Version 2026-08-18. The Operator in the footer is controller for account, billing, security, support, and minimal product analytics data. Contact: klabocha@me.com. Where a business determines why and how third-party data is recorded, that business is the controller and the Operator processes content on its instruction under the Data Processing Addendum.
The device may contain recordings and imported audio or video, transcripts, summaries, Ask AI questions and answers, clients, projects, quotes, signatures, photos, and company and bank details. The app does not request location permission or collect location data. Apple Watch can transfer a recording to the paired iPhone. Users may allow compatible Bluetooth, wired, USB, or Car Audio microphones. The app does not capture phone-call audio. A system interruption pauses recording; optional resume applies after at least 30 seconds. Cloud recording sync between phones is not active.
In version 1.2.1 and later, before data is first sent to an external AI provider, the app presents processing information and requires acceptance of the current Terms and acknowledgement of this Privacy Policy. Audio, title, context, and technical metadata are uploaded only after the user knowingly requests AI processing. Re-summarization and Ask AI send the relevant transcript, question, and segments. The server does not retain the audio file. A processing result, including the transcript and summary, may be stored briefly only to replay a response after a connection failure without charging the usage allowance again. Anonymous technical account, purchase, usage, cost, security, company, SMS confirmation, attestation, and closed-set product event data may remain. Campaign /go links store only the platform, closed campaign and creative categories, device category, an allowlisted referrer domain, time, and a random click identifier. We do not store an IP address, full User-Agent, full referrer URL, or free text for this purpose, and detected bots are not stored. Product events never contain a recording, transcript, summary, document content, free text, or client data. The current release does not expose external identity-provider linking, does not obtain a login-provider email address, has push notifications disabled, and does not send crash reports to Sentry.
Processing relies on performance of the contract, legal obligations, legitimate interests in security, abuse prevention, diagnostics, legal claims and minimal product analytics, or voluntary consent for optional features. We do not sell data, use it for behavioral advertising, or train Operator models on conversation content without separate voluntary consent. What We Agreed does not make automated decisions that produce legal or similarly significant effects on a person.
Depending on the selected feature, providers include Cloudflare, Supabase, OpenAI or ElevenLabs, Google Gemini or Anthropic Claude, SMSAPI, and Apple for App Store purchases and subscription management. Sentry and Firebase integrations are disabled in the current release. Providers receive only data needed for the feature. Transfers outside the EEA use an appropriate legal mechanism, such as an adequacy decision or standard contractual clauses, and additional safeguards where required.
A Personal note is only for recording the user. A Client conversation requires participant notice and required consent or another lawful ground. In-app confirmation is a technical control and does not replace the legality assessment. The user is responsible for purpose, legal ground, scope, and third-party rights. Special-category or criminal-conviction data should not be processed without a clear legal ground and safeguards.
Local data remains until deletion or uninstall, subject to device backups. A recovery result expires after 18 hours and is regularly deleted so that its operational retention does not exceed 24 hours. Account deletion removes it immediately with the usage history. Minimal campaign-click data is retained for no more than 90 days to measure channel effectiveness and prevent abuse under the Operator's legitimate interests. It is not linked to conversation content or an account identifier, so account deletion cannot identify a specific click record. Account data is retained for the service and periods required by law, security, or legal claims. In-app account deletion removes server and then local app data. Before losing access, a user can create a one-time emergency deletion code in Settings for use on the website. The server stores only the code's SHA-256 hash and a new code invalidates the previous one. The web form deletes server data after a valid code, does not confirm code validity or account existence, cannot delete device files, and cannot cancel a store subscription. After deletion, we retain for up to 6 years only irreversible hashes of the technical account identifier and purchase references to prevent a delayed store notification from recreating deleted data and where needed for security and legal claims. This mechanism does not retain raw purchase tokens. Users may export data and exercise access, correction, deletion, restriction, portability, objection, consent withdrawal, and supervisory authority complaint rights. We use transport encryption, access control, authentication, data minimization, and device security controls.
Polski | Terms | B2B DPA | Support | Account deletion