blurt.
Home›Security
Security & privacy

Your meetings
are yours

In short

By default, Blurt records and transcribes on your own computer. Blurt Cloud is optional: it's encrypted in transit and at rest, deletes audio after processing, and never uses your conversations to train models, ours or anyone else's.

Last updated September 26, 2026·Written for humans and IT teams
PrinciplesWhat goes whereYour data, item by itemBlurt CloudWho processes dataConsentComplianceFAQ
01

Local by default.

Recording, transcription, notes and your dictionary live on your computer. Blurt works fully offline.

02

Cloud only when you choose.

Blurt Cloud is off until you turn it on, for best-model summaries or sync. You can turn it off again anytime.

03

Never trained on.

Your conversations are never used to train models. Not ours, not our providers'. On every plan, including Free.

What goes where

The whole journey
of a meeting.

Everything starts and, by default, stays on your computer. If you turn on Blurt Cloud, this is exactly what travels, and where it ends.

Always
Your computer
  • Audio is recorded
  • Transcribed locally
  • Notes and archive stored
TLS 1.3
in transit
Only if you turn it on
Blurt Cloud
  • Best-model summaries
  • Sync to your devices
  • AES-256 at rest
After
processing
Audio
Deleted.

Cloud audio is deleted once it's processed. Notes stay until you delete them.

Prefer none of it?Leave Blurt Cloud off. Use a local model, or your own AI key, for summaries.
Your data, item by item

What we keep,
and for how long.

Last updated September 26, 2026
DataWhere it livesEncryptedKept forWho can see it
AudioYour computer. Blurt Cloud only while processing, if enabled.On your disk, per your OS · TLS 1.3 · AES-256Cloud: deleted after processingOnly you
Transcripts & notesYour computer. Blurt Cloud if sync is on.TLS 1.3 · AES-256Until you delete themYou, and teammates you share with
Your dictionaryYour computer. Synced if sync is on.TLS 1.3 · AES-256Until you delete itOnly you
AccountBlurtTLS 1.3 · AES-256While your account is openYou and Blurt support, when you ask
PaymentOur payment provider, never on Blurt's serversPCI DSS compliantAs required by lawPayment provider
App analyticsOff by default. Anonymous counts if you opt in.TLS 1.313 monthsBlurt, aggregated only
Blurt Cloud, in detail

When you do use the cloud,
here's exactly how.

In transit
TLS 1.3

Every connection between your devices and Blurt Cloud is encrypted.

At rest
AES-256

Synced notes and transcripts are encrypted on disk.

Audio retention
Deleted after processing

Audio sent for cloud summaries isn't kept once the summary is written.

Region
United States · EU option

Choose EU processing on Team plans.

Staff access
None by default

Blurt staff can't read your meetings. Support access only with your explicit, time-limited permission, and it's logged.

Deletion
One click

Delete a meeting, or your whole account and every synced copy, from Settings. Gone from backups within 30 days.

Who processes
data for us.

The companies Blurt Cloud relies on, what they do, and where. We'll notify you before adding anyone new.

CompanyWhat forWhereTrains on your data?
{Cloud host}Hosting, storage, syncUS · EUNo
{AI model provider}Cloud summaries (zero data retention)USNo
{Speech provider}Cloud transcription, if enabledUSNo
{Payment provider}Payments, tax, invoicesGlobalNo
{Email provider}Account and receipt emailsUSNo
Responsible disclosure

Found a flaw?
Tell us.

We welcome reports from security researchers. Tell us privately first, give us a reasonable window to fix it, and we'll credit you publicly if you'd like.

# blurtaway.com/.well-known/security.txt
Contact: mailto:security@blurtaway.com
Policy: https://blurtaway.com/security/disclosure
Preferred-Languages: en
Compliance

Where we are,
honestly.

We're a small company, so here's our real status, not a wall of badges.

  • GDPR-readyData processing agreement available on requestAvailable now
  • No training on customer dataContractual with every provider we useAvailable now
  • SOC 2 Type IAudit underwayTarget: first half of 2027
  • SOC 2 Type IIAfter Type ITarget: late 2027
Security FAQ

What IT
usually asks.

Doing a security review?

We'll fill in your questionnaire and join a call with your team.

security@blurtaway.com
Can Blurt employees read my meetings?
No. Local notes never reach us. Synced notes are encrypted, and staff have no access by default. Support can only look at something if you explicitly grant time-limited access, and every access is logged.
Where is Blurt Cloud hosted?
In the United States by default, with EU processing available on Team plans. The companies we use, and where, are listed above.
Do you use my meetings to train AI?
Never. Not our models, not our providers' models, on any plan. It's in our contracts with every provider that touches your data.
Is Blurt SOC 2 compliant?
Not yet. A SOC 2 Type I audit is underway, and we'll share the report as soon as it's issued. Until then, we're happy to complete your security questionnaire.
How do I delete everything?
Settings → Account → Delete account. That removes your account and every synced copy from Blurt Cloud immediately, and from backups within 30 days. Local files are yours to keep or delete.
Can we deploy Blurt with Blurt Cloud turned off?
Yes. Admins can disable Blurt Cloud across a Team workspace, so everything stays on company devices. Summaries then run on a local model or your own approved AI provider.