|
| 1 | +<!DOCTYPE html> |
| 2 | +<html lang="en"> |
| 3 | +<head> |
| 4 | + <meta charset="UTF-8" /> |
| 5 | + <meta name="viewport" content="width=device-width, initial-scale=1.0" /> |
| 6 | + <title>Privacy Policy - Addit</title> |
| 7 | + <meta name="description" content="Addit Privacy Policy - How we collect, use, and protect your data." /> |
| 8 | + <style> |
| 9 | + *, *::before, *::after { box-sizing: border-box; margin: 0; padding: 0; } |
| 10 | + body { |
| 11 | + font-family: 'Inter', -apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif; |
| 12 | + background: #0f172a; |
| 13 | + color: #cbd5e1; |
| 14 | + line-height: 1.7; |
| 15 | + padding: 2rem 1rem; |
| 16 | + } |
| 17 | + .container { max-width: 860px; margin: 0 auto; } |
| 18 | + header { margin-bottom: 2rem; border-bottom: 1px solid #1e293b; padding-bottom: 1.5rem; display: flex; align-items: center; gap: 1rem; } |
| 19 | + header a { color: #94a3b8; text-decoration: none; font-size: 0.9rem; } |
| 20 | + header a:hover { color: #fff; } |
| 21 | + h1 { font-size: 2rem; font-weight: 700; color: #f1f5f9; margin-bottom: 0.25rem; } |
| 22 | + .updated { color: #64748b; font-size: 0.9rem; margin-bottom: 2rem; } |
| 23 | + h2 { font-size: 1.25rem; font-weight: 600; color: #e2e8f0; margin: 2rem 0 0.75rem; padding-top: 1rem; border-top: 1px solid #1e293b; } |
| 24 | + h3 { font-size: 1rem; font-weight: 600; color: #cbd5e1; margin: 1.25rem 0 0.5rem; } |
| 25 | + h4 { font-size: 0.95rem; font-weight: 600; color: #94a3b8; margin: 1rem 0 0.4rem; } |
| 26 | + p { margin-bottom: 0.85rem; } |
| 27 | + ul, ol { margin: 0.5rem 0 0.85rem 1.5rem; } |
| 28 | + li { margin-bottom: 0.3rem; } |
| 29 | + a { color: #60a5fa; text-decoration: none; } |
| 30 | + a:hover { text-decoration: underline; } |
| 31 | + strong { color: #e2e8f0; } |
| 32 | + table { width: 100%; border-collapse: collapse; margin: 1rem 0; font-size: 0.9rem; } |
| 33 | + th, td { border: 1px solid #334155; padding: 0.6rem 0.75rem; text-align: left; } |
| 34 | + th { background: #1e293b; color: #e2e8f0; font-weight: 600; } |
| 35 | + tr:nth-child(even) td { background: #0f172a; } |
| 36 | + .card { background: #1e293b; border: 1px solid #334155; border-radius: 1rem; padding: 2.5rem; } |
| 37 | + @media (max-width: 640px) { .card { padding: 1.25rem; } h1 { font-size: 1.5rem; } } |
| 38 | + </style> |
| 39 | +</head> |
| 40 | +<body> |
| 41 | + <div class="container"> |
| 42 | + <header> |
| 43 | + <a href="/">← addit.dev</a> |
| 44 | + </header> |
| 45 | + <div class="card"> |
| 46 | + <h1>Privacy Policy</h1> |
| 47 | + <p class="updated">Last updated: January 16, 2026</p> |
| 48 | + |
| 49 | + <h2>1. Introduction and Scope</h2> |
| 50 | + <p>Welcome to Addit ("we," "our," "us," or "the Company"). Addit is a mobile application that provides call recording, voice memo recording, transcription, and AI-powered extraction services. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your information when you use our mobile application (the "App") available on iOS and Android platforms.</p> |
| 51 | + <p>This Privacy Policy applies to all users of the App worldwide. We are committed to protecting your privacy and complying with applicable data protection laws, including but not limited to the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), Lei Geral de Proteção de Dados (LGPD), Personal Information Protection and Electronic Documents Act (PIPEDA), UK General Data Protection Regulation (UK GDPR), Australian Privacy Act, and other applicable state, federal, and international privacy laws.</p> |
