Privacy Policy
Last updated: 26 August 2026
Blurt is a macOS menu-bar dictation app. You hold a push-to-talk key (Right Option by default), speak, and Blurt transcribes your voice, lightly formats the text, and types it into your active app. Where your audio is processed depends on which mode you use. This policy explains each one, what is stored, and who we share data with. It is written to match what the software actually does — please read the mode that applies to you.
1. Who we are
"Blurt", "we", and "us" refers to the maker of the Blurt app. The controller within the meaning of Art. 4(7) GDPR — the same person named in our Impressum — is:
Ivan Chabanenko
Lutherstraße 12
39112 Magdeburg
Deutschland / Germany
Email: support-blurt@chbnk.one
Blurt is run by an individual (Einzelunternehmen) and is not required to appoint a data protection officer. For dictation done entirely on your Mac (the default on Apple Silicon), Blurt does not receive your audio or text, and you control the data on your device. For the managed Cloud plan, where audio passes through our server, Blurt is the data controller for that processing and the providers listed below act as our processors under Art. 28 GDPR.
2. The two modes — and where your voice goes
Blurt can transcribe your speech in two different ways. The mode in effect depends on your Mac and your settings.
2a. On-device (default on Apple Silicon)
On Apple Silicon Macs, Blurt transcribes and cleans up your dictation entirely on your Mac by default, using an on-device speech-to-text model (WhisperKit or Parakeet) and a local language model for formatting. In this mode your audio and text never leave your Mac and no Blurt server or third party is involved in transcription. The models are downloaded once, on demand, to your Application Support folder.
2b. Managed Cloud (Blurt Pro, and the cloud option on Intel Macs)
With the paid Cloud plan — and on Intel Macs, which cannot run the on-device models, this is the only cloud option — Blurt handles transcription for you using our own keys. In this mode your audio is uploaded over TLS to Blurt's backend at api.blurt.me, which relays it to a third-party speech-to-text provider using Blurt's server-held keys. Which provider that is depends on the model you pick in the app:
- Live (streaming) speech, the words that appear in the pill while you hold the key — Soniox (
stt-rt-v5, the default) or ElevenLabs (scribe_v2_realtime). Both receive your voice as it is spoken. - Batch speech, the recording sent after you release the key — Groq (
whisper-large-v3-turbo, the default) or OpenAI (gpt-4o-mini-transcribe,whisper-1).
The provider returns a transcript, which our backend returns to your Mac. Our backend relays the audio and does not store the audio file after the request completes. However, on this plan your audio and the resulting transcript do pass through Blurt's server and the third-party provider named above. We do not use your audio or transcripts to train any model, we do not authorise our providers to do so either, and we do not sell them. This plan requires an account (see Accounts & stored data).
On the Cloud plan, the resulting transcript text is then sent over TLS to a language-model provider to clean up filler words and punctuation, apply your chosen writing style, carry out spoken edit commands, and — if you use the Translate feature — translate it. That provider receives the transcript text only, not your audio, and returns the polished text to your Mac:
- OpenRouter serves the default clean-up model (
openai/gpt-oss-120b). OpenRouter is a router, not the machine that runs the model: it forwards the request to one of a fixed list of hosts we allow — Baseten and Nebius — and never outside that list. Your transcript therefore reaches OpenRouter and the host that serves it. - OpenAI serves
gpt-4o-miniand is the fallback for any model not listed above.
In on-device mode this formatting is done locally and none of these providers is involved.
3. Processors we use
Depending on the mode and features you use, we rely on the following providers to deliver the service. Legally they are processors acting on our instructions under Art. 28 GDPR — Blurt is the controller, and none of them decides on its own what to do with your data. We share only what each one needs for its function. We do not authorise any of them to use your content to train their models, and we do not sell your data.
