Last updated: 8 September 2026
1. What Whistle Enterprise processes
Audio recordings of meetings the user runs on their own computer, whether recorded live or imported. Transcripts produced from those recordings, generated meeting documents and any files exported from those documents.
2. Where files are stored
Recordings, transcripts and generated documents are kept in a local workspace on the user's computer. The workspace can be set to a local drive or a network drive. Exports are written to whatever location the user chooses. If the user separately enables provider filing, that export is also uploaded to the configured Google Drive, SharePoint or OneDrive destination.
3. What leaves the device
Nothing in the base application. Recording, transcription, speaker labelling, document writing, search, licensing and updates do not make a provider request and Whistle does not phone home.
Extensions need to be installed, approved and enabled before they can connect. Microsoft and Google extensions read calendar details and can upload exported documents to OneDrive, SharePoint or Google Drive. The extensions page has the downloads and installation instructions.
Writing with Codex or Claude Code sends the full transcript and document template to OpenAI or Anthropic. Extracting action items can also send the generated overview. Audio stays on the computer. The privacy notice explains what is sent and how the account's settings affect its use.
4. Network behaviour
Whistle's own models work offline. Extensions need an internet connection to read calendars, upload documents or write through Codex or Claude Code. None of these extensions are part of the main installer.
Updates and previous versions are downloaded from the Whistle Enterprise website. There are no automatic updates and no callback to a server.
5. Encryption
The local workspace can be encrypted with a password. When the password is set, all recordings, transcripts and automatically generated documents inside the workspace are encrypted at rest. Without the password, the contents cannot be recovered.
6. Telemetry
Whistle sends us no telemetry, analytics events or usage data. It has no background error reporting. OpenAI and Anthropic have their own policies for data collected when you use Codex or Claude Code.
A user can send a diagnostic file by email. The file contains only technical state, not the contents of recordings, transcriptions or generated documents. Sending it is always a manual action by the user.
7. Provider credentials
Microsoft and Google extensions use desktop authorisation with PKCE. OAuth access and refresh tokens are stored in the operating system keychain, not in the workspace or the public settings file. Disconnecting or removing an integration deletes those local tokens. Switching an integration off stops provider requests without deleting the token.
The ordinary connection uses the public application identity owned by BlazingBanana Ltd. An administrator can instead configure an organisation owned OAuth application from advanced settings. Microsoft desktop clients do not use a client secret. Google issues desktop clients a value named a client secret and can require it at the token endpoint. The Google extension includes this value. It is not confidential and is not a person's password or OAuth token. A custom Google desktop client ID and secret are stored in the local application settings.
Codex and Claude Code handle sign-in through the software included in each extension. Login details are saved in a private folder for that extension, separate from any Codex or Claude Code login used in a terminal. Removing the extension deletes its login details.
8. AI models
Whistle's local writing model was fine tuned by BlazingBanana Ltd for meeting documents and runs on a normal laptop CPU. The transcription model is a published speech recognition model selected for accuracy and offline operation. Both models are bundled with the installer. Neither is loaded from a remote service at runtime.
We don't use your recordings, transcripts or documents to train models. If you write through Codex or Claude Code, check your OpenAI or Anthropic account's training settings and terms.
Questions or corrections
Anything missing from these notes, or wrong, can be flagged to [email protected]. Every message is read by a human and we aim to reply within two working days.