Research & academic workflows

Sending Research Audio to an AI Transcription Service: The Ethics Questions

Using an AI transcription service for research audio is an ethical decision as much as a practical one, because participant recordings leave your control and are processed by a third party. Before uploading anything, find out exactly where the audio goes and how long it stays there, make sure your consent wording covers it, assess the risks for your particular participants, and get your ethics board's view. Then record which tool you used and how you checked its output.

8 min read · Updated

Why the tool choice is an ethics question

When a researcher typed transcripts by hand, the recording stayed on the researcher's own equipment. Professional transcribers changed that, and ethics boards developed expectations about confidentiality agreements. AI transcription services raise similar questions in a new form: the audio is sent to servers operated by a company, processed by software, and possibly retained, logged or used in ways the participant never imagined.

The questions are not only about data security. They include whether participants were told and agreed, whether the processing matches what your approval describes, whether the tool's errors could misrepresent participants, and whether the convenience justifies any added risk. These are judgments for you and your ethics board, informed by your institution's policies and the data protection law that applies to you, which varies by country. This article lays out the questions; it does not answer them for your study.

What a review board may ask

Ethics committees and institutional review boards differ, but questions like these come up often when a protocol mentions automatic transcription:

  • Which service will be used, and who operates it?
  • What exactly is sent: the full recording, the audio only, or segments?
  • Where is the data processed and stored, and in which country or countries?
  • How long does the service keep uploaded audio and the resulting text?
  • Is any data used to train or improve the provider's models?
  • Who at the provider can access the data, and under what conditions?
  • Is the connection protected in transit, and how?
  • Does the provider act under an agreement with your institution, or under its standard terms?
  • What did participants agree to, and does this processing fall within it?
  • How will transcript accuracy be checked before analysis?

Prepare answers before you submit. Vague statements such as "a secure AI service" tend to bring the application back with questions.

Mapping the data flow

A simple data-flow map makes risks visible and gives the review board something concrete to assess. Draw or list every place the data goes, from recorder to archive:

  1. Capture: recorder or phone, and where its files are stored.
  2. Transfer to your computer or institutional storage.
  3. Preparation: any editing, trimming or conversion before upload.
  4. Upload: what leaves your device, to whom, over what kind of connection.
  5. Processing: what the service does, which components handle the data.
  6. Return: what comes back, and where you save it.
  7. Retention at the provider: how long each part is kept.
  8. Your copies: working transcripts, analysis files, backups, and when each is deleted.

For each step, note who can access the data and whether it is identifiable. Gaps in the map, such as "unknown" for where processing happens, are exactly what you should resolve with the provider or your institution before proceeding.

Risk assessment

Risk depends on your data and participants, not just the tool. A recording of professionals discussing workplace software carries different risks from a recording of undocumented migrants describing their journeys. Consider:

  • Sensitivity of content: health, sexuality, criminal activity, immigration status, political views or abuse raise the stakes considerably.
  • Identifiability: whether voices, names, places or stories could identify people.
  • Vulnerability: children, people in care, people at risk of reprisal.
  • Consequences of a breach for participants.
  • Consequences of transcription errors: a misheard negation in a quote can attribute the opposite view to someone. The article on Whisper-style hallucinations describes how recognition models can produce text nobody said.
  • Alternatives: transcribing yourself, an institutionally contracted transcriber, or software that runs entirely on your own computer.

Some projects reduce risk by trimming the consent preamble or identifying introductions from the file before upload, using pseudonyms during the interview itself, or transcribing only the least sensitive recordings automatically and the rest by hand. The comparison of AI and human transcription sets out other trade-offs, including confidentiality.

Hypothetical: two studies, two decisions

A health sciences department reviews two applications in the same month. The first study interviews hospital managers about procurement processes; the researcher proposes an automatic service, maps the data flow, cites the provider's deletion window and privacy policy, and adds a consent sentence. The board approves it with a request to correct all transcripts against the audio. The second study interviews people in recovery from addiction about relapse; the board asks the researcher to justify external processing given the sensitivity, and she chooses to transcribe the recordings herself on an encrypted laptop. Both decisions follow from the same questions applied to different risks.

