Security & privacy

We keep your history. We never keep your voice.

Conversation content goes to two specialist providers to do the work. What comes back is kept encrypted for your account—never sold, never advertised against, and never used to train models.

Nobody at BetterTalk reads your conversations as part of normal work.

Audio is never stored · Transcripts are encrypted and access is audited

What leaves your Mac

Two providers. Two narrow jobs.

Deepgram receives audio. Anthropic receives transcript text. Those are the only companies asked to make sense of the conversation. The transcript passes through a Cloudflare-hosted relay on the way, then comes back and is encrypted for your account.

01 · audio

Deepgram

Transcribes the recording and separates the two speakers. Audio travels directly from the app to Deepgram using a short-lived token, and the recording is deleted as soon as it is transcribed.

  • BetterTalk infrastructure never receives the audio
  • Every request opts out of model improvement
  • Live and final transcription only
Read Deepgram's model-improvement policy ↗

02 · transcript text

Anthropic

Analyzes speaker-labelled transcript turns to produce structured observations. No BetterTalk account, couple, device, email, billing, invitation, or session identifier is included.

  • Transcript text can still identify people by itself
  • Standard commercial API retention is up to 30 days
  • No Files, batch processing, prompt caching, or Workbench
Read Anthropic's commercial retention policy ↗

The complete data path

Follow one conversation, end to end.

  1. 01

    On your Mac

    Your Mac records

    Both people consent. Recording state stays visible. Audio begins in a protected temporary location on the Mac.

  2. 02

    External provider

    Deepgram hears audio

    The app sends audio directly to Deepgram for transcription and speaker separation. BetterTalk servers never receive the audio.

  3. 03

    On your Mac

    The transcript returns

    Speaker-labelled transcript turns return to the app and live in memory or protected temporary storage while the conversation is active.

  4. 04

    External provider

    Anthropic reads the words

    A stateless BetterTalk relay forwards transcript text and the analysis rubric to Anthropic. Product and account identifiers are excluded.

A precise note about the relay

The transcript does pass through a narrowly scoped BetterTalk relay on its way to Anthropic. The relay must read enough of the request to validate its shape and forward it, but it is built not to log, persist, or attach product identifiers to that content. Storage is a separate step: once the conversation ends, the transcript and the review are encrypted and written to your account, behind checks that require an authenticated device signed in as you.

What the developers can see

Two systems, held apart.

BetterTalk needs enough information to run accounts, consent, access, limits, and billing. Your conversations sit apart from that, encrypted, behind restricted and audited access.

Everyday operations

Content-free facts

  • Account, couple, device, and consent state
  • Conversation duration and entitlement usage
  • Provider, model, latency, status, token counts, and estimated cost
  • Content-free security and billing events

Tightly restricted

The conversation

  • Audio bytes, files, or URLs are never stored at all
  • Transcripts and reviews are encrypted for your account
  • Reads require an authenticated device signed in as you
  • Nobody reads conversations as part of normal work, and administrative access is logged

Retention, not hand-waving

What stays, where, and for how long.

Delete a conversation you recorded on your own and the transcript and review go with it. Deleting a conversation you recorded with a linked partner takes both of you approving it. The encryption keys for stored content are destroyed when that content is fully deleted.

DataLocationRetention
Live transcriptApp memoryUntil processing finishes or a bounded failure cleanup
AudioProtected Mac folderNever stored by BetterTalk; deleted after transcription, with a startup sweep for items older than 24 hours
Transcript and reviewEncrypted in your BetterTalk account, cached encrypted on the MacUntil the conversation is deleted; a shared conversation needs both partners to approve deletion
Anthropic input / outputAnthropic APIUp to 30 days under the standard commercial policy
Operational metadataBetterTalk control planeContent-free; provider and security telemetry defaults to 90 days

The honest limits

A real promise, not a magical one.

Removing account identifiers does not hide who is speaking. A conversation may name people, places, employers, diagnoses, or other identifying details.

BetterTalk makes an operational promise, not a cryptographic impossibility claim. Your transcripts are encrypted with keys BetterTalk holds, because the service has to read them to analyze the conversation and show you your history. Access is restricted, audited, and outside the reach of normal work—but that is a rule we keep, not a mathematical barrier.

Like any networked app, BetterTalk depends on your Mac, your network, and its service providers staying secure. No digital service can promise perfect security.