| 52 | + <p><strong>PLEASE READ THIS PRIVACY POLICY CAREFULLY.</strong> By downloading, installing, accessing, or using Addit, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree to this Privacy Policy, please do not use the App.</p> |
| 53 | + |
| 54 | + <h2>2. Data Controller Information</h2> |
| 55 | + <p>For the purposes of applicable data protection laws, the data controller responsible for your personal data is:</p> |
| 56 | + <p><strong>Addit</strong><br>Email: <a href="mailto:privacy@addit.dev">privacy@addit.dev</a></p> |
| 57 | + <p>For users in the European Economic Area (EEA), United Kingdom, or Switzerland, you may also contact our data protection representative at <a href="mailto:dpo@addit.dev">dpo@addit.dev</a>.</p> |
| 58 | + |
| 59 | + <h2>3. Information We Collect</h2> |
| 60 | + <p>We collect information to provide and improve our services. The types of information we collect depend on how you use the App and the permissions you grant.</p> |
| 61 | + |
| 62 | + <h3>3.1 Audio Recordings and Voice Data</h3> |
| 63 | + <p>When you use the App's recording features, we process audio data including:</p> |
| 64 | + <ul> |
| 65 | + <li>Phone call recordings (when you initiate recording)</li> |
| 66 | + <li>Voice memos and audio notes you create</li> |
| 67 | + <li>Audio files you import or share to the App</li> |
| 68 | + </ul> |
| 69 | + <p><strong>Storage:</strong> All audio recordings are stored locally on your device. Audio data is only transmitted to third-party transcription services (Deepgram or Gladia) when you initiate transcription, using API keys you provide.</p> |
| 70 | + |
| 71 | + <h3>3.2 Call Log Information</h3> |
| 72 | + <p>With your explicit permission (READ_CALL_LOG permission on Android), we access:</p> |
| 73 | + <ul> |
| 74 | + <li>Phone numbers of incoming and outgoing calls</li> |
| 75 | + <li>Call timestamps and duration</li> |
| 76 | + <li>Call type (incoming, outgoing, missed)</li> |
| 77 | + </ul> |
| 78 | + <p><strong>Purpose:</strong> This information is used solely to associate recordings with specific calls and display call context within the App. This data is stored locally on your device and is never transmitted to our servers.</p> |
| 79 | + |
| 80 | + <h3>3.3 Contacts Information</h3> |
| 81 | + <p>With your explicit permission (READ_CONTACTS), we access:</p> |
| 82 | + <ul> |
| 83 | + <li>Contact names associated with phone numbers</li> |
| 84 | + <li>Phone numbers in your contact list</li> |
| 85 | + </ul> |
| 86 | + <p><strong>Purpose:</strong> This information is used solely to display caller names with recordings for your convenience. Contact data is accessed locally and is never transmitted to external servers.</p> |
| 87 | + |
| 88 | + <h3>3.4 Calendar Information</h3> |
| 89 | + <p>With your explicit permission (Calendar access on iOS, Calendar permissions on Android), we can:</p> |
| 90 | + <ul> |
| 91 | + <li>Read existing calendar events (to avoid duplicates)</li> |
| 92 | + <li>Create new calendar events based on AI-extracted information from your recordings</li> |
| 93 | + </ul> |
| 94 | + <p><strong>Purpose:</strong> Calendar access is used solely to create events you approve from action items extracted from your recordings. Calendar data is accessed locally.</p> |
| 95 | + |
| 96 | + <h3>3.5 Transcription Data</h3> |
| 97 | + <p>When you transcribe recordings, the following data is processed:</p> |
