WhoTalked

Privacy

Short, because there is not much to say.

This page describes two separate things: what the desktop app does with your recordings, and what this website collects. Neither answer is complicated.

The desktop app

Your recordings, your transcripts, and the voice prints used to recognise people are written to your own disk and stay there. They are not uploaded, not synced, not backed up to anything, and not readable by anyone but you and whoever else can read that disk. There is no account, no login, and no server behind the product for them to travel to.

The app makes network requests only to fetch models. The speaker models, about 34 MB, come from GitHub release assets. The optional speech model, anywhere from 75 MB to 3.1 GB depending on which you choose, comes from Hugging Face. Every file is pinned to an exact SHA-256. This happens on first run, and again if you later pick a different speech model. Apart from that, ordinary use of the app, including recording, separating voices, and transcribing, opens no network connections at all.

Once the auto-updater ships, and not before, the app will also ask whotalked.com/update.json whether a newer version exists. That request contains the current version and nothing about you or your meetings, and it will be possible to turn off.

Nothing is encrypted by WhoTalked. Recordings are plain WAV files and the transcript and voice-print library live in a plain database file, all on your own disk. Whatever full-disk encryption your machine already runs is what protects them. If that matters for your work, check that it is switched on.
Voice prints are biometric data. Naming somebody stores a voice print that will re-identify them in later, unrelated meetings until you delete it. Several jurisdictions regulate biometric identifiers separately from recordings, and enrolling another person may require their consent on its own footing. Voice prints can be deleted individually from the People tab, and deleting a person removes every print stored for them.

You decide when a recording dies. Nothing expires on its own, and nothing is deleted without you asking. You can delete the audio and keep the transcript, or delete the whole meeting.

This website

No analytics, no cookies, no tracking pixels, no advertising SDKs, no embedded fonts, no CDN. Every asset on this site is served from this domain. You can verify that in about five seconds: open your browser's network tab and reload.

The site is hosted on Cloudflare Pages, which like any web host processes the request logs needed to serve a page. That is outside this project's control and is described in Cloudflare's own documentation.

Recording and the law

Whether you may record a given conversation depends on where you and the other participants are, and that is a question for your own counsel. WhoTalked records the audio your machine is already playing; it does not join meetings, notify anyone, or ask a meeting service for anything. If anything, a recorder the other side cannot see raises the stakes on getting consent rather than lowering them, and complying is yours to do. The law is also not the only constraint: contracts, employer policy and court rules can prohibit recording where a statute does not.

Questions: hello@whotalked.com.

Effective 15 August 2026. WhoTalked is run by Mathieu-Philippe Bourgeois, sole proprietor, Quebec, Canada. Material changes to this page will be dated and noted here.