tebDictate

Your voice stays on your phone.

Speech is turned into text on the device itself. The audio is never uploaded — not to us, not to Apple, not to Google. What reaches your computer is encrypted text that our server carries but cannot read.

tebDictate Privacy Policy

TebScribe LLC  ·  Effective July 28, 2026  ·  Applies to the tebDictate apps for iPhone and Android.

The short version: Your speech audio never leaves your phone. There are no accounts, so we hold no user records. Dictation sent to your computer is end-to-end encrypted, and our relay deletes it within minutes. We do not sell your data and we never use anything you dictate to train models. We do keep a small amount of anonymous usage data about how the service is used — section 5 lists every field.

Who we are: TebScribe LLC, the developer of tebDictate.
Contact: privacy@tebiq.com

1. What happens on your phone

Your microphone audio is converted to text on the device, by Apple's on-device recognizer on iPhone or Android's on-device recognizer on Android. It is never uploaded. If the language you pick has no on-device speech pack installed, tebDictate refuses to dictate and tells you why, rather than sending your audio somewhere else.

Text you keep — the Dictation pad, History, Snippets, Voice Form Fill documents — stays on your phone. Dictation history is encrypted at rest under a key held in the device's Keychain (iOS) or Keystore (Android). You can erase all of it at any time from Settings ▸ Privacy & data ▸ Delete all history, and deleting the app removes everything.

2. What happens on the way to your computer

When you scan the pairing QR code shown by tebchart.com/dictate, your phone and the browser perform an X25519 key exchange and derive a shared AES-256-GCM key using HKDF-SHA256. Every dictation message is encrypted with that key before it is sent. The browser's public key reaches your phone through the QR code — optically, off the network — so our relay cannot substitute a key of its own and read the traffic.

3. What our relay stores

Our relay stores only the ephemeral public keys used to set up the encrypted channel and the encrypted message envelopes themselves. It has no ability to read your dictation. Pairing tokens expire in about 15 minutes and stored envelopes in about 20 minutes, after which they are deleted. We keep no transcript, no audio, and no record tying a session to you.

4. IP addresses

To prevent abuse, our relay reads the requesting IP address when a pairing session is created and uses it to limit how many sessions one address can start. It is used for that check and is not written to our database.

5. Usage analytics — exactly what we record

We record anonymous usage events so we can see how much the service is used and whether it is working. This applies both to the website and to the app's requests to our relay. An event is a short row containing only these fields:

  • Which surface it came from (for example the dictation website, or the app).
  • Which event it was — a page view, a pairing session being created, a pairing completing, or a dictation message being relayed.
  • When, rounded to the hour.
  • Which page, chosen from a fixed list of known pages.
  • Country, as a two-letter code.
  • Device class — desktop, mobile, tablet, iOS or Android.
  • Where you came from, reduced to a short fixed list of referring sites, or "direct".

These rows are deleted automatically after about 30 days.

If you switch on "Send anonymous crash reports" in the app (Settings ▸ Privacy & data), a crash also records an anonymous report: app version, OS version, device model, and the technical stack trace — never your dictation, never an identifier. It is on by default and you can switch it off at any time.

What an event never contains: your IP address, any account, device or advertising identifier, any cookie, your browser's user-agent string, the contents of anything you dictate, or any free-text field of any kind. There is no identifier in these records, so they cannot be linked to you or joined together into a profile of one person, and we could not identify you from them if we tried.

6. Third-party components

Google ML Kit (on-device). Voice Form Fill, Translate mode and Interpreter run Google's ML Kit models on your device. Your photos, documents and text are processed on the phone and are not uploaded for these features. ML Kit itself reports diagnostic information to Google: device manufacturer, model and OS version, our app's bundle identifier and version, a per-installation identifier that is not intended to identify you, timings, event types, error codes, and — for Translate — the language pair you chose. Google documents this at developers.google.com/ml-kit/ios-data-disclosure. We cannot switch it off; if you would rather avoid it, do not use Voice Form Fill, Translate mode or Interpreter — the rest of tebDictate works without them.

WhisperKit model download (iPhone, optional, Pro). If you turn on the optional Whisper accuracy engine, the app downloads a speech model of about 486 MB once from Hugging Face. Model files come down; nothing about you goes up. Transcription still runs entirely on your phone.

Apple and Google. Purchases and subscriptions are handled by the App Store and Google Play. We never see your payment details.

7. What we do not do

  • We do not track you across apps or websites. tebDictate does not use Apple's App Tracking Transparency permission, because it does not track.
  • We do not show advertising.
  • We do not sell, rent or share your data with data brokers.
  • We do not use anything you dictate to train any model.
  • We do not knowingly collect information from children under 13.

8. Your choices and rights

Because there are no accounts, we hold no personal profile to export or delete. Everything tebDictate keeps about you is on your own phone and under your control:

  • Erase all dictation history: Settings ▸ Privacy & data ▸ Delete all history.
  • Revoke microphone, speech recognition, camera or photo access at any time in your phone's settings. The app keeps working and tells you what is switched off.
  • Delete the app to remove everything it stored.

If you want to exercise a right under the GDPR, UK GDPR, CCPA/CPRA or another privacy law, write to privacy@tebiq.com and we will respond. In practice our answer is usually that we hold nothing that identifies you.

9. Security

Dictation in transit is protected by end-to-end encryption: X25519 key agreement, HKDF-SHA256 key derivation, and AES-256-GCM with a fresh initialisation vector and a replay-resistant message counter. All network connections use HTTPS. Dictation history on the phone is encrypted at rest with AES-GCM under a key held in the device's secure keystore. No system is perfectly secure, and we make no guarantee that it is.

10. Changes

If we change this policy we will update the effective date above, and material changes will be described in the app's release notes.

11. Contact

TebScribe LLC — privacy@tebiq.com

This page is machine-translated from the English original. If anything here is unclear or seems to conflict with the English version, the English policy governs.