Privacy Policy
Last updated: August 26, 2026
1. Acceptance of policy
1.1. This Privacy Policy explains and lists the transparency information regarding what personal data is collected (Section 3) when you use our Service AI Summary - Meeting Notes and the services provided through it (together “Service”), how such personal data will be processed (Section 4), how meeting recording works and what rights you can exercise here (Section 6) and which rights do you have with respect to your personal data (Section 11).
1.2. By using the Service, you promise us that (i) you have read, understand, and agree to this Privacy Policy and the data processing described, and (ii) you are over 18 years of age. If you do not agree or are unable to make this promise, you shall not use the Service. In this case, you shall (a) delete your account and contact us and request deletion of your data; (b) cancel any active subscriptions; and (c) delete the Service from your devices.
1.3. The use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
1.4. We do not knowingly process personal data from persons under 18 years of age. If you learn that anyone younger than 18 has provided us with personal data, please contact us at notik_support@apptitude.cc.
1.5. If any questions remain unanswered or you would like to exercise your privacy rights, please also contact us at notik_support@apptitude.cc.
2. Personal data controller
AppTitude Technologies OÜ (with its legal address at Harju maakond, Tallinn, Mustamäe linnaosa, Mäealuse tn 2/1, 12618) is the data controller of your personal data ("we", "us", or "our").
3. Categories & sources of collected personal data
3.1. When you use the Service, we process data:
3.2. Data directly provided by you.
3.2.1. Identifiers: This may include your name and email address. You provide us with this information when you register for the Service, subscribe to our newsletters, or contact us by any other means.
3.2.2. Service data. You may also provide us with information necessary for Service functionality, such Images, videos, audio, files that you have shared with us,
3.2.3. Communication with support team: When you contact our support team, you may also provide us with some personal information.
3.3. Data we collect automatically
3.3.1. Meeting recordings as part of Service Data: When you invite our Service bot to your meetings, we collect audio and video recording of the meeting to provide transcription and summary features. By doing so, you represent and warrant that you have obtained all necessary prior consents, permissions, and notices from all meeting participants as required by applicable privacy and wiretapping laws before initiating the recording. If you do not agree to further audio and video recording, transcription, and processing of sessions through our Service bot, you shall remove the bot immediately.
3.3.2. Device and geolocation data: We collect language settings, Internet Protocol address, time zone, type and model of a device, device settings, OS version, Internet service provider, mobile carrier, hardware ID, and unique device identifiers (including IDFA or GAID).
3.3.3. Log and usage data: We collect information on how you interact with our Service. This may include information about what pages you have viewed, the features and content you interact with, how often you use the Service, how long you are on the Service.
3.3.4. Performance and Diagnostics Data: We collect information related to Services’ performance and diagnostics of Service as a result of your use of the Service. This may include crashlytics and diagnostics through logs monitoring.
3.3.5. User acquisition data: We also collect information about how you have found our Service that may include your referring app, URL or advertisement.
3.3.6. Cookies and similar technologies: Our products employ technologies (cookies, SDKs, etc.) to process your data to enhance your user experience, optimize ads, and analyze traffic. These technologies are activated when you interact with our services, visit our website, use our apps, or enable certain features like chats. Disabling these technologies may affect the functionality of certain features, although our products will remain usable.
3.4. Data provided by third parties
3.4.1. Calendar data. When you connect your Google Calendar to our Service, we access calendar data from Google Workspace APIs (including Google Meet and Google Calendar) that allows us to send our Service bot that you can accept into the meeting for meeting recording, transcription, and summary features. The use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3.4.2. Subscription data: You need to provide financial account data in order to purchase our Service. We do not collect or store, or have access to full credit card number data, though we may receive some limited information, including subscription terms, subscription ID, data about products or services purchased, date, time and amount of the purchase, the type of payment method used, limited digits of your card number.
3.4.3. Consumption information: When you use our Service and make the purchases at the App Store, we receive the following from Apple, such as Account Tenure, App Account Token (UUID), Consumption Status, Customer Consented, Delivery Status, lifetime Dollars Purchased, lifetime Dollars Refunded, Platform, play Time, Refund Preference, Sample Content Provided, and User Status.
