Privacy & GDPR

Privacy Policy

How Dictata collects, processes, and protects personal data plus GDPR rights for every user.

July 22, 2026

Privacy Policy

Last updated: July 22, 2026

1. Introduction

This Privacy Policy describes how we collect, use, disclose, and protect your personal data when you use our application (the “App”) and related services (collectively, the “Service”). We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable laws. By using the Service, you acknowledge that you have read this Policy.

Controller:<br /> Kirill Zolygin (sole proprietor)<br /> c/o Opus, Grunewaldstraße 91, 10823 Berlin, Germany<br /> Email: info@dictata.app

If you have any questions about privacy or wish to exercise your rights, contact us via the above email or postal address.

2. Personal Data We Collect

We collect the following categories of data:

  • Account & Authentication Data: Email address, account status (trial/paid, service mode), and magic-link login tokens. We do not store passwords.
  • Identity Checks for Abuse Prevention: If you delete an account that has used the Cloud service, we may retain a keyed, one-way cryptographic hash of your email address, the email domain, a reference to the former account, and aggregated Cloud-usage totals. We use this limited archive solely to prevent repeated free-trial use and related abuse (see Sections 3 and 6).
  • User Inputs & Content: Text prompts, audio recordings, transcripts, glossary terms, and outputs necessary to provide AI features. In live dictation mode, audio is streamed in real time to the speech-to-text provider used by the applicable App version and processing region. Current providers may include Gladia, Deepgram, and AssemblyAI. We retain content only transiently while fulfilling your request; long-term history (if enabled) is stored locally on your device.
  • Usage & Technical Data: Device type, operating system, App version, system locale, IP address, timestamps, account-, session-, and request-level identifiers, service mode, processing-region preference, subscription tier, request and event types, recording duration, word and token counts, selected transcription or translation language, provider/model identifiers, status and error information, latency, and similar telemetry that helps us secure, operate, bill, and improve the Service.
  • Payment & Billing Data: Subscription tier, billing country, invoices, Dodo Payments order IDs, and payment status. Dodo Payments, our merchant of record, collects and processes your payment method; we never see full card details.
  • Support Communications: Messages you send to our support channels and metadata necessary to resolve your request.
  • Cookies & Analytics Data: Online identifiers collected via cookies or similar technologies when you visit our website (see Section 4).

We do not intentionally collect special-category data (e.g., health information). Please avoid submitting such data through the Service.

3. How We Use Your Data & Legal Bases

PurposeDataLegal Basis (GDPR)
Provide and maintain the Service (account creation, magic-link login, routing prompts to AI providers, saving preferences)Account data, authentication tokens, user inputs, device infoArt. 6(1)(b) – performance of a contract
Process subscriptions and issue invoicesAccount data, billing data, Dodo Payments metadataArt. 6(1)(b) and Art. 6(1)(f) – performance of a contract and our legitimate interest in receiving payment
Communicate with you (login links, service notices, support responses)Email, usage contextArt. 6(1)(b) (service communications) / Art. 6(1)(f) (support)
Enforce Terms, prevent fraud/abuse (including hashed email list for free-trial enforcement)Usage metrics, hashed identifiers, logsArt. 6(1)(f) – legitimate interest in protecting our Service
Operate, secure, troubleshoot, and improve the App (product analytics and diagnostics)Account-linked or pseudonymous usage and technical data; aggregated statisticsArt. 6(1)(f) – our legitimate interests in maintaining, securing, and improving the Service
Analytics/marketing via cookiesCookie identifiers, device infoArt. 6(1)(a) – consent
Compliance with legal obligations (tax, accounting, regulatory inquiries)Billing data, invoices, correspondenceArt. 6(1)(c) – legal obligation

We will request additional consent before using your data for any purpose incompatible with this table.

