This policy explains how Capta processes the personal data of people who use the iPhone and Android app and related services (for example sharing links). For the capta.fyi website, see the website privacy notice.
We have tried to write it clearly. If something isn’t clear, write to privacy@capta.fyi.
In short
- You record a conversation: the audio is saved on your phone and, if you choose, sent to our servers for transcription and AI analysis.
- For this we use specialised providers (AssemblyAI, Gladia, OpenAI). We ask your permission before sending them anything, and you can withdraw it at any time.
- We don’t sell your data, don’t use it for advertising and don’t use it for anything other than the service.
- Transcripts stay available for 90 days, except the ones you protect. You can delete everything whenever you want.
- Some providers process data in the United States, with the safeguards required by the GDPR.
Controller
The controller is Alessandro Colombo, Via E. de Amicis 59, Cornate d'Adda (MB), Italia.
We have not appointed a Data Protection Officer, as this is not mandatory for our activity. You can use the contacts above for any request.
What data we process and why
| Data | Why we process it | Legal basis |
|---|---|---|
| Account: email, password (stored as a hash), Google or Apple identifier if you sign in with them, language, usage mode (For me / For work), preferences | Create and manage your account, let you sign in on several devices | Performance of the contract (Art. 6(1)(b) GDPR) |
| Device identifiers: a random code generated by the app and a device secret key (we store only its hashed fingerprint), notification token, operating system | Make the app work without an account, protect access to your data, send you notifications | Performance of the contract; legitimate interest in security (Art. 6(1)(f)) |
| Audio recordings, including those you import (for example call recordings made by your phone) and Live mode audio | Transcribe and analyse conversations, let you replay passages | Performance of the contract |
| Transcripts and generated content: text, speaker segmentation, names you give to speakers, title, summary, tasks, appointments, decisions, emails, minutes, quotes, your questions and the answers, vector representations of the text used for search | Provide transcripts, summaries, search, answers and documents | Performance of the contract |
| Health data or other special-category data that may appear in conversations (for example during a doctor’s visit) | Only to provide the service you requested on that recording | Your explicit consent (Art. 9(2)(a) GDPR), which we ask for in the app before transcription and analysis |
| Purchases: product bought, date, store transaction identifier, credit movements | Credit your minutes, handle disputes and automatic refunds | Performance of the contract; legal obligation to keep accounting and tax records (Art. 6(1)(c)) |
| Security data: IP address, device and browser type, date and time of sign-ins | Protect your account, alert you to sign-ins from new devices, prevent abuse | Legitimate interest in security |
| Welcome-minutes anti-abuse register: encrypted, irreversible fingerprint of the email, Google/Apple identifier, device code | Prevent free minutes from being claimed repeatedly by creating new accounts | Legitimate interest in preventing abuse |
| Usage statistics: app usage events (for example “recording completed”, “document generated”), installation and user identifier | Understand how the app is used and improve it | Your consent (Art. 6(1)(a)), which you can give or refuse in the app |
| Technical error data from our servers | Detect and fix malfunctions | Legitimate interest in the proper functioning of the service |
| Communications with us: email and content of support messages, reports, privacy requests | Reply to you and handle requests | Performance of the contract; legal obligation (for privacy requests and reports) |
| Consents: which consents you gave or withdrew, and when | Prove that consent was collected correctly | Legal obligation (Art. 7(1) GDPR) |
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Artificial intelligence is only used to generate texts for you (summaries, answers, documents).
What stays only on your phone
- Audio waiting to be uploaded and a copy of your transcripts, so you can read them offline.
- Appointments you add to the calendar: Capta writes them to your phone’s calendar after you confirm, but does not read your calendar or send it to us.
- If you turn on automatic detection of call recordings (some Android phones only), the app checks the recordings folder on your phone. No file leaves the phone until you choose to transcribe it.
Other people’s voices
Your recordings often contain other people’s voices and words. You decide what to record: that’s why the Terms of service ask you to inform the people taking part in the conversation and, where the law requires it, to obtain their consent. Capta reminds you before every recording.
We process this information only to provide the service to you. We cannot inform every recorded person directly, because we don’t know who they are: Art. 14(5)(b) GDPR applies. Anyone who believes they have been recorded and wishes to exercise their rights can write to privacy@capta.fyi.
