1. Who we are and what this Policy covers
This Policy applies to Talk Sorted: AI Speech to Text (the “App”), its controlled backend, and this Talk Sorted legal page. The data controller and App operator is:
Karalko Aliaksei
Ijslandstraat 11
1363 DR Almere
Netherlands
alsvarel.developer@gmail.com
This Policy does not govern services you independently choose to use, such as your email provider, device manufacturer, Google Play account, or a recipient to whom you share a recording. Their own terms and privacy notices apply.
The current App does not require a Talk Sorted user account. Local records and settings are associated with the App installation and device. Google Play may separately associate purchases with your Google account.
2. Your responsibility when recording people or device audio
Recording laws vary by country, state and context. Some require every participant's prior consent; additional rules may protect telephone calls, workplaces, schools, court proceedings, confidential communications, children, health information and trade secrets. You are solely responsible for deciding whether recording, transcription, translation, storage and sharing are lawful and appropriate.
- Tell participants clearly before recording and obtain affirmative consent where required.
- Do not use Talk Sorted for covert surveillance, unlawful interception, harassment, evidence tampering, or recording content you are not authorized to access.
- Android device-audio capture depends on the source app and system protections. Talk Sorted is not a call-recording service and must not be used to bypass protected audio or another service's rules.
- Avoid recording highly sensitive or regulated information unless you have assessed the legal, contractual and security requirements and accept the risks. Talk Sorted is not designed as a HIPAA, banking-secrecy, classified-information or legal-privilege archive.
Where you record other people, you may yourself be a data controller or otherwise legally responsible for their data. We process the material only to provide the features you request, but we do not monitor your recording environment, verify participant consent, or determine the law that applies to you.
3. How audio and AI processing work
On-device storage and recognition
The App saves the recording in its app-private device storage. When you select an on-device recognition engine, audio is transcribed locally. To create a follow-up, lecture summary, personal-journal entry, corrected title or translation, the resulting text and relevant existing result are still sent to our backend and OpenAI when you request or use that AI feature.
Cloud transcription
When cloud transcription is selected, the App uploads the audio, recording type, language and speaker-separation choice over HTTPS to our Render-hosted backend. The backend forwards the audio to OpenAI for transcription and may send the transcript to OpenAI to create the requested meeting follow-up, lecture notes, journal entry or title. The backend is stateless and deletes its temporary audio file after the request completes, including when processing fails.
Translation and sharing
When you request translation, the transcript and the relevant generated result are sent through our backend to OpenAI. Up to five translated language versions may be cached on the device. When you use email or the system share sheet, the selected text and files are passed to the app, provider and recipients you choose; that transfer is initiated and controlled by you.
4. Data we process
| Category | Examples | Where and why |
|---|---|---|
| Recordings and generated content | Microphone or permitted device audio, transcript, speaker labels, title, follow-up, tasks, lecture notes, journal text and translations | Stored locally; selected content is processed in the cloud only to perform transcription, summarization, correction or translation requested through the App. |
| Local settings and entitlements | Recording mode, AI engine, theme, notification cues, consent choices, daily minutes, subscription/no-ads state, non-expiring hour balance and purchase fingerprints | Stored on the device to operate the App, prevent duplicate local credit and remember your choices. |
| Backend technical data | IP address where present in hosting logs, time, endpoint, response status, request size, app version and coarse error information | Used for delivery, rate limiting, security, reliability, abuse prevention and troubleshooting. We do not intentionally put recording content or transcripts in access logs. |
| Optional analytics and attribution | App installation identifiers, device/app/OS information, install source, session, recording type and duration, plan, processing success/failure, product ID, purchase stage and coarse error code | Sent to Firebase Analytics and AppsFlyer only after you enable analytics and attribution. Audio, titles, transcripts and generated text are excluded from these events. |
| Optional crash diagnostics | Crash stack, app and OS version, device model/architecture, time, installation identifiers and technical context | Sent to Firebase Crashlytics only after you enable crash reporting. We design custom diagnostics not to include recording content. |
| Advertising and consent data | Advertising or SDK instance identifiers, IP address, device/app information, approximate location inferred from IP, consent choices, ad requests, impressions, interactions and fraud signals | Processed by Google Mobile Ads and authorized ad technology providers to request, deliver, measure and protect interstitial advertising. The Google consent flow runs before the App requests ads where required. |
| Purchase data | Google Play product ID, price/currency displayed by Google, purchase status, transaction token during verification, restore status and a one-way local fingerprint | Used to complete, restore and protect subscriptions, no-ads rights and extra-hour purchases. We do not receive your full card or bank details. |
| Support and legal requests | Your email address, correspondence, evidence you provide and request history | Used to answer you, verify a request, resolve disputes, prevent abuse and comply with law. |
| Legal-site traffic | IP address, user agent, requested URL and security signals | Processed by Cloudflare to deliver and protect this website. We do not place our own analytics cookies on this legal page. |
We do not intentionally collect your contacts, precise GPS location, government identifier, full payment credentials or biometric template. The content you choose to record may nevertheless contain personal or sensitive information about you or other people.