3.5. Please note that we do not collect personal data about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, and genetic and biometric data. We also do not collect any information about criminal convictions and offenses.
3.6. We also undertake to collect only such amounts and types of personal data strictly required for the purposes mentioned in Section 4 (Purposes & lawful bases for data processing). To the extent necessary for those purposes, we take all reasonable steps to ensure that personal data is reliable, accurate, complete, and current for its intended use.
4. Purposes & lawful bases for data processing
4.1. For the processing of your personal data, we rely on the following lawful bases:
4.2. We collect and utilize your data primarily to provide the Service and continuously improve it with the help of analytics. Furthermore, we aim to attract new customers to our products. Below, you may find a more comprehensive breakdown of how we use your information.
Reasons for Processing | Types of data | Lawful bases |
To use all Service functions. It is necessary to set up a profile and identify the user. The email address is additionally used to contact the user. | Identifiers. Name, email address. | Performance of the contract. Your consent. |
To provide the Service’s features based on received data | Service data. Images, videos, audio, files that you have shared with us. Audio and video recordings processed through Service bot participation in the meeting, as initiated by the user | Performance of the contract. Your consent. |
To send our Service bot that you can accept into the meeting for meeting recording, transcription, and summary features as part of the Service’s features | Calendar data. Data about your meetings from Google Workspace API | Performance of the contract. Your consent |
For analytical and marketing purposes. To provide, improve, and develop the Service. | Device and Geolocation Data. Includes language settings, Internet Protocol address, time zone, type and model of a device, device settings, OS version, Internet service provider, mobile carrier, hardware ID, and unique device identifiers (including IDFA or GAID). | Performance of a contract with you. Necessary for our legitimate interests |
For analytical and marketing purposes. To provide, improve, and develop the Service. | Log and Usage Data. Information about how you use our Service and user activity within the Service. | Performance of a contract with you. Necessary for our legitimate interests |
For app functionality and analytical purposes. To fix crashes & bugs as well as improve and develop the Service. | Performance and Diagnostics Data. Crashlytics, diagnostics through logs monitoring. | Performance of a contract with you. Necessary for our legitimate interests. |
It is required to identify the subscription the user selects, its duration, and its expiration. | Subscription data. The transaction data, ID subscriptions, and subscription terms. This is the information we get from the payment system when you buy our subscription. | Performance of the contract. Your consent. |
To participate in reviewing user refund requests to the Apple App Store or our suppliers to prevent fraudulent and deceptive actions by users. | Consumption Information. Account Tenure, App Account Token (UUID), Consumption Status, Customer Consented, Delivery Status, lifetime Dollars Purchased, lifetime Dollars Refunded, Platform, play Time, Refund Preference, Sample Content Provided, and User Status. | Your consent Necessary for our legitimate interests |
For analytical and marketing purposes. To provide, improve, and develop the Service. | User acquisition data. Information about your referring app, URL or advertisement. | Your consent. Necessary for our legitimate interests. |
4.3. We rely on the following legitimate interests:
5. Built-in artificial intelligence tools
5.1. The Service uses AI tools, such as Deepgram, OpenAI, RapidAI, and Recall.ai, in order to perform speech-to-text transcriptions or generate the summaries of transcriptions from audio/video recordings or meetings. The use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5.2. By accessing the Service, the user agrees to the transfer and processing of photos, videos, audio, files and inputs through integrated AI technologies. We do NOT transfer any data to AI technologies that can identify any user or be associated by AI technology with any user. Please note that if you accidentally upload any photo, video, audio, file or input containing a person or personal data (for instance, a document or a photo showing a face), we only process the content itself and do NOT process, retain, or identify any personal data or individuals within it. NOTWITHSTANDING THE ABOVE, PLEASE DO NOT UPLOAD FILES THAT MAY CONTAIN YOUR PERSONAL DATA OR THE PERSONAL DATA OF THIRD PARTIES.
