What Happens to Your File After Transcription
It is gone. Your file is not saved, queued, indexed or attached to an account — there is no account to attach it to. The entire life of the file is one HTTPS request: it is read into memory, converted and transcribed, and the response closes. We pulled the live configuration of our deployment today and it has exactly one binding, ai; no storage bucket, database or key-value namespace is attached to it, and no log pipeline is configured.
How long your file actually exists
Time to first byte and total time differ by less than a millisecond on every run, which means the answer arrives in one piece — there is no second request and no redirect to a results page. A five-minute recording therefore exists in memory for roughly half a minute. Then the request ends, and so does the file.
- 30 s of audio / 90,512 B — 9.3 s, 5.2 s, 10.2 s
- 60 s / 180,476 B — 12.4 s, 12.2 s, 14.3 s
- 300 s / 900,512 B — 45.1 s, 44.7 s, 30.5 s
What comes back — and what never does

What is not in there matters more. No job id, no result URL, no retrieval token, no handle you could query later. There is nothing to come back for, and we checked: a plain GET to the same endpoint answers 404 Not found. The transcript is handed to your browser once, and after that it exists only wherever you put it.
success— truetranscript— the text, and nothing elselanguage— reported as unknownengine— Cloudflare Workers AI (@cf/openai/whisper)fileSize— 61200, the exact byte count you sentfileName— the name of your file, echoed back to you
There is nowhere in our code to save it
A search of the deployed source for storage calls returns nothing at all — no KV, R2, D1, cache or local storage writes anywhere in the file. A worker with no storage binding can hold your bytes in memory for the duration of a request and then lose them. That is precisely what happens here, and it is a stronger guarantee than a deletion policy, because there is no code path that could keep the file even by mistake.
- bindings: one entry — name
AI, typeai - no key-value namespace
- no object storage bucket
- no database
- logpush: false
- tail consumers: empty
What we checked today, and how you could repeat it
- We uploaded a clip renamed with a random marker, then fetched the home page, the blog index, the sitemap, the privacy page and the about page. The marker appears zero times on all five.
- The transcription response sets no cookies.
- A GET to the transcription endpoint answers 404, so there is no stored result waiting to be fetched.
- The plain HTTP URL answers 301 to the HTTPS one; every page is served over HTTPS.
The part we will not claim
- Your audio is transcribed by Cloudflare Workers AI, not by hardware we own. That is a real third party in the path, and we are not going to hide it behind the word "encrypted".
- We do not run a training pipeline on uploads.
- We cannot show you what happens inside the isolate after the response is flushed, because we cannot inspect someone else's memory allocator. What we can show is that our code never writes the file anywhere and has nowhere to write it.
- If you need a guarantee that no third party ever touches the audio, the only version of that promise that holds is a tool running on your own machine. Ours is not that tool.
What this means in practice
- Do not upload audio you are not willing to send across a network.
- Copy the transcript out when you see it. It is delivered once.
- There is no account to delete and no history to clear, because there is no record for a history to live in.
- If the audio is legally sensitive — a recorded call, a medical or legal conversation — check your own obligations first. "We deleted it" is not a legal answer.
FAQ
Is my file stored anywhere after transcription?
No. The deployed worker has one binding, ai, and no storage of any kind attached to it. The file is read into memory, transcribed, and the request ends.
Can I come back and download my transcript later?
No. The response is 313 bytes of JSON delivered once, with no job id and no result URL. A GET to the same endpoint returns 404 Not found. Save the text when you see it.
Do you use my audio to train a model?
No. There is no training pipeline running on uploads, and there is no storage binding that could retain them.
Who actually processes the audio?
Cloudflare Workers AI, running the @cf/openai/whisper model. We name it in every response because you should be able to look up who is handling your audio.
Is the upload encrypted?
Yes, in transit — the transfer is over HTTPS and the plain HTTP URL redirects to it. Encryption protects the file on the way to us; it does not change the fact that we receive it.
Do you keep logs of what I upload?
On the deployed worker, logpush is false and there are no tail consumers configured. Beyond what we configure ourselves, platform-level request metadata is infrastructure we do not control, so we will not promise anything about it.