Legal
Privacy Policy
Meeting recordings are sensitive. This page sets out exactly what we hold, who else touches it, and how long any of it lasts — written to be read, not skimmed.
Last updated 27 August 2026
The short version
Your recordings are yours. We do not use them to train AI models and we do not share them with anyone except the transcription and summarisation providers listed below, who process audio on our behalf in order to produce your notes. We run no analytics, no advertising and no tracking cookies of any kind. Audio is deleted automatically 7 days after upload, and you can delete anything yourself at any time.
1. Who is responsible
Plaudipus is the data controller for the personal data described here, operating from Jakarta, Indonesia. For any privacy question or request, write to admin@plaudipus.com.
2. What we collect
Information you give us
- Account details — your email address and name. Your password is never stored; we keep only a salted
scrypthash from which the password cannot be recovered. - Waitlist details — the name, email and any context you send when requesting access.
- Audio recordings you upload or record in the browser.
- Meeting details you type — attendees, location, agenda, dates, hashtags, speaker names and any edits you make to a summary.
- Business cards you scan — the photograph is sent for reading and deleted immediately once the details are extracted. We never store the image. The extracted contact details are saved to your private contact list.
- Correspondence — what you send us by email or WhatsApp.
Information produced from your recordings
- Transcripts, with timestamps and — on Pro — speaker separation.
- Summaries, decisions, action items and mentioned locations derived from the transcript.
- Technical properties of the file, such as its duration, format, and the recording date embedded in its metadata.
A recording may contain personal data about other people — everyone who spoke in the meeting. You are responsible for having the right to record them and for telling them, where the law requires it. See section 3 of our Terms.
Information collected automatically
- Usage records — a line-by-line ledger of minutes added and spent, which you can see in full on your account page. This is how the balance is auditable.
- Server logs — IP address, timestamps and errors, kept for security and debugging. Failed login attempts are counted per IP address to block brute-force attempts.
We do not use analytics platforms, advertising networks, social media pixels, or any third-party tracking script. The site loads no third-party code at all.
3. Why we process it, and on what basis
- To provide the service — transcribing, summarising and storing your meetings. Basis: performance of our contract with you.
- To operate accounts and billing — authentication, metering minutes, and invoicing. Basis: contract, and our legal obligation to keep financial records.
- To keep the service secure — preventing abuse, brute-force attacks, and repeated claiming of the free starting minutes. Basis: our legitimate interest in protecting the service.
- To support you — answering your messages. Basis: contract and legitimate interest.
We do not sell personal data, and we do not use it for advertising or profiling.
4. Contacts you scan from business cards
Scanning a business card creates a record of someone else's personal data — their name, employer, phone number and email. We want to be plain about how that works.
- The photo is not kept. It is held in memory only for as long as the reading takes, then discarded. It is never written to our disks and never appears in any backup.
- The extracted details are yours. They sit in your private contact list, visible to nobody but you, and are not shared, sold, pooled between accounts, or used to build any directory.
- You can delete any contact at any time, which removes it permanently, and exporting a contact as a .vcf file puts a copy under your own control.
- Reading is done by a third party. The image is sent to OpenRouter, which routes it to the vision model that reads it, on the same terms as our other processors below.
Your responsibility. A person who hands you their business card expects you to contact them — but that does not automatically permit every use. You are responsible for handling their details lawfully, for honouring any request they make to you directly, and for not using Plaudipus to build a marketing list from cards collected for another purpose. If someone asks us to remove their details and we can identify them, we will tell you and act on it.
5. Who else processes your recordings
We use specialist providers to do the transcription and summarisation. They act on our instructions as processors, and each receives only what it needs for its step. All three are based in the United States, so your audio or transcript text is transferred there for processing.
| Provider | What it receives | What it does |
|---|---|---|
| Deepgram | Your audio file, when you choose speaker names for a meeting | Speech recognition with speaker separation |
| Groq | Your audio file at the standard rate, and transcript text | Speech recognition, and summarisation as a fallback |
| OpenRouter | Transcript text, and business-card images while they are being read | Routes the request to the model provider serving the model we use, for summarisation and for card reading |
We select providers that do not train their models on customer data submitted through their APIs. We cannot, however, control their internal practices, and their own terms and privacy policies govern their handling of the data. If we add or change a provider we will update this page and, where the change is material, tell you.
Beyond these, we disclose data only to a payment provider when you make a payment (which receives your billing details, never your recordings), and where we are legally required to — for example in response to a valid legal order.
6. How long we keep things
| What | How long |
|---|---|
| Audio files | 7 days after upload, then permanently deleted |
| Business card photos | Not stored — discarded as soon as the details are read |
| Contacts saved from cards | Until you delete them or close your account |
| Transcripts, summaries and meeting details | Until you delete them or close your account |
| Usage ledger and payment records | Retained as required for accounting and tax purposes |
| Server logs | A short rolling window, then overwritten |
Deleting a meeting removes its audio, transcript and summary immediately. Deleting your account removes all of them.
7. What remains after you delete your account
We want to be explicit about this, because it is the one thing that outlives your account.
When you close your account we delete your recordings, transcripts, summaries and profile. We keep a one-way cryptographic fingerprint (an HMAC-SHA256 hash) of your email address, together with the fact that this address has already received its free starting minutes, and the date. We do not keep the email address itself.
Why: new accounts receive free minutes. Without this, the same person could delete and re-register repeatedly to collect them over and over, and free access would be unsustainable for everyone. When you sign up again with the same address, the fingerprint matches and the free minutes are not granted a second time.
What it is not: the fingerprint is computed with a secret key held only by us, cannot be reversed back into your email address, and is not used to contact you, profile you, or for any purpose other than the one described. It is not shared with anyone.
Unused minutes are forfeited when an account is deleted and are not restored on re-registration. We also retain records of payments for as long as tax and accounting law requires, regardless of account deletion.
8. Cookies and local storage
We use one cookie: a session cookie that keeps you signed in. It is cryptographically signed, marked httpOnly and Secure, and expires after 30 days. It carries no tracking identifier.
Your browser's local storage holds small preferences such as your light or dark theme choice. These stay on your device and are never sent to us. There are no advertising or analytics cookies to consent to, because we do not use any.
9. Security
- All traffic is encrypted in transit with HTTPS.
- Passwords are stored only as salted
scrypthashes. - Sessions use signed tokens verified in constant time; login attempts are rate-limited per IP address.
- Recordings are stored on servers we control, accessible only to your account.
- Administrative access is restricted, and administrators cannot read your password — only reset it.
No system is perfectly secure. If a breach affecting your personal data occurs, we will notify affected users and the relevant authority as required by law.
10. Your rights
Under Indonesia's Personal Data Protection Law (UU No. 27 of 2022), and comparable laws where they apply to you, you may:
- Access the personal data we hold about you
- Correct anything inaccurate — you can edit summaries and meeting details directly in the app
- Delete your recordings or your entire account, at any time, from your account page
- Export your data — any meeting as text or PDF, or a full export on request
- Object to or restrict processing based on our legitimate interests
- Withdraw consent where we relied on it, without affecting processing already carried out
- Complain to the relevant data protection authority
To exercise any of these, email admin@plaudipus.com. We respond within 30 days and will verify your identity first. There is no charge unless a request is manifestly excessive.
11. Children
Plaudipus is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
12. Changes to this policy
We will update this page as the service changes, and the "last updated" date above always reflects the current version. For material changes — a new processor, a new category of data, a shorter retention period — we will give reasonable notice by email or in the app.
13. Contact
Privacy questions, requests and complaints: admin@plaudipus.com. Our postal address and WhatsApp number are on the Contact page.