5.3. Future and additional AI tools. To continuously improve the Service, we may integrate, use, or test additional AI tools beyond those listed above. By using the Service, you consent to the processing of your inputs (including images, videos, audio, files) through such tools and to any necessary transfers to third-party AI providers. We will apply the same data minimization and non-identification principles outlined in this Section.
6. Meeting recording through Service bot
6.1. The Services include features that allow you to invite an automated bot to join, record, transcribe, and generate AI summaries of your meetings. BY ACTIVATING OR ADDING OUR SERVICE BOT TO ANY MEETING, YOU EXPLICITLY CONSENT TO THE AUDIO AND VIDEO RECORDING, TRANSCRIPTION, AND PROCESSING OF THAT SESSION IN ACCORDANCE WITH THIS POLICY. YOU ALSO REPRESENT AND WARRANT THAT YOU HAVE OBTAINED ALL NECESSARY PRIOR CONSENTS, PERMISSIONS, AND NOTICES FROM ALL MEETING PARTICIPANTS AS REQUIRED BY APPLICABLE PRIVACY AND WIRETAPPING LAWS BEFORE INITIATING THE RECORDING.
6.2. IF YOU (OR OTHER MEETING PARTICIPANT) DO NOT AGREE TO FURTHER AUDIO AND VIDEO RECORDING, TRANSCRIPTION, AND PROCESSING OF SESSION THROUGH OUR SERVICE BOT, YOU (OR OTHER MEETING PARTICIPANT) SHALL REMOVE THE BOT IMMEDIATELY.
6.3. If you are a user of this Service that initiated the meeting recording, you can delete personal data related to this recording right in your Service functionality. If you are just a meeting participant and wish to delete personal data related to this recording, you should contact the person that initiated the meeting recording through our Service bot. We and our processors delete such personal data within a short timeframe after the end of the meeting, so that all personal data related to the meeting is only stored locally on the device of the user who initiated the meeting recording.
7. Third-party services and other disclosures of data
7.1. Apart from our employees, contractors, and affiliated companies (if any), we share information with the range of third parties that help operate, provide, improve, integrate, customize, support, and market our Service. We require all third parties to respect the security of your personal data and treat it under the law. The types of third parties we share information with include, in particular:
7.2. Service providers: We engage the partners mentioned below to carry out specific services or business functions on our behalf using their technologies and resources, based on our instructions. We do not allow our third-party service providers to use your personal data for their purposes and only permit them to process your personal data for specified reasons defined in this Privacy Policy.
Third Party | Its Service | Purpose of usage | Link to privacy materials of the Third Party |
Apple Inc. | Apple App Store | App publishing | https://www.apple.com/legal/privacy/en-ww/ |
Apple Inc. | Apple App Store | To automate the transfer of a user's audio file from iCloud to the Service | https://www.apple.com/legal/privacy/en-ww/ |
Amplitude, Inc. | Amplitude | Product analytics and event tracking | https://amplitude.com/privacy |
Google LLC | Firebase | User authentication and database management | https://policies.google.com/privacy?hl=en-US |
Functional Software, Inc. | Sentry | App development, performance & error monitoring | https://sentry.io/privacy/ |
AppsFlyer Ltd. | Appsflyer | Product analytics and event tracking | https://www.appsflyer.com/legal/processing-customer-data/ |
Meta Platforms Inc. | Meta Ads | Marketing management | https://www.facebook.com/privacy/policy/ |
Google LLC | Google Analytics | Product analytics and event tracking | https://policies.google.com/privacy?hl=en-US |
TikTok Inc. | TikTok | Marketing management | https://www.tiktok.com/legal/privacy-policy |
Snap Inc. | Snapchat | Marketing management | https://values.snap.com/privacy/privacy-policy |
Amazon Web Services, Inc. | AWS | Cloud storage | https://aws.amazon.com/privacy/ |
Microsoft Corporation | Bing | Marketing management | https://www.microsoft.com/en-us/privacy/privacystatement |
Supabase, Inc. | Supabase | Cloud storage and user authorization | https://supabase.com/privacy |
Upstash, Inc. | Upstash | Temporary data storage | https://upstash.com/trust/privacy.pdf |
84codes AB | Cloudamqp | Temporary data storage & server functioning | https://www.cloudamqp.com/legal/privacy_policy.html |
elasticsearch B.V. | Elastic | App development, performance & error monitoring | https://www.elastic.co/legal/privacy-statement |
Fly.io, Inc | App development, performance & error monitoring | https://fly.io/legal/privacy-policy/ | |
Artia International S.R.L. | IP-API | Product analytics | https://ip-api.com/docs/legal |