| 98 | + <ul> |
| 99 | + <li>Transcribed text from your audio recordings</li> |
| 100 | + <li>Speaker identification and diarization data</li> |
| 101 | + <li>Language detection information</li> |
| 102 | + <li>Timestamps and word-level timing</li> |
| 103 | + </ul> |
| 104 | + <p><strong>Storage:</strong> Transcriptions are stored locally on your device. The audio data is transmitted to your chosen transcription provider (Deepgram or Gladia) using your own API keys for processing.</p> |
| 105 | + |
| 106 | + <h3>3.6 AI-Extracted Information</h3> |
| 107 | + <p>When you use AI extraction features, we process transcriptions to extract:</p> |
| 108 | + <ul> |
| 109 | + <li>Calendar events (dates, times, descriptions)</li> |
| 110 | + <li>Reminders and action items</li> |
| 111 | + <li>Contact information mentioned in conversations</li> |
| 112 | + <li>Key facts and summaries</li> |
| 113 | + <li>Semantic embeddings for search functionality</li> |
| 114 | + </ul> |
| 115 | + <p><strong>Processing:</strong> Transcription text is sent to your chosen AI provider (OpenAI or Google Gemini) using your own API keys. Extracted data is stored locally on your device.</p> |
| 116 | + |
| 117 | + <h3>3.7 Technical and Device Information</h3> |
| 118 | + <p>We may collect limited technical information for app functionality:</p> |
| 119 | + <ul> |
| 120 | + <li>Device type and model</li> |
| 121 | + <li>Operating system version</li> |
| 122 | + <li>App version</li> |
| 123 | + <li>Error logs and crash reports (stored locally)</li> |
| 124 | + </ul> |
| 125 | + <p><strong>Note:</strong> We do not collect device identifiers, advertising IDs, or tracking identifiers. We do not use analytics services or tracking pixels.</p> |
| 126 | + |
| 127 | + <h3>3.8 User-Provided API Keys</h3> |
| 128 | + <p>To use transcription and AI features, you provide your own API keys for:</p> |
| 129 | + <ul> |
| 130 | + <li>Deepgram (transcription)</li> |
| 131 | + <li>Gladia (transcription)</li> |
| 132 | + <li>OpenAI (AI extraction and embeddings)</li> |
| 133 | + <li>Google Gemini (AI extraction)</li> |
| 134 | + </ul> |
| 135 | + <p><strong>Storage:</strong> API keys are stored securely using your device's native secure storage (iOS Keychain with kSecAttrAccessibleWhenUnlockedThisDeviceOnly, Android Keystore with hardware-backed encryption when available).</p> |
| 136 | + |
| 137 | + <h2>4. Legal Basis for Processing (GDPR/UK GDPR)</h2> |
| 138 | + <p>For users in the EEA, UK, and Switzerland, we process your personal data based on the following legal grounds:</p> |
| 139 | + |
| 140 | + <h3>4.1 Consent (Article 6(1)(a) GDPR)</h3> |
| 141 | + <p>We rely on your explicit consent for:</p> |
| 142 | + <ul> |
| 143 | + <li>Recording audio (microphone permission)</li> |
| 144 | + <li>Accessing your contacts (contacts permission)</li> |
| 145 | + <li>Accessing your calendar (calendar permission)</li> |
| 146 | + <li>Accessing your call logs (call log permission)</li> |
| 147 | + <li>Transmitting audio to transcription services</li> |
| 148 | + <li>Transmitting transcriptions to AI services</li> |
| 149 | + </ul> |
| 150 | + <p>You may withdraw consent at any time by revoking permissions in your device settings or deleting your data within the App.</p> |
| 151 | + |
| 152 | + <h3>4.2 Contract Performance (Article 6(1)(b) GDPR)</h3> |
| 153 | + <p>Processing necessary to provide the App's core functionality:</p> |
| 154 | + <ul> |
| 155 | + <li>Storing and displaying your recordings</li> |