The full table — what each provider receives, where it is located, and the transfer mechanism — is on our list of processors, which also carries the date of the last change and our promise to announce new providers normally 30 days in advance — and, where a failure or a security problem forces a faster swap, to update the list without delay and say why.
- Soniox — real-time streaming speech-to-text on the managed Cloud plan (2b), and the default for the live row of words. Receives your voice audio and returns an incremental transcript. Not used for on-device dictation. Privacy policy.
- ElevenLabs — the second real-time streaming speech-to-text provider on the managed Cloud plan (2b), used when you select that model in the app. Receives your voice audio and returns an incremental transcript. Not used for on-device dictation. Privacy policy.
- Groq — the default batch speech-to-text provider on the managed Cloud plan (2b). Receives your voice audio (relayed by our backend) and returns a transcript. Not used for on-device dictation. Privacy policy.
- OpenAI — batch speech-to-text and text clean-up. Receives your voice audio and/or transcript text when you pick an OpenAI model on the managed Cloud plan (2b), or as the fallback clean-up provider. Privacy policy · API terms & data usage.
- OpenRouter — routes the default clean-up model on the managed Cloud plan (2b). Receives your transcript text (not audio) and forwards it to one of the hosts we allow. Privacy policy.
- Baseten and Nebius — the only two hosts OpenRouter may forward the default clean-up request to. Each receives your transcript text (not audio) when it serves the request. Baseten privacy · Nebius privacy.
- DeepInfra — a former text clean-up provider, withdrawn on 23 August 2026. It serves no model and receives nothing. It is still named here, rather than quietly deleted, because it did receive transcript text before that date. Privacy policy.
- Cerebras — a standby text clean-up host. It is configured in our backend but currently serves no model and receives nothing; it is named here so that re-enabling it is not a surprise. If it is ever switched on it would receive transcript text (not audio), and we would announce it on the processor list first. Privacy policy.
- Hetzner Online GmbH — hosts our backend and database, in a data centre in Germany. Processes everything our backend processes, as our infrastructure provider. Privacy policy.
- Stripe — processes payments and manages billing for the paid plan. Receives your email address, payment card details, and billing address; it does not receive your audio or transcripts. Privacy policy.
- Resend — sends transactional email (email verification, password reset, the subscription confirmation, support messages). Receives your email address and the contents of those messages; it does not receive your audio or transcripts. Privacy policy.
- Apple and Google — only if you choose to sign in with "Sign in with Apple" or Google. The provider you pick handles the sign-in and returns a basic identifier and email to us. Here they are independent controllers for their own sign-in service, not our processors. Apple privacy · Google privacy.
4. International transfers
Our servers and database are in Germany (Hetzner). Most of the processors listed above are, however, established in the United States and process the data they receive there or in other countries outside the European Economic Area. That means your dictation audio or transcript leaves the EEA whenever you use the managed Cloud plan.
For each such transfer we rely on one of the two mechanisms the GDPR provides:
- Art. 45 GDPR — adequacy. Where the provider is certified under the EU–US Data Privacy Framework, the transfer is covered by the European Commission's adequacy decision of 10 July 2023. You can check any company's current certification in the official DPF list.
- Art. 46(2)(c) GDPR — Standard Contractual Clauses. Otherwise we rely on the Standard Contractual Clauses in the version adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), as contained in that provider's data processing terms, together with the supplementary measures described on our security page (transport encryption end to end, no storage of audio on our side, no training use).
The United States does not offer a level of protection identical to the EEA: in particular, US authorities may have access rights that have no equivalent under EU law, and the enforcement routes available to you differ. We tell you this plainly rather than burying it. If you would rather no data left your Mac at all, use on-device mode — the default on Apple Silicon — in which none of this applies.
Which mechanism applies to a specific provider, and a copy of the clauses where we are allowed to share them, is available on request: email support-blurt@chbnk.one and we will answer in writing.
