Legal
GDPR and the EU AI Act
Speechfy is an EU company selling an AI product to people in the EU, so two laws govern it: the GDPR, which is about your data, and the AI Act, which is about the system that processes it. This page is both, in one place, because they overlap and reading them apart makes neither clear.
- Effective
- 22 August 2026
- Last updated
- 22 August 2026
- Applies to
- the Speechfy application, the Speechfy service and this website
1. What actually happens to your voice
You hold a key and speak. The audio travels over an encrypted connection to Speechfy’s own service in the EU. Speechfy passes it to a speech model, which returns text, and then to a language model, which returns the tidied sentence. That sentence goes back to the application you were already typing in.
Then it is gone. The audio and the text made from it exist for the seconds the request takes. They are not written to a database, not kept for quality review, not read by anyone here, and not used to train, fine-tune or evaluate any model — ours or anybody else’s. That last point is a contract term with the model providers and not merely our own policy.
Everything on this page follows from that paragraph. Most of what the GDPR asks of a company is about data it is holding; the strongest thing we can say is that there is almost none to hold.
2. Your voice is personal data
A recording of somebody speaking is personal data under Article 4(1) of the GDPR, and so is the text made from it. We say so plainly because the opposite claim is common and wrong: “we only process it in memory” does not stop something being personal data, it only limits how long we are processing it for.
The content is also personal data about other people whenever you dictate about them, which is most messages. You are responsible for having the right to record and transcribe what you dictate; we are responsible for handling it correctly once it arrives.
3. It is not biometric data, and why that distinction matters
Article 9 of the GDPR gives special protection to biometric data processed for the purpose of uniquely identifying a natural person. Those last nine words are the whole test, and Speechfy fails it in the ordinary sense: we process your voice to work out which words you said, never which person you are. There is no voiceprint, no speaker model, no enrolment, and nothing that could be compared against another recording to identify you.
So Article 9 does not apply to the processing itself. It may still apply to what you say. If you dictate a sentence about your health, your religion or your politics, that sentence is special category data for the seconds it exists in the request. We reduce that risk the only way that genuinely works — by not keeping it — and we note it here rather than leaving it unsaid.
4. The lawful basis for each thing we do
| What | Basis | Why that one |
|---|---|---|
| Transcribing and polishing a dictation | Article 6(1)(b) — performance of a contract | It is the service you asked for. Consent would be the wrong basis: you cannot withdraw it and still have the product work, and a consent you cannot refuse is not consent. |
| Your account and your sign-in | Article 6(1)(b) — contract | There is no service without an account. |
| Invoices and tax records | Article 6(1)(c) — legal obligation | Kept for the statutory period whether either of us wants to or not. |
| Counting the words you use | Article 6(1)(b) — contract | The plan is sold in words a month; the count is how the plan works. It is a number, not a copy of your text. |
| Keeping the service up and secure | Article 6(1)(f) — legitimate interests | Error logs and rate limits. Balanced against you by keeping them short-lived and free of the content of any dictation. |
5. Not keeping it is the compliance, not a bonus
Article 5(1)(c) requires data minimisation and Article 5(1)(e) requires storage limitation. Most products satisfy these on paper with a retention schedule. Speechfy satisfies them by construction: there is no retention schedule for dictation audio or transcripts because there is no retention.
This is also why several of the obligations that follow are short. A breach of a database that does not exist cannot expose anything; a request to erase a recording we never wrote down has nothing to act on. It is the single most consequential design decision in the product, and it was taken for this reason as much as for any engineering one.
What we do hold is listed in the privacy policy: an email address, a password hash, a plan, a word count, invoices, and short-lived logs.
6. The transfer outside the EEA
This is the part of Speechfy that carries real GDPR weight, and it is not the part people expect. The company is established in the EU, and your account, billing and logs stay on EU infrastructure. But the models that hear you and write your sentence are operated by providers who are not all in the EEA, and some are in the United States.
So the dictation itself is a restricted transfer under Chapter V of the GDPR, and we treat it as one. It is made on the European Commission’s Standard Contractual Clauses under Article 46(2)(c), supported by a transfer impact assessment and by contractual terms forbidding retention and training. The transfer lasts as long as the request does.
Two honest notes. A US provider’s European data centre would not solve this on its own — a US company can be reached by US legal process regardless of where the disks are — which is why we describe the safeguard rather than pointing at a region. And if you need the transfer not to happen at all, Enterprise pins every model inside the EU and writes it into your data processing agreement.
7. The model providers, as processors
The companies whose models transcribe and polish your dictation are processors acting on our instructions, not independent controllers of your words. Each is bound by a written contract meeting Article 28 of the GDPR: they process only on our documented instructions, they are held to confidentiality and to appropriate security, and they are contractually barred from retaining your content or using it to train.
You do not choose the model and are not told which one answered. That is a product decision — keeping the quality at the top is our work rather than yours — but it has a data-protection consequence worth stating: because you cannot choose, the responsibility for choosing well is entirely ours, and changing the countries involved is a material change that you are told about in advance under section 13 of the privacy policy.
The current list of sub-processors, naming each company, what it does and the country it processes in, is available on request from hello@speechfy.io.