| 156 | + <li>Processing transcriptions you request</li> |
| 157 | + <li>Displaying extracted calendar events and action items</li> |
| 158 | + </ul> |
| 159 | + |
| 160 | + <h3>4.3 Legitimate Interests (Article 6(1)(f) GDPR)</h3> |
| 161 | + <p>We may process data based on our legitimate interests for:</p> |
| 162 | + <ul> |
| 163 | + <li>App improvement and bug fixing</li> |
| 164 | + <li>Security and fraud prevention</li> |
| 165 | + <li>Legal compliance and responding to legal requests</li> |
| 166 | + </ul> |
| 167 | + |
| 168 | + <h2>5. How We Use Your Information</h2> |
| 169 | + <h3>5.1 Core App Functionality</h3> |
| 170 | + <ul> |
| 171 | + <li>Recording, storing, and playing back audio recordings</li> |
| 172 | + <li>Transcribing audio using third-party services</li> |
| 173 | + <li>Extracting calendar events, reminders, and contacts using AI</li> |
| 174 | + <li>Displaying caller identification from your contacts</li> |
| 175 | + <li>Creating calendar events based on extracted information</li> |
| 176 | + <li>Providing search functionality across your recordings and transcriptions</li> |
| 177 | + </ul> |
| 178 | + |
| 179 | + <h3>5.2 App Improvement</h3> |
| 180 | + <ul> |
| 181 | + <li>Debugging and fixing errors</li> |
| 182 | + <li>Improving app stability and performance</li> |
| 183 | + </ul> |
| 184 | + |
| 185 | + <h3>5.3 Legal Compliance</h3> |
| 186 | + <ul> |
| 187 | + <li>Complying with applicable laws and regulations</li> |
| 188 | + <li>Responding to lawful requests from authorities</li> |
| 189 | + <li>Protecting our legal rights</li> |
| 190 | + </ul> |
| 191 | + |
| 192 | + <h2>6. Third-Party Services and Data Sharing</h2> |
| 193 | + <p>Addit uses third-party services for transcription and AI processing. When you use these features, your data is transmitted to these services using API keys that you provide. We do not have access to your accounts with these providers.</p> |
| 194 | + |
| 195 | + <h3>6.1 Transcription Services</h3> |
| 196 | + <h4>Deepgram</h4> |
| 197 | + <ul> |
| 198 | + <li><strong>Data Sent:</strong> Audio files for transcription</li> |
| 199 | + <li><strong>Privacy Policy:</strong> <a href="https://deepgram.com/privacy" target="_blank" rel="noopener noreferrer">https://deepgram.com/privacy</a></li> |
| 200 | + <li><strong>Terms of Service:</strong> <a href="https://deepgram.com/terms" target="_blank" rel="noopener noreferrer">https://deepgram.com/terms</a></li> |
| 201 | + </ul> |
| 202 | + <h4>Gladia</h4> |
| 203 | + <ul> |
| 204 | + <li><strong>Data Sent:</strong> Audio files for transcription</li> |
| 205 | + <li><strong>Privacy Policy:</strong> <a href="https://www.gladia.io/privacy-policy" target="_blank" rel="noopener noreferrer">https://www.gladia.io/privacy-policy</a></li> |
| 206 | + <li><strong>Terms of Service:</strong> <a href="https://www.gladia.io/terms-of-use" target="_blank" rel="noopener noreferrer">https://www.gladia.io/terms-of-use</a></li> |
| 207 | + </ul> |
| 208 | + |
| 209 | + <h3>6.2 AI Processing Services</h3> |
| 210 | + <h4>OpenAI</h4> |
| 211 | + <ul> |
| 212 | + <li><strong>Data Sent:</strong> Transcription text for analysis, text for embeddings</li> |
| 213 | + <li><strong>Privacy Policy:</strong> <a href="https://openai.com/privacy" target="_blank" rel="noopener noreferrer">https://openai.com/privacy</a></li> |
| 214 | + </ul> |
| 215 | + <h4>Google Gemini</h4> |
| 216 | + <ul> |
| 217 | + <li><strong>Data Sent:</strong> Transcription text for analysis</li> |
