In layman terms, simple answer would be "no, you should not be worried about privacy when using Hey Cortana feature". I believe you are not ready to accept more technical explanation (which previous commenters had already provided and you dismissed it). If you are so worried about privacy, you should NOT be using a smartphone. Companies like Google, Apple and Microsoft already know too much about you anyway. As said, any application running under lock screen can listen to you and send data anywhere without your knowledge. And you asked about terms & conditions, AFAIK, MS is stating that they are not sending any data nor voice sample to any servers, it stays on your device (and there is really no technical reason to do it otherwise). If I would be Microsoft and I would want to spy on you, I wouldn't really need Hey Cortana to do that and I would be already doing it for years.