5. Service providers, disclosures and international processing
We disclose data only as needed to operate the App, comply with law, protect rights and security, or complete a transfer you initiate. Our principal providers are:
- Render Services, Inc. — backend hosting and technical logs. Privacy · DPA
- OpenAI, L.L.C. and affiliates — speech-to-text, structured notes, journal formatting, title generation and translation. API requests use
store=falsefor Responses. OpenAI states that API customer content is not used to train models unless the customer opts in. API data controls · Privacy - Google LLC — Google Play distribution and billing, Firebase Analytics, Firebase Crashlytics, Google Mobile Ads/AdMob, consent management and authorized advertising vendors. Privacy · Firebase privacy and security
- AppsFlyer Ltd. and affiliates — optional installation attribution, product analytics and fraud prevention. Services Privacy Policy · Device opt-out
- Cloudflare, Inc. — delivery, TLS and security of this legal website. Privacy
We may also disclose information to professional advisers, courts, regulators or law-enforcement authorities when reasonably necessary to establish or defend legal claims, comply with a valid legal obligation, protect a person from serious harm, investigate fraud or secure the service. If the App or its assets are transferred in a merger, reorganization or sale, data may transfer subject to this Policy and applicable law.
Providers may process data in the United States, the EEA and other countries. Where required, we rely on provider data-processing terms and legally recognized transfer mechanisms such as adequacy decisions, the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses. No mechanism eliminates all foreign-law or governmental-access risk.
No sale of recordings. We do not sell or rent recordings, transcripts or AI results and do not disclose them to analytics or advertising providers. Advertising identifiers and activity may be considered “sharing,” “targeted advertising” or a “sale” under some U.S. state definitions even when no money is paid for the data; the choices below are available where applicable.
6. Purposes and legal bases
Where the GDPR, UK GDPR or similar law applies, we rely on:
- Performance of a contract or steps you request: recording, local storage, cloud processing, translation, sharing, quota and purchase delivery.
- Consent: optional Firebase Analytics, AppsFlyer attribution, Crashlytics reporting, and advertising storage/personalization where consent is legally required. You may withdraw consent for future processing in the App.
- Legitimate interests: service security, minimal access logging, fraud prevention, debugging, enforcing limits, defending claims and improving reliability, balanced against your rights.
- Legal obligations: tax/accounting records, lawful authority requests, consumer rights and incident response.
Talk Sorted does not use your recordings or AI results to make decisions producing legal or similarly significant effects about you. Advertising and analytics providers may perform automated measurement, attribution, fraud detection or ad selection under their own documented controls.
7. How long data is kept
- Local recordings, transcripts, results, translations and settings: until you delete a recording, delete all local data, clear App storage or uninstall the App. The App requests that Android cloud backup of App data be disabled, but device images, exports and copies you shared are outside our control.
- Backend audio: stored only in a temporary file during the request and deleted after the request finishes or fails. The backend does not operate a recording or transcript database.
- OpenAI: as of this Policy date, OpenAI documents no abuse-monitoring or application-state retention for the audio transcription endpoint. Text sent to the Responses API may appear in abuse-monitoring logs for up to 30 days by default even when
store=false, unless a different approved retention control applies or longer retention is legally or safety-required. - Render service logs: ordinarily 7 to 30 days depending on the hosting workspace plan, unless an incident, legal duty or separately configured log stream requires a different period.
- Firebase Crashlytics: Google states that crash traces, minidump-derived data and associated installation identifiers are retained for 90 days before removal begins.
- Firebase Analytics: according to the retention controls of our Analytics property and Google's aggregate-reporting rules. We do not configure custom analytics events to contain recording content.
- AppsFlyer: AppsFlyer's services policy states that end-user data is kept no longer than 24 months unless directed, allowed or required otherwise; some aggregated reporting may be retained up to 25 months and partner-specific periods may apply.
- Advertising data: according to your consent, Google/vendor controls and their retention rules. We do not maintain a separate copy of ad-bid or ad-profile data.
- Purchases and legal records: local entitlements remain while App data remains; Google keeps store records under its policies. Support, tax, fraud and dispute records may be kept for the legally required period or ordinarily up to 24 months after the matter closes if no longer period is necessary.
