PRIVACY POLICY • AICHE TECHNOLOGIES
Effective Date: August 13, 2026
0) Summary of This Policy
This summary is for convenience only. It does not replace the full Privacy Policy. The full policy controls.
- We don't keep your voice. Audio is processed, then deleted. We do not keep a copy.
- Notes stay on your device. A temporary server cache also holds your recent text so you can recover a session. It clears 24 hours after your last recording on that device, so it lasts longer if you record every day. Cloud Sync is off by default, opt-in, and end-to-end encrypted. We store ciphertext. We cannot read it.
- We only keep the account data we need. Email, billing metadata, and the custom vocabulary you save so transcription can use it.
- We don't sell your data. Not your voice. Not your notes. Not your account. Full stop.
- Your content is never used for AI training.
1) Who We Are & The Scope of This Policy
Company Information
Company: AICHE Technologies, LLC Entity type: Delaware limited liability company Jurisdiction: Delaware, USA Privacy Contact: privacy@aiche.app
DPO and EU/UK Representative
As a U.S.-based company at our current scale, a formal Data Protection Officer is not required under GDPR. For all privacy matters, you can contact our dedicated privacy team directly at privacy@aiche.app. We will appoint a formal EU/UK representative if and when our scale of operations requires it.
Applicability
This policy applies to your use of:
- The AICHE website (aiche.app and subdomains)
- Desktop applications (Windows, macOS, Linux)
- Mobile applications (iOS, iPadOS, watchOS, Android)
- Obsidian Plugin (AICHE Voice for Obsidian)
- Browser extension
- APIs and developer tools
- Any related services (collectively, the "Service")
Important Distinction:
- Website: Uses analytics and ads cookies only after you accept, or never if your browser sends Do Not Track
- Desktop Apps: No analytics, no tracking
- Mobile Apps: Firebase Analytics for sign-in and subscription events only. No audio. No transcripts. No ad ID on Android
- Obsidian Plugin and browser extension: Same content model as the desktop apps
User Categories
- Individual Users: Personal accounts without business agreements
- Business/Enterprise Users: Organizations with business agreements and DPAs
Our Roles (under GDPR)
- For Individual Users: We act as the Data Controller for all personal data we collect
- For Business/Enterprise Users: We act as a Data Processor for content processed under a Data Processing Addendum (DPA)
2) The Three Buckets: How We Handle All Data
All data we handle falls into one of three buckets.
Bucket 1: Account & Billing Data (to run your account)
This is the personal data about you that we keep on our servers.
| Data Point | What We Collect | Why We Need It | Retention Period |
|---|---|---|---|
| Account Basics | Your email address, name (optional) | To create and maintain your account, authenticate you, and send essential service notices | While your account is active |
| Billing Info | Subscription plan, payment history (billing metadata via payment processor) | To manage your subscription and comply with tax/financial laws | As required by law (e.g., up to 7 years for invoices) |
| Custom vocabulary | Words and names you save | So transcription can spell them the way you want | While your account is active, or until you delete the entries |
Bucket 2: Content Data (to provide the service to you)
- Audio: The audio stream of your voice. We send it to our AI processors, get text back, then delete the audio. We do not keep a copy.
- Text, default: The transcript returns to your device. We also hold a copy in a temporary server cache so you can recover a session. That cache clears 24 hours after your last recording on that device. If you keep recording, entries stay longer than a day. We keep no long-term transcript archive.
- Text, public REST API: If you use our developer API, the job result holds the transcript so you can fetch it. We delete it 1 hour after the job completes.
- Text, Cloud Sync on: You can turn on Cloud Sync. The note is encrypted on your device first. We store only ciphertext. We do not hold the key. We cannot read the note.
- Why we need it: To perform speech-to-text and, if you turn sync on, to move your notes between your devices.
- We never use any of this data to train AI models.
