Skip to main content
WAIMAKERS
About UsCareersContact
|
Start a conversation
Back to overview

Wispr Flow

Wispr AI

By deploymentEU: UnavailableOpt-out availableRetention by settingsHosting: US

Assessment labels are editorial guidance, not GDPR certifications. Validate the exact plan, lawful basis, DPA, subprocessors, retention, residency and feature settings. EU storage and no-training terms alone do not establish GDPR compliance. ¹ No training applies under the reviewed plan’s terms.

Rolling out Wispr Flow safely?

We assess the actual plan, settings, data flows and governance controls, then turn the findings into a practical rollout decision.

Request an assessment

Pricing / Contract Route

Per user/month: Pro USD15 monthly or USD12 billed annually; Growth/Business from USD23 monthly or USD18 billed annually; Enterprise custom

Enterprise Features

Training and Cloud Sync controls, enterprise ZDR enforcement, HIPAA/BAA route, SSO and administrative privacy controls

Last Updated

September 10, 2026

Reviewed: 10 September 2026 - prepared by WAIMAKERS B.V.


1 Purpose

Deployment-specific review. Wispr Flow can support lower-risk EU dictation when model-improvement and cloud-storage controls are configured, the DPA is accepted, and US transfers are assessed. “Privacy Mode” alone is not zero data retention: Wispr's current documentation treats model-improvement and cloud storage as independent controls.


2 Comparison of Wispr Flow Tiers (EU focus)

The figures below come from Wispr's current pricing and organisational-plan guide.

Plan Central controls Public price at review date
Free User settings; desktop limit 2,000 words/week, iPhone 1,000/week, Android shown as unlimited Free
Pro Individual/team billing and usage analytics; user controls data settings unless organisation policy applies $15/user/month or $12/user/month billed annually
Growth / Business SSO, SCIM, domains and organisation-wide model-training policy From $23/user/month or $18/user/month billed annually
Enterprise Enforced ZDR, MDM, audit logs and custom legal/commercial terms Custom

The public pricing page and implementation guide use both “Growth” and “Business” for the intermediate organisational plan. Confirm the order form's plan name and controls.


3 Is Wispr Flow GDPR-Compliant?

Training, storage and location

  • ✅ The “Improve the model for everyone” control determines training. When it is off, Wispr says dictation audio, transcripts and edits are not used to evaluate or improve its models. It is on by default for trial and standard accounts; Enterprise and BAA customers default to no sharing.
  • ⚠️ “Dictation cloud storage” independently controls server storage used for transcript history, syncing and related features. Zero data retention means model improvement off and dictation cloud storage off.
  • ✅ Organisation ZDR can force both controls. A signed BAA also locks relevant controls, but HIPAA status does not establish GDPR compliance.
  • ⚠️ User-triggered transcript feedback uploads the full record. Synced snippets, dictionaries, account data, logs, analytics and local device data are separate flows and are not all erased by the dictation ZDR setting.
  • ⚠️ Wispr says all customer data is processed and stored in the United States. Its August 2026 DPA incorporates the EU SCCs and a UK Addendum. A transfer assessment must cover the actual subprocessors and safeguards.
  • ✅ The DPA applies when an authorised customer representative accepts it or transfers personal data under its acceptance mechanism; it is not limited to Enterprise in the public wording.

Assurance conflict

Wispr's marketing privacy page advertises SOC 2 Type II, ISO 27001 and HIPAA. Its more detailed Security and Compliance FAQ, updated 7 September 2026, says the current independent evidence is an A-LIGN SOC 2 Type I report from April 2026, that SOC 2 Type II observation is underway, and that ISO 27001 Stage 2 had not yet been reported as complete. The FAQ also says earlier SOC 2 Type II and ISO 27001 evidence was proactively invalidated in March 2026.

Until Wispr resolves this conflict with a current report, buyers should record SOC 2 Type I confirmed by the detailed FAQ; SOC 2 Type II and ISO 27001 current status unresolved. Request the actual reports under NDA. Do not describe marketing badges as certification evidence.


4 EU Rollout Checklist (Practical)

  1. Accept and archive the current DPA; review its SCC selections and live subprocessor list.
  2. Assess the US transfer and supplementary measures for the intended data categories.
  3. Turn “Improve the model for everyone” off and disable dictation cloud storage. For teams, enforce both centrally where the purchased plan supports it.
  4. Configure local-device retention separately and document the effect on synced snippets, dictionaries and context features.
  5. Tell users that submitting feedback intentionally uploads the record and that Android controls may differ from desktop/iOS.
  6. Exclude special-category, confidential or privileged dictation unless the documented risk assessment specifically permits it.
  7. Obtain the current SOC/ISO reports and reconcile them with the public marketing claims before relying on assurance badges.

5 Notes & Caveats

Open procurement questions

  • Has A-LIGN issued a SOC 2 Type II report or completed ISO 27001 Stage 2 since the September FAQ update?
  • Which subprocessors receive dictation content under each feature, and what retention applies to safety, support and feedback flows?
  • What data is retained in account records, synced dictionaries/snippets, analytics, logs, local history and backups after ZDR is enabled?
  • Can Growth/Business enforce both training opt-out and cloud-storage-off, or is full ZDR enforcement Enterprise-only in the order offered?
  • How are data-subject access and deletion requests fulfilled across local devices and cloud systems?

6 References

  • Wispr pricing
  • Wispr organisational plans
  • Wispr model-improvement and cloud-storage controls
  • Wispr Security and Compliance FAQ
  • Wispr DPA
  • Wispr marketing privacy page
  • GDPR, official text

7 Disclaimer

This page is a practical procurement and data-risk overview, not legal advice. Suitability depends on configured controls, device platform, contract, subprocessors, data classes and the customer's GDPR assessment.

Compare related tools

LovableMeta Llama

Need help navigating AI?

Start a conversation
WAIMAKERS

Learn. Lead. Make.

AI Transformation Boutique · Amsterdam

Make work exciting, make businesses unstoppable.

Who We Help

View all roles & industriesCEOs & Board MembersPE & Investment ManagersCFOs & Finance LeadersInnovation DirectorsCTOs & IT LeadersCommercial Directors

What We Do

View all servicesOur ApproachLearnTailored Training ProgrammesAI Champions ProgrammeAI Champions — Executive (London)Agentic Way of WorkingE-learningLeadMake

Company

About UsResourcesContactCareersPodcast ↗

© 2026 WAIMAKERS. All rights reserved.

Privacy PolicyCookie Policy