Deepgram Inc. | Deepgram | Speech-to-text transcription and language understanding | https://deepgram.com/privacy |
OpenAI OpCo, LLC or OpenAI Ireland Limited | ChatGPT | Creating summaries of transcriptions generated within the Service | https://openai.com/policies/row-privacy-policy/ |
R Software Inc. | RapidAPI | Generating transcriptions and summaries from YouTube videos. | https://rapidapi.com/page/privacy |
Hyperdoc Inc. | Recall.ai | Generating transcripts, recordings, and metadata from meetings. | https://www.recall.ai/privacy |
7.3. Public authorities, including law enforcement agencies: We may use and disclose personal data to enforce our legal rights or Terms of Use, to protect our rights, privacy, safety, or property, and/or that of our affiliates, you or others, and to respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, or in other cases provided for by law.
7.4. Third parties as part of a merger and acquisition: As we develop our business, we may buy or sell assets or business offerings. Customers’ information is generally one of the transferred business assets in these types of transactions. We may also share such information with any affiliated company (if any) and may transfer such information in the course of a corporate transaction, such as the sale of our business, a divestiture, merger, consolidation, or asset sale, or in the unlikely event of bankruptcy.
8. Cross-border transfer of personal data
8.1. We may transfer personal data to employees, contractors and third parties from countries other than the country in which the data was originally collected in order to provide the Service and for purposes indicated in this Privacy Policy. If these countries do not have the same data protection laws as the country in which you initially provided the information, we deploy special safeguards.
8.2. In particular, if we transfer personal data from the EEA to countries with not adequate level of data protection, we use one of the following legal bases: (i) Standard Contractual Clauses approved by the European Commission (details available here), or (ii) the European Commission adequacy decisions about certain countries (details available here).
9. Data security & retention policies
9.1. We have implemented appropriate security measures to prevent your data from being accidentally lost, used, accessed unauthorized, altered, or disclosed. In addition, we limit access to your data to employees, agents, contractors, and other third parties who have a business need to know. They will only process your data based on our instructions and are subject to a duty of confidentiality.
9.2. We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
9.3. We also use technical data encryption tools like SSL protocols to secure your data.
9.4. We will store your personal data for as long as it is reasonably necessary for achieving the purposes set forth in the Terms of Use and Privacy Policy, which includes the period during which you have an account with the Service. We will also retain and use your personal data as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
9.5. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your data, the purposes for which we process your data, and whether we can achieve those purposes through other means, and the applicable legal requirements.
10. Changes to policy
We reserve the right to and may change this privacy notice occasionally. If we make any material changes, we will notify you through our Service, email, or by presenting you with a new version of this privacy notice for you to accept if we, for example, add new processing activities or collect additional personal data from you. Your continued use of the Service after the effective date of an updated version of the Privacy Policy will indicate your acceptance of the Privacy Policy as modified.
11. Your legal rights
11.1. This Section explains legal rights applicable to users that are residents of certain economic areas, countries, or states as set forth below. Except as otherwise provided herein, you may exercise your legal rights by contacting us at notik_support@apptitude.cc. To ensure that we properly handle the requests you make regarding your rights, we are required to verify those requests. Depending on the type of request and the product used by you, this may include your name, age, email, date of subscription purchase, date of last activity, date of account creation, or some other Service use data that will reasonably identify you as an owner of the account, etc. We may also ask you for additional proof of identity, if necessary, but we strive to ask less according to the data minimization principle.
