AICHE Trust Center
Last Updated: August 13, 2026
At AICHE, transparency is a core part of our commitment to your privacy and security. Audio is processed, then deleted. Your text stays on your device, and a temporary server cache holds a copy until 24 hours after your last recording on that device. Cloud Sync is end-to-end encrypted. We do not sell your data.
Core Privacy Architecture
Our Fundamental Design
- Audio: Processed, then deleted. We do not keep a copy.
- Text, default: Returns to your device. A temporary server cache holds it for session recovery and clears 24 hours after your last recording on that device. No long-term archive.
- Text, public REST API: Job results hold the transcript for 1 hour after the job completes, then delete.
- Cloud Sync: Off by default. Opt-in. Encrypted on your device. We store ciphertext. We cannot read it.
- No AI Training: Your content is never used to train AI models
- Clear Separation: Website uses analytics and ads cookies only after you accept. Desktop apps have zero tracking. Mobile uses Firebase for sign-in and subscription events only.
Policy updates
| Date | What changed |
|---|---|
| August 13, 2026 | Aligned Privacy Policy, Terms, and this page with Cloud Sync, current AI vendors, cookie consent, and DNT. Removed OpenRouter (not used). Replaced hardcoded prices with a link to /pricing. LLC wording. Narrowed user indemnity. Allowed public benchmarks. Replaced the 30-day change-notice and consent gate with notice plus continued use. Described our voluntary diagnostic reports. Moved the transparency report to a cumulative count. Disclosed the temporary transcript session cache, which clears 24 hours after your last recording on a device. Added Google Cloud Vertex AI as a text-enhancement fallback subprocessor. Corrected log retention figures. |
| January 14, 2026 | Prior Privacy Policy effective date |
| October 5, 2025 | Prior Terms and Trust Center text |
Data Processing Partners
We use a minimal number of carefully selected vendors ("Subprocessors") to provide specific functions. We have Data Processing Addendums (DPAs) in place with all partners.
|Provider|Purpose|Location|Privacy & Security Notes| |:--|:--|:--| |Groq Inc.|Speech-to-text|USA|Processes the request. We delete audio after processing. No training on user content.| |Google Generative AI|Speech-to-text and text enhancement|USA/Global|Processes the request. No retention. No training on user data per our DPA.| |DeepInfra|Speech-to-text and text enhancement fallback|USA|Processes the request when another provider is unavailable. No retention. No training on user content.| |Google Cloud Vertex AI|Text enhancement fallback|USA/Global|Receives transcribed text only, never audio. Used only when the providers above are unavailable. No retention. No training on user data per our DPA.| |Hetzner Online GmbH|Server infrastructure|Germany (EU)|Provides dedicated servers. Hetzner handles physical security; we manage the software stack and data security.| |DigitalOcean, LLC|Server infrastructure|USA (NYC3, SFO3)|Provides cloud compute. We maintain control over the software stack and security configuration.| |Stripe, Inc.|Payment processing|USA/Global|Handles payment information in a PCI-compliant manner.| |Google Firebase|Mobile sign-in and subscription analytics|USA/Global|Records account events only. Does not receive audio or transcripts. Android advertising ID is not collected.|
Website-only (after you accept cookies)
| Provider | Purpose | Notes |
|---|---|---|
| Google Analytics | Website visitor analytics | Loads only after Accept. Never if DNT is on. Not used in desktop apps. |
| PostHog (self-hosted at analytics.aiche.app) | First-party product analytics and session recording | Data stays on our servers. Loads only after Accept. Never if DNT is on. |
| Meta Pixel (Facebook) | AICHE's own ad conversion tracking and remarketing | Loads only after Accept. Never if DNT is on. This is not a sale of your data. |
What we do not use
- OpenRouter: Not used in production.
AI Processing Strategy
We use more than one AI provider so that:
- A request can fail over if one provider is down
- We can pick a model that fits the task
- We keep latency and cost under control
We update the list above when we add or remove a subprocessor.
