Blabb Get Blabb free

Dictating confidential content
an architecture guide

The moment your voice leaves your machine, someone else is processing your content. For NDA work, health information, and client data, that single architectural fact drives everything else. This guide maps the obligations to the architectures. Informational, not legal advice — confirm specifics with your counsel or compliance team.

01What the rules say

Cloud dictation creates a vendor relationship

HIPAA: the vendor becomes a Business Associate

Under HIPAA, any vendor that creates, receives, maintains, or transmits Protected Health Information on behalf of a covered entity is a Business Associate and needs a signed BAA — dictation and transcription services explicitly included (HIPAA Journal). A vendor that won't sign a BAA is not a lawful option for PHI. And a BAA governs the risk; it doesn't remove it — your PHI is still on someone else's systems.

NDAs and client confidentiality

Many NDAs and engagement letters restrict disclosing client information to third parties without consent. Routing dictated client content through a cloud speech vendor — especially one whose terms permit using data to improve AI models unless you opt out — is exactly the kind of question you don't want to argue about later. Check the vendor's data-use terms before the first sentence, not after.

Training-data terms are the trap

Several cloud dictation products may use your content to train or improve models unless a privacy mode is enabled — an opt-in toggle on paid tiers in some cases. For confidential work, a setting you must remember to enable is a control that will eventually fail. Prefer architectures where the failure mode doesn't exist.

02The architecture answer

On-device processing removes the vendor from the chain

No transmission, no disclosure question

When speech recognition and AI cleanup both run on your own machine, the confidential content is never transmitted to anyone. There's no Business Associate because no vendor ever touches the PHI; no NDA disclosure because nothing is disclosed. The compliance conversation collapses to "the same machine you already type on."

Verify it, don't trust it

The test for any "private" dictation tool: unplug the network. Blabb keeps dictating — both models ship inside the installer and run on your CPU or GPU, and no audio or text is uploaded. The one thing that needs the network is the licence check: once your subscription has been verified, dictation runs offline for 30 days before Blabb has to check again. Local history is encrypted with keys tied to your Windows account, retention is yours to set — don't save history at all, or 1 day, 1 week (the default), 1 month, or forever — and one click deletes your history, saved words and logs.

What Blabb doesn't claim

Blabb is not "HIPAA certified" (no software is — HIPAA compliance is a property of an organization's practices, not a product badge). What the architecture gives you: dictated PHI and client content never leave the machine, which removes the transmission risk entirely and keeps the rest of your compliance posture where it already lives — on your device and policies. For the full analysis — encryption, audit logging, the PHI egress inventory, and why Blabb is generally not a Business Associate — see our HIPAA & Security page.

The most private dictation is the kind with nowhere to leak from.

Two weeks free. Your audio and transcripts stay on the machine.

Get Blabb free How on-device works

FREE TIER 2,000 WORDS/DAY · 14-DAY UNLIMITED TRIAL IN-APP · CANCEL ANY TIME