Privacy Policy

PRIVACY POLICY • AICHE TECHNOLOGIES

Effective Date: August 13, 2026


0) Summary of This Policy

This summary is for convenience only. It does not replace the full Privacy Policy. The full policy controls.

  • We don't keep your voice. Audio is processed, then deleted. We do not keep a copy.
  • Notes stay on your device. A temporary server cache also holds your recent text so you can recover a session. It clears 24 hours after your last recording on that device, so it lasts longer if you record every day. Cloud Sync is off by default, opt-in, and end-to-end encrypted. We store ciphertext. We cannot read it.
  • We only keep the account data we need. Email, billing metadata, and the custom vocabulary you save so transcription can use it.
  • We don't sell your data. Not your voice. Not your notes. Not your account. Full stop.
  • Your content is never used for AI training.

View our Live Trust Center →

1) Who We Are & The Scope of This Policy

Company Information

Company: AICHE Technologies, LLC Entity type: Delaware limited liability company Jurisdiction: Delaware, USA Privacy Contact: privacy@aiche.app

DPO and EU/UK Representative

As a U.S.-based company at our current scale, a formal Data Protection Officer is not required under GDPR. For all privacy matters, you can contact our dedicated privacy team directly at privacy@aiche.app. We will appoint a formal EU/UK representative if and when our scale of operations requires it.

Applicability

This policy applies to your use of:

  • The AICHE website (aiche.app and subdomains)
  • Desktop applications (Windows, macOS, Linux)
  • Mobile applications (iOS, iPadOS, watchOS, Android)
  • Obsidian Plugin (AICHE Voice for Obsidian)
  • Browser extension
  • APIs and developer tools
  • Any related services (collectively, the "Service")

Important Distinction:

  • Website: Uses analytics and ads cookies only after you accept, or never if your browser sends Do Not Track
  • Desktop Apps: No analytics, no tracking
  • Mobile Apps: Firebase Analytics for sign-in and subscription events only. No audio. No transcripts. No ad ID on Android
  • Obsidian Plugin and browser extension: Same content model as the desktop apps

User Categories

  • Individual Users: Personal accounts without business agreements
  • Business/Enterprise Users: Organizations with business agreements and DPAs

Our Roles (under GDPR)

  • For Individual Users: We act as the Data Controller for all personal data we collect
  • For Business/Enterprise Users: We act as a Data Processor for content processed under a Data Processing Addendum (DPA)

2) The Three Buckets: How We Handle All Data

All data we handle falls into one of three buckets.

Bucket 1: Account & Billing Data (to run your account)

This is the personal data about you that we keep on our servers.

Data PointWhat We CollectWhy We Need ItRetention Period
Account BasicsYour email address, name (optional)To create and maintain your account, authenticate you, and send essential service noticesWhile your account is active
Billing InfoSubscription plan, payment history (billing metadata via payment processor)To manage your subscription and comply with tax/financial lawsAs required by law (e.g., up to 7 years for invoices)
Custom vocabularyWords and names you saveSo transcription can spell them the way you wantWhile your account is active, or until you delete the entries

Bucket 2: Content Data (to provide the service to you)

  • Audio: The audio stream of your voice. We send it to our AI processors, get text back, then delete the audio. We do not keep a copy.
  • Text, default: The transcript returns to your device. We also hold a copy in a temporary server cache so you can recover a session. That cache clears 24 hours after your last recording on that device. If you keep recording, entries stay longer than a day. We keep no long-term transcript archive.
  • Text, public REST API: If you use our developer API, the job result holds the transcript so you can fetch it. We delete it 1 hour after the job completes.
  • Text, Cloud Sync on: You can turn on Cloud Sync. The note is encrypted on your device first. We store only ciphertext. We do not hold the key. We cannot read the note.
  • Why we need it: To perform speech-to-text and, if you turn sync on, to move your notes between your devices.
  • We never use any of this data to train AI models.