| 218 | + <li><strong>Privacy Policy:</strong> <a href="https://policies.google.com/privacy" target="_blank" rel="noopener noreferrer">https://policies.google.com/privacy</a></li> |
| 219 | + </ul> |
| 220 | + |
| 221 | + <h3>6.3 What We Do NOT Share</h3> |
| 222 | + <ul> |
| 223 | + <li>We do NOT sell your personal data to any third party</li> |
| 224 | + <li>We do NOT share your data for advertising or marketing purposes</li> |
| 225 | + <li>We do NOT provide your data to data brokers</li> |
| 226 | + <li>We do NOT use your data to train AI models</li> |
| 227 | + <li>We do NOT transfer your data to our servers (all data remains on your device)</li> |
| 228 | + </ul> |
| 229 | + |
| 230 | + <h2>7. Data Storage and Security</h2> |
| 231 | + <h3>7.1 Local Storage</h3> |
| 232 | + <p>All your personal data, including recordings, transcriptions, extracted items, and settings are stored locally on your device. We do not operate servers that store your personal data.</p> |
| 233 | + |
| 234 | + <h3>7.2 Security</h3> |
| 235 | + <ul> |
| 236 | + <li><strong>op-sqlite:</strong> For structured data (recordings, transcriptions, events)</li> |
| 237 | + <li><strong>MMKV:</strong> For preferences and settings, with AES encryption</li> |
| 238 | + <li><strong>iOS Keychain / Android Keystore:</strong> For API keys, with hardware-backed encryption</li> |
| 239 | + <li>All data transmitted to third-party services uses HTTPS/TLS encryption</li> |
| 240 | + </ul> |
| 241 | + |
| 242 | + <h2>8. Data Retention</h2> |
| 243 | + <p>Data stored on your device is retained until you delete it. You control retention through individual deletion, cache clearing, full data deletion, or app uninstallation. Data transmitted to third-party services is subject to their respective retention policies.</p> |
| 244 | + |
| 245 | + <h2>9. Your Rights and Choices</h2> |
| 246 | + <p>Since all data is stored locally on your device, you can exercise most rights directly through the App:</p> |
| 247 | + <ul> |
| 248 | + <li><strong>Access:</strong> View all your data directly in the App</li> |
| 249 | + <li><strong>Deletion:</strong> Delete individual items or all data through Settings > Data Management > Delete All Data</li> |
| 250 | + <li><strong>Export:</strong> Export your data in JSON format through Settings > Data Management > Export Data</li> |
| 251 | + <li><strong>Permission Control:</strong> Revoke App permissions at any time through your device's settings</li> |
| 252 | + </ul> |
| 253 | + <p>For requests that cannot be fulfilled through the App, contact us at <a href="mailto:privacy@addit.dev">privacy@addit.dev</a>.</p> |
| 254 | + |
| 255 | + <h2>10. GDPR Compliance (EEA, UK, Switzerland)</h2> |
| 256 | + <ul> |
| 257 | + <li><strong>Right of Access (Article 15)</strong></li> |
| 258 | + <li><strong>Right to Rectification (Article 16)</strong></li> |
| 259 | + <li><strong>Right to Erasure (Article 17)</strong> — "right to be forgotten"</li> |
| 260 | + <li><strong>Right to Restrict Processing (Article 18)</strong></li> |
| 261 | + <li><strong>Right to Data Portability (Article 20)</strong> — JSON export</li> |
| 262 | + <li><strong>Right to Object (Article 21)</strong></li> |
| 263 | + <li><strong>Right to Withdraw Consent (Article 7(3))</strong></li> |
| 264 | + </ul> |
| 265 | + <p>Contact our DPO at <a href="mailto:dpo@addit.dev">dpo@addit.dev</a>. You may lodge a complaint with your local supervisory authority.</p> |
| 266 | + |