Bucket 3: Operational Data (to fix and secure the service)
- What it is:
- Minimal, anonymized service metadata (timestamps, error codes - never your text/audio)
- Website analytics and ads cookies on aiche.app, only after you accept (see Section 5a)
- Mobile sign-in and subscription events via Firebase Analytics
- Support communications you send us
- Why we need it: To monitor service health, measure the website, attribute a sign-up, and provide support
- Retention:
- Web server logs: 14 days. Application logs: rotated by size, so there is no fixed day count. Error records: 6 months. Anonymized transcription metadata, which never contains your text or audio: 3 years
- Support tickets: Up to 24 months
- Website analytics: Per provider retention settings, and only if you accepted cookies
3) How Your Data Flows: Our Technical Privacy Guarantee
The Data Journey
- Your Device (mic captures audio)
- → Encrypted Transit (TLS 1.3+)
- Our processors (Groq, Google Generative AI, and/or DeepInfra handle the request)
- → Encrypted Transit (TLS 1.3+)
- Your Device (text returned/pasted into your active application)
- Audio deleted (we delete the audio after processing; we do not keep a copy)
If Cloud Sync is off, the only thing left on our side is the transcript in our temporary recovery cache. That cache clears 24 hours after your last recording on that device. Nothing else about that recording stays with us.
If Cloud Sync is on, your device then encrypts the note and sends ciphertext to us. Other devices you authorize pull that ciphertext and decrypt it locally.
Our Core Pledges
- No audio archive: We delete audio after processing. We do not keep a copy.
- No long-term transcript archive: Transcript text sits in a temporary server cache for session recovery. It clears 24 hours after your last recording on that device, so it lasts longer while you keep recording. We build no searchable transcript store. Cloud Sync stores ciphertext we cannot read.
- No AI Training: We strictly prohibit the use of your content to train any AI models
- No Human Review: The process is fully automated. No human reviews your audio or your plaintext notes
- Desktop App Privacy: Our desktop applications contain no analytics, no trackers, no telemetry
4) Sharing & Subprocessors
We use a small number of trusted service providers ("Subprocessors") to operate AICHE. We will never sell your personal information.
Infrastructure & Processing
- Groq Inc.: Speech-to-text inference (processes the request, no retention)
- Google Generative AI: Speech-to-text and text enhancement (processes the request, no retention)
- DeepInfra: Speech-to-text and text enhancement fallback (processes the request, no retention)
- Google Cloud Vertex AI: Text enhancement fallback. It receives transcribed text only, never your audio. We use it only when the providers above are unavailable
- Hetzner & DigitalOcean: Server infrastructure
- Stripe: Payment processing (PCI-compliant)
- Google Firebase: Mobile sign-in and subscription analytics. Not used for audio or transcripts
Website-Only Services
These load on aiche.app only after you accept cookies, and never if your browser sends Do Not Track:
- Google Analytics: Website visitor analytics (not used in desktop apps)
- First-party product analytics (PostHog, self-hosted): Page views and session recording on aiche.app. Data stays on our servers
- Meta Pixel (Facebook): Advertising conversion tracking and remarketing for AICHE's own ads (website only, not in apps)
Trust Center
A current and detailed list of our subprocessors is maintained on our Trust Center.
5) Your Privacy Rights & Controls
We believe you should have simple, powerful control over your information.
Your Privacy Controls
- Delete Your Data: Delete your account from Account Settings. This erases your account data, your custom vocabulary, and any Cloud Sync ciphertext. We keep billing records only where tax law requires it
- Manage Communications: Use the unsubscribe link in any marketing email. Account and billing emails always send
- See Your Data: Email privacy@aiche.app and we send you a copy of your account and billing data
- Fix Your Data: Email privacy@aiche.app to correct your name or email address
Your Additional Rights
You may also have the right to:
- Object to or restrict certain processing
- Data portability
- Withdraw consent for optional processing
- Lodge a complaint with supervisory authorities
To exercise any rights, contact privacy@aiche.app. We'll respond within 30 days.
