say” — is a competitor's framing, and it is sharper than the documentation strictly supports. But he did not have to dig for it. The company published the evidence itself.
The Default Setting Is the Whole Story
Wispr Flow's own Security and Compliance FAQ is unusually clear, which is to its credit. It says that without Privacy Mode — standard mode — audio and transcription data may be used to evaluate, train and improve Wispr's models, and that this is the default for trial and standard accounts. Zero data retention exists, but it is defined as a combination: Privacy Mode on and Cloud Sync off. Enterprise and HIPAA BAA customers get it by default. You, on a $15/month personal plan, do not.
So there was no violation here. An employee queried a dataset the company is contractually permitted to hold, and posted a chart. Every step was allowed.
What most users assume
Audio goes up, text comes back, the audio is discarded. Privacy is the default and the settings screen is for edge cases.
What the docs say
Retention and training are on unless you go to Settings → Data & Privacy and turn them off, then also turn off Cloud Sync.
Defaults are the actual privacy policy. Everything else is a document nobody reads. Ask yourself honestly how many of the people dictating into a tool eight hours a day have opened that menu — and then remember that this is a product whose entire pitch is that it removes friction from typing. The users least likely to go hunting through settings are precisely the ones who adopted it fastest.
Why Builders and Professionals Should Care
Dictation is not a note-taking app. It is the input layer for everything you write. Think about what actually goes through it in a week: client emails, case notes, patient summaries, investor updates, pricing you have not announced, a Slack message about someone on your team, the messy first draft of a difficult conversation.
I made this point on X yesterday and the responses came fast, because the professions map straight onto it. A lawyer dictating privileged notes. A doctor or therapist dictating anything at all about a patient. A founder dictating a term sheet reaction. Someone talking through a personal crisis into their own journal. None of those people opted into a research corpus in any meaningful sense — a checkbox they never saw did it for them.
And if you build software, the second-order lesson is the one to sit with: your defaults will eventually be read out loud by a stranger on the internet, in the least generous framing available. Wispr Flow has raised roughly $81 million and employs around 80 people. It has a security FAQ, a BAA and a compliance page. It still lost a news cycle to one marketing chart, because the chart made an abstract permission concrete.
Stay Ahead of the Trends
Get insights like this before they're everywhere. Weekly, no fluff.
A Policy You Can Toggle Off Is a Policy Someone Else Can Toggle Back On
Here is the part the discourse mostly skipped. Everyone spent this week arguing about whether Wispr Flow behaved badly. Wrong question. The right question is what class of risk you accepted the moment your speech started leaving your machine.
A retained corpus is not a single risk, it is a category. Marketing can query it. A future policy update can re-scope it. A subprocessor can inherit it. A breach can expose it. A subpoena can reach it. An acquirer can revalue it. Privacy Mode is a promise about how a company will treat data it definitively has — and promises are administered by people who change jobs, and by legal teams that update terms on 30 days' notice.
On-device processing removes the category rather than managing it. If transcription happens locally and the audio is discarded from memory when it is done, there is no corpus. No word-frequency study is possible, not because policy forbids it, but because the data does not exist anywhere a marketer, a subpoena or an attacker could reach.
That is the distinction worth internalising: trust me versus you don't have to.
Default
Privacy Mode off for trial and standard Wispr Flow accounts
2 toggles
Privacy Mode on and Cloud Sync off, to reach zero retention
190K+
Views on the competitor's screenshot within 24 hours
What To Do This Week
Four steps, in order of how much they matter.
1. If you're staying on Wispr Flow, fix the defaults now
Settings → Data & Privacy. Turn Privacy Mode on and Cloud Sync off — you need both for zero retention, one alone does not get you there. If you handle health data, ask for the BAA. Do this on every device, including mobile, and re-check it after major updates.
2. Assume everything before today is already in the corpus
Flipping a toggle today does nothing about the months you dictated before you read this. Request deletion, and if you ever dictated a credential, an API key or a password into a text field, rotate it. If you dictated something that belongs to a client under an NDA, that is worth an honest look at your obligations rather than a hope that nobody asks.
