Privacy Policy
Version 2026-09-04 · Last updated 4 September 2026
What we collect, why, how long we keep it, and your rights.
Controller
Mykhailo Kulinich, individual entrepreneur (FOP), Ukraine, 21 Nadii Kurchenko St., apt. 4, 84300 Kramatorsk, Donetsk region, Ukraine. Data protection contact: [email protected].
The short version
We process your speech to turn it into subtitles, and nothing else. Audio is never written to disk. Transcripts exist only if you turn them on, and they are deleted automatically.
Which third parties see your data depends on your processing tier, and this page says so explicitly rather than making a blanket promise. See the AI Transparency Notice for what the models do and how they fail.
What we process
We process the following categories of data:
- Account data: email address, name (optional), password hash, locale, sign-in timestamps.
- Audio stream: processed in memory in real time, never stored.
- Transcripts and translations: only when you enable saving for a session.
- Meeting fingerprint (company accounts only): a one-way hash of the call's address, kept with a saved transcript so that recordings of one call made by several colleagues appear as a single entry. The address itself is never stored.
- Usage metadata: session start/end, duration, target language, detected source language, number of utterances, confidence scores.
- Billing data: plan, minute-balance transactions, Paddle customer identifier. Card details are handled by Paddle, our merchant of record, and never reach our servers.
- Consent records: type of consent, policy version, timestamp, IP address, user agent.
- Device sessions: user agent and IP of active sign-ins, so you can revoke them.
- Country of your request, derived from your IP address by our proxy when you register or pay. It is used only to check sanctions restrictions and is discarded immediately — we do not store it against your account and we do not track your location.
Legal bases (GDPR Art. 6)
- Performance of a contract: providing translation, billing you.
- Legitimate interests: security, fraud prevention, service reliability.
- Consent: optional transcript storage, marketing email, non-essential cookies.
- Legal obligation: retaining invoices for tax purposes, and checking that we are allowed to serve you at all under applicable sanctions law.
Where processing happens — and it depends on your tier
SHARED TIER (the default): your audio is sent to third-party AI providers for speech recognition and translation. Those providers process it on their infrastructure under contract with us. They are listed on the Subprocessors page.
"Your audio" normally means the sound the chosen tab is playing. If you have switched on both saving a conversation and adding your own replies to it, it also means your microphone, and that audio goes to the same speech recognition provider — for transcription only, never for translation. Both are processed in memory and neither is stored. Switching either one off stops it immediately.
With dubbing set to the AI voice, the translated text is also sent to a speech synthesis provider, which returns audio for us to play. Nobody's real voice is involved: the synthetic voice is generated from text and is not modelled on the speaker. The audio is played and discarded, exactly like the audio coming in. With dubbing set to the browser voice, nothing leaves your machine at all — your own browser does the speaking.
LOCAL TIER (enterprise): processing runs on infrastructure we control, and audio is not sent to any third-party AI provider.
We state this distinction plainly because it matters: the phrase "your data never leaves our infrastructure" is true only for the local tier, and we will not claim it for shared-tier customers.
Retention
- Audio: not retained. In memory only, for the duration of processing.
- Transcripts: private accounts keep them 24 hours — long enough to download the file, which the extension does for you automatically at the end of the conversation — and a scheduled job deletes them after that. Company accounts keep them up to 30 days in the company admin panel, and the company may shorten that.
- AI summaries of saved conversations: stored inside the conversation they summarise, and deleted with it — they never outlive the transcript they were written from.
- Conversation recap emails (off by default, switched on by you in the dashboard): when they are on, the summary and the details of each finished conversation are sent to your address through our email provider, listed on the Subprocessors page. A sent email is in your mailbox, not in our system: we cannot delete it later, and the link inside stops working once the conversation is deleted or expires.
- Session metadata: 24 months, for billing disputes and capacity planning.
- Invoices and minute-balance ledger: as required by tax law (typically 7-10 years), in a form no longer linked to your identity after account deletion.
- Consent records: for the duration of the account plus the applicable limitation period.
Your rights
Under GDPR you can access, rectify, erase, restrict, port and object to processing of your data. Two of these are self-service in the dashboard:
- Export (Art. 15 and 20): download everything we hold about you as JSON and as a readable text file.
- Deletion (Art. 17): delete your account. Personal fields are anonymised immediately and access is revoked; a scheduled purge removes the rest.
- For anything else, or to complain, contact [email protected]. You also have the right to lodge a complaint with your local supervisory authority.
California residents (CCPA/CPRA)
We do not sell personal information, and we do not share it for cross-context behavioural advertising. You may still exercise your Do Not Sell or Share right using the link in the footer.
You have the right to know, delete, correct, and to non-discrimination for exercising these rights.
International transfers
Our infrastructure is hosted in the EU. Where a subprocessor processes data outside the EEA, transfers rely on Standard Contractual Clauses. The Subprocessors page names each one and its location.
Biometric data
We do not create voiceprints or voice embeddings, we do not attempt to work out who a speaker is, and we never match a voice against any other conversation or against anything outside the one it was spoken in.
Our speech provider does separate voices within a single conversation, so that turns can be labelled “Speaker 1” and “Speaker 2” in the subtitles and in a saved transcript. That separation exists for the length of that one conversation, attaches to no identity, and is discarded with the audio. It is not a biometric identifier and is not used as one.