What stays on your device
Privacy
The short version: speech is turned into text on your computer, your audio never reaches us, and our servers hold only your email, your plan, and your word counts.
Last updated: August 22, 2026
Who we are and what this covers
Blurt is made by SDEREKS, LLC, a Texas limited liability company in Austin, Texas ("Blurt", "we"). This policy covers every Blurt client: the Mac app, the Windows app, the Blurt browser extension, and justblurt.com, including the /start setup wizard, the /connect sign-in page, and the /license checkout. Speech recognition works differently depending on which client you use, so please read the next section.
Where speech recognition happens
Mac and Windows apps: speech-to-text runs on your computer, using an on-device speech engine. Your audio is processed in memory and discarded. It is never written to disk and never sent to Blurt or anyone else.
Browser extension: your audio is processed by your browser's speech service, not on-device. The extension uses the browser's built-in speech recognition (the Web Speech API). In Chrome that means your audio is sent to Google's speech recognition service to produce the transcript, under Google's terms, not Blurt's. Blurt never receives or stores that audio. Schools that need audio to stay on the device should use the Mac or Windows app.
On every platform, Blurt's own servers never receive or store your audio, and we do not create voiceprints or any other biometric identifier.
Your account and what we store
Every Blurt client needs a Blurt account to dictate: a quick email sign-in with a one-time code, no password. Your account carries your plan, your weekly word count, and your Premium features. On our servers we store:
- Your email address and the sign-in tokens for your devices
- Your plan and subscription state, and, if you bought a license, the license code, the purchaser's email, the student or user name you entered for the receipt, the order reference, and the amount paid
- Usage counts: the number of words you dictated each week. Never the words.
- Feedback you send us from the apps or the site, with the email you attach to it
- Setup answers from the /start wizard (what you write, your preferred key) so the app can apply them
Payments are processed by Stripe; Blurt never sees your card number. We do not run analytics on the content of your dictation, we do not sell personal information, we do not run ads, and we do not build profiles of you.
AI cleanup (Premium)
AI cleanup sends the text of a dictation (never the audio) to Anthropic's Claude to be reformatted, then returns it. On desktop it is off by default. In the browser extension it is on by default for Premium users, with a visible "Polish my speech" switch in the extension popup. If cleanup is on, your custom vocabulary words go with the request so names and jargon are spelled correctly. Desktop supports bringing your own Anthropic key, stored in the macOS Keychain or Windows Credential Manager; the extension uses only Blurt's hosted cleanup. Anthropic's API terms apply to that text, and Blurt's hosted cleanup does not retain your dictation text.
Private mode and local-only
Private mode (formerly Clinical mode) is a hard lock in the Mac and Windows apps: cloud AI cleanup is unreachable, and transcripts are never written to disk. The check happens where the network call would be made, not only in the settings screen. IT departments can force it on for every user with a managed setting; see Local-only configuration. With Private mode on, the only network traffic is sign-in, the plan check, and word counts.
Who else touches your data (subprocessors)
We use these companies to run Blurt. Each one sees only what is listed. All of them store data in the United States unless noted.
| Company | What it does for Blurt | What it can see |
|---|---|---|
| Supabase | Accounts, sign-in, and the database | Email address, sign-in tokens, plan, weekly word counts, license records |
| Vercel | Hosts justblurt.com and Blurt's account service | Request metadata (IP address, time); holds our server secrets |
| Stripe | Payments and invoices | Name, email, billing details, card (never seen by Blurt) |
| Anthropic | AI cleanup (Premium only, only when on) | The dictated text during the cleanup request, plus your custom vocabulary; not used to train models under Anthropic's API terms |
| Resend | Sends our emails: sign-in codes, license codes, receipts, and the optional onboarding course | Email address and the content of those emails |
| Upstash | Rate-limit counters that protect the service | Hashed account and IP keys; no content |
| GitHub | Hosts downloads and the update feed | Public download traffic only |
| Hugging Face | Hosts the on-device speech model the Mac app (macOS 14 to 25) and the Windows app download on first run | A download request; no user data |
| Apple | On macOS 26, provides the on-device speech assets | Asset download only; no dictation audio leaves the Mac |
| Chrome's built-in speech recognition, used only by the browser extension | Your audio, to turn it into text, under Google's terms |
We sign written agreements with subprocessors that hold personal information, requiring protection no less strict than this policy. We will update this table before adding a new subprocessor.
