1. Who we are and what this policy covers
Dictaphone is provided by Amzu Information Technology Ltd (company number 08516330, “Amzu”, “we”, “us” or “our”). This policy covers the Dictaphone iPhone and iPad app, the Dictaphone service, and the Dictaphone product pages. For privacy questions or requests, contact venkat@amzuit.com.
2. The short version
Eligible everyday dictation is processed on your iPhone. Dictaphone does not receive that note audio or nearby note text. Meeting recording is different: after you confirm that every participant has agreed and finish recording, encrypted meeting audio is sent through the Dictaphone API to Groq for transcription. We return the result to your device and do not intentionally store your recording or transcript content in our service database.
3. Data that stays on your device
Notes, note audio, saved transcripts, your local dictionary, local speaker labels, and privacy receipts are stored on your iPhone. Temporary note audio is deleted when you finish or cancel. Finished notes and meeting transcripts remain in your local Library until you delete them. Dictaphone does not use iCloud to synchronise this content.
If a meeting upload fails, the app may keep a protected local retry copy for up to 15 minutes. It is deleted after successful processing, when that retry window expires, or when you delete the meeting.
4. Data used for cloud meetings
When you choose cloud meeting transcription, we process the recording you provide, the selected language, the meeting duration, and the information needed to deliver the result. The Dictaphone API forwards the audio to Groq’s speech-transcription service and returns the timed text to the app. Groq is the named transcription provider for this route. The service is configured for zero data retention before production use; nevertheless, you should not use cloud transcription for content you are not authorised to share.
Dictaphone does not intentionally store cloud meeting audio or transcript content in its database. We retain non-content service records such as the pseudonymous service identifier, processing date and duration, billed duration, provider and model, status, and estimated service cost. These records help us operate the allowance, prevent abuse, investigate failures, and account for use of the service.
If you import an audio file, it follows the same consent-gated cloud meeting path. Dictaphone does not capture live telephone-call audio.
5. Free minutes and Apple purchases
To provide 30 free cloud meeting minutes per month without an account, the app keeps a random key in the device Keychain and our service stores only its SHA-256 digest with an anonymous usage record. When the allowance is first claimed, the app sends an Apple-generated DeviceCheck token to Apple so Apple can help prevent the allowance being reset by reinstalling. Dictaphone does not receive a hardware identifier from this process.
For subscriptions and credit packs, Apple processes your purchase. To verify an entitlement, Dictaphone processes Apple-signed transaction information, including transaction identifiers, product ID, expiry, environment and, where Apple provides it, an app account token. We do not receive your payment-card details and do not require your name or email address to use a subscription.
6. What we do not do
We do not sell personal data, show advertising, use advertising identifiers, or track you across apps and websites for advertising or measurement. We do not create reusable voice profiles from meetings. We do not use recordings or transcripts to train Dictaphone models.
7. Why we process data
We process data to provide the features you request, including returning cloud meeting transcripts and checking App Store entitlements. Where applicable, we rely on performance of our contract with you; your choice to use cloud meeting transcription and confirm participant consent; our legitimate interests in securing the service, preventing fraud and abuse, and maintaining service records; and legal obligations such as accounting and tax requirements.
8. Who receives data
We share only what is necessary with service providers: Apple for purchases, entitlement verification and DeviceCheck; Groq for the cloud meeting transcription you request; and Railway for hosting the Dictaphone API and database. We require processors acting for us to use personal data only to provide their service to us, protect it appropriately, and provide a level of protection consistent with this policy. We may also disclose information where required by law or necessary to protect rights, safety, or the service.
9. International transfers
Our providers may process service data outside your country, including in the United States. Where applicable, we use the safeguards available through our provider arrangements and applicable data-protection law. Cloud meeting transcription is optional; you can continue using eligible on-device dictation without it.
10. Retention and deletion
Content follows the deletion rules in sections 3 and 4. We retain pseudonymous usage, entitlement, credit, security, and operational records only for as long as reasonably necessary to provide and protect the service, resolve disputes, and meet legal, accounting, fraud-prevention, and security obligations. We then delete or anonymise them where feasible. You can delete local notes, meetings, transcripts, and privacy receipts in Dictaphone at any time.
To request deletion of server-side records associated with your subscription or free allowance, email venkat@amzuit.com. We may need limited information to verify the request and may retain records where law requires it or where they are necessary to establish, exercise, or defend legal claims.
11. Your privacy choices and rights
You can choose on-device dictation instead of cloud meetings, decline a cloud meeting, stop or delete a local recording, delete local content, manage a subscription through Apple, and contact us to request access, correction, deletion, restriction, objection, or portability where applicable. You may also complain to your local data-protection authority; in the UK this is the Information Commissioner’s Office. We do not use personal data for direct marketing or automated decisions that produce legal or similarly significant effects.
12. Security
We use transport encryption, short-lived service access tokens, protected local files, and content-blind administration. No method of transmission or storage is completely secure; please keep your device protected and do not share recordings or transcripts that you are not authorised to disclose.
13. Apple App Store privacy information
Apple requires a publicly accessible privacy-policy link and accurate App Privacy disclosures for data collected by the app and its third-party partners. Our App Store disclosures are maintained to reflect the practices described here, including pseudonymous purchase and usage records and the absence of advertising tracking. If those practices change, we will update this policy and the App Store disclosure.
14. Changes to this policy
We may update this policy when Dictaphone, our providers, or the law changes. We will post the updated policy and effective date here. Material changes will apply prospectively as required by law.