Guides · For researchers
How to transcribe research interviews without uploading the audio.
General information for researchers, not institutional or legal advice. Your IRB or ethics board has the final word on your protocol.
AI transcription saves days of work, but most services do it by sending your participants' voices to a company's servers. More universities now restrict that. Here is what they ask for, the ways to transcribe without uploading anything, and consent language that says so plainly.
Universities are pulling back from cloud transcription
Over the last two years, a growing number of universities have told researchers and staff to stop sending recordings to unvetted AI transcription services and meeting bots:
- The University of Iowa's IT guidance for researchers lists Otter.ai as a prohibited technology, and says any external AI transcription service needs security review before it touches university data (University of Iowa ITS).
- Ohio State's technology office warned staff about Otter.ai and pointed them to university-approved tools. Otter is not on its approved AI tools list (Ohio State OTDI, August 2025).
- The University of Waterloo does not permit third-party AI note-taking bots, naming Fireflies.ai, Otter.ai and Read.ai, in university-hosted meetings (University of Waterloo, July 2026).
- Loughborough University warned that tools such as otter.ai and MeetGeek carry significant risk with personal data, including UK GDPR transfers and recordings used for AI training, and pointed staff to the transcription built into Word and Teams (Loughborough, February 2026).
- McMaster University's ethics-reviewed guidance says online transcription services suit only low and medium risk data, and recommends offline transcription or a human transcriber under a confidentiality agreement for high-risk data (McMaster, July 2025).
The pattern is the same everywhere: the concern is not transcription, it is where the audio goes, who keeps it, and whether it trains someone else's model.
What your IRB will ask about
Boards differ, but published guidance keeps returning to four questions.
How is the recording transcribed, and does the consent form say so?
UC Berkeley's board asks consent forms to say whether an AI tool is used, whether it is university-licensed or an outside commercial service, whether the vendor keeps the data and for how long, and whether the data trains AI (Berkeley CPHS AI consent language guide). Michigan added AI questions to its IRB application in 2026 and asks the same of consent forms (Michigan HRPP).
Where is the audio stored, and how is it protected?
Recordings are treated as identifiable data. Berkeley asks for encryption before anything crosses a network, and for a check of a cloud provider's data rights, deletion policy and storage location before using it (Berkeley CPHS data security guidelines). Washington State treats audio and video recordings as confidential data that must be encrypted (WSU HRPP).
Who else touches it?
A transcription service is a third party. Northeastern asks protocols to name it and to keep a written confidentiality assurance (Northeastern HSRP). For health data, HHS gives a transcription vendor as an example of a business associate that needs a business associate agreement (HHS).
When is it destroyed?
Boards expect a retention period in the consent form and a plan to destroy recordings. Berkeley's template plans to transcribe soon after the interview and then delete the audio (Berkeley consent template); UMass Amherst asks the form to state the time frame, who has access and where recordings are stored (UMass Amherst IRB).
Tell participants when AI transcribes them
In a joint editorial, the editor-in-chief and an associate editor of the Journal of Empirical Research on Human Research Ethics recommend, cautiously, that researchers tell participants when AI software will transcribe their recordings and get explicit consent for it, in a specific, plain-language clause. Their reason is the upload: AI transcription usually means sending recordings to a cloud service that may keep them to improve its models. They also suggest letting participants decline AI transcription and still take part, and having a person check every AI transcript (Samuel and Wassenaar, 2024).
If the transcription never leaves the device, that clause becomes simple to write, because the answer to "where does my voice go?" is short.
Ways to transcribe without uploading
- Desktop software that runs a speech model locally. Library guides point researchers to tools built on Whisper, such as aTrain, noScribe and MacWhisper, which transcribe on your own computer (Temple University Libraries, NYU Libraries, McMaster on aTrain). They are thorough but heavy: Temple notes some take hours per hour of audio. Check whether a tool labels speakers.
- Transcription on the phone that made the recording. Recent phones can run speech recognition on the device itself, so a recording can be transcribed without ever being copied anywhere. This is how Interview works.
- A human transcriber under a confidentiality agreement. Still the standard for the most sensitive data, at a cost in time and money.
- A service your university hosts or licenses. Some institutions run their own transcription or approve a licensed tool. If yours does, it is usually the easiest path through review.
Whichever you choose, the protocol should still name it, say where files are stored and say when they are deleted. On-device transcription removes the vendor from the picture. It does not remove your board's other questions.
Check your device rules first
Some institutions do not allow personal phones for research recordings at all. Washington State says a personal smartphone should not be used to record research audio and recommends its secure Zoom client or a recorder that is not connected to the internet (WSU). UConn requires university-owned devices for voice recordings of identifiable data (UConn), and the University of Iowa's human subjects office says personal phones may not be used for research recordings (University of Iowa HSO).
If that is your institution, an app on your personal phone will not satisfy the rule, however private the app is. A study-owned phone with the same app, plus the university's storage for exported files, may. Ask before you buy.
Consent language for on-device transcription
None of the institutional templates we checked include wording for transcription that happens on the device, so here is a starting point. Adapt it with your board; it is a suggestion, not approved language.
- "With your permission, this interview will be audio recorded on a phone used only for this study."
- "The recording will be transcribed by software that runs on that phone. The audio is not uploaded to a transcription service, and it is not used to train any AI system."
- "The research team will check the transcript for accuracy. The recording will be deleted [after transcription / by DATE], and the transcript will be stored on [university storage], where only the research team can access it."
- "You may decline to be recorded and still take part. If you do, the researcher will take written notes instead."
Be exact about the rest of the device. If the phone backs up to a cloud service, say so, or switch off backup for the recording app before the study starts.
If your participants are in the EU or UK
Under GDPR and UK GDPR a voice is generally personal data, and your institution is the controller. When audio goes to a cloud transcription service, that service is a processor and needs a written contract under Article 28, and a service that reuses the audio to train its models can become a controller for that use (ICO, AEPD). The ICO also says a company that only supplies software is not a processor for it. So, as we read it, transcribing on a device you control keeps the software maker out of the data: no processor contract and no international transfer for that step. Your other duties, such as a lawful basis, transparency, security, retention and a DPIA where needed, stay the same.
A checklist before the first interview
- Confirm which devices your institution allows for research recordings.
- Name the transcription method in the protocol and in the consent form.
- Decide where exported transcripts are stored, and who can open them.
- Set a deletion date for the audio, and put it in the consent form.
- Check the device's backup and sync settings against your data plan.
- Plan to review every transcript. Accuracy drops with strong accents, crosstalk and noise.
Where Interview fits
Interview records and transcribes on the phone itself, labels who said what, and exports Word, PDF, Markdown or plain text for coding. There is no account and no server, so the audio is not uploaded anywhere. The app sends anonymous usage counts, never audio or text, as its privacy policy describes. Named voices are remembered on the phone and can be deleted when the study closes.
Related
Interview for researchers · Recording consent laws by state · Interview vs Otter and Fireflies