Account access
Whispek uses email verification codes for sign-in. Sessions use short-lived access credentials and rotating refresh credentials. On Windows, the refresh credential is stored in the operating system’s credential store. You can review and remove other signed-in devices from your account.
Cloud request controls
Speech requests are authorized by the Whispek service. Provider API credentials stay on the server, and a voice stream uses a short-lived, single-use ticket. Production service configuration requires encrypted WebSocket connections. These controls do not make processing end-to-end encrypted: Whispek and its processing service need to handle your submitted content.
Local information and diagnostics
Voice and chat history are stored on your computer. Protect the Windows account and disk that hold them; we do not describe local history as an independently encrypted vault.
Production server configuration rejects diagnostic content capture. Quick Ask diagnostics record operational metadata such as timing and status, not conversation bodies. Development configurations can behave differently, so review any diagnostic files before sharing them.
Questions and responsible reporting
We do not claim a SOC 2, ISO 27001 or other independent certification on this site. If your organization requires an assessment, tell us which controls and evidence you need.
To report a suspected security issue, email a concise description, affected version and steps to reproduce. Omit live credentials and other people’s private content.