5. On-device dictation history
By default, Blurt keeps a history of your dictations on your Mac so you can review and re-copy past results. This history is stored locally on your device (using SwiftData, under ~/Library/Application Support). It holds up to the most recent 1,000 entries, and each entry includes the raw transcript, the cleaned-up text, the name of the app you dictated into, and a timestamp.
This history is stored unencrypted on your Mac and persists after you quit Blurt until it is cleared or rolls over past 1,000 entries. It stays on your device — Blurt does not upload your history. Because dictation can include sensitive content, you can control it:
- Turn it off: enable Privacy Mode in Blurt to stop new dictations from being saved to history.
- Clear it: clear the stored history from within the app at any time.
6. Accounts & stored data
You only need an account if you sign in or subscribe to the paid Cloud plan. On-device dictation does not require an account. When you do create one, our backend (a PostgreSQL database, hosted in Germany) stores the following, depending on how you sign up and use the service:
- Account details: your email address and name.
- Authentication: if you use email/password, a scrypt hash of your password (never the password itself); if you use Google or Apple, the OAuth provider, the subject identifier they assign you, and the email they return.
- Sessions & devices: hashes of your refresh tokens together with the device User-Agent, so you can stay signed in across devices and we can detect token misuse.
- Usage: monthly word counters, used to operate and meter the service and to enforce the fair-use ceiling described in our Terms. The counters hold numbers only — never the text you dictated.
- Subscription: the Stripe subscription and customer identifiers, plan, status and period end. Card numbers are held by Stripe, never by us.
- Email/security tokens: short-lived tokens for email verification and password reset.
- Free-trial device marker: a salted hash of your Mac's hardware identifier, so a single machine cannot start the free trial repeatedly. The raw identifier is never stored, and the hash cannot be turned back into it.
We include no third-party analytics, tracking or crash-reporting SDKs in the app or on this website — no Google Analytics, no Firebase, no Sentry, no advertising or attribution kit, and this website loads no third-party resources at all. Blurt does have its own usage analytics: it is off unless you switch it on, it contains no text and no audio, it never reaches anyone but us, and it is described in full in Section 7.
6a. Connection metadata
When your app or browser connects to our backend, we process standard connection metadata — your IP address and User-Agent — server-side to operate the service securely and to prevent fraud and abuse (for example, rate-limiting). The website's static pages are served without request logging by our web server.
6b. Lawful basis (GDPR)
Where GDPR applies, we rely on:
- Art. 6(1)(b) — performance of a contract. Your account, the paid Cloud plan, and the dictation itself: relaying your audio to a speech provider and your transcript to a clean-up provider is the service you asked for. This is the basis for the core function, not consent.
- Art. 6(1)(f) — legitimate interests. Connection metadata, rate limiting, the free-trial device marker and other abuse and fraud defence — our interest being to keep a small service affordable and available to the people paying for it.
- Art. 6(1)(c) — legal obligation. Billing and invoice records, which German tax and commercial law requires us to retain (§ 147 AO, § 257 HGB).
- Art. 6(1)(a) — consent. The optional usage analytics, and nothing else. See Section 7d, which also explains how to withdraw it and what withdrawing deletes.
We do not rely on consent for dictation. The macOS microphone permission is a system permission granted to the app on your own Mac — it is not a GDPR consent, and withdrawing it stops the app from recording rather than changing our legal basis. Where we ever do ask for consent for something optional, you may withdraw it at any time with effect for the future (Art. 7(3) GDPR), without affecting the lawfulness of what happened before.
6c. Is providing data required?
Providing an email address is a contractual requirement for an account and for the paid Cloud plan: without it we cannot create the account, bill you, or send you the statutory contract confirmation. You are under no obligation to provide it — the consequence of not doing so is simply that the paid Cloud plan is unavailable to you. On-device dictation on Apple Silicon needs no account and no data at all.
6d. No automated decision-making
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. The AI models Blurt uses transcribe and tidy your words; they do not evaluate, score or decide anything about you.
