Legal
Privacy Policy
Effective: August 9, 2026
1. Summary
Your recordings are yours. We do not train AI on them, sell them, or share them with anyone outside the narrow set of infrastructure providers required to deliver the service. Audio is encrypted in transit and at rest. You can delete any recording — or your whole account — at any time, and it is actually deleted.
2. Who we are
Recordd is a personal recording and transcription product. References to “Recordd”, “we”, “us”, or “our” refer to the operator of the website at recordd.co and the associated Mac, iOS, and browser-extension apps. Contact: privacy@recordd.co.
3. Data we collect
- Account data: your email address, authentication provider identifier (e.g. Apple or Google sign-in), display name, and an optional profile photo.
- Recordings: audio files you create, derived transcripts, summaries, action items, AI chat conversations scoped to a recording, and any tags, notes, attached people, or calendar associations you add.
- People library: records you create for speakers in your recordings (name, email, phone if you add it, photo). You can also import entries from your operating-system contacts to speed this up — the contact picker runs on your device with your permission, and only the specific entries you attach to a recording or link to a person are synced to our servers.
- Calendar context: if you grant calendar access, we read event titles, times, and attendees so you can attach a meeting to a recording in one click. We do not read event descriptions, locations, or unrelated calendars.
- Location (optional):if you enable location tagging, we store the approximate place name (e.g. “Munich” or a street address) and coordinates of each recording so you can find recordings by where they happened. Location is off by default and can be turned off at any time in Settings. We do not track your location outside of the moment you start a recording.
- Device and diagnostic data: minimal technical metadata required to operate the service (the platform you signed in from, the app version, and aggregated usage counters such as minutes recorded). We use Sentry to collect crash reports and performance traces so we can fix bugs — these are not linked to your account identifier and are not used for advertising or tracking. No browsing history, screen contents, or keystrokes.
- Billing data: if you subscribe, our payment processor (RevenueCat / Stripe) stores the information required to process payment. We receive a customer identifier and subscription status; we do not receive or store full card numbers.
4. How we use your data
We process the data above strictly to provide and improve the service you signed up for:
- To authenticate you and protect your account.
- To store, transcribe, summarize, and search your recordings, and to power features such as Chat-with-recording and AI-generated titles, action items, and people suggestions.
- To send you account-related communications (sign-in confirmations, receipts, important service updates). We do not send marketing email without your explicit opt-in.
- To detect and prevent abuse, fraud, and security incidents.
- To comply with legal obligations and to enforce our Terms of Service.
We do notuse your recordings, transcripts, or any other content you upload to train machine-learning models — ours or any third party’s.
5. Subprocessors
We rely on the following third-party providers to operate Recordd. Each is contractually bound by their own data-processing terms and we do not authorize any of them to use your content for training their own products.
- Supabase — authentication, database, and audio file storage.
- Deepgram — speech-to-text transcription. Audio is sent to Deepgram for processing and is not retained for training under our contract.
- OpenAI and/or Anthropic — used to generate summaries, titles, action items, and to power the Chat-with-recording feature. We use API tiers that explicitly disable training on your data.
- RevenueCat + Stripe — billing and subscription management. Used only if you subscribe.
- Vercel — hosting for the marketing site and service APIs.
- Sentry — crash-report and performance-trace collection. Receives error traces and diagnostic metadata, never your recordings, transcripts, or account content.
6. Microphone, system audio, and screen capture
The Recordd desktop app requests microphone and system-audio permissions to record the audio you choose to capture. Recording is always user-initiated. We never silently record. The macOS app uses ScreenCaptureKit to access system audio (the same API used by screen-recording tools); we do not capture video frames or screen contents.
7. Data retention
Recordings and associated data remain in your account until you delete them. Deletes remove the underlying audio, transcripts, summaries, and chat history within a short window across primary storage and backups (typically within 30 days). If you delete your account, all data we hold for you is removed on the same schedule. We retain a minimal amount of billing and security-log data for legal and accounting compliance.
8. Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted to a small set of operators using multi-factor authentication. Row-level security policies in our database ensure your data is only accessible to your account.
9. Your rights
Subject to your jurisdiction (including the GDPR, CCPA, and similar laws), you may:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Export your data in a machine-readable format.
- Delete your data and your account.
- Object to or restrict certain processing activities.
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, email privacy@recordd.co. We aim to respond within 30 days.
10. International transfers
Our subprocessors operate data centers in the United States and the European Union. If you are located outside these regions, your data may be transferred to and processed in either jurisdiction. We rely on appropriate safeguards (such as Standard Contractual Clauses) where required by law.
11. Children
Recordd is not directed to children under 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
12. Changes to this policy
We may update this policy as the product evolves. Material changes will be communicated via the app or by email to the address on file. The “Effective” date at the top reflects the current version.
13. Contact
Privacy questions and data-rights requests: privacy@recordd.co.