Security & privacy.
Dictivo is local-first, not cloud-only. This page lists the boundary: what Local keeps on the device, what Cloud Fast uploads when you choose it, and how installs and updates are protected.
Local mode keeps voice data on your device.
Local dictation runs against an on-device speech engine. Dictivo processes microphone audio locally, transcribes it on the same machine, and keeps the transcript, history, dictionary, snippets, and local model state in your profile directory.
- Audio that Local transcribes never leaves the device.
- Local transcripts never upload for storage, analytics, or model training.
- Local history and dictionary files live in your profile directory; you can delete them at any time.
Cloud Fast uploads only recordings started while it is selected.
Cloud Fast is an optional speed path and the only engine that uploads. A recording is bound to the engine it started with: a recording started while Cloud Fast is selected is sent for faster transcription, and a recording started while Local is selected, or while Cloud Fast is locked, is transcribed on this device. A recording started in Local finishes in Local; changing the selection during a recording only affects the next one.
- Used in Cloud Fast — the recording audio needed to return the transcript, its duration and language.
- Kept local — dictionary terms, snippets, local history, and local settings.
- Returned to the app — transcript text, then local cleanup runs on the desktop.
What happens to a Cloud Fast recording.
A Cloud Fast recording goes to Dictivo's relay server, which passes it to a chain of third-party speech-to-text providers and returns the transcript. Dictivo's relay does not store recordings or transcripts. Each provider processes the recording under its own terms and retention; Dictivo does not independently verify deletion at any provider. From version 0.3.51 the desktop app names the providers currently in use under Settings › Privacy › Where Cloud Fast audio goes.
Dictivo does not offer a data processing agreement. If your work requires one, use Local and lock Cloud Fast: Local transcribes on this device, and a recording it transcribes never leaves it.
Lock Cloud Fast when a stray click must not upload anything.
From version 0.3.51, Settings › Privacy has a Lock Cloud Fast switch. While it is on, Cloud Fast is greyed out everywhere: no click, link or purchase can switch recordings to it, and every recording you start is transcribed on this device. No recording started while Cloud Fast is locked is ever uploaded. A recording already in progress when you lock finishes with the engine it started with: a Cloud Fast recording that was being recorded or transcribed at that moment is still uploaded, and the next recording is Local.
Local dictation, automatic update checks and your licences are unchanged while locked. Cloud Fast licence and status checks (for example activating, refreshing or signing out a Cloud Fast licence) may still contact the Cloud Fast service, but they never send a recording. You unlock it yourself in Settings › Privacy, after the same explanation. The companion, the menu bar or tray menu and the main window all show the locked state.
What actually crosses the network.
A desktop product does need network access for licensing, updates, downloads, and optional Cloud Fast. Local mode keeps everyday dictation on your device. Every host the desktop app can contact:
| Host | When | Carries | While Cloud Fast is locked | Safe to block? |
|---|---|---|---|---|
| downloads.dictivo.app | Update manifest (/latest.json) about 5 s after launch and every 24 h; model downloads you start |
The updater component's name and version as its user agent; the installer you download is platform-specific | Unchanged | Yes; no update checks and no model downloads from this mirror (fallback: huggingface.co; offline model import exists) |
| app.dictivo.app | Trial start; the first Local trial transcription you paste or copy; usage statistics only if you opt in; purchase claims after you start a checkout, until the licence arrives; Local price and renewal information when that screen opens | Hashed device id, platform, app version, timestamps; a one-time checkout nonce (the reply carries the licence key and product family); statistics events carry operational metadata — never content | Unchanged | Yes; paste the licence key manually after buying |
| api.dictivo.app | Only Cloud Fast: entitlement, session, transcription, device sign-out. Versions before 0.3.51 also use it for trial reports, statistics and purchase claims | The recording, its duration, language, audio format and the output style you chose; session and device identifiers (licence key, instance id, device id and label, platform, app version) | Recordings started while locked are not uploaded. A Cloud Fast recording already in progress when you lock finishes as Cloud Fast, and Cloud Fast licence or status checks may still contact this service. | Yes, if you never use Cloud Fast |
| Licence service (third-party merchant; hostname in Settings › Privacy › Connections) | When you activate, refresh or remove a licence; once after a reinstall restores a licence | Licence key, machine name | Unchanged | Except during activation |
| huggingface.co (model mirror fallback) | Only if downloads.dictivo.app fails | A plain download request; no Dictivo licence or installation id is added | Unchanged | Yes |
| Run check (Settings › Account & Billing) | Only when you click it: probes the update host, app.dictivo.app, the Cloud Fast service and the licence service | Nothing beyond the probe requests | Unchanged | — |
Links you click in the app — checkout, billing, the website — open in your browser and are not app connections.
- Usage statistics — off by default. Only if you turn on “Share usage statistics” in Settings (“Share anonymous usage statistics” before 0.3.51) does the app send metadata-only events (which step of setup was reached, whether microphone access was granted, dictation duration and word count), each with a hashed device identifier that does not name you. No audio, no transcript text, no file or app names. You can turn it off again at any time.
- Trial milestones — independent of the usage-statistics setting, the Local trial reports its start and the first Local transcript successfully copied or pasted to app.dictivo.app (api.dictivo.app in versions before 0.3.51). Reports contain a hashed device identifier, platform, app version, trial-start time and a capability flag; the success report adds its time. Failed deliveries may retry. Neither report contains audio or transcript text.
That table is the whole desktop network surface. Dictivo does not use third-party ads, third-party analytics, or hidden tracking in the desktop app. The only request that carries your audio is a Cloud Fast transcription, and no request carries your transcript text. If you want to check it yourself, run the Local mode network test.
Verifiable downloads, signed where the platform allows it.
Every public desktop release is prepared for platform security checks before it reaches customers.
- Mac installer — built for Apple Silicon and Intel Macs, Developer ID signed and notarized by Apple.
- Windows installer — NSIS and MSI builds for Windows 11 x64, publicly available. Not yet Authenticode-signed, so SmartScreen may show an unknown-publisher notice; verify the SHA-256 checksums published in downloads.json.
- Official downloads — available from the Dictivo website.
Updates verify themselves before they install.
Dictivo verifies app updates before replacing the running app, so update checks stay quiet and deliberate.
Tell us before you tell the internet.
If you think you've found a security issue in Dictivo, the desktop installers, or anything on dictivo.app, please email security@dictivo.app with reproduction steps. We aim to acknowledge within two business days and to ship a fix or mitigation as quickly as the severity warrants.
Last reviewed .