Why we delete your audio after transcription

2026-07-31 · star365 engineering

When you upload a recording to our transcription service, the audio file is deleted as soon as the transcript exists. This post is about what that sentence does and does not promise, because vague privacy claims are worse than none.

What actually happens to the file

  1. The upload lands on disk on the server that served you the page.
  2. whisper.cpp, compiled on that same server, reads it and produces a transcript.
  3. The source audio is deleted.
  4. The transcript stays for the retention period of your plan.

There is no inference API in that path. The audio does not travel to a third party, because there is no third party in the transcription step.

The exception, stated plainly

The optional AI summary is different. If you tick that box, the transcript text — not the audio — is sent to an external language model to be condensed into decisions and action items.

If you do not tick it, nothing leaves.

We are spelling this out because "your data never leaves our servers" is the kind of claim that is technically false in one corner and gets a company deservedly torn apart when someone finds the corner. The corner is the summary step. Now you know where it is.

What is retained, and for how long

plantranscript retention
Free7 days
Creator90 days
Pro365 days

Audio: not retained on any plan.

You can check the engine's live state yourself at /api/health — it reports whether the local engine is running, which is the same signal our own monitoring uses.

Why this is the product, not a feature

The people who need transcription most are frequently the people least able to use it: lawyers with privileged client conversations, clinicians with patient recordings, accountants with material non-public information. Every hosted option we evaluated ships the audio to an inference provider. For those users that is not a preference, it is a disqualification.

So the architecture was not chosen for marketing. It was chosen because it is the only version of the product those users can adopt at all.

What we do not promise

We are not zero-knowledge. The audio is on our disk while it is being processed, and the transcript stays until retention expires. If your threat model requires that no operator can technically read your data, this is not that product — and you should run whisper.cpp yourself. It is MIT-licensed, it works, and on modest hardware it is genuinely fine. We would rather tell you that than sell you a mismatch.

We are not a compliance product. We have not been audited against any framework. If you need a signed DPA or a certification, we do not have one yet.

We do not promise perfect accuracy. Transcription quality depends on the model, the audio, the accents, the crosstalk. The free tier uses the smaller base model; paid plans use small, which is meaningfully better but still not a court reporter.

The consent problem nobody puts in their marketing

A meeting recording contains other people's voices.

Recording laws vary by jurisdiction and some of them are strict. Whether you were allowed to make the recording, and whether the other participants agreed to it being processed, is not something we can determine from a file upload — and it is not something we take responsibility for.

That responsibility sits with the person uploading. This is written in the product UI, not buried here, because it is the single most likely way a user of a transcription service gets into trouble, and it has nothing to do with where the servers are.

The short version

The audio stays on our server and is deleted after transcription. The optional summary sends transcript text to an external model. Transcripts are kept for 7, 90 or 365 days depending on plan. We are not zero-knowledge, we are not audited, and consent to record is yours to obtain.

If that set of trade-offs fits, the service is at voice.star365.site. If it does not, run whisper.cpp locally — genuinely.