Bucket 3: Operational Data (to fix and secure the service)

  • What it is:
    • Minimal, anonymized service metadata (timestamps, error codes - never your text/audio)
    • Website analytics and ads cookies on aiche.app, only after you accept (see Section 5a)
    • Mobile sign-in and subscription events via Firebase Analytics
    • Support communications you send us
  • Why we need it: To monitor service health, measure the website, attribute a sign-up, and provide support
  • Retention:
    • Web server logs: 14 days. Application logs: rotated by size, so there is no fixed day count. Error records: 6 months. Anonymized transcription metadata, which never contains your text or audio: 3 years
    • Support tickets: Up to 24 months
    • Website analytics: Per provider retention settings, and only if you accepted cookies

3) How Your Data Flows: Our Technical Privacy Guarantee

The Data Journey

  1. Your Device (mic captures audio)
  2. Encrypted Transit (TLS 1.3+)
  3. Our processors (Groq, Google Generative AI, and/or DeepInfra handle the request)
  4. Encrypted Transit (TLS 1.3+)
  5. Your Device (text returned/pasted into your active application)
  6. Audio deleted (we delete the audio after processing; we do not keep a copy)

If Cloud Sync is off, the only thing left on our side is the transcript in our temporary recovery cache. That cache clears 24 hours after your last recording on that device. Nothing else about that recording stays with us.

If Cloud Sync is on, your device then encrypts the note and sends ciphertext to us. Other devices you authorize pull that ciphertext and decrypt it locally.

Our Core Pledges

  • No audio archive: We delete audio after processing. We do not keep a copy.
  • No long-term transcript archive: Transcript text sits in a temporary server cache for session recovery. It clears 24 hours after your last recording on that device, so it lasts longer while you keep recording. We build no searchable transcript store. Cloud Sync stores ciphertext we cannot read.
  • No AI Training: We strictly prohibit the use of your content to train any AI models
  • No Human Review: The process is fully automated. No human reviews your audio or your plaintext notes
  • Desktop App Privacy: Our desktop applications contain no analytics, no trackers, no telemetry

4) Sharing & Subprocessors

We use a small number of trusted service providers ("Subprocessors") to operate AICHE. We will never sell your personal information.

Infrastructure & Processing

  • Groq Inc.: Speech-to-text inference (processes the request, no retention)
  • Google Generative AI: Speech-to-text and text enhancement (processes the request, no retention)
  • DeepInfra: Speech-to-text and text enhancement fallback (processes the request, no retention)
  • Google Cloud Vertex AI: Text enhancement fallback. It receives transcribed text only, never your audio. We use it only when the providers above are unavailable
  • Hetzner & DigitalOcean: Server infrastructure
  • Stripe: Payment processing (PCI-compliant)
  • Google Firebase: Mobile sign-in and subscription analytics. Not used for audio or transcripts

Website-Only Services

These load on aiche.app only after you accept cookies, and never if your browser sends Do Not Track:

  • Google Analytics: Website visitor analytics (not used in desktop apps)
  • First-party product analytics (PostHog, self-hosted): Page views and session recording on aiche.app. Data stays on our servers
  • Meta Pixel (Facebook): Advertising conversion tracking and remarketing for AICHE's own ads (website only, not in apps)

Trust Center

A current and detailed list of our subprocessors is maintained on our Trust Center.

5) Your Privacy Rights & Controls

We believe you should have simple, powerful control over your information.

Your Privacy Controls

  • Delete Your Data: Delete your account from Account Settings. This erases your account data, your custom vocabulary, and any Cloud Sync ciphertext. We keep billing records only where tax law requires it
  • Manage Communications: Use the unsubscribe link in any marketing email. Account and billing emails always send
  • See Your Data: Email privacy@aiche.app and we send you a copy of your account and billing data
  • Fix Your Data: Email privacy@aiche.app to correct your name or email address

Your Additional Rights

You may also have the right to:

  • Object to or restrict certain processing
  • Data portability
  • Withdraw consent for optional processing
  • Lodge a complaint with supervisory authorities

To exercise any rights, contact privacy@aiche.app. We'll respond within 30 days.

