Privacy Policy
Last updated: 2 October 2026
This Policy describes how Audinote collects and uses information when you use our meeting transcription service.
1. Data we collect
Account data: name, email, authentication provider identifiers and profile fields you provide. Usage data: credit buckets, transactions, meeting metadata and operational logs. Content: audio and derived transcripts or summaries. Stripe processes payments; we store customer/subscription identifiers, not full card numbers. Billing requests contain your message, optional transaction reference, status and administrative reply. Administrative role, credit and plan changes have audit records.
2. How we use data
We use data to authenticate you, provide transcription and summaries, bill for credits, prevent abuse, improve reliability, and comply with law. We do not sell personal data.
3. Processors
We use infrastructure and processing vendors for hosting, storage, payments, transcription, summaries, and speech generation. Examples include Cloudflare for hosting/storage and Stripe for payments. Speech processors receive the content needed to fulfill your request under their own terms and our configuration.
4. Retention
We retain account and billing records while your account is active and as required for legal/tax purposes. Meeting audio and transcripts may be deleted according to product retention settings or when you delete content/account, subject to backup windows.
5. Your choices
You can update profile details, link or unlink social logins, manage billing via Stripe’s portal, and request account deletion at /delete-requests or by contacting support. Browser language and theme preferences are stored locally on your device.
6. Security
We use industry-standard controls appropriate to a cloud SaaS (HTTPS, access controls, secret management). No method of transmission is 100% secure.
7. International users
The service may be hosted in regions chosen for performance and availability. If you access Audinote from another country, your information may be processed outside your home jurisdiction with safeguards appropriate to our providers.
8. Children
Audinote is not directed at children under 16. We do not knowingly collect personal data from children.
9. Changes
We may update this Policy by posting a new version with an updated date. Continued use means you acknowledge the revised Policy.
10. Contact
For privacy questions, sign in and submit a billing/support request at /account/billing. Request account deletion at /delete-requests. Do not include card numbers or unnecessary sensitive data in messages.
11. API data
For API requests, we process the audio or text you submit through our configured speech providers to return the requested output. We store hashed API key secrets and key identifiers and usage records, including model category, units, credits charged, status, and timestamps. API usage records do not store the submitted audio or text. Administrators can see route and estimated provider cost data. Private asynchronous speech source audio and results use expiring access grants and expire after 24 hours.
12. Connected AI applications (MCP)
When you authorize an MCP client, it can read your meeting notes, transcripts, summaries, exports and credit balance under the permissions you approve. Write permission also allows it to request summaries. Existing API keys allow these owner-only MCP operations. Connected clients may retain information they have already received under their own policies. We store client registration, consent and expiring token records to control access. Revoke OAuth access at /account/connections or API keys at /account/api; revocation stops future requests and cannot erase copies already held by a client.
App assistant
When you use the app assistant, your typed messages and recent chat context are sent to the configured AI provider for app guidance. The assistant does not automatically retrieve your meetings, transcripts or account data. Audinote does not persist chat messages on the server; they remain in browser memory until you clear the chat, reload, sign out or change users. Do not paste passwords, API keys or sensitive information. The configured provider may retain messages under its own terms.