Is a full backup file encrypted on iPhone?
Short answer: no, not by itself. Making a full backup produces an ordinary JSON file, and a JSON file has no lock built into the format, regardless of what app wrote it or how much it contains. Inside the app, everything sits behind your iPhone's own passcode-derived encryption. The instant a backup exists as a standalone file, that is no longer the protection doing the work.
People tend to ask about encryption before exporting a single transcript, and think less about the one file meant to carry an entire library at once. That is backwards from how much is actually riding on each file: a full backup is not one recording's words, it is all of them, which makes the question of what protects it afterward worth answering properly rather than assuming it inherits some extra safeguard for being labelled "backup."
What is actually inside the file
A full backup is a single JSON file covering every recording in the library at once — title, date, duration and transcript for each one, built to restore the app to the state it was in rather than to be read line by line. It does not include the audio itself; the recordings stay as separate .m4a files, shared on their own if you want copies of the sound. What the backup does carry, all in one place, is every transcript you have — which is exactly why it is worth treating differently from a single export.
What protects it while it is still inside the app
Before you tap anything in Settings, that data is not a separate file at all — it is part of the app's own storage, and on iPhone that storage sits behind device-level encryption with a key derived from your passcode. A locked phone with no passcode entered is not handing that data to anyone, the same guarantee that covers the recordings, photos and messages sitting alongside it. Nothing about a backup being "everything at once" weakens that; it is still just data inside the app until you export it.
What creating the backup actually does
Building the backup turns that protected, in-app data into an ordinary file — handed off through the same share sheet as anything else, or found afterward sitting in the Files app. JSON is a plain-text format. It has no password field, no lock, nothing that requires a key to open, because being readable by any program on any device is the entire reason to export a file in that format in the first place. An app does not wrap its own backup in extra encryption on top of that, for the same reason a transcript export is not wrapped either: doing so would mean inventing a private format nothing else could open, which defeats the point of a backup that is supposed to be restorable later, possibly by a version of the app that no longer exists.
Why this file deserves more care than a single export
A single transcript export puts one recording's words at risk if it ends up somewhere it should not. A full backup puts all of them there at once — every title, every date, every transcript you have ever kept, sitting in one file with a name that makes its contents obvious. That is not a reason to avoid making one; a backup you never make cannot save you when you actually need it. It is a reason to be more deliberate about where that particular file goes than you might be about a single transcript you are sending to one person for one reason.
Where it lands, and what actually protects it there
Files, kept on the phone
A backup saved "On My iPhone" sits behind the same device encryption as everything else local to the phone — no different in that respect from the app's own storage a moment earlier.
Files, synced to a cloud folder
Save it into a folder tied to a cloud storage service instead, and its protection now depends on that service's own account security, not on the phone or the app the backup came from. That is worth knowing before a backup ends up there by default rather than by choice.
Email, messages, AirDrop
Send a backup to yourself or hand it to someone else and the file becomes a question about that channel, the same as any attachment — iMessage encrypted in transit between two Apple devices, an SMS not, an email protected however the provider and the recipient's device happen to protect it. None of that has anything to do with the app that produced the file.
Closing the gap yourself
- Keep it "On My iPhone" rather than a folder synced to a cloud service, unless that service's own account security is one you already trust with everything else in it.
- Make a fresh one when you actually need it — before a new phone, before a reinstall — rather than letting old copies sit scattered across a cable transfer, an old email and a forgotten folder.
- Treat sending it to anyone else, even yourself, as handing over a copy you no longer fully control from that point on.
- Remember it is built to be restored, not read — there is little reason for it to live anywhere you would not also be comfortable storing every transcript you have, individually, in plain text.
How Voice Studio fits in
Settings has one full backup: a single JSON file with every recording's title, date, duration and transcript, meant to restore the library rather than to be opened and read. It carries no encryption of its own, for the same reason a TXT or JSON transcript export does not — a plain, restorable file is the entire point. There is no account and no CloudKit sync moving that file anywhere on its own; it goes exactly where you choose to save or send it, through the ordinary share sheet, and nowhere else. What protects it once it exists is the same thing that protects any file you create yourself: where you decide to keep it.
Common questions
Is a full backup file protected the same way the app's own storage is?
Only until it exists as a separate file. Inside the app, everything sits behind your iPhone's passcode-derived device encryption. The moment you export a backup, it becomes a plain JSON file with no encryption of its own — what protects it afterward depends on where it lands.
Does the backup include the audio recordings, so is less actually at risk than it sounds?
The audio is not included — a backup covers every recording's title, date, duration and transcript, not the .m4a files. That still means every transcript in your library sits in one file, which is worth treating with more care than a single export, not less.
Is it safer to keep several copies of a backup in different places?
Not really. Each additional copy is one more place the same complete set of transcripts could end up exposed. A single, deliberately stored copy, refreshed when you actually need a current one, is easier to account for than several scattered ones.
Does Voice Studio encrypt the backup file it creates?
No. It is a plain JSON file, the same as a TXT or JSON transcript export — no password or lock built into the format, and no extra encryption added on top, since a backup only works if it can be read back in and restored later.
Try it in Voice Studio
Voice Studio records, transcribes on your iPhone, and files each note by time and place — so the thought you had in the car is still findable next month.
Free to download · iPhone and iPad · iOS 16.4 or later