5a) Cookies & Tracking

Website (aiche.app)

Our website uses:

  • Essential cookies: For session management and security. These are always on.
  • Analytics cookies: Google Analytics and first-party product analytics (including session recording), only after you accept
  • Marketing cookies: Meta Pixel (Facebook) for conversion tracking and remarketing of AICHE's own ads, only after you accept

We ask before we set analytics or marketing cookies. A cookie banner on aiche.app lets you Accept or Reject. Reject leaves essential cookies only.

If your browser sends a Do Not Track (DNT) signal, we treat that as Reject. We do not load Google Analytics, Meta Pixel, or PostHog.

You can change your choice later from the Cookies link in the website footer.

Desktop Applications

Our desktop apps use:

  • No cookies
  • No analytics
  • No tracking pixels
  • No telemetry

Obsidian Plugin

When you use AICHE Voice for Obsidian:

Data Collection:

  • Audio recordings are sent to AICHE servers for transcription
  • Device information: device ID, operating system, app version
  • Authentication tokens stored locally in your Obsidian vault

Data Processing:

  • Audio is processed, then deleted. We do not keep a copy
  • Transcribed text is returned directly to your device
  • We keep no long-term transcript archive. Transcript text sits in a temporary server cache that clears 24 hours after your last recording on that device

Offline Mode:

  • Failed recordings are encrypted locally using AES-GCM
  • Encrypted audio is stored in your vault until successfully uploaded
  • Once uploaded and processed, local encrypted data is deleted

Authentication:

  • OAuth flow via obsidian://aiche-auth protocol handler
  • Tokens encrypted at rest using Web Crypto API
  • Session can be revoked from account settings

Third-Party:

  • The Obsidian plugin interacts only with AICHE servers (api.aiche.app)
  • No data is shared with Obsidian or third parties

iOS, iPadOS, and watchOS

When you use AICHE on iOS, iPadOS, or watchOS:

Data Handling:

  • Audio is deleted after processing. We do not keep a copy
  • Text transcripts remain on your device under your control
  • A temporary server cache also holds recent transcript text. It clears 24 hours after your last recording on that device
  • If you turn on Cloud Sync, encrypted notes sync across your devices. We store ciphertext only
  • Your device's backup feature (iCloud, etc.) may include app data. Configure your backup settings according to your privacy preferences
  • You can delete all transcripts and history anytime from the app settings
  • Firebase Analytics records sign-in and subscription events only. It does not receive audio or transcripts

Android

When you use AICHE on Android:

Data Handling:

  • Same content model as iOS: audio deleted after processing, text on your device, optional end-to-end encrypted Cloud Sync
  • The same temporary server cache applies. It clears 24 hours after your last recording on that device
  • Firebase Analytics records sign-in and subscription events only
  • We do not collect the Android advertising ID (AD_ID)

Diagnostic Reports

Our desktop apps do not send crash reports on their own. When something goes wrong, you can choose to send us a diagnostic report. Nothing leaves your device unless you send it. We use the report only to fix the problem.