11.2. European Economic Area residents
As a data subject, you have the right to interact with its data directly or through a request to us. This section describes these rights and how you can exercise them:
Right | Description |
Right to access | You can request an explanation of the processing of your personal data. |
Right to rectification | You can change the data if it is inaccurate or incomplete. |
Right to erasure | You can send us a request to delete your personal data from our systems. We will remove them unless otherwise provided by law. |
Right to restrict the processing | You may partially or completely prohibit us from processing your personal data. |
Right to data portability | You can request all the data you provided to us and request to transfer data to another controller. |
Right to object | You may object to the processing of your personal data. |
Right to withdraw consent | You can withdraw your consent at any time. |
Right to file a complaint | If your request was not satisfied, you could file a complaint to the regulatory body. |
To exercise your rights, contact us. If your request is not satisfied, you can submit a complaint to your local Data Protection Authority. You may find it here. UK residents enjoy the same rights but may lodge a complaint at the other Authority in the UK – Information Commissioner’s Office. You can contact them at 0303 123 1113 or go online at www.ico.org.uk/concerns. | |
Please note! Depending on the state and legislative requirements, we have from 30 to 60 days to exercise your request, with the right to postpone it for 30 days more. |
If your complaint is not satisfied, you can file a complaint with the Federal Trade Commission.
Your rights vary depending on the laws that apply to you, but may include:
Right | Description | Area | |
Right to access | You can request an explanation of how your personal data is processed. |
|
|
Right to correct | You can change the data if it needs to be more accurate or complete. |
|
|
Right to delete | You can request to delete your personal data from our systems. |
|
|
Right to portability | You can request all the data you provided to us and request to transfer data to another controller. |
|
|
Right to opt out of sales | The right to opt out of the sale of personal data to third parties. |
|
|
Right to opt out of certain purposes | The right to opt-out of processing for profiling/targeted advertising purposes. |
|
|
Right to opt out of the processing of sensitive data | The right to opt-out of processing of sensitive data. |
| |
Right to opt in for sensitive data processing | The right to opt in before processing sensitive data. |
|
|
Right against automated decision-making | A prohibition against a business making decisions about a consumer based solely on an automated process without human input |
|
|
Private right of action | The right to seek civil damages from a controller for statute violations. |
| |
Please note! Some states do not have privacy laws. The rights of residents of such states are governed by U.S. federal law. If your state is missing from the list, please contact us. | |||
California residents have the right under the California Consumer Privacy Act (“CCPA”) to opt out of a company governed by the CCPA's “sale” of their personal information.
We do not sell your personal information to anyone, nor use your data as a business model.
However, we support the CCPA by allowing California residents to opt out of the future sale of their personal information. Please contact us if you would like to record your preference so that we do not sell your data in the future.
11.5. Access rights under California’s Shine the Light
California also provides its residents with additional access rights. Under the Shine the Light law, the residents may ask companies once a year what personal information they share with third parties for those third parties' direct marketing purposes. Learn more about what is considered to be personal information under the statute.
To obtain this information from us, please send an email message to notik_support@apptitude.cc, which includes “Request for California Shine the Light Privacy Information” on the subject line and your state of residence and email address in the body of your message. Please be aware that not all information sharing is covered by the “Shine the Light” requirements and only information on covered sharing will be included in our response.
11.6. Do-not-track requests
California residents visiting the Service may request that we do not automatically gather and track information about their online browsing movements across the Internet.
Such requests are typically made through web browser settings that control signals or other mechanisms that allow consumers to exercise choice regarding collecting personal data about an individual consumer’s online activities over time and across third-party websites or online services.
We currently do not have the ability to honor these requests. We may modify this privacy notice as our abilities change.
As data subjects, you have privacy rights prescribed by Canada’s federal and provincial privacy laws.
If you want additional information, please contact us by filling a request.
If you are not satisfied with the response, you can file a complaint with the Office of the Privacy Commissioner of Canada.
12. Contact us
If you have any questions about this Privacy Policy and/or want to exercise your legal rights, you may contact us at notik_support@apptitude.cc.