6e. Retention
- Account data (email, name, authentication, usage counters) is kept while your account is active, and is deleted when you delete your account (see your rights below).
- Refresh-token records are retained for the life of the session and removed on logout, rotation, or expiry.
- Email/security tokens are short-lived and expire automatically.
- Audio on the managed Cloud plan is relayed in-flight and is not stored by our backend after the request completes.
- Connection metadata (IP, User-Agent) in server logs is not archived. It exists as a rolling, size-bounded buffer used to diagnose faults and defend against abuse, and it is overwritten automatically as new requests arrive. It is never exported, never combined with dictation content, and never used to build a profile.
- Support tickets and the messages in them are kept while the request is open and afterwards as a record of what was asked and answered — at the latest until three years after the last message on the ticket, matching the regular limitation period (§ 195, § 199 BGB), then deleted. If you delete your account earlier, the ticket is depersonalised: the link to your account is removed and only the reply address on the request itself remains.
- Billing and invoice records are kept for 10 years where German tax and commercial law requires it (§ 147 AO, § 257 HGB). This obligation survives account deletion — it is the one thing we cannot delete on request.
- The free-trial device marker (a salted hash, never the raw identifier) deliberately outlives account deletion, so that deleting an account does not reset the one-per-Mac free trial.
- Usage analytics, if you switched it on: individual events for 90 days from receipt, then deleted automatically; afterwards only an anonymous daily total remains, which contains no identifier. Switching analytics off deletes what was already sent — see Section 7e.
- On-device history is controlled entirely by you on your Mac, as described in Section 5.
7. Usage analytics — optional, and off unless you switch it on
Blurt can send us anonymous counts of how the app is used, so that we can see which features earn their place and where dictation is failing people. It is off until you say yes. We ask once, in the app; if you say no, we do not ask again, and nothing about Blurt behaves differently either way.
7a. Exactly what is sent
Counters, drawn from a fixed list. Every event name, every property and every property value is a token from that list, and our server refuses anything that is not on it — so there is no field in which a sentence could be stored even by mistake. The complete list is:
- that the app was opened, how (by hand or at login), and how old this install is as a band — "1–6 days", "7–29 days" and so on;
- which step of the first-run tutorial you reached, and whether you finished it or skipped out;
- that a dictation finished or failed, with: on-device or cloud, push-to-talk or Workspace, your clean-up level and tone, whether translation is on, the spoken language, and the length as a band ("10–24 words", "10–29 seconds") — never the exact figure;
- which screens you open, and which settings you change — the setting and the value it was set to, both as tokens;
- whether you met the subscription wall, where, and whether you went on to open checkout;
- whether an on-device model download started, finished, failed or was deleted;
- that one of six features was used at all: word rules, voice editing, hands-free, a Workspace document, the support form, or starting an update.
Each batch also carries: a random identifier this install generated for itself (see 7c), your app build number, macOS as major.minor only — never the patch level, your interface language, your plan tier (free / trial / Pro) and your Mac's processor architecture.
7b. What is never sent
Nothing you dictate. No audio, no transcript, no cleaned-up text; no personal word rules; no Workspace document titles or contents; no names of the apps or windows you dictate into; no file names; no microphone name; not even which keys you use for push-to-talk (only that you changed them).
No email address, no name, no account identifier. These events are not linked to your account: the requests carry no login token at all, and the table they land in has no column that could hold one. Your IP address reaches our server because every internet connection does — it is used to rate-limit the endpoint and is never written down with these events.
7c. The identifier
A random UUID the app generates on your Mac at the moment you switch analytics on. It is not your account identifier, not your Mac's hardware identifier (the one behind the one-per-Mac free trial), and not derived from either. Switching analytics off destroys it; switching it back on later creates a brand-new one, so it cannot follow you across a change of mind.