5b) U.S. State Privacy Rights & Disclosures

For Residents of California and other applicable states

  • Categories of Data: Account & Billing Information (Bucket 1), custom vocabulary, transcript text held in our temporary session cache, Cloud Sync ciphertext if you turn sync on, and website analytics if you visit aiche.app and accept cookies
  • Do Not Sell: We do not "sell" your personal information. We do not sell your voice, your notes, or your account.
  • Share for ads: If you accept marketing cookies on aiche.app, Meta Pixel may receive website visitor data so we can measure and show AICHE's own ads. That is not a sale of your account or content. You can Reject cookies, or send DNT, and this does not run.
  • Sensitive Information: We do not collect or process "sensitive personal information" to infer characteristics about you
  • Your Rights: You have the right to know, delete, and correct your information. Delete your account from Account Settings, or contact privacy@aiche.app for anything else
Our ActionLegal BasisYour Control
Provide the AICHE serviceContractDelete your account at any time
Secure our platform & prevent fraudLegitimate InterestsYou may object by contacting us
Send optional marketing emailsConsentYou can unsubscribe at any time
Keep billing & tax recordsLegal ObligationN/A (required by law)
Website analytics and ads cookiesConsentAccept or Reject on the cookie banner. DNT counts as Reject
Desktop app processingContractControl through app settings
Cloud Sync (optional)Contract / ConsentOff by default. You turn it on. You can turn it off

Legitimate Interests Balancing Test (Security)

When we rely on Legitimate Interests for security and fraud prevention, we perform a balancing test to ensure our interests don't override your fundamental rights and freedoms. We:

  • Assess necessity and proportionality
  • Minimize data collection (no audio archive, no long-term transcript archive)
  • Implement strong safeguards (encryption, access controls, limited retention)
  • Provide you the ability to object by contacting privacy@aiche.app

A summary of this assessment is on our Trust Center.

Website vs App Processing

  • Website visits: Analytics and ads cookies run only after you accept
  • Desktop app usage: Processing is strictly necessary for service delivery under our contract with you
  • The key difference: You can browse our website without an account. The apps require an account and process only what the feature needs

7) Security & Incident Response

We protect your data with these measures:

  • Encryption: TLS 1.3+ in transit, AES-256 for any local storage
  • Cloud Sync: AES-256-GCM on the device. Key derived from your passphrase with Argon2id. We never receive the passphrase or the key
  • Access controls: Role-based access, principle of least privilege
  • Regular audits: Security assessments and penetration testing
  • Secure development: Code reviews and security scanning

Incident Response Timeline Commitments

Detection & Triage: We continuously monitor for suspicious activity. Once aware of a potential incident, we initiate triage within 24 hours.

Containment & Assessment: We aim to contain confirmed incidents promptly and assess impact as quickly as possible.

Notification to Authorities: Where legally required (e.g., GDPR), we'll notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach.

Notification to Affected Users: We'll notify affected users without undue delay when a breach is likely to result in high risk to their rights and freedoms - generally within 72 hours of confirming material impact.

Status Updates: We'll provide follow-up updates as material information becomes available, and a final summary after closure.

Note: These timelines apply except in cases of force majeure or circumstances beyond our reasonable control.

Security Reporting

Report security issues to: security@aiche.app

  • We appreciate responsible disclosure
  • Please allow reasonable time for fixes before public disclosure
  • Security researchers may be eligible for acknowledgment

8) International Data Transfers

We're based in the United States. Here's how we handle international data:

Account & Billing Data

  • Processed in the United States
  • For EU and UK users, we transfer the data under Standard Contractual Clauses
  • For other regions, we use the transfer mechanism that local law allows

Content Processing

  • May be processed in the data center region closest to you for performance
  • Audio is deleted after processing
  • No audio archive means less transfer risk

Cloud Sync

  • Ciphertext may be stored in our infrastructure regions
  • We cannot read it

Website Analytics

  • Google Analytics and Meta Pixel process data according to their policies, and only if you accepted cookies
  • You can Reject cookies, send DNT, or use Google's opt-out tools

For more information, see our Trust Center and any region-specific disclosures we publish.