Documenting the tool

Methods sections and audit trails increasingly record transcription tools with the same care as analysis software. Record:

  • The service name, and the speech recognition model if the provider states it.
  • The date or period of use, since services change.
  • Settings used, such as language selection.
  • What was uploaded, and any pre-processing.
  • How transcripts were checked: who listened, how much of each recording, what was corrected.
  • Known limitations, such as no speaker labels or a tendency to drop fillers.

A sentence in the methods section might read: "Recordings were transcribed automatically using [service], then checked in full against the audio and corrected by the interviewer, who also added speaker labels and anonymized identifying details." Your audit trail can hold the detail. The article on managing research recordings covers where those records fit in a data management plan.

Risks of getting it wrong

  • Uploading before approval, then discovering the consent form did not cover it.
  • Relying on a provider's marketing summary instead of its privacy policy and terms.
  • Treating automatic transcripts as accurate without checking, so errors enter quotes and findings.
  • Using a personal account on a service your institution has not assessed.
  • Forgetting copies: results emailed to yourself, downloaded files left in a shared folder.
  • Assuming that because a tool is popular, it must be acceptable for sensitive research.

Facts about mydubly for your ethics application

If you are considering mydubly, these are its data-handling facts, stated without any claim that it satisfies a particular regulation, ethics standard or institutional policy. Only your ethics board and institution can decide that.

What stays on your device
The video picture of video files; the browser decodes audio locally
What is uploaded
Audio only, downmixed to mono, cut into chunks of roughly 30 seconds and compressed, sent over HTTPS
Speech recognition
Whisper large-v3-turbo in the default deployment (a deployment can use OpenAI's whisper-1 instead)
Translation, if requested
A translation engine configured in the deployment
Retention
Uploaded audio chunks and results deleted within 30 minutes of a job finishing; unfinished jobs expire after 24 hours
Training
The privacy policy states user data is not used for training
Outputs
Plain and timestamped transcripts, SRT and VTT files, downloaded to your device
Not provided
Speaker labels, storage of your files, any institutional agreement or certification

Questions this table does not answer, such as where servers are located or which sub-processors are involved, should be put to the provider and checked against the current privacy policy before you submit. The private video translation page explains the processing model, and the article on cloud speech processing privacy lists questions worth asking any provider. Transcription costs one credit per minute, minimum five credits.

Next step

Draft your data-flow map and the answers to the review board questions above for the specific service you want to use, then take them to your supervisor and ethics office before any participant audio is uploaded. If approval is granted, keep the documentation with your project records and follow the step-by-step guide to transcribing audio on a non-sensitive test recording first, so you know exactly what the tool produces.

Frequently asked questions

Do I need ethics approval to use AI transcription?

If your study needed ethics approval, the use of a third-party transcription service is usually something the board expects to know about, and participants may need to be told. Requirements differ by institution and country, so ask your ethics office. Do not upload participant audio until you know the answer.

Is it enough that a transcription service uses HTTPS?

HTTPS protects data in transit, which is necessary but only part of the picture. Boards also ask about where data is processed, how long it is kept, who can access it, whether it is used for training and what participants agreed to. Gather those facts from the provider's privacy policy and terms.

What should consent forms say about automatic transcription?

In plain language, that recordings will be transcribed by software run by an external provider, what is sent, how long the provider keeps it if known, and that the research team will check the transcript. Use your ethics board's template wording if one exists, and make the details match the actual service.

Can I use AI transcription if my consent form did not mention it?

Ask your ethics board before doing so. Depending on the study and the board, you may need an amendment, re-consent from participants, or to transcribe without an external service. Do not assume that general wording about transcription covers a third party.

Does mydubly meet my university's requirements?

mydubly makes no claim to meet any regulation, ethics standard or institutional policy. You can give your institution its factual data handling: audio-only upload in chunks over HTTPS, deletion within 30 minutes of a job finishing, and a privacy policy stating user data is not used for training. Your institution decides whether that is acceptable.

How should I report AI transcription in my methods section?

Name the service and model if known, the period of use, what was uploaded, and how transcripts were checked and corrected, including who did it. Mention relevant limitations, such as the absence of speaker labels. Keep fuller detail in your audit trail.

Are on-device transcription tools always the safer option?

Processing everything on your own computer avoids sending audio to a third party, which can reduce risk for sensitive data. It does not remove other risks, such as insecure storage, unencrypted laptops or inaccurate transcripts. Weigh accuracy, practicality and your board's view alongside where processing happens.