Preview — payments disabledYou can create an account and use the site, but checkout is switched off and no subscription can be started here.
Skip to main content
Xuula

Where your words go

This page describes what actually happens, step by step. It is written to be checked against the product rather than to reassure. The Privacy Policy is the formal version.

1On your PC

  • Detecting the hotkey and capturing microphone audio — and, during a meeting recording, Windows system audio.
  • Showing the recording indicator and the live words as they settle.
  • Inserting the finished text into whichever field has focus.
  • Storing your dictation history. In this release, history is local only and is not uploaded.
  • Storing meeting recordings, transcripts, translations, notes, speaker names, word timestamps and AI insights — all of it in local files, organised into Projects. None of it is uploaded to Xuula servers.
  • Storing your personal dictionary and per-project vocabulary locally so they can be applied to recognition.

2Sent to cloud services

  • Audio, while a dictation or a meeting recording you started is active — for meetings, the microphone and, when enabled, system audio

    Speech recognition provider

    To convert speech to text, including language switches, speaker separation in meetings, and optional translation.

  • The transcript text, plus your selected style and relevant dictionary terms

    AI provider

    To remove filler words, fix grammar and apply punctuation. Skipped entirely when cleanup is off.

  • The speaker-labelled meeting transcript text — never the recording

    AI provider

    Only when you request an AI meeting action: a summary, key points, to-dos, quotes, or an assistant answer.

  • A word count, a device identifier and a timestamp

    Xuula servers

    To enforce the free plan’s weekly allowance and to keep an auditable usage record. The words themselves are not sent.

  • Email address and subscription state

    Xuula servers and the payment processor

    To run your account and take payment. Card details go directly to the payment processor.

What is not sent to our servers

  • Your audio — dictation or meetings. It goes to the speech provider, not to us, and we do not store it.
  • Your transcripts, meeting recordings, notes and Projects. Usage reporting sends a count, not the content.
  • The contents of the application you were typing into.
  • Your full IP address as a stored record. We keep at most a country code.

Providers involved

Each provider has its own retention and model-training terms. Those terms are stated in the Privacy Policy only where they have been confirmed against a signed agreement — anywhere they have not been, the page says so rather than guessing.

  • Soniox

    Needs review

    Speech-to-text transcription, including mixed-language recognition, meeting transcription with speaker separation, and optional translation.

    • · Microphone audio captured while dictation is active
    • · During a meeting recording: microphone audio and, when enabled, Windows system audio, mixed into one stream
    • · Language hints and, when configured, personal-dictionary terms and per-project vocabulary used as recognition context

    The retention and model-training terms that apply to the Xuula account must be confirmed against the signed Soniox agreement before any “no retention” or “no training” statement is published.

  • OpenAI

    Needs review

    Optional AI processing: dictation cleanup (grammar, filler removal, punctuation, writing style), final meeting-transcript polish, and on-demand meeting insights (summary, key points, to-dos, speaker quotes, assistant answers).

    • · The raw transcript text of the current dictation
    • · The selected writing style and personal-dictionary terms relevant to that dictation
    • · When an AI meeting action is used: the speaker-labelled meeting transcript text (never the audio)

    API retention and training terms must be confirmed against the signed OpenAI agreement (including whether zero-data-retention is enabled for the account) before publishing any claim.

  • Stripe

    Payment processing, subscription management, invoicing and tax calculation.

    • · Email address and account identifier
    • · Billing details and payment method entered directly into Stripe
    • · Subscription and invoice records

    Card numbers never reach Xuula servers; they are entered into Stripe-hosted Checkout. Stripe acts as an independent controller for fraud prevention and regulatory purposes.

  • [HOSTING PROVIDER]

    Needs review

    Serving the website and running the application server.

    • · IP address and request metadata in transient access logs
    • · All data processed by the application

    Name the hosting provider and its data-processing region before launch.

  • [MANAGED POSTGRESQL PROVIDER]

    Needs review

    Storing account, subscription, usage-ledger and device records.

    • · All persisted application data

    Name the database host and its region, plus the backup retention period.

  • [TRANSACTIONAL EMAIL PROVIDER]

    Needs review

    Sending sign-in verification, billing notifications and support replies.

    • · Email address
    • · Message content of transactional emails

    Name the email provider and its log-retention period. The codebase ships a provider-agnostic interface with a Resend adapter and a console adapter.

  • Cloudflare R2

    Needs review

    Off-site storage of encrypted logical database backups, held with a different vendor from the database itself.

    • · An encrypted archive of the application database: account, subscription, device, usage-ledger and billing-event rows
    • · No audio, transcripts, meeting recordings or Projects — those never reach this server

    Archives are encrypted with AES-256-GCM before they leave the server, so Cloudflare stores ciphertext and never holds the key. Confirm the bucket region, the account’s data-processing terms and the object-lifecycle configuration before naming R2 in the published Privacy Policy.

  • [PRIVACY-FRIENDLY ANALYTICS PROVIDER — optional]

    Needs review

    Aggregate website traffic measurement.

    • · Page path, referrer, coarse country, device class
    • · No dictation content and no account identifiers

    Analytics is disabled by default in this repository. If enabled, name the provider and confirm whether it sets cookies — that determines whether a consent banner is legally required.

How long things are kept

Audio on Xuula servers
Not stored
Transcripts on Xuula servers
Not stored by default
Meeting recordings, transcripts and Projects
On your PC, for as long as you keep them
Usage ledger (counts only)
24 months
Account records after deletion
30 days

What you control

  • Turning AI cleanup off, so no transcript text is sent for rewriting.
  • AI meeting insights run only when you ask for them — there is no background processing.
  • Muting your microphone during a meeting recording, and pausing or stopping the recording at any time.
  • Turning live translation on or off per meeting.
  • Clearing your local dictation history at any time from the app; meeting files are ordinary local files you can delete yourself.
  • Exporting everything your account holds, as JSON.
  • Deleting your account, which removes your data after a short recovery window.

Recording a conversation can require the notice or consent of the people in it, depending on the jurisdictions involved. You are responsible for obtaining any legally required consent before recording a meeting.

Read the full Privacy Policy