Dicta Privacy Policy
Last updated: 28 August 2026
Dicta is a Chrome voice-typing extension published by LIVIA CARE PTY LTD, trading as Intellova ("we", "us"). This policy covers Dicta and its supporting authentication, transcription, history and billing services. The Intellova website and other products have separate privacy terms.
1. The short version
- Dicta captures microphone audio only after you deliberately start recording.
- Audio crosses Dicta's private, authenticated voice gateway to Amazon Transcribe in AWS's Sydney region.
- Encrypted recordings and transcripts remain in your Dicta history until you delete them.
- We do not sell user data, serve advertising, assess creditworthiness, or include advertising or behavioural-analytics SDKs in the extension.
2. Information Dicta processes
- Sign-in information: your email address, provider account identifier, name and profile picture supplied by Google or Microsoft through Amazon Cognito.
- Audio: microphone audio captured during a recording, limited to 120 seconds per session.
- History: encrypted transcript text, WAV audio, duration and creation time retained until deletion.
- Settings: language, insertion and shortcut preferences stored locally in Chrome.
- Plan and payment status: pseudonymous plan entitlements and monthly usage in AWS. Stripe processes payment details and invoices; payment-card data is not stored in the extension or Dicta's AWS database.
- Security and operations data: pseudonymous user/session identifiers, request identifiers, status, latency and bounded rejection reasons. Application logs must not contain audio, transcript text, tokens, email addresses, page content or destination URLs.
Dicta does not read your browsing history or retain the hostname, URL, page title or surrounding content where you dictate. The page-facing component cannot access tokens, audio or history. Password, PIN, one-time-code and payment fields are blocked from transcript insertion.
3. How voice transcription works
After sign-in, Dicta's API checks membership, plan allowance, rate limits and whether another recording is active. It creates a cryptographically random, single-use ticket that expires after 60 seconds. The extension presents that ticket through Dicta's WAF and TLS-protected gateway; the private gateway calls Amazon Transcribe using its AWS task role and returns partial and final text. AWS credentials and provider URLs never reach the extension. When recording finishes, Dicta stores the WAV recording and encrypted transcript in private AWS storage. Audio is never captured while Dicta is idle.
4. Encrypted history and retention
- Transcript text is encrypted with AES-256-GCM using a per-user data key wrapped by AWS Key Management Service.
- Recordings use private Amazon S3 storage with AWS KMS encryption; transcripts use encrypted DynamoDB storage.
- History is isolated to your authenticated account. Playback uses an authenticated URL that expires after five minutes.
Recordings and transcripts do not expire automatically. They remain until you delete an item, clear all history or delete the account. DynamoDB point-in-time recovery copies are retained for seven days and are handled under deletion-reconciliation controls.
5. Sign-in, billing and service providers
Dicta uses Amazon Cognito with authorisation code and PKCE. Access and ID tokens expire after 15 minutes, refresh tokens rotate and are revoked at sign-out, and tokens remain in trusted extension session storage. Dicta never receives your Google or Microsoft password. Checkout and subscription management use Stripe-hosted pages; signed Stripe webhooks update the plan entitlement stored in AWS.
| Provider | Purpose | Receives |
|---|---|---|
| Amazon Web Services, Sydney | Sign-in, API, transcription, encrypted history and plan enforcement | Account claims, audio during recording, encrypted history and pseudonymous usage |
| Google or Microsoft | User-selected sign-in | Identity and authentication information they process |
| Stripe | Checkout, subscription management and invoices | Contact and payment information supplied during checkout |
| Google Chrome Web Store | Extension distribution | Store account and installation information collected by Google |
Although Dicta's AWS services are configured in Sydney, Google, Microsoft, Stripe and their supporting networks may process information in other countries under their own privacy terms. Dicta's use and transfer of information received from Google APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
6. Export, deletion and account closure
You can delete individual entries, clear history, or export transcript history as an unencrypted JSON file to your device. Treat that export like any other sensitive local file. Delete account first cancels an active Dicta subscription without a prorated refund unless the law requires one, then revokes access and signs you out. An encrypted retry queue removes your history, recordings, session and billing-entitlement records, wrapped encryption key and Cognito account. Stripe retains transaction records where required for payment, tax, fraud-prevention and legal obligations. We retain a minimal pseudonymous deletion ledger so a recovery copy cannot silently recreate a deleted account; it does not contain your email or transcript text.
7. Security and your choices
Dicta uses strict extension origins, per-route server authorisation, signed Stripe webhooks, encryption in transit and at rest, rate limits, monitoring and separate development and production AWS accounts. No internet service can promise absolute security. You can deny microphone permission, sign out, delete individual history, delete your account, or remove the extension at any time.
8. Your rights and contact
You may ask to access or correct personal information we hold, or complain about our handling of it under the Australian Privacy Principles. Contact:
LIVIA CARE PTY LTD, trading as Intellova
Email: apps@intellova.com.au
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au. We may update this policy when Dicta changes; the date above identifies the current version.