The worry with a tool that hears you and works on your computer is that someone is reading everything and knows what each person does. Here is, in plain words, why that is not how Saywork works — and how you can check.
The microphone records only while you hold the dictation key, while a meeting you started is recording, or after the wake word — and the wake word is detected on your computer.
History, notes, meetings, the agent's memory, dictionary and settings are files on your computer. We don't have a copy.
Turning speech into text and doing a task needs an AI model. What that request needs goes through our server to the model and back. We don't store it, and we don't train on it.
Counts, timings, error codes, which step failed. Content fields are removed on your computer, and our server refuses anything that still has them.
Sharing corrected dictations to improve recognition is off unless you turn it on, stored without your name, and withdrawable.
Settings → Privacy shows what is sent right now, gives you everything in one file, and deletes your account and everything our server holds.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Cloudflare | Server, database, storage, logs | What our server stores or relays | Global; United States |
| Groq | Speech recognition, text cleanup | Audio and text per request, not stored by us | United States |
| DeepSeek | Language model for the agent and Ask | Requests per task, not stored by us | China |
| Sign-in; Google services you connect | Account; your requests | United States | |
| Resend | Address, name, message | United States | |
| Telegram | The Saywork bot, if you link it | Messages to the bot (held ≤ 24 h) | Per Telegram |
| Vercel | This website | Request logs | United States |
| Microsoft | Microsoft Store distribution and updates | Per Microsoft | Global |
We will update this list before adding a provider that processes personal information. Details and legal bases are in the privacy policy.
"Aligned with" is not "certified". We use these standards' controls and guidance to design and check how Saywork works. Saywork is not certified to any ISO standard and has no SOC 2 report: those require an independent audit by an accredited body, which is on our roadmap below. No ISO logo is used on this page because ISO does not allow its logo to suggest certification.
| Standard | What it covers | How we use it |
|---|---|---|
| ISO/IEC 27001 | Information security management | Our security controls are mapped to its Annex A themes (access, cryptography, operations, supplier relationships). |
| ISO/IEC 27701 | Privacy information management | Records of processing, data-flow map, retention schedule, rights handling. |
| ISO/IEC 42001 | AI management systems | We document what each AI feature does, its data, and its human checks (approval before sending). |
| NIST AI RMF 1.0 | Managing AI risk | Map, measure and manage: failures are counted by step and fixed through the skill library. |
| OWASP ASVS | Application security verification | Used as the checklist for our security reviews of the app and API. |
| OWASP Top 10 for LLM Applications | Risks specific to AI apps | Prompt injection, excessive agency and sensitive-information disclosure are addressed by approvals, server-side prompts and content stripping. |
| GDPR | EU data protection law | Legal bases, rights, retention and transfers are in the privacy policy; export and delete work in the app. |
| Item | Status | What it means |
|---|---|---|
| Data-flow map and retention schedule | Done | Published in the privacy policy; retention enforced in code. |
| Google OAuth app verification | In progress | Google's review of how Saywork uses Google data, including the Limited Use requirements. |
| CSA STAR Level 1 self-assessment | In preparation | A public questionnaire (CAIQ) about our security controls, listed in the Cloud Security Alliance STAR Registry. It is a self-assessment, not an audit. |
| Independent penetration test | Planned | An outside firm tests the app and API. |
| SOC 2 Type I, then Type II | Planned | An independent auditor's report on our controls at a point in time (Type I), then over a period (Type II). |
| ISO/IEC 27001 certification | Planned | Certification of our security management system by an accredited body. |
Found a vulnerability? Write to [email protected]. Please give us a reasonable time to fix it before making it public; we will not pursue good-faith research that respects people's privacy and does not disrupt the service. Privacy questions and requests: [email protected].