How long we keep things
| Data | Kept for |
|---|---|
| Microphone audio | Not kept. Processed in memory on your device and discarded. (Extension: handled by your browser's speech service, not by Blurt.) |
| Transcript text | Kept only on your device, in a history you can clear, and not at all in Private mode. Blurt's servers never store it. |
| Text sent for AI cleanup | Not retained by Blurt after the cleanup response is returned |
| Account (email, plan, tokens) | Until you delete your account |
| Word counts | Weekly totals, kept with your account |
| License and purchase records | Seven years, for tax and accounting |
| Feedback you send | Until it is handled, then up to 12 months |
| Server logs | Kept briefly by our hosting provider; they contain no dictation content |
Deleting your data
Email support@justblurt.com from your account email and ask. We delete your account and everything tied to it within 60 days, usually within a few days, and confirm in writing. Purchase records we must keep for tax law are kept apart from your account. Schools and districts can request deletion for their students the same way, and we confirm in writing.
Children and schools
Blurt is a general-audience product. We do not knowingly collect personal information from children under 13 without a parent's consent. If you believe a child under 13 has an account without consent, email us and we will delete it.
When a school or district uses Blurt with students, the school may consent on the parent's behalf for educational use only, as the Federal Trade Commission's COPPA guidance for schools allows. In that case:
- We use student information only to provide Blurt to the school, never for any commercial purpose of our own. No ads, no profiling, no selling.
- We give the school a description of what we collect (the account email and word counts, and, only if the school turns on AI cleanup, the dictated text during the cleanup request), the ability to review it, and the ability to have it deleted.
- Audio: in the Mac and Windows apps audio never leaves the device and is never stored. In the Chrome extension, audio goes to Google's speech service solely to be turned into text and is not kept by Blurt. Schools that need audio to stay on the device should use the Mac or Windows app.
- Written retention policy for children's personal information: account email and word counts are kept until the school or parent asks us to delete them or the account goes unused for 24 months; dictated text and audio are not retained by Blurt at all.
- We do not place COPPA responsibility on the school; it is ours.
We sign the Texas student data privacy agreement (TX-NDPA) and equivalent state agreements on request, and we follow Texas Education Code chapter 32, subchapter D: no targeted advertising, no student profiles, no selling or renting student information, deletion within 60 days of a district's request.
Security
Data moves over HTTPS. Our database provider encrypts it at rest. Admin accounts use multi-factor sign-in, server keys are scoped to what each service needs, and app updates are signed. If a security incident affects your data we will notify you, and for a school we will notify the district within 72 hours of confirming it. Our security controls follow the NIST Cybersecurity Framework 2.0.
Custom vocabulary, sign-in codes, and what stays on your device
Your custom vocabulary list (names, jargon) is stored on your device. It is only sent off your device as part of an AI cleanup request, and only when cleanup is on.
justblurt.com/connect signs the browser extension into your account with one click. It mints a single-use, short-lived sign-in code and hands it to the extension inside your browser. Session tokens travel only over HTTPS and never in a URL.
In the extension, your settings, your signed-in session, and a short recent-dictations list (a local backup so a missed insertion never loses your words) stay in the browser's extension storage; the list can be cleared from the popup and is never sent to Blurt. On desktop, transcript history stays on your device and can be cleared in Preferences.
Your choices
- See, correct, or delete your data: email support@justblurt.com.
- Turn off AI cleanup at any time; turn on Private mode for a hard lock.
- Unsubscribe from the optional emails with the link in any of them. Sign-in codes and purchase emails are transactional and keep coming while you have an account.
- Residents of Texas, California, and other states with privacy laws have the rights those laws give them; we honor the same requests for everyone.
Changes and contact
When this policy changes we update the date at the top. For material changes we email account holders. Questions: support@justblurt.com, or write to SDEREKS, LLC, Austin, Texas.
Earlier version: July 16, 2026. This version names our legal entity, lists every subprocessor, states retention periods, and adds the 60-day deletion commitment and the school and children section.
This page describes the product's behavior and our commitments. It is not legal advice.