8. Your rights, and the one we cannot fully give you
Articles 15 to 22 give you rights of access, rectification, erasure, restriction, portability and objection over the data we hold. They are set out in full in the privacy policy and they are honoured from hello@speechfy.io.
One of them we cannot satisfy in the way you might expect, and the reason is the point of the product. If you ask for a copy of your dictations under Article 15, there is nothing to send: we did not keep them. The same is true of erasure — there is nothing on our side to delete. If you dictated something you should not have, the place to check is whatever application received the text, and, if you left it on, Speechfy’s own history, which is a file on your machine that we never receive.
We would rather write that plainly than let anyone discover it by asking.
9. The AI Act: where Speechfy sits
Regulation (EU) 2024/1689 — the AI Act — entered into force on 1 August 2024 and applies in stages: the prohibited practices and the AI-literacy duty from 2 February 2025, the general-purpose model obligations from 2 August 2025, and the bulk of the remainder from 2 August 2026.
Speechfy is a provider of an AI system in the Act’s sense, and a deployer of general-purpose AI models that we did not build. The Act sorts systems by risk, and here is where this one falls:
| Tier | Applies? | Why |
|---|---|---|
| Prohibited (Article 5) | No | No social scoring, no subliminal manipulation, no exploitation of vulnerability, no untargeted scraping of faces, no emotion inference in workplaces or schools, no predictive policing, no real-time remote biometric identification. Speechfy does none of these and none of them are near what it does. |
| High risk (Article 6, Annex III) | No | Annex III lists biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and justice. Turning somebody’s own speech into their own text is in none of them, and Speechfy is not a safety component of a regulated product. |
| Transparency (Article 50) | Assessed — see section 10 | This is the one that needs a real answer rather than a shrug. |
| AI literacy (Article 4) | Yes | Applies to providers and deployers alike from February 2025. Everyone who works on Speechfy is required to understand what these models do, how they fail, and what the failure costs a user. |
A note on honesty about tiers: “minimal risk” is where most software lands, and claiming a higher tier would be theatre. It does not mean nothing applies. Article 4 applies today, Article 50 needed the assessment below, and the GDPR applies in full regardless of what the AI Act says.
10. Article 50, clause by clause
Article 50 requires that people are told when they are dealing with an AI system, and that certain generated content is marked as machine-generated. Taken clause by clause:
- 50(1) — systems that interact with people. You must be told you are talking to a machine unless it is obvious. Speechfy is a key you hold to dictate; it does not converse, answer, or present itself as a person. This page, the product name and every line of the marketing say what it is. We consider the duty met and the obviousness plain.
-
50(2) — synthetic content must be machine-readably
marked. This is the clause that needed a decision, and the
Article itself carries the exemption we rely on: it does not apply
where the system “performs an assistive function for
standard editing or does not substantially alter the input data
provided by the deployer or the semantics thereof”.
That is a precise description of what Speechfy does.
It removes the “um”, applies the self-correction you
spoke aloud, and puts in the punctuation you did not. The words are
yours; the sentence means what you meant. It writes nothing you did
not say.
The product is built to stay inside that exemption. It refuses to summarise, to answer a question inside your transcript, or to add content — those are the behaviours that would take it outside — and the refusals are enforced in the prompt and checked by a guard that rejects a result which dropped or invented material. - 50(3) — emotion recognition and biometric categorisation. Not applicable. Speechfy does neither, and section 11 commits to not starting.
- 50(4) — deepfakes and synthetic media passed off as real. Not applicable. Speechfy generates no audio, no images and no video, and produces no text about anybody except what you dictated yourself.
11. What Speechfy is not, and will not become
A list of absences is worth more than a list of assurances, because each of these would be a material change you would be told about before it happened.
- No speaker identification. No voiceprint is made, stored or compared. Speechfy cannot tell whether two dictations came from the same person.
- No emotion recognition. Nothing infers your mood, stress or state from your voice, and nothing ever will — it is prohibited in workplaces and schools under Article 5, and it is not a product we want to sell anywhere else either.
- No biometric categorisation. Nothing infers age, gender, ethnicity, health or anything else from how you sound.
- No profiling and no automated decisions producing legal or similarly significant effects, so Article 22 of the GDPR does not bite.
- No training on your words. Not by us, not by the model providers. It is a contract term, not a preference.
- No advertising, no data sale, no third-party analytics. This website sets no cookies and counts nobody.
- No reading of your notes. They are Markdown files in a folder you chose on your own machine, and they never reach us at all.
12. The paperwork, and how to ask for it
Everything on this page is backed by a document, and the documents are available to anyone who has to justify the choice of Speechfy to somebody else. Write to hello@speechfy.io and ask for any of them by name.
- The data processing agreement, for organisations that need Speechfy under a contract of their own.
- The Standard Contractual Clauses covering the transfer described in section 6, and the transfer impact assessment that supports them.
- The current sub-processor list, naming each company, what it does and the country it processes in.
- The record of processing activities under Article 30, and the data protection impact assessment carried out under Article 35.
Requests are answered by a person, not a form. If a question here does not have the answer your legal team needs, ask it directly and you will get a straight one.
See also the privacy policy, which carries the full detail of what is held and for how long, and the terms of service, which govern the subscription itself.