Apple used its September 2026 launch event to enter a feature category it has mostly avoided until now: ambient listening. Siri Recap, Live Rewind, Music Recognition with Shazam, and Sound Recognition all landed on the Apple Watch Series 12 and Apple Watch Ultra 4. All four depend on the watch microphone picking up sound around you far more often than any previous Apple product has.
Siri Recap listens for conversations throughout your day and turns them into short AI summaries you can check later. Live Rewind is smaller in scope but arguably more useful day-to-day. It transcribes the last 15 seconds of whatever was just said with a double-press of the crown. This is perfect for catching a name, a book title, or directions you missed the first time. Music Recognition uses Shazam to identify songs playing nearby without you lifting a finger, much like Now Playing on Google’s Pixel devices. Sound Recognition is a useful accessibility feature that listens for sirens, doorbells, and alarms to alert users who have a hearing impairment.
How Apple Says it keeps what the Apple Watch hears private
None of these features work without a watch that’s always listening in some sense. That part is bound to make people feel uneasy, and Apple clearly knows it. Which is why the company published a privacy overview alongside the announcement, laying out exactly how these features process audio.
At the center of the whole Audio Intelligence system is something Apple calls the Secure Exclave. This hardware compartment built into the new S11 chip is completely isolated from the user, third-party apps, and even Apple itself. The company explains that audio captured by the watch’s microphone goes straight into that walled-off space where a lightweight on-device model checks for speech, sound, or music without transcribing or saving anything.
Apple
When Siri Recap detects a conversation, the audio is encrypted and sent to the Secure Exclave on the paired iPhone. Once that transfer finishes, the copy on the watch is permanently deleted. On the iPhone, on-device speech recognition converts that audio to text. A second on-device model condenses it to less than half its original length, and the raw audio is deleted for good. Only that condensed text gets encrypted again and sent to Private Cloud Compute.
It travels along with a bit of context, like whether music was playing or what is on the calendar, to help generate an accurate title. Apple says the finished summary comes back encrypted, lives in the Siri app, and deletes itself after seven days unless saved. It also syncs across devices, end-to-end encrypted, if iCloud with two-factor authentication is turned on.
Apple
Live Rewind works the same way on a smaller scale, and it comes with a nice touch competitors keep getting wrong. An audible chime and a full-screen animation play every time you use it. This happens even if the watch is silent, making sure people around you know you used the feature.
How Apple’s privacy measures hold up against competitors
I’ve read a lot of corporate privacy documents that amount to marketing dressed up as engineering, but Apple’s Audio Intelligence Privacy Overview is not that. Routing raw audio through hardware that even Apple can’t query is a major step to ensure privacy. Deleting it within seconds of transcription and requiring an opt-in plus granular scheduling controls before any of this activates is a meaningfully higher bar than a simple promise to trust the company. That isn’t true for several competitors.
Bee, the company behind the $50 wearable that continuously listens to everything you say, claims it processes raw audio in real-time and deletes it right after. That sounds close to the pitch from Apple, but Bee’s privacy policy clearly highlights how it extracts far more than ephemeral sound clips. The company collects transcripts, voice patterns, location data, health information, and much more, all of which get sent to cloud servers.
Bee
What’s even worse is that Bee was acquired by Amazon, a company that doesn’t have a stellar track record when it comes to user privacy. It has previously handed Ring doorbell footage to police without a warrant and even employed contractors to analyze customer voice recordings. Ring has now made it mandatory for law enforcement to furnish a warrant before requesting access to footage. Additionally, the new TAKE (Throw Away the Key Encryption) system locks the video footage using rotating encryption keys so that only you have private access to it.
While Bee maintains it only records people who give verbal consent, without chip-level guardrails, that is just a policy promise you have to take on faith. The Limitless Pendant attempted to solve the ambient recording problem with Consent Mode, a software feature designed to pause recording when it hears an unfamiliar voice. However, Limitless’ privacy policy explicitly confirmed that your data still left the device, noting that transcripts and audio outputs were sent to external cloud servers and third-party AI tools.
Limitless
Making matters worse, Limitless was acquired by Meta, placing users’ everyday conversations inside the ecosystem of a tech giant with a notorious history of privacy blunders. Limitless stopped selling the Pendant to new customers in December 2025, but that’s not the end of the story. Meta is reportedly developing its own always-listening AI pendant, so the same idea looks set to resurface under Meta’s own name.
There’s little reason to expect Meta’s version to behave any differently, given the track record already on display in the company’s current product line. The company saves voice interactions to the cloud by default for US users and uses human reviewers to check when its assistant mishears a wake word. Meta says you can review and delete that voice log yourself. That is true, but it’s an opt-out choice for a feature most people never asked to have turned on. The company is also reportedly testing super-sensing prototype glasses that would capture continuous audio and photos throughout the day. That’s especially concerning in light of a class action lawsuit filed against the company this March.
Andy Boxall / Digital Trends
The lawsuit alleges that footage from Ray-Ban Meta glasses was routed to contractors in Kenya for AI training labeling. Meta disputes the allegations and says its review practices are consistent with the rest of the industry. Whatever the lawsuit ultimately finds, the underlying pipeline it describes involves footage leaving the device and landing in front of a human reviewer somewhere. That is exactly the kind of thing Apple prevents with its Secure Exclave.
Even purpose-built AI recorders that promise better privacy fall into the same trap. The Plaud NotePin might seem closer to Apple’s approach at first glance. The company claims it deletes audio immediately after transcription as long as you keep its cloud sync feature turned off. But a deeper look at its privacy policy shatters that illusion.
Nirave Gondhia / Digital Trends
Plaud strictly requires cloud synchronization for its desktop and web apps to function at all. It does not process your audio on device. Instead, it ships your voice off to third-party AI providers to generate transcripts and summaries. The company even extracts data from your recordings to build personalized profiles and uses hashed email identifiers for its own marketing. Turn cloud sync on, and your recordings stay on Plaud servers until you manually delete them. Your privacy is left entirely in the hands of a toggle and corporate promises. That is a stark contrast to hardware that physically cannot store or read raw audio regardless of your settings.
None of this is to say that these companies are lying about how they process your data. The audio deletion claims from Bee and Plaud check out so far. But every single competitor still routes voice data through a server that someone could, in theory, query or break into. Against that field, Apple’s willingness to build the restriction at the silicon level is a bit more reassuring. That isn’t true for several competitors, and the three covered here are only a small slice of the ambient listening devices already on the market.
The guardrail Apple still hasn’t built
While Apple’s approach addresses privacy concerns an Apple Watch user may have, it doesn’t address the privacy of everyone else around them. The Secure Exclave guarantees that Apple cannot read what the watch hears, but it does nothing to stop the device from recording and analyzing the voices of friends, coworkers, or strangers all day long without their explicit consent.
Apple
Apple offers settings like Manual Control, Places, and Times to let users limit when Siri Recap runs, but relying on human etiquette to protect bystanders rarely works in practice. Live Rewind gets the social dynamic right by warning nearby people with a chime and a full-screen visual. The Limitless Pendant’s Consent Mode offers another practical template, and Apple should take inspiration from features like it to plug that remaining gap in an otherwise tight architecture.