5a) Cookies & Tracking
Website (aiche.app)
Our website uses:
- Essential cookies: For session management and security. These are always on.
- Analytics cookies: Google Analytics and first-party product analytics (including session recording), only after you accept
- Marketing cookies: Meta Pixel (Facebook) for conversion tracking and remarketing of AICHE's own ads, only after you accept
We ask before we set analytics or marketing cookies. A cookie banner on aiche.app lets you Accept or Reject. Reject leaves essential cookies only.
If your browser sends a Do Not Track (DNT) signal, we treat that as Reject. We do not load Google Analytics, Meta Pixel, or PostHog.
You can change your choice later from the Cookies link in the website footer.
Desktop Applications
Our desktop apps use:
- No cookies
- No analytics
- No tracking pixels
- No telemetry
Obsidian Plugin
When you use AICHE Voice for Obsidian:
Data Collection:
- Audio recordings are sent to AICHE servers for transcription
- Device information: device ID, operating system, app version
- Authentication tokens stored locally in your Obsidian vault
Data Processing:
- Audio is processed, then deleted. We do not keep a copy
- Transcribed text is returned directly to your device
- We keep no long-term transcript archive. Transcript text sits in a temporary server cache that clears 24 hours after your last recording on that device
Offline Mode:
- Failed recordings are encrypted locally using AES-GCM
- Encrypted audio is stored in your vault until successfully uploaded
- Once uploaded and processed, local encrypted data is deleted
Authentication:
- OAuth flow via obsidian://aiche-auth protocol handler
- Tokens encrypted at rest using Web Crypto API
- Session can be revoked from account settings
Third-Party:
- The Obsidian plugin interacts only with AICHE servers (api.aiche.app)
- No data is shared with Obsidian or third parties
iOS, iPadOS, and watchOS
When you use AICHE on iOS, iPadOS, or watchOS:
Data Handling:
- Audio is deleted after processing. We do not keep a copy
- Text transcripts remain on your device under your control
- A temporary server cache also holds recent transcript text. It clears 24 hours after your last recording on that device
- If you turn on Cloud Sync, encrypted notes sync across your devices. We store ciphertext only
- Your device's backup feature (iCloud, etc.) may include app data. Configure your backup settings according to your privacy preferences
- You can delete all transcripts and history anytime from the app settings
- Firebase Analytics records sign-in and subscription events only. It does not receive audio or transcripts
Android
When you use AICHE on Android:
Data Handling:
- Same content model as iOS: audio deleted after processing, text on your device, optional end-to-end encrypted Cloud Sync
- The same temporary server cache applies. It clears 24 hours after your last recording on that device
- Firebase Analytics records sign-in and subscription events only
- We do not collect the Android advertising ID (AD_ID)
Diagnostic Reports
Our desktop apps do not send crash reports on their own. When something goes wrong, you can choose to send us a diagnostic report. Nothing leaves your device unless you send it. We use the report only to fix the problem.
5b) U.S. State Privacy Rights & Disclosures
For Residents of California and other applicable states
- Categories of Data: Account & Billing Information (Bucket 1), custom vocabulary, transcript text held in our temporary session cache, Cloud Sync ciphertext if you turn sync on, and website analytics if you visit aiche.app and accept cookies
- Do Not Sell: We do not "sell" your personal information. We do not sell your voice, your notes, or your account.
- Share for ads: If you accept marketing cookies on aiche.app, Meta Pixel may receive website visitor data so we can measure and show AICHE's own ads. That is not a sale of your account or content. You can Reject cookies, or send DNT, and this does not run.
