Legal

Privacy Policy

Last updated: 26 August 2026

Blurt is a macOS menu-bar dictation app. You hold a push-to-talk key (Right Option by default), speak, and Blurt transcribes your voice, lightly formats the text, and types it into your active app. Where your audio is processed depends on which mode you use. This policy explains each one, what is stored, and who we share data with. It is written to match what the software actually does — please read the mode that applies to you.

1. Who we are

"Blurt", "we", and "us" refers to the maker of the Blurt app. The controller within the meaning of Art. 4(7) GDPR — the same person named in our Impressum — is:

Ivan Chabanenko
Lutherstraße 12
39112 Magdeburg
Deutschland / Germany
Email: support-blurt@chbnk.one

Blurt is run by an individual (Einzelunternehmen) and is not required to appoint a data protection officer. For dictation done entirely on your Mac (the default on Apple Silicon), Blurt does not receive your audio or text, and you control the data on your device. For the managed Cloud plan, where audio passes through our server, Blurt is the data controller for that processing and the providers listed below act as our processors under Art. 28 GDPR.

2. The two modes — and where your voice goes

Blurt can transcribe your speech in two different ways. The mode in effect depends on your Mac and your settings.

2a. On-device (default on Apple Silicon)

On Apple Silicon Macs, Blurt transcribes and cleans up your dictation entirely on your Mac by default, using an on-device speech-to-text model (WhisperKit or Parakeet) and a local language model for formatting. In this mode your audio and text never leave your Mac and no Blurt server or third party is involved in transcription. The models are downloaded once, on demand, to your Application Support folder.

2b. Managed Cloud (Blurt Pro, and the cloud option on Intel Macs)

With the paid Cloud plan — and on Intel Macs, which cannot run the on-device models, this is the only cloud option — Blurt handles transcription for you using our own keys. In this mode your audio is uploaded over TLS to Blurt's backend at api.blurt.me, which relays it to a third-party speech-to-text provider using Blurt's server-held keys. Which provider that is depends on the model you pick in the app:

The provider returns a transcript, which our backend returns to your Mac. Our backend relays the audio and does not store the audio file after the request completes. However, on this plan your audio and the resulting transcript do pass through Blurt's server and the third-party provider named above. We do not use your audio or transcripts to train any model, we do not authorise our providers to do so either, and we do not sell them. This plan requires an account (see Accounts & stored data).

On the Cloud plan, the resulting transcript text is then sent over TLS to a language-model provider to clean up filler words and punctuation, apply your chosen writing style, carry out spoken edit commands, and — if you use the Translate feature — translate it. That provider receives the transcript text only, not your audio, and returns the polished text to your Mac:

In on-device mode this formatting is done locally and none of these providers is involved.

3. Processors we use

Depending on the mode and features you use, we rely on the following providers to deliver the service. Legally they are processors acting on our instructions under Art. 28 GDPR — Blurt is the controller, and none of them decides on its own what to do with your data. We share only what each one needs for its function. We do not authorise any of them to use your content to train their models, and we do not sell your data.

The full table — what each provider receives, where it is located, and the transfer mechanism — is on our list of processors, which also carries the date of the last change and our promise to announce new providers normally 30 days in advance — and, where a failure or a security problem forces a faster swap, to update the list without delay and say why.

4. International transfers

Our servers and database are in Germany (Hetzner). Most of the processors listed above are, however, established in the United States and process the data they receive there or in other countries outside the European Economic Area. That means your dictation audio or transcript leaves the EEA whenever you use the managed Cloud plan.

For each such transfer we rely on one of the two mechanisms the GDPR provides:

The United States does not offer a level of protection identical to the EEA: in particular, US authorities may have access rights that have no equivalent under EU law, and the enforcement routes available to you differ. We tell you this plainly rather than burying it. If you would rather no data left your Mac at all, use on-device mode — the default on Apple Silicon — in which none of this applies.

Which mechanism applies to a specific provider, and a copy of the clauses where we are allowed to share them, is available on request: email support-blurt@chbnk.one and we will answer in writing.

5. On-device dictation history

By default, Blurt keeps a history of your dictations on your Mac so you can review and re-copy past results. This history is stored locally on your device (using SwiftData, under ~/Library/Application Support). It holds up to the most recent 1,000 entries, and each entry includes the raw transcript, the cleaned-up text, the name of the app you dictated into, and a timestamp.

This history is stored unencrypted on your Mac and persists after you quit Blurt until it is cleared or rolls over past 1,000 entries. It stays on your device — Blurt does not upload your history. Because dictation can include sensitive content, you can control it:

6. Accounts & stored data

You only need an account if you sign in or subscribe to the paid Cloud plan. On-device dictation does not require an account. When you do create one, our backend (a PostgreSQL database, hosted in Germany) stores the following, depending on how you sign up and use the service:

We include no third-party analytics, tracking or crash-reporting SDKs in the app or on this website — no Google Analytics, no Firebase, no Sentry, no advertising or attribution kit, and this website loads no third-party resources at all. Blurt does have its own usage analytics: it is off unless you switch it on, it contains no text and no audio, it never reaches anyone but us, and it is described in full in Section 7.

6a. Connection metadata

When your app or browser connects to our backend, we process standard connection metadata — your IP address and User-Agent — server-side to operate the service securely and to prevent fraud and abuse (for example, rate-limiting). The website's static pages are served without request logging by our web server.

