Exposing the SECRET of Wispr Flow 🔎😱
It reads what's on your screen (Bank account pages, Private Chats) and sends it to servers that aren't even theirs. On by default.
Wispr Flow is the most popular dictation app on the market: 4,000+ businesses, millions of users, and $260M raised last month. You don't hand $260M to a voice-to-text app you could build in a weekend. So I got curious and reverse-engineered their flagship product to find out what's really going on.
1. Every time you dictate, Wispr reads the text around your cursor: your open DMs, your bank balance, the doc behind the window, plus your app and the exact URL you're on.
And... Sends it to their cloud for inference.
Have your bank account open, a private DM, or a confidential doc open behind the cursor? That context goes too.
This is ON by default. It's controlled by a flag called useAxContext `(default: true)`. not by any privacy setting you can see.
And full-screen capture? It's already wired into the shipped app
`(shouldOCRScreenCapture, desktopCapturer.getSources({types:["screen"]})`
grabs your entire display, not just the active window). It's one toggle away, sitting in the code, ready to go.
2. None of this runs on your computer. It runs on servers that aren't even Wispr's.
Open Activity Monitor while you dictate and watch the connections light up. Your audio, plus everything above, gets sent to Baseten, a completely separate third-party company, for processing, then to Wispr's own servers. Your voice and the contents of your screen are being handed to a vendor most users have never heard of and were never told about.
For a dictation app, almost none of this needs to leave your device. It could run locally. It doesn't.
3. The privacy switch is a placebo
There's a setting called "Help improve Flow's features and AI models." You turn it off, you assume you've opted out. You haven't.
Their own code proves it. When you turn it off, the app literally logs: "Usage data sharing is off, only uploading metadata", and then uploads anyway. The switch doesn't stop the live transmission. It doesn't stop the analytics. All it does is strip some text out of one upload channel; the upload still happens, still carrying your app, your URL, and a per-word map of every correction you made.
The privacy setting never worked. And unless Wispr patches it before this goes viral, it still won't.
4. It watches your keystrokes after every paste.
A background helper tracks every app you switch to, all day, not just while you're dictating. And after it pastes text for you, it watches the keystrokes in that field to see how you edit it. Wispr's own internal notes describe this mechanism as, their words. "keylogger-shaped."
You don't have to trust me...
The entire forensic report is signed against Apple's own notarization. The hash of Wispr's shipped code `(app.asar)` matches Apple's signed seal exactly proving these are bytes Wispr provably authored, not something I could have altered. That code is sitting in the Wispr Flow install on your computer right now, and on millions of others.
So verify it yourself. Back up your Wispr Flow install and ask Claude to reverse-engineer it. I'll drop the exact prompt in the comments.
A dictation app should convert your voice to text. This one reads your screen, hands your audio to a third party, tracks you before you log in, watches your keystrokes, and gives you a privacy switch that does nothing.
Attaching the full Wispr Flow Forensic Report.
It's your computer. It's your call. But you deserve to know.
I want to talk about a video we posted last week, the one titled "Google is coming for us."
Most of the replies fell into two categories....
1. "Wispr is a wrapper anyone could build in a weekend."
Yes, you can vibe code a version of Wispr. We encourage it, honestly. It's a fun build and you'll learn a lot. But getting from 6/10 to 9/10 is incredibly hard. Making dictation feel instant, getting names and jargon right every time, formatting a text differently in an email, editing mid sentence with just your voice, these are incredibly tough (fun) challenges. Most models cap out well before what top-tier voice dictation needs to be to deserve trusted, habitual usage. We deeply understand this problem - because it is all we have thought about for years - and recently launched Wispr Advanced Interfaces Lab to create a step change in voice quality. We see how this can be significantly better and will prove it.
2. "Wispr has gotten too hype."
This post lacked the authenticity we aim to deliver. We started building Wispr in public closely with the X community and we want to make sure we are as grounded and humble as we always have been. We will continue to have fun, be open and push the boundaries through our content, models, and product innovations.
--
Going forward, we'll be releasing more benchmarks, regular product updates, challenges we face, and incorporating all the product feedback we get here back into what we're building. The future of voice is an exciting one, and we care about what you think we should do next!