Trust & security

The worry with a tool that hears you and works on your computer is that someone is reading everything and knows what each person does. Here is, in plain words, why that is not how Saywork works — and how you can check.

Our practices

We don't listen all the time

The microphone records only while you hold the dictation key, while a meeting you started is recording, or after the wake word — and the wake word is detected on your computer.

Your stuff stays on your computer

History, notes, meetings, the agent's memory, dictionary and settings are files on your computer. We don't have a copy.

Processed, not kept

Turning speech into text and doing a task needs an AI model. What that request needs goes through our server to the model and back. We don't store it, and we don't train on it.

We learn what happened, not what you said

Counts, timings, error codes, which step failed. Content fields are removed on your computer, and our server refuses anything that still has them.

Opt-in means off

Sharing corrected dictations to improve recognition is off unless you turn it on, stored without your name, and withdrawable.

Export or delete, any time

Settings → Privacy shows what is sent right now, gives you everything in one file, and deletes your account and everything our server holds.

Where your data goes

Saywork data flow Your computer keeps your history, notes, meetings and memory. For each request, voice or text goes through the Saywork server to an AI provider and the result comes back; nothing is stored. Content-free usage counts go to the Saywork server. Corrected dictations go to a de-identified dataset only if you opt in. Connected services receive only the requests you make. Your computer Stays here, never synced: • dictation history • notes and reminders • meetings and recordings • the agent's memory • dictionary, snippets, settings • wake-word detection Offline: dictation runs entirely here. Content fields are removed before anything is queued. Saywork server api.getsaywork.com Relays each request to the model; counts usage. Content: not stored. Keeps: account, counts (30 days), task outcomes, encrypted service grants. Deletes on schedule, every hour. Delete everything: within the hour. AI providers Speech recognition, language model. Processed, not trained on. Services you connect Google, Slack, Notion… Only your requests pass. Speech dataset Opt-in only. No name, no account, PII removed. Withdrawable 30 days. voice / text result counts only opt-in corrections
Every arrow is in section 3 of the privacy policy, and Settings → Privacy in the app shows which ones are active on your computer right now.

Who processes data for us

ProviderPurposeDataLocation
CloudflareServer, database, storage, logsWhat our server stores or relaysGlobal; United States
GroqSpeech recognition, text cleanupAudio and text per request, not stored by usUnited States
DeepSeekLanguage model for the agent and AskRequests per task, not stored by usChina
GoogleSign-in; Google services you connectAccount; your requestsUnited States
ResendEmailAddress, name, messageUnited States
TelegramThe Saywork bot, if you link itMessages to the bot (held ≤ 24 h)Per Telegram
VercelThis websiteRequest logsUnited States
MicrosoftMicrosoft Store distribution and updatesPer MicrosoftGlobal

We will update this list before adding a provider that processes personal information. Details and legal bases are in the privacy policy.

Security controls

Standards we align with

ISO/IEC 27001aligned with ISO/IEC 27701aligned with ISO/IEC 42001aligned with NIST AI RMF 1.0aligned with OWASP ASVSaligned with OWASP Top 10 for LLM Applicationsaligned with GDPRaligned with

"Aligned with" is not "certified". We use these standards' controls and guidance to design and check how Saywork works. Saywork is not certified to any ISO standard and has no SOC 2 report: those require an independent audit by an accredited body, which is on our roadmap below. No ISO logo is used on this page because ISO does not allow its logo to suggest certification.

StandardWhat it coversHow we use it
ISO/IEC 27001Information security managementOur security controls are mapped to its Annex A themes (access, cryptography, operations, supplier relationships).
ISO/IEC 27701Privacy information managementRecords of processing, data-flow map, retention schedule, rights handling.
ISO/IEC 42001AI management systemsWe document what each AI feature does, its data, and its human checks (approval before sending).
NIST AI RMF 1.0Managing AI riskMap, measure and manage: failures are counted by step and fixed through the skill library.
OWASP ASVSApplication security verificationUsed as the checklist for our security reviews of the app and API.
OWASP Top 10 for LLM ApplicationsRisks specific to AI appsPrompt injection, excessive agency and sensitive-information disclosure are addressed by approvals, server-side prompts and content stripping.
GDPREU data protection lawLegal bases, rights, retention and transfers are in the privacy policy; export and delete work in the app.

Assurance: where we are

ItemStatusWhat it means
Data-flow map and retention scheduleDonePublished in the privacy policy; retention enforced in code.
Google OAuth app verificationIn progressGoogle's review of how Saywork uses Google data, including the Limited Use requirements.
CSA STAR Level 1 self-assessmentIn preparationA public questionnaire (CAIQ) about our security controls, listed in the Cloud Security Alliance STAR Registry. It is a self-assessment, not an audit.
Independent penetration testPlannedAn outside firm tests the app and API.
SOC 2 Type I, then Type IIPlannedAn independent auditor's report on our controls at a point in time (Type I), then over a period (Type II).
ISO/IEC 27001 certificationPlannedCertification of our security management system by an accredited body.

Report a problem

Found a vulnerability? Write to [email protected]. Please give us a reasonable time to fix it before making it public; we will not pursue good-faith research that respects people's privacy and does not disrupt the service. Privacy questions and requests: [email protected].