Website vs Applications
Website (aiche.app)
Cookies after you say yes:
- Google Analytics for visitor insights
- First-party product analytics with session recording (self-hosted, data stays on our servers)
- Meta Pixel (Facebook) for AICHE's own advertising conversion tracking
- Essential cookies for functionality (always on)
- A cookie banner lets you Accept or Reject. Do Not Track counts as Reject
Desktop Applications (Windows, macOS, Linux)
Complete privacy by design:
- No analytics or tracking
- No telemetry collection
- No crash reporting (unless explicitly opted in)
- No usage monitoring
- Only essential functionality for transcription
- Audio deleted after processing
Mobile Applications (iOS, iPadOS, watchOS, Android)
- Firebase Analytics for sign-in and subscription events only
- No audio in analytics
- No transcripts in analytics
- No Android advertising ID
Data Flow & Processing
How Your Voice Becomes Text
- Local Recording: Audio captured on your device
- Encrypted Transmission: TLS 1.3+ to our infrastructure
- Temporary Processing: Brief file creation on our servers (Hetzner/DigitalOcean)
- AI Transcription: Sent to Groq, Google Generative AI, and/or DeepInfra. Text enhancement may fall back to Google Cloud Vertex AI
- Return Journey: Text sent back encrypted to your device
- Audio deleted: We delete the audio after processing. We do not keep a copy
If Cloud Sync is on
- Your device encrypts the note (AES-256-GCM, key from your passphrase via Argon2id)
- We store ciphertext
- Your other devices pull the ciphertext and decrypt it locally
- We cannot read the note
What We Can't Do (By Design)
- Play back your past recordings (audio is deleted after processing)
- Read your Cloud Sync notes (ciphertext only; we do not hold the key)
- Train AI on your content
- Sell your data
- Provide a transcript once the session cache for that device has cleared (we no longer have it)
Security Measures
Technical Safeguards
- Encryption: TLS 1.3+ for all data in transit
- Temporary Files: Encrypted during the processing period
- Cloud Sync: AES-256-GCM on the device. Argon2id key derivation. We never receive the passphrase
- Infrastructure: Dedicated servers with full stack control
- Access Controls: Strict role-based access, audit logging
- Regular Audits: Penetration testing and security assessments
Responsible Disclosure
We work with security researchers to identify and resolve vulnerabilities:
- Report security issues to: security@aiche.app
- We'll acknowledge receipt within 48 hours
- Eligible researchers may receive public acknowledgment
Compliance & Certifications
Current Compliance
- GDPR: Full compliance for EU/UK users with Standard Contractual Clauses. Website analytics and ads cookies run on consent.
- CCPA: California privacy rights fully supported. We do not sell personal information.
- PIPEDA: Canadian privacy requirements met
Not Applicable
- HIPAA: We are currently NOT HIPAA compliant. Do not process Protected Health Information (PHI)
Legitimate Interests Assessment (Security and Fraud Prevention)
Our Privacy Policy relies on Legitimate Interests for one purpose only: to keep the platform secure and to prevent fraud. This is the summary of that assessment.
Necessity and proportionality. We cannot run an account service without detecting abuse, credential stuffing, and payment fraud. We use the smallest set of signals that achieves this: authentication events, request metadata, and error codes. We do not read your content to secure the platform.
Impact on you. The impact is low. A security review works on authentication events, request metadata, and error codes. It does not read your content. There is no audio archive and no long-term transcript archive. Access is role-based and least-privilege, data is encrypted, and logs rotate on the schedule published in the Privacy Policy.
Your right to object. You can object at any time by emailing privacy@aiche.app. We stop the processing unless we must continue for a legal reason, and we tell you which reason applies.
Transparency & Accountability
Transparency Report
We report:
- Government data requests received
- Our response and compliance rates
- Confirmation no audio or plaintext content was provided
- Notable legal challenges
- Current status of our warrant canary
As of August 13, 2026, and counting from the day we founded the company, AICHE Technologies LLC has received 0 government or law enforcement requests for user data. We have therefore disclosed no account data, no audio, and no transcripts. We update this figure whenever we republish this page.
Warrant Canary
As of August 13, 2026, AICHE Technologies LLC has NOT received:
- National Security Letters
- FISA court orders
- Gag orders preventing disclosure
We update this statement when we republish this page and can attest to it. A missing or unchanged canary after a republication is not proof of any specific event.
Law Enforcement Guide
Since we delete audio after processing and keep no long-term transcript archive:
- We can provide: Account email, subscription status, custom vocabulary (with valid legal process)
- We can provide, but only what is still in the session cache: Transcript text from a device that has recorded recently. The cache clears 24 hours after the last recording on that device. Once it clears, we cannot recover it
- We cannot provide: Voice recordings, any transcript older than that cache window, readable Cloud Sync notes
Enterprise Services
Available for Business Customers
- Data Processing Addendum (DPA)
- Service Level Agreement (SLA)
- Security questionnaires and documentation
- Custom Master Service Agreements (MSA)
- Audit rights per agreement terms
Contact for Enterprise
- Sales: sales@aiche.app
- Security documentation: security@aiche.app
- Legal/compliance: legal@aiche.app
Contact Information
| Purpose | |
|---|---|
| Security Issues | security@aiche.app |
| Privacy Questions | privacy@aiche.app |
| Legal/Compliance | legal@aiche.app |
| Enterprise Sales | sales@aiche.app |
| General Support | support@aiche.app |
AICHE Technologies LLC
A Delaware limited liability company
Voice to text for people who think faster than they type.
© 2026 AICHE Technologies LLC All rights reserved.