← Back to home

Courtesy translation. This English version is provided for convenience only. The legally binding document is the French original. In case of any discrepancy, the French version prevails.

Privacy Policy (GDPR)

This page explains how Audiostranscribe collects, uses and protects your personal data. If you have a question, write to us at [email protected].

📋 Table of contents

  1. Data controller
  2. Data collected
  3. Purposes and legal bases
  4. Subprocessors and transfers
  5. Retention periods
  6. Cookies
  7. Your rights
  8. Security
  9. Minors
  10. Changes
  11. Contact and complaints

Summary: AudiosTranscribe turns your audio recordings into AI-generated transcriptions and structured summaries. Audio is automatically deleted after processing. Transcriptions are kept for as long as your account is active, and are automatically deleted after 12 months of inactivity (free plan) or 24 months (paid plans). AI processing is performed by AssemblyAI (transcription and speaker identification, hosted in Ireland) and Google Cloud (summaries, storage and orchestration). Your data never leaves the European Union. Payments are handled by Stripe (no banking data is stored by us).

1. Data controller

The data controller is MTLABS, the sole proprietorship that publishes the AudiosTranscribe service.

GDPR contact: [email protected].

2. Data collected

2.1 Account data

2.2 Content data

⚠️ Caution: depending on the content you send, the audio and/or the transcription may contain personal data or even sensitive data. We recommend that you avoid sending information that you do not want to be processed by technical providers (see the "Subprocessors" section).

2.3 Payment data

Payments are handled by Stripe. We do not store any payment card data. We may retain technical information related to payment:

2.4 Desktop application

The AudiosTranscribe desktop application records the audio of your meetings locally on your computer (AppData folder). The files are then sent to our servers only if the automatic upload option is enabled or if you click "Send". Optional metadata (meeting name, participants, type, notes) is transmitted with the file to improve the quality of the transcription.

The authentication token is stored in encrypted form via your operating system's secure storage system (Windows Credential Manager).

2.5 Technical data

💡 Analytics: AudiosTranscribe does not use any advertising cookies, any third-party trackers in your browser, or any cross-site tracking. We only measure use of the service (key actions in the application) by means of technical events linked to your account identifier, for the purpose of improving the product. This measurement is carried out server-side, without any tracking cookie or advertising profiling. You can object to it (see "Your rights").

3. Purposes and legal bases

Purpose Data concerned Legal basis
Create and manage your account Email, user ID Performance of the contract
Transcribe audio and generate a summary Audio, transcription Performance of the contract
Manage billing and subscriptions Stripe ID, subscription status Performance of the contract + legal obligation
Ensure security and prevent abuse Technical logs Legitimate interest
User support Email, content provided to support Legitimate interest / performance of the contract
Measure and improve use of the service Account identifier, usage events Legitimate interest (right to object)
Send a meeting report by email to the recipients you enter, solely on your instruction Recipients' email addresses (entered by you, used for sending, never reused for prospecting purposes) Performance of the contract (at your request)
Attribute your sign-up to one of our own links (referral invitation, shared meeting report) The source of the link you arrived through (referral or share), recorded at sign-up. No tracker is stored in your browser: the information comes from the clicked link's address and is processed server-side. Legitimate interest (right to object)
Protect the deliverability of our emails (suppression list) Addresses that generated a permanent error or a complaint, kept so as never to solicit them again Legitimate interest (security and quality of mailings)

4. Subprocessors and transfers

We use technical providers (data processors within the meaning of the GDPR) to deliver the service:

  • Google Cloud: temporary storage of audio files (Cloud Storage), processing orchestration (Cloud Run) and generation of summaries by artificial intelligence (Vertex AI Gemini). Main processing in the European Union (Paris region for audio, multi-region EU for summary inference).
  • AssemblyAI: audio-to-text transcription and speaker identification (diarization). Processing in the European Union (Ireland). Audio files are automatically deleted from AssemblyAI servers at the end of processing.
  • Supabase: database and authentication, hosted in the European Union (Sweden).
  • Vercel: hosting of the web application, in the European Union (France).
  • Stripe: payment and billing. No banking data is stored by us (PCI-DSS Level 1). Governed by the European Commission's SCCs.
  • Resend: sending of transactional emails, in the European Union.
  • Upstash: anti-abuse protection (rate limiting), in the European Union (Germany).
  • Sentry: technical monitoring and error logging, in the European Union (Germany).
  • Cloudflare: DNS and distribution of the desktop application. May process technical data (IP address) as part of network routing. Governed by the SCCs.
  • PostHog: usage measurement and product improvement (usage statistics, feature testing). Data transmitted server-side, limited to an account identifier and usage events, without any transcription content or browser cookie. Hosting in the European Union (Cloud EU, Frankfurt). Company established in the United States, transfers governed by the standard contractual clauses (SCCs).

Data location: all main processing (audio, transcriptions, user account) is hosted in the European Union. No audio or transcription data is transferred outside the European Union. Stripe and Cloudflare may process technical metadata (IP, payment data) on global infrastructures, governed by the standard contractual clauses (SCCs).

5. Retention periods

5.1 Audio

Audio files are stored temporarily on Google Cloud Storage in region europe-west9 (Paris, France) only for the duration of processing. As soon as the transcription is complete, the audio file is automatically deleted from the server. If deletion fails, a lifecycle rule guarantees deletion within a maximum of 24 hours.

The processing flow is as follows: your audio file is uploaded to a server in France (europe-west9 Paris), processed by our transcription service also hosted in France (europe-west9 Paris), then the text result (transcription and summary) is saved in our database. The original audio is never kept after processing.

5.2 Transcriptions and summaries

Transcriptions and AI summaries are retained so that you can consult them, organize them into projects and export them at any time. The retention periods are as follows:

Inactivity is determined by the date of last login to your account. Automatic deletion concerns the text of the transcriptions stored in the database. The source audio files are deleted as soon as processing is complete (see section 5.1), regardless of account activity.

5.3 User account

Account data (email, identifier, subscription profile, acquisition source) is kept for as long as the account is active. In the event of voluntary deletion of the account, all data is deleted as soon as possible, with the exception of data strictly necessary to comply with legal and accounting obligations (e.g. invoices, in accordance with Article L. 123-22 of the French Commercial Code).

5.4 Billing

The data necessary for billing (invoices) is retained in accordance with legal obligations (e.g. accounting).

⚠️ Important: deletion in our systems does not necessarily immediately erase the technical traces strictly necessary for security or compliance (e.g. limited technical logs, legal obligations).

6. Cookies

Audiostranscribe only uses technical cookies and trackers necessary for operation (e.g. session, security). No advertising or marketing-tracking cookies are deployed to date. The marketing site may use privacy-respecting audience measurement, configured without advertising cookies or cross-site tracking.

We do not use any attribution tracker in your browser. When you arrive through one of our own links (a referral invitation or a shared meeting report), the source of that link is determined from the visited address and recorded server-side only if you create an account, to measure our acquisition channels. No information is stored on your device for this purpose, no cross-site tracking is performed, and this data is never shared with third parties. You can object to it (see "Your rights").

7. Your GDPR rights

You have the following rights:

To exercise your rights: [email protected]. We respond within a maximum of 30 days.

8. Security

We implement appropriate security measures, in particular:

9. Minors

The service is not specifically intended for minors and no systematic age verification is in place. Legal guardians remain responsible for the use of the service by a minor.

10. Changes

We may update this policy to reflect changes in the service or the legal framework. In the event of a significant change, we will inform users by an appropriate means.

11. Contact and complaints

For any question: [email protected].

If you believe that your rights are not being respected, you may lodge a complaint with the CNIL (French data protection authority).

Need a deletion / export?
Write to us at [email protected] and we will handle your request.
Contact GDPR support