9) Children's Privacy

Our Policy

  • Service not directed to individuals under 13 (or 16 in EU/UK)
  • We don't knowingly collect personal information from children
  • If we learn a child provided information, we'll delete it promptly

For Parents

If you believe your child has provided us with personal information:

  • Contact us immediately at privacy@aiche.app
  • We'll verify and delete the information
  • We'll prevent future access if appropriate

Age Verification

  • We rely on users to provide accurate age information
  • Business/Enterprise accounts are responsible for ensuring their users meet age requirements

10) Law Enforcement Requests

Our Stance

  • We require valid legal process (e.g., court order) for any user data request
  • We don't keep audio after processing, so we have no audio to provide
  • We keep no long-term transcript archive, so there is no history to search
  • Cloud Sync ciphertext cannot be decrypted by us
  • We'll challenge overly broad or improper requests when appropriate

What We Can Provide

We hold very little, so most requests return very little:

  • Can provide: Account email, subscription status, billing records, custom vocabulary
  • Can provide, but only what is still in the session cache: Transcript text from a device that has recorded recently. That cache clears 24 hours after the last recording on that device, so on a device in daily use it can still hold older entries. Once it clears, we cannot recover it
  • Cannot provide: Voice recordings, any transcript older than that cache window, readable Cloud Sync notes

Transparency Commitment

We publish transparency reports on our Trust Center including:

  • Number of requests received by type and jurisdiction
  • Number of accounts identified in requests
  • Our compliance/rejection rate
  • Whether any audio or transcript content was provided
  • Number of requests we challenged

Warrant Canary

We maintain a warrant canary statement in our Trust Center. A warrant canary is a statement that, as of a given date, we have not received certain kinds of secret legal demands. If the canary is removed or not updated when we republish the Trust Center, it may indicate a change in circumstances.

Note: Legal restrictions may limit what we can say. A missing canary is not definitive proof of any specific event.

11) Common Privacy Questions (FAQ)

Q: Can any AICHE employee listen to my recordings? A: No. We delete audio after processing, so there is nothing to play back.

Q: Can any AICHE employee read my notes? A: The transcript sits in our temporary recovery cache in readable form until that cache clears, which happens 24 hours after your last recording on that device. On a device you use daily, it is present. Our process is automated and our policy forbids staff from reading your notes, but we will not pretend it is technically impossible during that window. If Cloud Sync is on, we hold only ciphertext and we do not have the key, so those notes we genuinely cannot read.

Q: Do you use my voice or text to train your AI? A: Never. Our privacy-by-design architecture and contracts with AI providers prohibit this.

Q: Do you sell my data? A: No. We do not sell your voice, your notes, or your account. We do not sell website visitor data either.

Q: Why does the website have a cookie banner? A: The website uses analytics and ads cookies for our own marketing. That is not a sale of your data. EU law still wants a yes or no. We ask. Desktop apps never see those cookies.

Q: What happens to my data if I'm offline? A: The app queues recordings locally in encrypted storage. When you're back online, they're processed and the audio is deleted after processing. The local queue is also cleared after successful processing.

Q: Can I use AICHE for confidential business conversations? A: Yes, with one detail you should know before you decide. We delete audio after processing, and your text stays on your device. A copy of the transcript also sits in our temporary recovery cache, which clears 24 hours after your last recording on that device. On a device you use every day, that copy stays. If that is unacceptable for a specific conversation, do not dictate it. Cloud Sync, if you turn it on, is end-to-end encrypted. For enterprise needs, we offer additional contractual protections via our Business agreements.

12) Changes to This Policy & Contact Us

Policy Updates

If we change this policy, we will:

  • Post the new version at aiche.app/privacy with a new effective date
  • Update the "Last Updated" date at the top
  • Maintain a change log on our Trust Center
  • Notify you by email or in-app notice for material changes

Where the law requires your consent for a new use of your data, we will ask for it.

Types of Changes

  • Minor changes (typos, clarifications): Posted without notice
  • Material changes (new data uses, new subprocessors): Posted, with email or in-app notice

Contact Information

For any questions about this policy or to exercise your privacy rights:

Email: privacy@aiche.app
Response time: Within 30 days (sooner for urgent matters)
Languages: English (primary), other languages as available

For other inquiries:

13) Automated Decision-Making

Current State

We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you within the meaning of GDPR Article 22.