- Sensitive Information: We do not collect or process "sensitive personal information" to infer characteristics about you
- Your Rights: You have the right to know, delete, and correct your information. Delete your account from Account Settings, or contact privacy@aiche.app for anything else
6) Our Legal Bases for Processing (GDPR)
| Our Action | Legal Basis | Your Control |
|---|---|---|
| Provide the AICHE service | Contract | Delete your account at any time |
| Secure our platform & prevent fraud | Legitimate Interests | You may object by contacting us |
| Send optional marketing emails | Consent | You can unsubscribe at any time |
| Keep billing & tax records | Legal Obligation | N/A (required by law) |
| Website analytics and ads cookies | Consent | Accept or Reject on the cookie banner. DNT counts as Reject |
| Desktop app processing | Contract | Control through app settings |
| Cloud Sync (optional) | Contract / Consent | Off by default. You turn it on. You can turn it off |
Legitimate Interests Balancing Test (Security)
When we rely on Legitimate Interests for security and fraud prevention, we perform a balancing test to ensure our interests don't override your fundamental rights and freedoms. We:
- Assess necessity and proportionality
- Minimize data collection (no audio archive, no long-term transcript archive)
- Implement strong safeguards (encryption, access controls, limited retention)
- Provide you the ability to object by contacting privacy@aiche.app
A summary of this assessment is on our Trust Center.
Website vs App Processing
- Website visits: Analytics and ads cookies run only after you accept
- Desktop app usage: Processing is strictly necessary for service delivery under our contract with you
- The key difference: You can browse our website without an account. The apps require an account and process only what the feature needs
7) Security & Incident Response
We protect your data with these measures:
- Encryption: TLS 1.3+ in transit, AES-256 for any local storage
- Cloud Sync: AES-256-GCM on the device. Key derived from your passphrase with Argon2id. We never receive the passphrase or the key
- Access controls: Role-based access, principle of least privilege
- Regular audits: Security assessments and penetration testing
- Secure development: Code reviews and security scanning
Incident Response Timeline Commitments
Detection & Triage: We continuously monitor for suspicious activity. Once aware of a potential incident, we initiate triage within 24 hours.
Containment & Assessment: We aim to contain confirmed incidents promptly and assess impact as quickly as possible.
Notification to Authorities: Where legally required (e.g., GDPR), we'll notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach.
Notification to Affected Users: We'll notify affected users without undue delay when a breach is likely to result in high risk to their rights and freedoms - generally within 72 hours of confirming material impact.
Status Updates: We'll provide follow-up updates as material information becomes available, and a final summary after closure.
Note: These timelines apply except in cases of force majeure or circumstances beyond our reasonable control.
Security Reporting
Report security issues to: security@aiche.app
- We appreciate responsible disclosure
- Please allow reasonable time for fixes before public disclosure
- Security researchers may be eligible for acknowledgment
8) International Data Transfers
We're based in the United States. Here's how we handle international data:
Account & Billing Data
- Processed in the United States
- For EU and UK users, we transfer the data under Standard Contractual Clauses
- For other regions, we use the transfer mechanism that local law allows
Content Processing
- May be processed in the data center region closest to you for performance
- Audio is deleted after processing
- No audio archive means less transfer risk
Cloud Sync
- Ciphertext may be stored in our infrastructure regions
- We cannot read it
Website Analytics
- Google Analytics and Meta Pixel process data according to their policies, and only if you accepted cookies
- You can Reject cookies, send DNT, or use Google's opt-out tools
For more information, see our Trust Center and any region-specific disclosures we publish.