6b. Lawful basis (GDPR)

Where GDPR applies, we rely on:

We do not rely on consent for dictation. The macOS microphone permission is a system permission granted to the app on your own Mac — it is not a GDPR consent, and withdrawing it stops the app from recording rather than changing our legal basis. Where we ever do ask for consent for something optional, you may withdraw it at any time with effect for the future (Art. 7(3) GDPR), without affecting the lawfulness of what happened before.

6c. Is providing data required?

Providing an email address is a contractual requirement for an account and for the paid Cloud plan: without it we cannot create the account, bill you, or send you the statutory contract confirmation. You are under no obligation to provide it — the consequence of not doing so is simply that the paid Cloud plan is unavailable to you. On-device dictation on Apple Silicon needs no account and no data at all.

6d. No automated decision-making

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. The AI models Blurt uses transcribe and tidy your words; they do not evaluate, score or decide anything about you.

6e. Retention

7. Usage analytics — optional, and off unless you switch it on

Blurt can send us anonymous counts of how the app is used, so that we can see which features earn their place and where dictation is failing people. It is off until you say yes. We ask once, in the app; if you say no, we do not ask again, and nothing about Blurt behaves differently either way.

7a. Exactly what is sent

Counters, drawn from a fixed list. Every event name, every property and every property value is a token from that list, and our server refuses anything that is not on it — so there is no field in which a sentence could be stored even by mistake. The complete list is:

Each batch also carries: a random identifier this install generated for itself (see 7c), your app build number, macOS as major.minor only — never the patch level, your interface language, your plan tier (free / trial / Pro) and your Mac's processor architecture.

7b. What is never sent

Nothing you dictate. No audio, no transcript, no cleaned-up text; no personal word rules; no Workspace document titles or contents; no names of the apps or windows you dictate into; no file names; no microphone name; not even which keys you use for push-to-talk (only that you changed them).

No email address, no name, no account identifier. These events are not linked to your account: the requests carry no login token at all, and the table they land in has no column that could hold one. Your IP address reaches our server because every internet connection does — it is used to rate-limit the endpoint and is never written down with these events.

7c. The identifier

A random UUID the app generates on your Mac at the moment you switch analytics on. It is not your account identifier, not your Mac's hardware identifier (the one behind the one-per-Mac free trial), and not derived from either. Switching analytics off destroys it; switching it back on later creates a brand-new one, so it cannot follow you across a change of mind.

7d. Lawful basis, and how to withdraw

Consent — Art. 6(1)(a) GDPR, together with § 25 Abs. 1 TDDDG for storing that identifier on your own device. Nothing is collected before you agree. You may withdraw at any time with effect for the future (Art. 7(3) GDPR) in Settings › Data & Privacy › Usage analytics — the same one click it took to give, which is what the law asks of us and what we would want anyway.

Withdrawing also deletes what was already sent: the app asks our server to erase everything recorded under that identifier, then destroys the identifier. The same action is available on its own, as Erase sent data, if you want the record removed but would like to keep helping.

7e. Where it goes, and how long it is kept

To our own backend in Germany — the same server and the same PostgreSQL database as the rest of the service. There is no third party in this at all: no Google Analytics, no Firebase, no Sentry, no Amplitude, no advertising or attribution SDK of any kind. This feature adds nobody to our list of processors.

Individual events are deleted automatically 90 days after we receive them. Before they go, each day is folded into a plain daily total — how many times each event happened that day, and how many installs were seen — which carries no identifier of any kind and is kept as an anonymous statistic.

8. Your rights

Subject to applicable law (including GDPR and CCPA), you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). For data held in your account, you can:

Where GDPR applies you also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). For us that is the Landesbeauftragte für den Datenschutz Sachsen-Anhalt, Otto-von-Guericke-Straße 34a, 39104 Magdeburg, Germany (datenschutz.sachsen-anhalt.de) — but you may complain to the authority in your own country of residence instead.

We do not sell or "share" personal information as those terms are defined under US state privacy laws. To exercise any right, use the in-app controls or email support-blurt@chbnk.one. We answer within one month (Art. 12(3) GDPR).

9. Permissions and why

Blurt does not read your screen contents, does not log keystrokes, and does not monitor your typing.

10. A note on sensitive content

Because Blurt inserts whatever you dictate, transcribed text may briefly pass through the macOS clipboard during insertion, is saved to your on-device history unless you turn that off, and — outside on-device mode — is sent to a third-party API for processing. If you are using the managed Cloud plan, avoid dictating passwords or other secrets you do not want transmitted to a third party. For maximum privacy, use on-device mode (default on Apple Silicon) and enable Privacy Mode to skip history.

11. Children

Blurt is not directed to children. You must be at least 16 years old to create a Blurt account or to use the managed Cloud plan (Art. 8 GDPR; Germany has not lowered that age). Separately, under §§ 106 ff. BGB a person under 18 needs their parent's or guardian's agreement to enter into a paid subscription. If we learn that we hold data of a child under 16 without the required authorisation, we delete it.

12. Security

All transmission to our backend and its processors uses TLS. Passwords are stored only as scrypt hashes; refresh tokens are stored only as hashes; the backend and database run in Germany. The full description of our technical and organisational measures is on our security page, and it is also the annex to our data processing agreement for business customers.

13. Changes

The current version of this policy is always available at blurt.me/privacy.html. If we make material changes, we will update the date above. New processors are announced on the processor list normally 30 days before they start receiving data; where an outage or a security problem forces a faster change, the list is updated without delay, with the reason.

14. Contact

Questions about privacy? Email support-blurt@chbnk.one.