Privacy Policy
Draft — not legal advice
This document is a draft prepared alongside the product implementation. It has not been reviewed by a qualified lawyer and must not be published or relied on as a legal agreement until it has been. Values shown as [BRACKETED TEXT] are business decisions that have not been made yet.
This policy describes what Xuula collects, why, who else sees it, and what you can do about it. It is written to match what the product actually does. Where a detail depends on a provider agreement that has not been finalised, this policy says so instead of making a claim.
1. Who is responsible for your data
[LEGAL ENTITY NAME] ([ENTITY TYPE, e.g. LLC / Ltd / OÜ / GmbH]), registered in [COUNTRY OF INCORPORATION] under number [COMPANY REGISTRATION NUMBER] at [REGISTERED OFFICE ADDRESS], is the controller of the personal data described in this policy.
For privacy questions and for any request about your data, write to privacy@xuula.example.
Where required, our representative and the supervisory authority you can complain to are [EU / UK REPRESENTATIVE — if required] and [LEAD SUPERVISORY AUTHORITY].
2. What we collect
The categories below are exhaustive for the current release. If we start collecting something new, this policy changes first.
Account data
- Your email address, which is how you sign in and how we contact you.
- A hash of your password. We never store the password itself and cannot recover it.
- An optional display name.
- Your interface language, the languages you expect to dictate in, and your time zone.
- Your preferences: recording mode, theme, and whether AI cleanup is on.
Billing data
- Your subscription state: plan, status, billing period and renewal date.
- An identifier linking your account to your customer record at our payment processor.
- We do not receive or store your card number, expiry date or security code. Those are entered directly into the payment processor’s hosted checkout page.
Device data
- For each computer you authorise: a name you can edit, an installation identifier generated by the app, the application version, and the Windows version.
- The installation identifier is generated on first run and changes if you reinstall. It is not a hardware fingerprint.
- When each device was authorised and when it was last used.
Usage records
- For each dictation: the number of words, a timestamp, which device reported it, and the language tags that were detected.
- We do not receive the words themselves. Usage reporting sends a count, not text.
- These records form an append-only ledger. That is what lets us enforce the free plan’s weekly allowance and answer a billing dispute with evidence.
Audio and transcripts
- While you are recording, audio is streamed from your PC to a speech recognition provider. It does not pass through, and is not stored on, Xuula servers.
- If AI cleanup is enabled, the recognised text is sent to an AI provider to be edited, together with your selected writing style and any relevant personal-dictionary terms. If cleanup is disabled, no text is sent anywhere.
- The edited text is returned to your PC and inserted into the field you were typing into. Xuula servers do not store it.
- Your dictation history is stored on your own computer. In this release there is no cloud history and nothing is uploaded.
Meetings, recordings and Projects
- When you start a meeting recording, the Windows app captures your microphone and, if you enable it, the audio your PC is playing. Both are mixed into one recording saved on your computer.
- That audio is streamed to the speech recognition provider while the recording runs, so it can produce a transcript with separated speakers and, if you enable it, a translation. It does not pass through, and is not stored on, Xuula servers.
- The recording, the transcript, any translation, your notes, the speaker labels and names you assign, and word-level timestamps are written to local files on your computer, organised into Projects you create.
- AI meeting insights — summary, key points, to-do items, speaker quotes and assistant answers — are produced only when you request them. The transcript text is sent to the AI provider for that request; the recording is not.
- The recognition context and vocabulary you attach to a Project are sent to the speech provider as recognition hints for meetings saved to it.
- None of this meeting content is uploaded to Xuula servers in this release. There is no cloud sync, no server-side copy, and no sharing with other accounts. The files are yours to back up or delete.
Personal dictionary and writing styles
- The terms you add — names, brands, technical vocabulary — and any spelling variants, along with the language each belongs to.
- Your writing-style names and instructions.
- Dictionary terms relevant to a dictation are sent to the speech and AI providers as recognition and editing context. Do not put anything in the dictionary that you would not want sent to those providers.
Support messages
- What you write to us through the contact form or by email, and our replies.
- The email address you asked us to reply to, and the topic you selected.
Technical and security data
- A short summary of your browser and operating system, such as “Chrome on Windows”, for the list of active sessions. We do not store the full user-agent string.
- A two-letter country code derived from your connection, where our hosting platform provides one. We do not retain full IP addresses in application records.
- Rate-limiting counters and authentication events, used to detect abuse.
3. Why we use it
We use the data above only for the purposes listed here.
- To run your account: authenticate you, keep you signed in, and let you authorise and revoke devices.