Artificial intelligence and providers
To transcribe and analyse conversations we rely on specialised providers acting as our processors (Art. 28 GDPR), under contracts that limit the use of data to the service they provide to us.
| Provider | What it does for us | Data involved | Where |
|---|---|---|---|
| AssemblyAI, Inc. | Audio transcription (including real-time, Live mode) | Audio | United States |
| Gladia SAS | Transcription for some languages | Audio | European Union (France) |
| OpenAI (OpenAI Ireland Ltd. and OpenAI, L.L.C.) | Title, summary, answers, documents, Live suggestions, search; backup transcription if the main service is unavailable | Transcript text, questions, rarely audio | United States |
| Cloudflare, Inc. | Storage of audio files and exports, network and security | Audio, export files | Global network; headquartered in the United States |
| Railway Corporation | Application servers and database | All service data | United States or EU depending on the configured region |
| Google Ireland Ltd. / Google LLC (Firebase) | Push notifications; usage statistics, only with your consent | Notification token, recording titles in notifications; usage events | European Union and United States |
| Resend, Inc. | Sending service emails (email verification, security alerts, password reset) | Email address, email content | United States |
| Functional Software, Inc. (Sentry) | Server error monitoring | Technical data, identifier of the user affected by the error | United States |
Before sending audio to the transcription service, and text to the AI service, we ask for a specific consent in the app, naming the providers. You can withdraw it at any time in Settings → Consents: from then on we won’t send new content to those providers, but without them the related features are not available.
Your content is not used to train artificial intelligence models: we don’t do it, and our providers’ API contracts exclude it or let us exclude it. OpenAI may keep data sent via the API for up to 30 days solely for abuse monitoring, after which it is deleted.
Independent controllers. When you sign in with Google or Apple, or buy credits on the App Store or Google Play, Apple and Google process your data as independent controllers under their own policies. We only receive what we need: your identifier and email for sign-in; the purchase confirmation and identifier for credits.
Transfers outside the European Union
Some providers process data in the United States. In those cases the transfer relies on the European Commission’s adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR) for certified providers, or on the standard contractual clauses approved by the Commission (Art. 46 GDPR), with the supplementary measures offered by the providers. You can ask for a copy of the safeguards by writing to privacy@capta.fyi.
Sharing links
If you share a recording, we create a secret link. Anyone with the link can see the transcript, analysis, questions and answers and listen to the audio, until you revoke the link or delete the recording. Shared links are not indexed by search engines. When someone opens your link we don’t record who they are.
How long we keep data
| Data | Retention |
|---|---|
| Audio recordings, transcripts and generated content | 90 days from creation, then deleted. If you protect a transcript, it stays until you delete it. If you have an account, we remind you before it expires. |
| Deleted or expired content | Permanently removed within 7 days |
| Account | Until you delete it. After the request you have 30 days to change your mind; then we delete the account and content |
| Recordings made without an account | As above (90 days), or until you delete them |
| Data export files | 7 days |
| Technical logs of AI processing | 7 days |
| Security data (IP, sign-ins) | 6 months |
| Usage statistics (Firebase) | Up to 14 months, linked to the installation |
| Purchase records and credit movements | 10 years, for accounting and tax obligations |
| Welcome-minutes anti-abuse register | 5 years from the grant, even after account deletion (the email only as a hashed fingerprint) |
| Support messages | 24 months from the last communication |
| Content reports | 24 months from the report, even after account deletion (no longer linked to you) |
| Consent register | For the life of the account and up to 5 years after deletion, to demonstrate lawful processing |
| Backup copies | Overwritten on rotation within 30 days |
Security
We use encrypted connections (HTTPS/TLS) for all transfers, private storage reachable only through temporary signed links, passwords stored only as hashes, a secret key for each device, and access limited to strictly necessary personnel. No system is 100% secure: in the event of a data breach likely to put you at risk, we will inform you as required by law.
Your rights
You can ask us at any time to:
- access your data and get a copy (in the app: Settings → Export your data);
- correct it if it is inaccurate;
- delete it (in the app, or as explained on the Delete your account page);
- restrict its processing;
- receive your data in a structured format and port it to another service;
- object to processing based on legitimate interest;
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
Write to privacy@capta.fyi. We reply within one month; we may ask you to confirm your identity.
You also have the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or with the supervisory authority of the country where you live or work.
Minimum age
Capta is only for people aged 18 or over. We do not knowingly collect data from minors as users. If you believe a minor has given us data, write to us and we will delete it.
Mandatory and optional data
Without microphone access you cannot record; without sending audio to the transcription and AI services you cannot get transcripts, summaries and documents. Everything else is optional: you can use the app without an account (with some limits) and without usage statistics.
Changes to this policy
If we materially change how we process your data, we will tell you in the app or by email before the changes take effect. The date of the last update is shown at the top.