4. Cookies, Analytics, and Tracking

App product analytics

When you are signed in, the App sends limited product-analytics and diagnostic events to our Supabase backend. These events may be linked to your account and an App session and may include the technical and usage data listed in Section 2. We use them to operate the Service, enforce plan limits, diagnose failures, understand feature adoption, and improve reliability.

We do not include microphone audio, transcript text, prompt text, clipboard content, glossary terms, API keys, or authentication tokens in product-analytics event properties. Product analytics is distinct from website cookie analytics and is processed on the basis of our legitimate interests described in Section 3. You may object to this processing as described in Section 9.

Website cookies and analytics

We use cookies and similar technologies on our website. Essential cookies are necessary for basic functionality (e.g., remembering your login) and rely on our legitimate interest. Non-essential cookies (analytics/marketing) are used only with your consent through our cookie banner.

  • Google Analytics 4 (GA4): Measures website traffic. IP addresses are truncated in the EU. Data may be stored on Google servers in the EU or US.
  • Meta Pixel: Tracks conversions from Facebook/Instagram campaigns; controlled per your Meta privacy settings.
  • Microsoft Clarity: Provides anonymized session insights (clicks, scrolls) to improve usability.
  • Other Testing Tools: From time to time we may test additional analytics tools; we will update this Policy before enabling any new trackers.

You can withdraw cookie consent via our banner, adjust browser settings, or install opt-out extensions (e.g., GA opt-out add-on). Refusing cookies may limit some website features.

5. Third Parties & Processors

We do not sell your personal data. We share it only with trusted processors or independent controllers as described below:

  • AI Infrastructure:
    • Gladia SAS and Gladia Inc. – Provide real-time speech-to-text streaming for current Cloud live dictation. Your microphone audio and any glossary terms enabled for live recognition are sent to Gladia for the active session. EU and US/Global workloads are routed to the corresponding regional Gladia infrastructure. See Gladia's Privacy Notice.
    • Deepgram, Inc. – May provide real-time speech-to-text streaming for supported App versions or routes. EU workloads use Deepgram's EU endpoint; US/Global workloads use its global infrastructure. See Deepgram's Privacy Policy.
    • AssemblyAI Inc. – Provides real-time speech-to-text streaming for legacy App versions and supported routes. EU workloads use AssemblyAI's EU endpoint; US/Global workloads use its US infrastructure. See AssemblyAI's Privacy Policy.
    • Google Cloud (Cloud Run + Vertex AI, Google LLC) – Handles authentication of Cloud requests, batch transcription and recovery where applicable, text cleanup, formatting, translation, and other AI processing. Data is routed according to the processing region you select and is processed by Vertex AI (Gemini) or another configured Google Cloud model.
    • Bring Your Own Key (BYOK): If you supply your own API key (e.g., OpenAI or Google), content requests are processed under your provider account and that provider's terms. We do not control the provider's retention or usage policies. We do not store your API key or BYOK content in our database, but we may retain limited BYOK usage metadata such as provider, model, duration, word/token counts, estimated cost, status, error code, and latency for billing, security, and product analytics.
  • Supabase Inc. – Hosts our application backend (currently in Frankfurt, EU). It stores authentication data, account profiles, subscription and configuration metadata, usage records, and product-analytics events.
  • Dodo Payments – Acts as merchant of record and an independent controller for buyer payment, billing, tax, fraud-prevention, and compliance data. Dodo Payments collects payment details and billing information, processes VAT, and issues invoices. We receive limited transaction and subscription metadata such as customer/order/subscription identifiers, amounts, status, and tax-country information. See Dodo Payments' Privacy Policy.
  • Email & Communication Tools: Services we use to send transactional emails or respond to support tickets (e.g., a transactional email provider). These providers act under our instructions.
  • Analytics & Marketing Partners: Google, Meta, Microsoft Clarity (as detailed above) operate as independent controllers for cookie data once you consent.
  • Professional Advisors & Authorities: Tax advisors, accountants, or legal counsel when necessary, and governmental or law-enforcement bodies when legally required.