- To provide dictation: transmit audio for recognition and, when enabled, text for editing.
- To enforce plan limits: count words against the free plan’s weekly allowance and apply the fair-use thresholds on Pro.
- To take payment and manage subscriptions, including renewals, failed payments and refunds.
- To answer support requests and to contact you about your account, billing or security.
- To keep the service secure: rate limiting, abuse detection and investigating suspicious activity.
- To meet legal obligations, such as retaining invoicing records for tax purposes.
- To send product updates, only if you opted in, and only until you opt out.
We do not sell personal data. We do not use your dictation content for advertising, and we do not build advertising profiles.
4. Legal bases (EEA and UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases.
- Performance of a contract: running your account, providing dictation, and taking payment for a subscription you bought.
- Legitimate interests: keeping the service secure, preventing abuse, and enforcing fair use. We have considered your interests and rights against ours in each case.
- Legal obligation: retaining billing records and responding to lawful requests.
- Consent: optional AI cleanup, optional marketing email, and any optional analytics. You can withdraw consent at any time, and withdrawal does not affect processing that already happened.
5. Who else processes your data
We use the providers below. Each is listed with what is sent to it, why, and what we can and cannot truthfully say about how long it keeps that data.
Where a provider’s retention or model-training terms have not yet been confirmed against a signed agreement, this policy says so. We will not make a claim about a third party that we cannot evidence.
| Providers involved | Sent to cloud services | How long things are kept |
|---|---|---|
| SonioxNeeds reviewSpeech-to-text transcription, including mixed-language recognition, meeting transcription with speaker separation, and optional translation. |
| The retention and model-training terms that apply to the Xuula account must be confirmed against the signed Soniox agreement before any “no retention” or “no training” statement is published. ↗ |
| OpenAINeeds reviewOptional AI processing: dictation cleanup (grammar, filler removal, punctuation, writing style), final meeting-transcript polish, and on-demand meeting insights (summary, key points, to-dos, speaker quotes, assistant answers). |
| API retention and training terms must be confirmed against the signed OpenAI agreement (including whether zero-data-retention is enabled for the account) before publishing any claim. ↗ |
| StripePayment processing, subscription management, invoicing and tax calculation. |
| Card numbers never reach Xuula servers; they are entered into Stripe-hosted Checkout. Stripe acts as an independent controller for fraud prevention and regulatory purposes. ↗ |
| [HOSTING PROVIDER]Needs reviewServing the website and running the application server. |
| Name the hosting provider and its data-processing region before launch. |
| [MANAGED POSTGRESQL PROVIDER]Needs reviewStoring account, subscription, usage-ledger and device records. |
| Name the database host and its region, plus the backup retention period. |
| [TRANSACTIONAL EMAIL PROVIDER]Needs reviewSending sign-in verification, billing notifications and support replies. |
| Name the email provider and its log-retention period. The codebase ships a provider-agnostic interface with a Resend adapter and a console adapter. |
| Cloudflare R2Needs reviewOff-site storage of encrypted logical database backups, held with a different vendor from the database itself. |
| Archives are encrypted with AES-256-GCM before they leave the server, so Cloudflare stores ciphertext and never holds the key. Confirm the bucket region, the account’s data-processing terms and the object-lifecycle configuration before naming R2 in the published Privacy Policy. ↗ |
| [PRIVACY-FRIENDLY ANALYTICS PROVIDER — optional]Needs reviewAggregate website traffic measurement. |
| Analytics is disabled by default in this repository. If enabled, name the provider and confirm whether it sets cookies — that determines whether a consent banner is legally required. |
We do not transfer your data to anyone else except where required by law, or as part of a merger or acquisition — in which case we would notify you before your data became subject to a different policy.
6. Model training
Xuula does not train models. We have no speech or language models of our own, and we do not use your audio, transcripts or dictionary to train anything.
Whether a provider we send data to may use it for its own training depends on the agreement in place with that provider. Those terms are stated in the provider table above where they have been confirmed. Where the table says a claim is unconfirmed, treat it as unconfirmed: we are not asserting that your data is excluded from training by that provider.
If you would rather no transcript text left your PC at all, turn AI cleanup off in your settings. Speech recognition still requires audio to be sent, because recognition does not run locally.
7. How long we keep things
Retention is per category, not a single global period.
| Account records after a deletion request | 30 days |
|---|---|
| Invoicing and tax records | 7 years |
| Usage ledger (word counts only) | 24 months |
| Audio on Xuula servers | not-stored |
| Transcripts on Xuula servers | not-stored-by-default |
| Opt-in cloud history (not shipped in this release) | 90 daysNeeds review |
| Support messages | 24 months |
| Authentication and rate-limit logs | 90 days |
When a retention period ends, records are deleted or irreversibly anonymised. Backups are overwritten on their own cycle, so a deleted record can persist in a backup for a short additional period before being cycled out.
