Voice Assistant Privacy: Where Your Data Goes
October 6, 2026 · privacy guide · 10 minutes read
Every time you say "Hey Google" or "Alexa", your voice travels through the internet, gets transcribed, analyzed, and stored. The companies say it's for "improving the service." But where exactly does your voice go? Who can access it? And can you opt out?
The Three Levels of Voice Data
Voice assistants collect data at three levels:
- The recording itself: Raw audio of your voice
- The transcription: Text version of what you said
- Metadata: When you spoke, what device, your location, what action was taken
Different assistants handle these differently. Let's break it down.
Google Assistant / Gemini
What Gets Collected
- Audio recordings: Stored by default, linked to your Google account
- Transcriptions: Stored indefinitely
- Context: Device ID, location, time, search history, app usage
- Action results: What you asked for and what Assistant did
Who Has Access
- Google's AI systems: Used to train models and improve recognition
- Google employees: Can access recordings for "quality control"
- Third-party contractors: Google admits some recordings are reviewed by humans
- Law enforcement: Can be subpoenaed (happened in murder investigations)
How Long It's Stored
By default: forever, until you manually delete it.
You can set auto-delete after 3, 18, or 36 months, but it's opt-in (Settings → Google Account → Data & Privacy → Web & App Activity).
Can You Opt Out?
Partially:
- You can disable "Web & App Activity" — but then Assistant loses context and becomes less useful
- You can delete recordings manually via myactivity.google.com
- You can't use Assistant without a Google account
Amazon Alexa
What Gets Collected
- Audio recordings: Stored by default
- Transcriptions: Stored indefinitely
- Purchase history: What you bought via Alexa
- Smart home logs: Every command to your devices
Who Has Access
- Amazon's AI systems: Training data for Alexa improvements
- Human reviewers: Amazon admitted in 2019 that thousands of employees listen to recordings
- Amazon marketing: Used for product recommendations
- Law enforcement: Subpoenable (Amazon has fought some requests, but complied with others)
How Long It's Stored
By default: forever.
You can enable auto-delete (3 or 18 months), but it's hidden deep in settings.
Can You Opt Out?
Partially:
- You can disable "Help improve Amazon services" — but Alexa still stores recordings
- You can delete recordings in the Alexa app → Settings → Alexa Privacy
- You can't use Alexa without an Amazon account
Apple Siri
What Gets Collected
- Audio recordings: NOT stored by default (Apple's main privacy selling point)
- Transcriptions: Stored with a random identifier, not linked to Apple ID
- Metadata: Device type, approximate location, interaction logs
Who Has Access
- Apple's AI systems: Training data (but anonymized)
- Apple employees: Can review transcriptions, but not recordings (unless you opt in)
- Law enforcement: Apple can't provide recordings (they don't have them), but can provide transcriptions if subpoenaed
How Long It's Stored
Transcriptions: up to 6 months, then anonymized further.
Audio (if you opt in): 2 years.
Can You Opt Out?
Yes:
- Siri doesn't store recordings by default
- You can disable "Improve Siri & Dictation" to prevent transcription analysis
- You can use Siri without iCloud (though some features break)
Amalia (Open Source)
What Gets Collected
- Audio recordings: NOT stored at all — audio is sent to Groq for STT, then discarded
- Transcriptions: Stored locally on device (encrypted DataStore)
- Conversation history: Stays on your phone, never leaves unless you manually export
- Metadata: None. No analytics, no telemetry, no crash reporting
Who Has Access
- You: Only you. Conversations are encrypted and stored locally
- Groq (during STT): Receives audio for transcription, processes it, returns text — no storage per their privacy policy
- Groq (during LLM): Receives transcription + system prompt, generates response — processed in memory, not stored
- Fish Audio (during TTS): Receives text, synthesizes speech, streams audio — no storage
How Long It's Stored
- On device: Until you clear app data
- On Groq/Fish Audio servers: Zero. Requests are processed in memory and discarded
Can You Opt Out?
Fully:
- No account required
- No analytics to opt out of (there are none)
- Source code is open — you can verify nothing is collected: github.com/kurumi-mProject/amalia
Privacy Comparison Table
| Feature | Alexa | Siri | Amalia | |
|---|---|---|---|---|
| Stores audio recordings | ✓ (default) | ✓ (default) | ✗ (opt-in) | ✗ |
| Stores transcriptions | ✓ Forever | ✓ Forever | ✓ 6 months | Device only |
| Human reviewers listen | ✓ | ✓ | ✗ (no audio) | ✗ |
| Linked to account | ✓ Google ID | ✓ Amazon ID | Random ID | No account |
| Used for ads/marketing | ✓ | ✓ | ✗ | ✗ |
| Can be subpoenaed | ✓ | ✓ | Partial | Device only |
| Open source (auditable) | ✗ | ✗ | ✗ | ✓ (MIT) |
Real-World Privacy Incidents
2018: Amazon Alexa sent private conversation to random contact
A Portland couple's conversation was recorded, transcribed, and sent to one of the husband's employees without their knowledge. Amazon confirmed it was a "rare" bug.
2019: Google contractors listen to Assistant recordings
Belgian news outlet VRT revealed that Google contractors listen to recordings to improve speech recognition. Google suspended the program, then resumed it with an opt-out option.
2021: Siri recordings reviewed without consent
Apple paid $95M settlement after admitting contractors listened to Siri recordings that included private medical information, drug deals, and sexual encounters.
2022: Police subpoena Alexa recordings in murder case
Arkansas court ordered Amazon to hand over Alexa recordings as evidence. Amazon initially refused, then complied.
The Open Source Difference
With Amalia, privacy is verifiable:
- Source code is public: github.com/kurumi-mProject/amalia
- No analytics SDK, no crash reporting, no telemetry
- Conversations stored in encrypted DataStore — you can inspect the database
- API keys are yours (Groq + Fish Audio) — you control access logs
You don't have to trust the developer's word — you can audit the code yourself.
How to Protect Your Privacy
If You Use Google/Alexa/Siri:
- Delete your recordings regularly: Google: myactivity.google.com | Alexa: App → Privacy | Siri: Settings → Siri & Search → Delete History
- Disable human review: Opt out of "improve service" programs (buried in settings)
- Use auto-delete: Set shortest retention period available
- Mute when not in use: Physical mute buttons exist for a reason
If You Want Real Privacy:
- Use open source alternatives: Amalia (MIT license), Dicio (GPL), Rhasspy (offline)
- Self-host everything: Whisper.cpp + local LLM + Piper TTS = fully offline (guide: offline voice assistants)
- Use your own API keys: With Amalia, you control Groq/Fish Audio keys — check their access logs yourself
The Bottom Line
Every mainstream voice assistant collects data. The difference is:
- Google/Alexa: Collect everything, store forever, use for ads, human reviewers listen
- Siri: Doesn't store audio by default, but still collects transcriptions
- Amalia: On-device storage only, no account, open source, auditable
If privacy matters to you, use open source. If you're okay with the trade-off, at least configure auto-delete and disable human review.
Want to try a privacy-first assistant? Download Amalia and see what it's like when your conversations stay yours.
Related: open source voice assistants · offline options · Google Assistant alternatives