3. Ask the architecture question, not the policy question
Stop reading privacy policies as your first move and ask one thing instead: where does the transcription happen? If the answer is “our servers,” every guarantee after that is a promise. If the answer is “your machine,” most of the guarantees become unnecessary. Apply the same question to your meeting recorder, your AI notepad and your email assistant.
4. If the answer matters to your work, switch to a local-first tool
On a Mac this is a solved problem — Whisper models run well enough on Apple Silicon that cloud round-trips buy you very little. Voibe transcribes on-device on Apple Silicon so audio and text never leave the machine, and runs a zero-retention cloud mode on Windows with no stored audio and no account tied to your dictation. It is $7.50/month, $59/year or $149 once, against roughly $144 a year for Wispr Flow Pro. Superwhisper also runs local models on Mac and is the stronger pick if you need 100+ languages. Our full breakdown is in the Wispr Flow alternatives guide.
Disclosure: I build Voibe. I have an obvious interest in how this argument lands, so the claims above are the ones you can verify yourself — Wispr Flow's retention defaults come from their published Security and Compliance FAQ, linked in the sources, and Voibe's processing model is on its own site. Check both before taking my word for it.
Where This Goes Next
The likely near-term outcome is small: the post comes down, Privacy Mode gets promoted in onboarding, and the defaults quietly flip within a couple of product cycles. That is the pattern every time a defaults story trends, and it is a real improvement.
The bigger shift is on the hardware side. On-device transcription used to be the compromise option — slower, less accurate, worth it only if you were paranoid. On current Apple Silicon that gap has largely closed for English dictation, which means cloud processing is increasingly a business decision rather than a technical necessity. Once users understand that, “we process in the cloud” starts reading as “we keep the data,” whether or not that is fair.
Expect local-first to become a marketing wedge rather than a niche preference over the next year, and expect the regulated professions to move first, because they are the ones with something to lose beyond embarrassment.
The Bottom Line
- Nothing leaked: aggregate word counts were published, not transcripts — but the counts prove a queryable corpus of user speech exists
- The default did this, not a rogue employee: Privacy Mode is off unless you turn it on, and zero retention needs Cloud Sync off as well
- Ask where transcription happens before you read a single line of a privacy policy — architecture beats promises
- If your dictation touches client work, move to a local-first tool like Voibe or Superwhisper, and treat everything you have already dictated as retained
Related Reading
- Best Wispr Flow Alternatives in 2026 — Offline and privacy-first dictation apps, compared on price and processing
- 8 Best Dictation Apps for Vibe Coding in 2026 — Speed, IDE integration and where each one processes your audio
- Google Indexed Hundreds of Claude Share Links — The 10-minute AI privacy audit every founder should run
- The Enterprise Deal You Lose Before the Demo — Why privacy-by-design is a commercial decision, not a compliance one
- Anthropic Pulled Fable 5 and Mythos 5 Overnight — Why cloud AI is a platform risk and local models are the hedge
Sources
- Voibe: Wispr Flow LinkedIn dictation data analysis (original breakdown of the post)
- Neil Chudleigh (founder, Superwhisper) on X
- Ayush Chaturvedi on X: why this reads as bragging, not confessing
- Wispr Flow Help Center: Security and compliance FAQ
- Wispr Flow: Data Controls
- The Globe and Mail: How a Toronto AI startup hopes to make the keyboard obsolete
Don't Miss the Next Big Shift
Every week, we break down the trends that matter for indie hackers and SaaS founders. Stay informed, stay ahead.
Join 3,000+ founders who stay ahead of the curve
Keep Reading
Google Indexed Hundreds of Claude Share Links. Every AI Tool You Use Has the Same Button.
Google indexed hundreds of Claude share links, exposing resumes, business docs and legal questions. Here’s the 10-minute AI privacy audit every founder should run.
Anthropic Is Now the Only Frontier Lab Not Backing Open Weights. Here’s What the Standoff Means for Your Model Strategy.
Anthropic became the lone frontier lab not signing the industry open-weights letter. Here is what the open-weights standoff really means for your model strategy.
Curl Took July Off to Escape AI Slop. The Open-Source Supply Chain Is the Founder Risk No One Prices In.
curl paused all security reports for July 2026 to escape open-source AI slop. Here is why maintainer burnout is the supply-chain risk founders are not pricing in.