8. What you control
- AI cleanup: turn it off and no transcript text is sent for editing.
- AI meeting insights: they run only when you ask for one. Nothing is generated in the background.
- Meeting recording: start and stop it yourself, pause it, and mute your microphone while it runs. System-audio capture and live translation are each switched on or off by you.
- Meeting files: the recording, transcript, notes and insights are ordinary local files. Delete a conversation or the whole folder and it is gone from your computer.
- Local history: clear it at any time from the Windows app. It is on your computer, so it is yours to delete.
- Cloud storage: there is none for dictation or meeting content in this release. If we add opt-in cloud storage or sync, it will be off by default and this policy will change before it ships.
- Personal dictionary: add, edit and remove terms at any time.
- Devices: see every authorised computer and revoke any of them. Revocation takes effect within minutes.
- Sessions: see every browser signed in to your account and sign out of any of them.
- Export: download everything your account holds as a JSON file, from your account settings.
- Deletion: delete your account from your account settings.
- Marketing email: opt out at any time. Account, billing and security emails are not optional, because they are part of running your account.
9. Recording meetings and consent
The Windows app can record a conversation: your microphone, and the audio your computer is playing. Recording starts only when you start it, and a recording indicator is visible while it runs.
Whether you may lawfully record a conversation, and whom you must tell first, depends on the law where you are and where the other participants are. Some jurisdictions require every participant to consent; others require only one. Workplace policies, professional duties and contracts can add further restrictions.
You are responsible for giving any notice and obtaining any consent that the law requires before you record, and for how you use the recording, the transcript and anything generated from them. We do not make that assessment for you, and nothing here is legal advice.
The recording is made and stored on your own computer. We do not receive it, cannot review it, and cannot delete it for you — deleting it is done on your PC.
10. Your rights
Depending on where you live, you may have some or all of the following rights. You can exercise most of them yourself from your account settings; for anything else, write to privacy@xuula.example.
- Access: a copy of the personal data we hold about you.
- Rectification: correction of anything inaccurate.
- Erasure: deletion of your data, subject to records we must keep by law.
- Restriction: limiting how we process your data while a dispute is resolved.
- Portability: your data in a structured, machine-readable format — this is what the export feature produces.
- Objection: objecting to processing based on legitimate interests.
- Withdrawal of consent: for anything we do on the basis of consent.
- Complaint: to your data protection authority. Ours is [LEAD SUPERVISORY AUTHORITY].
We will respond within the deadline that applies to you — one month under the GDPR, which can be extended for complex requests. We do not charge for a first request, and we will ask you to confirm your identity before acting on one.
11. Security
- Passwords are stored as memory-hard hashes with per-account salts. A database dump does not reveal them.
- Session cookies, device tokens and reset links are stored only as hashes, so they cannot be replayed from a database copy.
- Card details never reach our servers; they go directly to the payment processor.
- Access tokens issued to the Windows app are short-lived, and revoking a device invalidates them.
- We do not log access tokens, API keys, transcripts or audio.
- Data is encrypted in transit. Storage encryption depends on the hosting and database providers named above.
No system is perfectly secure. If you find a vulnerability, please report it to security@xuula.example rather than disclosing it publicly, and give us a reasonable chance to fix it.
12. International transfers
Our providers process data in several countries, including outside your own. Where personal data leaves the EEA or the UK, we rely on the appropriate safeguard for that transfer — an adequacy decision where one exists, or standard contractual clauses.
The specific hosting and processing regions are listed in the provider table above once each provider is confirmed.
13. Age requirements
Xuula is not for children. You must be at least 16 to hold an account, or at least 13 if you are in the United States, where a lower statutory floor applies.
If we learn that an account belongs to someone below the applicable age, we delete it. If you believe a child has created an account, tell us at privacy@xuula.example.
15. Changes to this policy
If we change this policy in a way that materially affects you, we will email account holders before the change takes effect and update the date at the top of the page.
Changes that only clarify wording take effect when published.
16. Contact
Privacy and data requests: privacy@xuula.example
Security reports: security@xuula.example
Everything else: support@xuula.example
Postal address: [REGISTERED OFFICE ADDRESS]
Data protection officer or representative: [DATA PROTECTION OFFICER OR REPRESENTATIVE — if required]
Related documents
Questions about this document
Write to legal@xuula.example.