| 267 | + <h2>11. CCPA/CPRA Compliance (California Residents)</h2> |
| 268 | + <table> |
| 269 | + <thead> |
| 270 | + <tr><th>Category</th><th>Examples</th><th>Collected</th></tr> |
| 271 | + </thead> |
| 272 | + <tbody> |
| 273 | + <tr><td>Identifiers</td><td>Contact names, phone numbers</td><td>Yes (locally)</td></tr> |
| 274 | + <tr><td>Audio/Visual Information</td><td>Voice recordings, call audio</td><td>Yes (locally)</td></tr> |
| 275 | + <tr><td>Internet Activity</td><td>Browsing history, search history</td><td>No</td></tr> |
| 276 | + <tr><td>Geolocation</td><td>Precise location</td><td>No</td></tr> |
| 277 | + <tr><td>Sensitive Personal Information</td><td>Contents of communications</td><td>Yes (locally)</td></tr> |
| 278 | + </tbody> |
| 279 | + </table> |
| 280 | + <p><strong>Addit does NOT sell your personal information</strong> and does NOT share it for cross-context behavioral advertising.</p> |
| 281 | + |
| 282 | + <h2>12. Other Regional Compliance</h2> |
| 283 | + <p><strong>LGPD (Brazil):</strong> Contact our DPO at <a href="mailto:dpo@addit.dev">dpo@addit.dev</a>. Response within 15 days.</p> |
| 284 | + <p><strong>PIPEDA (Canada):</strong> Complaints may be filed with the Office of the Privacy Commissioner at <a href="https://www.priv.gc.ca" target="_blank" rel="noopener noreferrer">priv.gc.ca</a>.</p> |
| 285 | + <p><strong>Australian Privacy Act:</strong> Complaints may be filed with the OAIC at <a href="https://www.oaic.gov.au" target="_blank" rel="noopener noreferrer">oaic.gov.au</a>.</p> |
| 286 | + <p><strong>U.S. State Laws:</strong> We comply with VCDPA, CPA, CTDPA, UCPA, and other applicable state privacy laws. Exercise rights at <a href="mailto:privacy@addit.dev">privacy@addit.dev</a>.</p> |
| 287 | + |
| 288 | + <h2>13. Call Recording and Privacy</h2> |
| 289 | + <p><strong>IMPORTANT:</strong> You are solely responsible for complying with all applicable laws regarding call recording in your jurisdiction. Many jurisdictions require consent from all parties to a call. Please understand and comply with your local laws before recording calls.</p> |
| 290 | + |
| 291 | + <h2>14. Children's Privacy</h2> |
| 292 | + <p>Addit is intended for users who are at least 17 years of age (18 in some jurisdictions). We do not knowingly collect personal information from children under 13. If you believe your child has used the App, contact us at <a href="mailto:privacy@addit.dev">privacy@addit.dev</a>.</p> |
| 293 | + |
| 294 | + <h2>15. Changes to This Privacy Policy</h2> |
| 295 | + <p>We may update this Privacy Policy from time to time. We will update the "Last updated" date and, for material changes, provide notice through the App. Continued use after changes constitutes acceptance.</p> |
| 296 | + |
| 297 | + <h2>16. Contact Us</h2> |
| 298 | + <p><strong>General Privacy:</strong> <a href="mailto:privacy@addit.dev">privacy@addit.dev</a></p> |
| 299 | + <p><strong>Data Protection Officer (GDPR/LGPD):</strong> <a href="mailto:dpo@addit.dev">dpo@addit.dev</a></p> |
| 300 | + <p><strong>Legal:</strong> <a href="mailto:legal@addit.dev">legal@addit.dev</a></p> |
| 301 | + |
| 302 | + <p style="margin-top:2rem; font-size:0.85rem; color:#475569;">This Privacy Policy is effective as of January 16, 2026, and will remain in effect except with respect to any changes in its provisions in the future, which will be in effect immediately after being posted on this page.</p> |
| 303 | + </div> |
| 304 | + </div> |
| 305 | +</body> |
| 306 | +</html> |
0 commit comments