Data handling summary for IT and procurement review. Last updated 28 July 2026, app version 1.2.5.
5cut records and transcribes audio and video entirely on the user's device. There is no 5cut server, no account system, and no cloud processing. Recordings, transcripts and exports never leave the device unless the user exports them somewhere themselves.
| Question | Answer |
|---|---|
| Is customer audio uploaded anywhere? | No |
| Is a third-party transcription service used? | No |
| Are accounts or logins required? | No |
| Is there analytics or telemetry? | No |
| Is a Data Processing Agreement required? | No — see below |
| Is data encrypted at rest? | Yes — see below |
| Can it run without network access? | Yes, after model download |
A data processing agreement governs a processor handling personal data on a controller's behalf. 5cut never receives your data, so there is no processing relationship to govern. The developer has no technical ability to access, view, or retain any recording, transcript, or export — not because of a policy commitment, but because no system exists that could receive them.
If your process requires a signed statement to that effect rather than a policy page, contact us and we will provide one.
Two layers apply. Every modern iPhone encrypts its storage in hardware with a key fused into the silicon, which defeats physically extracting the flash. On top of that, iOS Data Protection gives each file a key wrapped by a class key derived in part from the user's device passcode. 5cut's files use:
Two limits worth stating plainly. Data Protection derives its strength from the user having a device passcode; without one, protection falls back to the hardware layer alone — which is why a passcode policy enforced through MDM matters. And it protects a lost or stolen device, not a device that is unlocked in an attacker's hands. Once a user exports a file to Photos or Files, it is governed by that destination's protection, not by 5cut's.
All speech processing runs locally using on-device models:
Earlier versions could fall back to Apple's server-side speech recognition for language and device combinations without on-device support. That path was removed in version 1.2.5. The app no longer requests the iOS Speech Recognition permission at all, which is independently verifiable: the permission does not appear in the app's Info.plist, and iOS will not grant an app access to a capability it has not declared.
The app makes outbound requests in exactly two situations, and neither transmits user content:
There are no analytics, crash-reporting, attribution, or advertising SDKs. The app's internal analytics helper compiles to debug-build logging only and is inert in App Store builds.
All are open-source, run locally, and perform inference or utility work only. None transmit user data:
Speech Recognition is not requested. Contacts, location, calendar, and tracking permissions are not requested.
Users can export transcripts and notes to Apple Notes, Markdown, Anki, Notion or Obsidian, and video to Photos or Files. These are deliberate user actions with a normal iOS share sheet. If your organisation restricts destinations, this is governed by your existing MDM and Managed Open In policies — 5cut adds no independent channel.
5cut is a small independent app, and it is worth being precise about the limits.
There is no SOC 2 report, no ISO 27001 certification, and no third-party penetration test. Those attest to organisational controls around handling customer data — controls that exist to manage a risk 5cut does not create, because no customer data is received.
There is also no admin console, no central policy enforcement, and no audit log, because there is no account system to attach them to. Deployment and control are handled entirely through Apple Business Manager and your MDM.
5cut is distributed through the App Store and can be deployed to managed devices via Apple Business Manager and your MDM. Note that Apple does not permit in-app purchases to be bought in volume — for an organisation-wide licence, contact us about a custom build with the paid features already enabled.
Security or procurement questions
support@get5cut.comSee also the privacy policy and 5cut for organisations.
← Back to 5cut