The microphone button on your iPhone keyboard is one of the most used features on iOS. Tap it, speak, and your words appear on screen. Most people assume this works entirely on their device. The reality is more nuanced.
On modern iPhones (12 and later) with supported languages, dictation runs on-device by default — audio never leaves your phone. But on older devices, unsupported languages, or when the system decides it needs server assistance, audio is still sent to Apple's servers. Whether a given session stays on-device is invisible to you. This post walks through what we know.
How iOS dictation works
iOS dictation has two processing paths. On modern hardware (iPhone 12 and later, iPad with M1/A14+) with supported languages, dictation runs on-device via the Neural Engine — audio never leaves your phone. On older devices, unsupported languages, or when the system decides it needs server assistance, audio is sent to Apple's servers over an encrypted connection.
When server-side processing is used, Apple's privacy page states that audio is associated with a random identifier — not your Apple ID — and is retained for up to six months to improve transcription quality. After six months, Apple says the audio is deleted, though the transcript may be retained longer.
What the documentation doesn't address: which data centers process your audio, whether the data crosses jurisdictions, or which subprocessors handle the audio pipeline.
On-device dictation: what applies and what doesn't
Apple has invested heavily in on-device dictation. Starting with iOS 16, basic on-device recognition was added. At WWDC 2026, Apple announced a significantly upgraded AI dictation system based on the AFM 3 model — running entirely on-device with contextual spelling, punctuation, and capitalization correction. This is a meaningful quality upgrade over the earlier on-device mode.
However, the conditions that determine on-device vs. server-side processing are still not fully transparent:
- Hardware gating. The new AFM 3-based dictation requires recent hardware (M3+ Macs, iPhone 17 Pro, iPads with M4+ and 12GB+ RAM). The standard iPhone 17 (8GB) is excluded. Older devices fall back to the pre-AFM on-device mode or server-side processing.
- Language support. On-device processing is available for a growing but limited set of languages. If you dictate in an unsupported language, audio is sent to Apple's servers regardless of your hardware.
- No user-visible indicator. There is no UI element that tells you whether a given dictation session was processed on-device or server-side. You cannot tell from the microphone button which path your audio is taking.
- Opt-in at launch. As of the iOS 27 beta, the new AI dictation is disabled by default — users must enable it manually in Settings.
The practical implication: Apple is moving in the right direction — more processing on-device, better quality, broader language support. But you still cannot guarantee that a given session stayed on-device, and the best features are hardware-gated to the newest (and most expensive) devices.
What the privacy policy actually says
Apple's approach is better than most: the random identifier isn't tied to your account, the retention window is disclosed (six months), and they've invested in on-device processing as an architectural direction. For casual use cases — texting, quick searches, short notes — this is probably fine.
But Apple's policy has meaningful gaps for professional use:
- No contractual zero-retention commitment. The six-month retention window is a policy statement, not a contract clause. Policies change.
- No named subprocessors for the audio pipeline. Apple's privacy documentation doesn't enumerate which infrastructure vendors handle speech recognition.
- Opt-out is limited to toggling dictation off entirely. There's no option to use dictation while opting out of server-side retention.
- HIPAA coverage is not guaranteed for dictation. Apple's BAA (Business Associate Agreement) for Apple Business Manager doesn't explicitly cover third-party app dictation data paths. Healthcare organizations using iOS dictation for clinical notes should verify their compliance posture independently.
The alternative: zero-retention dictation
Verity takes a different architectural approach. Audio is transcribed on Verity-operated infrastructure and discarded immediately — no retention period, not even for improvement purposes, and no third-party AI provider in the path to take on trust. Everything in the audio path is documented in our privacy architecture deep dive and on our trust page.
| Feature | iPhone Dictation | Verity |
|---|---|---|
| Default audio routing | On-device (modern hardware) or Apple servers (older/unsupported) | Verity servers (zero retention) |
| Retention period | Up to 6 months | Zero (deleted after transcription) |
| Contractual zero-retention | No | Yes — DPA with named processors |
| Named subprocessors | Not published | Published on privacy page |
| On-device option | Partial (hardware + language constraints) | Zero-retention cloud STT (audio discarded after transcription) |
| Used for model training | Yes (opt-out via identifier reset) | No |
| AI polish (filler removal, sentence restructuring) | No — punctuation and capitalization only | Yes — 3 personas (minimal, casual, formal) |
Apple Dictation has improved significantly — on-device processing is now the default on modern hardware, and the WWDC 2026 AI upgrade added better correction. But it still gives you raw transcription, not polished writing. And on older devices or unsupported languages, audio is still sent to servers with six-month retention on infrastructure you can't audit. If you dictate sensitive material, those gaps matter.
What to do
If you use iPhone dictation for sensitive material — medical notes, legal documents, financial analysis, confidential work conversations — a few options:
- Use Verity instead of the keyboard mic. Verity is a dedicated dictation app with a zero-retention architecture. It's available as a free download and works across Mac, Windows, Linux, iOS, and Android.
- Audit your language settings. If you're on a supported device and dictate in a supported language, verify whether on-device dictation is available to you via Settings → General → Keyboard → Enable Dictation. The option appears when on-device is supported, though there's still no per-session indicator.
- Reset the dictation identifier periodically. If you're using Apple Dictation and want to minimize retention linkage, toggling Enable Dictation off and back on resets the random identifier.
The dictation built into your keyboard is convenient. It's also not designed for privacy-first use cases. Knowing the difference lets you make an informed choice. (For the same analysis on Windows, see our Windows Voice Typing privacy breakdown.)
Dictation that doesn't retain your audio
Zero-retention architecture · Named processors · Free to start
Download Verity