9) Children's Privacy
Our Policy
- Service not directed to individuals under 13 (or 16 in EU/UK)
- We don't knowingly collect personal information from children
- If we learn a child provided information, we'll delete it promptly
For Parents
If you believe your child has provided us with personal information:
- Contact us immediately at privacy@aiche.app
- We'll verify and delete the information
- We'll prevent future access if appropriate
Age Verification
- We rely on users to provide accurate age information
- Business/Enterprise accounts are responsible for ensuring their users meet age requirements
10) Law Enforcement Requests
Our Stance
- We require valid legal process (e.g., court order) for any user data request
- We don't keep audio after processing, so we have no audio to provide
- We keep no long-term transcript archive, so there is no history to search
- Cloud Sync ciphertext cannot be decrypted by us
- We'll challenge overly broad or improper requests when appropriate
What We Can Provide
We hold very little, so most requests return very little:
- Can provide: Account email, subscription status, billing records, custom vocabulary
- Can provide, but only what is still in the session cache: Transcript text from a device that has recorded recently. That cache clears 24 hours after the last recording on that device, so on a device in daily use it can still hold older entries. Once it clears, we cannot recover it
- Cannot provide: Voice recordings, any transcript older than that cache window, readable Cloud Sync notes
Transparency Commitment
We publish transparency reports on our Trust Center including:
- Number of requests received by type and jurisdiction
- Number of accounts identified in requests
- Our compliance/rejection rate
- Whether any audio or transcript content was provided
- Number of requests we challenged
Warrant Canary
We maintain a warrant canary statement in our Trust Center. A warrant canary is a statement that, as of a given date, we have not received certain kinds of secret legal demands. If the canary is removed or not updated when we republish the Trust Center, it may indicate a change in circumstances.
Note: Legal restrictions may limit what we can say. A missing canary is not definitive proof of any specific event.
11) Common Privacy Questions (FAQ)
Q: Can any AICHE employee listen to my recordings? A: No. We delete audio after processing, so there is nothing to play back.
Q: Can any AICHE employee read my notes? A: The transcript sits in our temporary recovery cache in readable form until that cache clears, which happens 24 hours after your last recording on that device. On a device you use daily, it is present. Our process is automated and our policy forbids staff from reading your notes, but we will not pretend it is technically impossible during that window. If Cloud Sync is on, we hold only ciphertext and we do not have the key, so those notes we genuinely cannot read.
Q: Do you use my voice or text to train your AI? A: Never. Our privacy-by-design architecture and contracts with AI providers prohibit this.
Q: Do you sell my data? A: No. We do not sell your voice, your notes, or your account. We do not sell website visitor data either.
Q: Why does the website have a cookie banner? A: The website uses analytics and ads cookies for our own marketing. That is not a sale of your data. EU law still wants a yes or no. We ask. Desktop apps never see those cookies.
Q: What happens to my data if I'm offline? A: The app queues recordings locally in encrypted storage. When you're back online, they're processed and the audio is deleted after processing. The local queue is also cleared after successful processing.
Q: Can I use AICHE for confidential business conversations? A: Yes, with one detail you should know before you decide. We delete audio after processing, and your text stays on your device. A copy of the transcript also sits in our temporary recovery cache, which clears 24 hours after your last recording on that device. On a device you use every day, that copy stays. If that is unacceptable for a specific conversation, do not dictate it. Cloud Sync, if you turn it on, is end-to-end encrypted. For enterprise needs, we offer additional contractual protections via our Business agreements.
12) Changes to This Policy & Contact Us
Policy Updates
If we change this policy, we will:
- Post the new version at aiche.app/privacy with a new effective date
- Update the "Last Updated" date at the top
- Maintain a change log on our Trust Center
- Notify you by email or in-app notice for material changes
Where the law requires your consent for a new use of your data, we will ask for it.
Types of Changes
- Minor changes (typos, clarifications): Posted without notice
- Material changes (new data uses, new subprocessors): Posted, with email or in-app notice
Contact Information
For any questions about this policy or to exercise your privacy rights:
Email: privacy@aiche.app
Response time: Within 30 days (sooner for urgent matters)
Languages: English (primary), other languages as available
For other inquiries:
- Security issues: security@aiche.app
- General support: support@aiche.app
- Legal matters: legal@aiche.app
- Business inquiries: sales@aiche.app
13) Automated Decision-Making
Current State
We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you within the meaning of GDPR Article 22.