What Our AI Does

  • Transcribes speech to text: A tool you control
  • Enhances text: Only when you request it
  • Does NOT: Make decisions about you, profile you, or determine your access to services

Your Control

  • You review and edit all outputs before use
  • You decide whether to accept AI suggestions
  • The AI is a tool, not a decision-maker

Future Changes

If we ever introduce automated decision-making that affects your legal rights or status:

  • We'll provide clear advance notice
  • Explain the logic involved
  • Offer human review options
  • Update this policy before implementation

14) Additional Disclosures & Regional Rights

For European Economic Area (EEA) and UK Residents

  • Legal basis for processing: See Section 6
  • Data Protection Authority: You may lodge complaints with your local DPA
  • Transfers: Standard Contractual Clauses for data transfers to the US

For California Residents

  • CCPA Rights: See Section 5b
  • Shine the Light: We don't share data with third parties for their direct marketing of their own products
  • Do Not Track: Our website honors DNT. We treat it as a Reject of analytics and marketing cookies

For Other Regions

We extend core privacy rights to all users regardless of location:

  • Access to your data
  • Correction capabilities
  • Deletion options
  • Portability features

Check our Trust Center for region-specific information.

15) Data Retention Summary

Data TypeRetention PeriodWhy
Voice audioDeleted after processing. We do not keep a copyPrivacy by design
Text (Cloud Sync off)On your device. A temporary server cache also holds it, and clears 24 hours after your last recording on that deviceLocal by default, with a recovery window
Text (public REST API job results)Deleted 1 hour after the job completesSo you can fetch your result
Text (Cloud Sync on)Ciphertext on our servers until you delete the note, turn sync off, or delete your accountSo your devices can share the note. We cannot read it
Custom vocabularyWhile your account is active, or until you delete the entriesNeeded for transcription
Account DataWhile account is activeService provision
Billing RecordsUp to 7 years after last transactionLegal requirement
Support TicketsUp to 24 monthsService continuity
Website AnalyticsOnly if you accepted cookies. Then per provider settings (Google Analytics: 14-26 months; Meta Pixel: per Meta's data policy)Service improvement and our own ads
Desktop App AnalyticsNone - we don't collect anyComplete privacy
Web server logs14 daysSecurity monitoring
Application logsRotated by size, no fixed day countDebugging and service health
Error records6 monthsFixing faults
Transcription metadata (duration, success, language, provider; never your text or audio)3 yearsService health and capacity planning

16) Privacy Policy Interpretation

Guiding Principles

This Privacy Policy should be interpreted:

  • In favor of user privacy when ambiguous
  • Consistently with our Core Pledges
  • Reasonably and in good faith
  • With recognition that desktop apps, mobile apps, and the website have different privacy models

Conflicts

If there's a conflict between:

  • This policy and our Terms of Service: This policy controls for privacy matters
  • This policy and a Business Agreement: The Business Agreement controls for that customer
  • Different language versions: The English version controls

Severability

If any provision of this Privacy Policy is found unenforceable:

  • That provision will be limited to the minimum extent necessary
  • All other provisions remain in full effect
  • We'll update the policy to address the issue when feasible

Summary: Your Privacy at AICHE

What We Don't Do

  • Keep your voice after processing
  • Build a searchable archive of your transcripts
  • Train AI on your content
  • Sell your personal data
  • Track you in our desktop apps
  • Allow human review of your audio or your plaintext notes

What We Do

  • Process audio, then delete it
  • Keep notes on your device, with a temporary recovery cache on our servers
  • Store ciphertext only if you turn on Cloud Sync
  • Keep the account data needed to run the service
  • Ask before we set website analytics or ads cookies
  • Give you control over your data

The Bottom Line

Website visitors: Cookies only after you say yes. DNT means no.
App users: Audio deleted after processing. Notes on your device, plus a temporary server cache that clears 24 hours after your last recording on that device.
Everyone: We do not sell your data. Your content is not a product.


Questions? Contact privacy@aiche.app

Want details? Visit our AICHE Trust Center or read our AI Policy