Protected provider backups, fraud/security records and data required for legal claims may remain for limited additional cycles. De-identified aggregate information that can no longer reasonably identify you may be retained longer.
8. Your controls and deletion options
- Delete an individual recording from its meeting screen.
- Open Settings → Privacy and data to delete all local meetings, audio, transcripts, AI results, cached translations, prepared share files and locally stored backend access data.
- Clear Talk Sorted storage in Android settings or uninstall the App to remove the App's local data. This does not retract copies you previously emailed or shared.
- Disable Analytics/attribution or Crashlytics in Talk Sorted settings. This stops future optional collection but does not instantly erase provider data already lawfully processed.
- Use the App's advertising privacy-options entry where required, in-ad controls, Android advertising settings, or AppsFlyer's opt-out page to change applicable choices.
- Cancel subscriptions and manage refunds through Google Play. Removing the App does not itself cancel a subscription.
Because Talk Sorted currently has no developer-operated user account and no persistent backend content store, there is no separate Talk Sorted cloud account to delete. To request deletion or access relating to telemetry, support or technical records, email us. We may need an installation/provider identifier and proportionate evidence to locate data and prevent unauthorized requests; never send us a recording, transcript, payment-card number or Google password merely to identify yourself.
9. Privacy rights
Depending on where you live, you may have rights to information, access, correction, deletion, restriction, objection, portability, withdrawal of consent and appeal. You may also complain to a data-protection authority and must not be discriminated against for exercising a right.
EEA users may contact the Dutch Data Protection Authority or their local supervisory authority. California and other covered U.S. residents may request the categories and specific pieces of personal information processed, correction or deletion, and may opt out of sale/sharing or targeted advertising where applicable. We do not use sensitive recording content to infer characteristics or target ads.
Submit a request to alsvarel.developer@gmail.com. We will respond within the period required by applicable law, normally within one month under the GDPR, subject to permitted extensions and verification. A request cannot require us to erase data held solely on your device, by a recipient you selected, or by an independent provider acting under its own relationship with you.
10. Security and incident limits
Measures include HTTPS/TLS, Android app-private storage, disabled Android App backup, a stateless backend, temporary-file deletion, authenticated backend requests, minimal content logging, provider access controls and user-controlled analytics/crash collection. Local text metadata is not separately end-to-end encrypted by Talk Sorted; anyone with sufficient access to an unlocked, compromised or rooted device may be able to reach it.
No transmission, storage or AI service is completely secure. We cannot guarantee that a provider, device, network or user-selected recipient will never experience unauthorized access, loss or disclosure. Keep your device updated and locked, delete material you no longer need, and contact us promptly if you suspect a security issue. We will investigate and provide notices where law requires.
11. Children
Talk Sorted is not directed to children under 16, and we do not knowingly collect their personal data. A person below the age at which they can independently consent in their country may use the App only with authorization and supervision from a parent or legal guardian. The person starting a recording must not record a child without every authorization required by law, the child's institution and the parent/guardian. Contact us if you believe a child's data reached our providers unlawfully.
12. AI accuracy, professional use and limits of responsibility
Speech recognition, diarization, titles, summaries, journal formatting and translations are probabilistic and may omit, invent, misattribute or mistranslate information. Always compare important output with the original audio and obtain human review before using it for employment, education, healthcare, safety, finance, legal matters, evidence, deadlines or decisions affecting another person.
Talk Sorted is an organizational tool, not professional advice, a certified transcript, a secure evidence vault, an emergency service or a substitute for a qualified translator or stenographer. Features may be unavailable, delayed or changed, and providers may impose limits.
To the maximum extent permitted by applicable law, we are not responsible for loss caused by unlawful recording or disclosure, failure to obtain consent, inaccurate AI output, a decision made from that output, loss of local data, third-party services, a recipient you selected, or use contrary to this Policy. Nothing in this Policy excludes privacy, consumer, product, death/personal-injury, fraud, intentional-misconduct or other liability that cannot legally be excluded or limited, and nothing removes mandatory rights available in your country. This Policy is a transparency notice and does not create a warranty that the service is risk-free or suitable for a regulated purpose.
13. Changes and contact
We may update this Policy when features, providers, retention controls or law change. The date above will change; material changes will receive an appropriate in-App or store notice where required. We will request new consent before applying a materially new consent-based purpose.
Privacy, security and legal requests:
Karalko Aliaksei
Ijslandstraat 11
1363 DR Almere
Netherlands
alsvarel.developer@gmail.com