Where a service provider acts as our processor, we use applicable data-processing terms or agreements requiring it to act on our instructions and implement appropriate security measures. Some recipients, including Dodo Payments in its merchant-of-record role and certain analytics or marketing providers, act as independent controllers for their own processing.

6. Data Retention

  • Account data: Stored while your account is active and normally deleted within 30 days after you close your account, unless retention is required by law or expressly described below.
  • Abuse-prevention archive: If created when an account is deleted, the keyed email hash, email domain, former-account reference, and aggregated Cloud-usage totals are retained for up to 24 months to prevent repeated free-trial use.
  • User inputs/content: Only stored transiently to fulfill the request (usually minutes). Long-term history remains on your own device unless you export it.
  • Usage logs: Security logs (including IP addresses) are typically retained for up to 30 days unless needed for investigations.
  • App product analytics: Raw product-analytics events are retained for up to 180 days. Daily activity rollups are retained for up to 24 months. Account-linked records are deleted or de-identified when the account is deleted unless another retention rule applies.
  • Billing records: Retained for 10 years to comply with German/EU tax law.
  • Website analytics data: Retained by the respective providers according to the configured schedules (e.g., GA4 user-level data for up to approximately 14 months); we keep aggregated reports as needed for business analysis.
  • Support correspondence: Retained for the life of the support ticket and up to 24 months afterward for audit purposes.

When the retention period ends, data is deleted or irreversibly anonymized.

7. International Data Transfers

Although we host most core systems in the EU and route EU Cloud workloads to regional infrastructure where available, some providers or their subprocessors may process data outside the European Economic Area:

  • Gladia, Deepgram, and AssemblyAI – US/Global live-dictation workloads and certain subprocessors may involve processing outside the EEA; EU live workloads use the providers' applicable EU regional endpoints where available.
  • Google Cloud – US/Global AI processing and some support operations may involve processing outside the EEA.
  • Dodo Payments and its group or service providers – payment and compliance data may be processed internationally according to the Dodo entity and payment method involved.
  • Google, Meta, and Microsoft – consented website analytics and marketing data may be processed in the United States or other countries.
  • Email providers or support tools – may operate globally, depending on the vendor.

Where personal data is transferred outside the EEA, we use an applicable transfer mechanism such as an adequacy decision (including the EU–US Data Privacy Framework where available) or the European Commission's Standard Contractual Clauses (SCCs), together with supplementary technical and organizational measures where required. Information about applicable safeguards can be requested using the contact details in Section 12.

8. Data Security

We apply administrative, technical, and organizational measures to protect your data, including TLS encryption, access controls, monitoring, and regular security reviews. Despite our efforts, no method of transmission or storage is 100% secure, so we cannot guarantee absolute security.

9. Your Rights

Under GDPR you have the right to:

  1. Access your personal data (Art. 15).
  2. Rectify inaccurate data (Art. 16).
  3. Erase your data (“right to be forgotten”) (Art. 17).
  4. Restrict processing (Art. 18).
  5. Data portability for information you provided (Art. 20).
  6. Object to processing based on legitimate interests (Art. 21).
  7. Withdraw consent at any time where processing is based on consent (e.g., cookies).
  8. Lodge a complaint with your local supervisory authority. Our lead authority is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin, Germany).

To exercise any rights, email info@dictata.app. We may ask for verification before fulfilling your request.

10. Children’s Privacy

The Service is intended for users aged 18 and older. We do not knowingly collect personal data from children. If you believe a child has provided data to us, please contact us so we can delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the App, website, or email as appropriate. The “Last updated” date reflects the latest revision. Where applicable law requires consent for a new processing activity, we will request that consent separately before the activity begins.

12. Contact

If you have questions, requests, or concerns about privacy, contact:

Kirill Zolygin
Email: info@dictata.app
Address: c/o Opus Grunewaldstraße 91, 10823 Berlin, Germany