What Our AI Does
- Transcribes speech to text: A tool you control
- Enhances text: Only when you request it
- Does NOT: Make decisions about you, profile you, or determine your access to services
Your Control
- You review and edit all outputs before use
- You decide whether to accept AI suggestions
- The AI is a tool, not a decision-maker
Future Changes
If we ever introduce automated decision-making that affects your legal rights or status:
- We'll provide clear advance notice
- Explain the logic involved
- Offer human review options
- Update this policy before implementation
14) Additional Disclosures & Regional Rights
For European Economic Area (EEA) and UK Residents
- Legal basis for processing: See Section 6
- Data Protection Authority: You may lodge complaints with your local DPA
- Transfers: Standard Contractual Clauses for data transfers to the US
For California Residents
- CCPA Rights: See Section 5b
- Shine the Light: We don't share data with third parties for their direct marketing of their own products
- Do Not Track: Our website honors DNT. We treat it as a Reject of analytics and marketing cookies
For Other Regions
We extend core privacy rights to all users regardless of location:
- Access to your data
- Correction capabilities
- Deletion options
- Portability features
Check our Trust Center for region-specific information.
15) Data Retention Summary
| Data Type | Retention Period | Why |
|---|---|---|
| Voice audio | Deleted after processing. We do not keep a copy | Privacy by design |
| Text (Cloud Sync off) | On your device. A temporary server cache also holds it, and clears 24 hours after your last recording on that device | Local by default, with a recovery window |
| Text (public REST API job results) | Deleted 1 hour after the job completes | So you can fetch your result |
| Text (Cloud Sync on) | Ciphertext on our servers until you delete the note, turn sync off, or delete your account | So your devices can share the note. We cannot read it |
| Custom vocabulary | While your account is active, or until you delete the entries | Needed for transcription |
| Account Data | While account is active | Service provision |
| Billing Records | Up to 7 years after last transaction | Legal requirement |
| Support Tickets | Up to 24 months | Service continuity |
| Website Analytics | Only if you accepted cookies. Then per provider settings (Google Analytics: 14-26 months; Meta Pixel: per Meta's data policy) | Service improvement and our own ads |
| Desktop App Analytics | None - we don't collect any | Complete privacy |
| Web server logs | 14 days | Security monitoring |
| Application logs | Rotated by size, no fixed day count | Debugging and service health |
| Error records | 6 months | Fixing faults |
| Transcription metadata (duration, success, language, provider; never your text or audio) | 3 years | Service health and capacity planning |
16) Privacy Policy Interpretation
Guiding Principles
This Privacy Policy should be interpreted:
- In favor of user privacy when ambiguous
- Consistently with our Core Pledges
- Reasonably and in good faith
- With recognition that desktop apps, mobile apps, and the website have different privacy models
Conflicts
If there's a conflict between:
- This policy and our Terms of Service: This policy controls for privacy matters
- This policy and a Business Agreement: The Business Agreement controls for that customer
- Different language versions: The English version controls
Severability
If any provision of this Privacy Policy is found unenforceable:
- That provision will be limited to the minimum extent necessary
- All other provisions remain in full effect
- We'll update the policy to address the issue when feasible
Summary: Your Privacy at AICHE
What We Don't Do
- Keep your voice after processing
- Build a searchable archive of your transcripts
- Train AI on your content
- Sell your personal data
- Track you in our desktop apps
- Allow human review of your audio or your plaintext notes
What We Do
- Process audio, then delete it
- Keep notes on your device, with a temporary recovery cache on our servers
- Store ciphertext only if you turn on Cloud Sync
- Keep the account data needed to run the service
- Ask before we set website analytics or ads cookies
- Give you control over your data
The Bottom Line
Website visitors: Cookies only after you say yes. DNT means no.
App users: Audio deleted after processing. Notes on your device, plus a temporary server cache that clears 24 hours after your last recording on that device.
Everyone: We do not sell your data. Your content is not a product.
Questions? Contact privacy@aiche.app
Want details? Visit our AICHE Trust Center or read our AI Policy