7d. Lawful basis, and how to withdraw
Consent — Art. 6(1)(a) GDPR, together with § 25 Abs. 1 TDDDG for storing that identifier on your own device. Nothing is collected before you agree. You may withdraw at any time with effect for the future (Art. 7(3) GDPR) in Settings › Data & Privacy › Usage analytics — the same one click it took to give, which is what the law asks of us and what we would want anyway.
Withdrawing also deletes what was already sent: the app asks our server to erase everything recorded under that identifier, then destroys the identifier. The same action is available on its own, as Erase sent data, if you want the record removed but would like to keep helping.
7e. Where it goes, and how long it is kept
To our own backend in Germany — the same server and the same PostgreSQL database as the rest of the service. There is no third party in this at all: no Google Analytics, no Firebase, no Sentry, no Amplitude, no advertising or attribution SDK of any kind. This feature adds nobody to our list of processors.
Individual events are deleted automatically 90 days after we receive them. Before they go, each day is folded into a plain daily total — how many times each event happened that day, and how many installs were seen — which carries no identifier of any kind and is kept as an anonymous statistic.
8. Your rights
Subject to applicable law (including GDPR and CCPA), you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). For data held in your account, you can:
- Export your data — request a copy of your account data from within the app, or by emailing us.
- Delete your account — delete your account and its associated data from within the app, or by emailing us; this removes your account record and the data linked to it, and cancels related subscription entitlements. Records we must keep by law (see Retention) are retained and blocked from further use.
- Erase your usage analytics — Settings › Data & Privacy › Erase sent data, which removes everything recorded under this install's identifier. It works whether or not you have an account, because these events were never attached to one; deleting your account does it too.
Where GDPR applies you also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). For us that is the Landesbeauftragte für den Datenschutz Sachsen-Anhalt, Otto-von-Guericke-Straße 34a, 39104 Magdeburg, Germany (datenschutz.sachsen-anhalt.de) — but you may complain to the authority in your own country of residence instead.
We do not sell or "share" personal information as those terms are defined under US state privacy laws. To exercise any right, use the in-app controls or email support-blurt@chbnk.one. We answer within one month (Art. 12(3) GDPR).
9. Permissions and why
- Microphone — to record your voice while you hold the key. There is no always-on listening and no wake word.
- Input Monitoring — to detect the push-to-talk key being held. Blurt uses a listen-only tap and does not capture or log your other keystrokes.
- Accessibility — to insert the transcribed text into other apps.
Blurt does not read your screen contents, does not log keystrokes, and does not monitor your typing.
10. A note on sensitive content
Because Blurt inserts whatever you dictate, transcribed text may briefly pass through the macOS clipboard during insertion, is saved to your on-device history unless you turn that off, and — outside on-device mode — is sent to a third-party API for processing. If you are using the managed Cloud plan, avoid dictating passwords or other secrets you do not want transmitted to a third party. For maximum privacy, use on-device mode (default on Apple Silicon) and enable Privacy Mode to skip history.
11. Children
Blurt is not directed to children. You must be at least 16 years old to create a Blurt account or to use the managed Cloud plan (Art. 8 GDPR; Germany has not lowered that age). Separately, under §§ 106 ff. BGB a person under 18 needs their parent's or guardian's agreement to enter into a paid subscription. If we learn that we hold data of a child under 16 without the required authorisation, we delete it.
12. Security
All transmission to our backend and its processors uses TLS. Passwords are stored only as scrypt hashes; refresh tokens are stored only as hashes; the backend and database run in Germany. The full description of our technical and organisational measures is on our security page, and it is also the annex to our data processing agreement for business customers.
13. Changes
The current version of this policy is always available at blurt.me/privacy.html. If we make material changes, we will update the date above. New processors are announced on the processor list normally 30 days before they start receiving data; where an outage or a security problem forces a faster change, the list is updated without delay, with the reason.
14. Contact
Questions about privacy? Email support-blurt@chbnk.one.