Privacy and security

Transcribe audio without uploading it anywhere

The page reads your file and writes the transcript inside your browser tab. The site has no way to receive the file: there is no upload endpoint, and the page may connect only to this site. Below is what your browser downloads, what it keeps, what the host still sees, and how to check it yourself.

Stays on your device
  • The audio or video file you add
  • The sound the page reads from it
  • The language you choose
  • The transcript and what you search for in it
  • The TXT files you download and the text you copy
Never sent to us
  • The audio or video
  • Its file name
  • Its metadata, such as the recording date or location
  • The transcript made from it
  • Your searches in the transcript

Where the transcription happens

The transcription engine, the part that turns speech into text, runs inside your browser tab. It is a WebAssembly program and an open-source speech recognition model, both downloaded from this site the first time you add a file. Inside the tab, the page reads your file's sound and hands it to the engine a slice at a time; the transcript is written into the page. Nothing goes back to the site. How the transcription runs in your browser explains each step.

What your browser downloads, and nothing else

Opening the transcription tool downloads the page itself, its styles, its scripts, and a few images, all from this site. When you add your first file, the page also downloads, from this site, the engine (about 1.5 MB), the media reader that decodes your file's sound (about 0.3 MB), and the model you picked: about 60 MB for the smaller one or about 265 MB for the larger one, in parts, plus a voice detector of under 1 MB that finds the stretches with speech. When your browser offers a usable WebGPU adapter, it also downloads the engine's WebGPU build (about 3.4 MB). There are no fonts or scripts from other sites, no analytics, and no ads.

What stays in your browser afterwards

The model and the voice detector. The page keeps their verified parts in your browser's Cache Storage for this site when the browser has room for them, so later visits skip the download. They hold only the model and the voice detector, never your recordings or transcripts. To remove them, clear this site's data in your browser; the next file then downloads the model again. Like the page's other files, the engine may also sit in your browser's ordinary cache. The transcript lives only in the open tab, and the browser discards it when you close the tab. Apart from those parts, the page's scripts store nothing: no cookies, no localStorage or sessionStorage, and no IndexedDB.

The page can read only the file you give it

You hand the page a file by choosing it or dropping it on the drop area. A web page cannot browse your folders: the browser gives it the one file you picked and nothing else. The page checks that the file is an audio or video file and refuses anything else with a message.

What the browser enforces

The site sends security headers with every page, and your browser enforces them no matter what the page's scripts try to do. In plain language:

Security headers on every page (from the site's header rules)
HeaderWhat it does
Content-Security-Policy: connect-src 'self'The page's scripts may connect only to this site. The browser blocks a request to any other server.
Content-Security-Policy: form-action 'self'A form on the page can submit only to this site.
Content-Security-Policy: script-src 'self' 'wasm-unsafe-eval'Only scripts served by this site run. The second value lets the browser compile WebAssembly, the format the transcription engine is built in.
Content-Security-Policy: media-src 'none'The page cannot play audio or video from anywhere. It does not need to: it reads your file's contents instead of playing it.
Permissions-Policy: camera=(), microphone=(), geolocation=()The camera, the microphone, and location are switched off for the page. It cannot even ask for them: the tool takes files, never live sound.
Content-Security-Policy: frame-ancestors 'none' and X-Frame-Options: DENYNo other site can show this page inside a frame, which blocks clickjacking (a fake page laid over the real one).
Content-Security-Policy: worker-src 'self' blob:The workers that read your file and run the engine may start only from this site's scripts or from inside the tab.
Cross-Origin-Opener-Policy and Cross-Origin-Embedder-PolicyThey isolate the tab from other sites. Browsers require this isolation before a page may share memory between threads, which the engine's multi-threaded build uses.

Behind the headers, the site is a set of static files on a content delivery network. No server program of ours runs behind it, so there is no endpoint that could accept a file even if the page tried to send one.

Check it yourself

Your browser's developer tools list every request a page makes, so you can check this on your own computer (Chrome's Network panel guide explains the panel):

  1. Open the transcription tool on a computer and press F12 (or Cmd+Option+I on a Mac) to open developer tools, then choose the Network tab. In Safari, first turn on the developer features in Settings, Advanced.
  2. Reload the page. You should see the page, its styles, scripts, and images, all from transcribe-audio.online.
  3. Add an audio or video file. The first time, new rows appear for the engine and the parts of the model, all from transcribe-audio.online. On a later visit the model's parts come from your browser's storage, so only a few small files that list them are requested again.
  4. Check the Method column (if it is hidden, right-click a column header to show it). Every row should read GET or HEAD, and every address should be transcribe-audio.online. Rows starting with blob: or data: are links inside your tab, not network transfers.

An upload looks different: a request with the POST or PUT method whose size is about the size of your file, often to another domain. If you ever see one when you add a file here, something is wrong, and we want to hear about it at support@transcribe-audio.online.

What our automated test checks

An automated browser test loads a built copy of the site in Chromium, the engine behind Chrome and Edge, and adds a file. Every change to the site runs it. Among its checks:

  • Every request of the session goes to this site, and every one is a GET or HEAD request with no body, so nothing is uploaded. A request to any other server fails the test.
  • Opening the page downloads no engine, no model, and no worker: they come from this site only once you add a file.
  • Sample recordings are transcribed inside the tab: a WAV file, an MP4 video, and a WebM file, read in slices, and the transcript reads as expected.
  • The copied text and the downloaded TXT file hold exactly the paragraphs the page shows, with and without timestamps.
  • Cancel stops a transcription, and the next file uses the model the browser already keeps, with no model part downloaded again.
  • The site is served with its production headers, and the browser reports no Content-Security-Policy violation.

What "no upload" does not cover

  • The host sees ordinary requests. Like any website's host, the hosting and delivery provider processes standard request data, such as your IP address and browser details, to serve the files and protect the site. Those requests contain nothing from your file.
  • The page needs a connection to load. There is no offline mode.
  • Extensions can see the page. An extension you allowed to read and change websites sees what this page shows. For a sensitive recording, use a browser profile without extensions.
  • Downloads are ordinary files. Once you save a transcript, it follows your device's rules: a synced folder, a backup, or an email attachment takes it wherever those go. Text you copy goes to your clipboard, which some systems sync to your other devices.
  • Your device is your own. Malware, or other people with access to your computer, are outside what any web page can control.

Privacy questions

How do I remove what the site stored?

Clear this site's data in your browser. That deletes the saved parts of the model and the voice detector, the only things the page stores. In Chrome or Edge, open developer tools, then Application, Storage, and Clear site data (Chrome's guide); Firefox explains it in clear cookies and site data. Your next file downloads the model again.

Can I use it for a confidential recording?

The recording and the transcript never reach us, so we cannot see, keep, or lose them. Whether a tool fits your own rules, for a client, a patient, or an employer, is a decision we cannot make for you; the facts on this page are what you can check.

Can a browser extension see my recording?

It can if you allowed it to read and change the pages you visit. Such an extension sees what this page shows, the transcript included, and no web page can stop that. For a sensitive recording, use a browser profile with no extensions installed.

Privacy and trust guide

Continue exploring this topic

Related topics: How the transcription works

Transcribe a recording

Nothing you add leaves your device. Watch the requests while it runs, if you like.

Open the transcription tool