Legal

Security

Technical and organisational measures under Art. 32 GDPR · Last updated: 23 August 2026

This page describes what actually protects your data. It doubles as Annex II to our data processing agreement, so a business customer's procurement questionnaire and a curious individual user get the same answers.

What we do not claim. Blurt is run by one person. We hold no SOC 2 report, no ISO 27001 certificate and no third-party penetration test. Saying otherwise would be easy and false. What follows is the concrete list of measures that are in place — judge it on that.

The strongest measure is architectural

On Apple Silicon, Blurt transcribes and cleans up on your Mac by default. In that mode there is no upload, no server, no provider and no account — the safest data is the data that never travels. Everything below concerns the optional managed Cloud plan.

Where your data lives

In transit

Credentials and sessions

The running system

Backups and recovery

Data minimisation

Supplementary measures for transfers

For the providers outside the EEA listed on our processor page, the measures above are what supplements the contractual transfer mechanism: encryption in transit end to end, no audio at rest anywhere in our control, minimum necessary content per request (a provider receives the audio or the text, never your account, your history or your other dictations), and no training use.

Organisational measures

Reporting a vulnerability

If you find a security problem in Blurt, the backend or this website, please tell us at support-blurt@chbnk.one with "security" in the subject. We will confirm receipt within 72 hours and keep you updated until it is closed.

We will not take legal action against anyone who reports a problem in good faith, keeps it confidential until we have fixed it, and does not access, modify or delete other people's data while investigating. Please avoid denial-of-service testing and automated scanning of the production service — one small server serves everyone.

Related

See our Privacy Policy, the list of processors, the data processing agreement and the Terms of Use.