Blabbermouth privacy notice Last updated: 8 September 2026. Who is responsible Blabbermouth is operated by James Wilmington, trading as Blabbermouth, who is the controller responsible for the personal information described in this notice. For privacy enquiries, contact hello@wilmo.co.uk. Business correspondence: 15 Market Street, Northwich, CW9 5BD, United Kingdom. Speech and files on your PC Blabbermouth processes microphone audio, speech recognition, file transcription and installed translation packs locally on your Windows PC. The licensing service does not receive your recordings, dictated text, translations, vocabulary, snippets or transcript history. Settings and downloaded models are stored locally. Optional transcript history stores text rather than microphone recordings. Recovery audio can be held temporarily in memory and is written to a file when you explicitly save it. You control exported files. Uninstalling may preserve local data for reinstallation; use the app's controls or manage the files yourself to remove them. Applications you dictate into have their own privacy practices. Licensing, purchases and support Activation and periodic licence checks send licence information, an app-generated pseudonymous installation identifier, the app version and information needed to validate the signed licence certificate. The identifier is not your Windows username, PC name or hardware serial number. We keep licence status, edition, permitted installations and relevant timestamps to administer access and support. Stripe processes website purchases. We receive the purchase email, transaction references, product, amount, currency and payment or refund status needed to fulfil and administer the purchase. We do not receive complete payment-card or bank details. Support enquiries include the contact details and message you provide. Website contact-form submissions are delivered by email. Please provide only information needed for support and never send a full licence key. If you deliberately attach a recording or transcript to an enquiry, it becomes part of that support correspondence. Internet requests also expose network information such as an IP address, request time and requested resource. We use operational and security records to maintain the service, prevent abuse and investigate failures. We do not sell dictation content or use the app for advertising or behavioural tracking. Why we use personal information We process necessary purchase, licensing and related support information to perform our contract with you, or take steps at your request before entering into it. Our legitimate interests in answering other enquiries, protecting the service and resolving problems support necessary correspondence and security processing. We retain information required to meet legal obligations, including applicable tax and accounting requirements. Without the necessary licensing information, we cannot activate or validate a licence. How long information is kept - Licence and installation records are kept while the licence remains usable. After permanent closure, continued retention depends on unresolved support, refunds, disputes, security investigations and legal obligations, rather than continued use of the app alone. - Support correspondence is stored in Gmail and is managed manually, without a fixed automatic deletion period. Retention decisions take account of the enquiry, continuing support for the associated licence, disputes and legal obligations. You can ask us to delete correspondence that is no longer needed. - Purchase and financial evidence is retained for the applicable accounting and tax record-keeping period, and longer where an unresolved refund, dispute or legal requirement makes this necessary. These obligations may prevent immediate erasure of some purchase records. - The licensing service schedules removal of raw Stripe event payloads 30 days after processing or resolution. Unresolved events are kept until resolved. This cleanup does not remove the separate purchase and licence records described above. - Routine server web logs are configured for daily rotation with 14 rotated files retained. Other diagnostic, security and audit records may be retained where needed to investigate an incident or document its handling. This is not a promise that all security records expire after 14 days. - Nightly server backups normally cover about the last four nights. Separate manual database exports are also kept for recovery and have no automatic expiry; their retention depends on whether they are still needed for recovery or a legal obligation. The nightly backup window is therefore not a maximum lifetime for every copy. Deleting a live record does not immediately remove it from existing backups; deletion requests must also consider retained exports and recovery copies. - Files stored by the app on your own PC remain under your control until you remove them. Providers and international processing We administer the licensing server ourselves. The following providers handle information needed for their services: - Cloudflare protects and delivers website and licensing requests, processing network and request information. - Amazon Web Services Simple Email Service sends licence and website contact emails through its London-region endpoint. This includes recipients' addresses and message contents; licence-delivery messages contain the issued licence key. - Google Gmail receives and stores support correspondence, including contact details and message contents. - Stripe handles website payments, payment security and related records. Microsoft handles Store downloads and associated platform activity under its own privacy arrangements. - Hugging Face, GitHub and Mozilla's download infrastructure supply requested speech models and translation packs. These providers receive download-request information, not speech recordings or transcripts from the app. These providers operate internationally, including in the United States. The London email endpoint does not mean all email processing or storage stays in the UK. Depending on the provider and transfer, protections include applicable adequacy arrangements, the UK Extension to the EU-US Data Privacy Framework, or Standard Contractual Clauses with the UK Addendum. The providers describe their transfer arrangements and safeguards here: AWS service terms: https://aws.amazon.com/service-terms/, Cloudflare data-processing terms: https://www.cloudflare.com/cloudflare-customer-dpa/, Google's transfer frameworks: https://policies.google.com/privacy/frameworks?hl=en-GB, and Stripe's privacy centre: https://stripe.com/gb/legal/privacy-center. Contact hello@wilmo.co.uk for further information or copies of relevant safeguards. Providers may also process service, payment or security information for their own purposes under their privacy notices. Website cookies The contact form uses a session cookie to protect form submissions. It is set to expire with the browser session and is not an advertising cookie. Cloudflare may also use cookies or similar mechanisms needed to protect and deliver the site. Your choices and rights Depending on the circumstances, you can request access, correction, deletion, restriction or a portable copy of your personal information. You can object to processing based on legitimate interests. Contact hello@wilmo.co.uk; we may need proportionate evidence of identity to protect your information. Never send a full licence key. We will explain where an active licence, legal obligation or other applicable exception limits what can be deleted. You can complain to the UK Information Commissioner's Office: https://ico.org.uk/make-a-complaint/. The app does not use behavioural profiling to make decisions about you with legal or similarly significant effects; licence checks apply purchased or granted access rules.