LEGAL

Privacy Policy

Effective May 8, 2026
이 문서는 영어로만 제공돼요. 다른 언어로 도움이 필요하신 경우 [email protected]로 문의해 주시면 도와드릴게요.
The short version. We collect the minimum data needed to transcribe and structure your audio. Audio uploads are deleted automatically within 72 hours. We never use your content to train AI models, and we never sell your information.

1. Who we are

audien.to is the AI audio service these terms refer to (“audien.to”, “we”, “our”). This policy explains what personal information we collect when you use the website and services at audien.to (the “Service”), how we use it, who we share it with, and the rights you have.

For data-protection inquiries, including requests to access, correct, or delete your data, contact us at [email protected].

2. What we collect

We collect the following categories of information:

  • Account information (paid users only). Your email address and the password hash stored by our authentication provider, Keycloak. We do not collect your name, phone number, or physical address. If you sign in with Google, we receive your email and your Google account ID — nothing more.
  • Audio you upload. The audio file itself is stored in Cloudflare R2 object storage at a path tied to your user ID (or anonymous session ID).
  • Transcripts and AI-generated outputs. Stored in our application database, linked to your user ID or anonymous session.
  • Usage data. File durations, request counts, language selections, error logs, and aggregated quality metrics. We use this to enforce quotas and improve product reliability. It does not include the content of your audio or transcripts.
  • Connection data. Your IP address (used for abuse prevention and quota enforcement; retained briefly) and browser user-agent string.
  • Payment data (paid users only). Your Stripe customer ID, subscription ID, and current plan status. We do not see or store your card number, expiry, or CVV — Stripe handles those directly under their PCI-DSS compliance.
  • Cookies. See Section 9.

3. How we use information

We use information for these purposes only:

  • To transcribe and structure the audio you submit.
  • To enforce free-tier and paid-tier quotas.
  • To process payments and manage subscriptions for paid users.
  • To prevent fraud, abuse, and violations of our Terms of Service.
  • To communicate with you about your account, billing, service changes, or required legal notices (paid users; anonymous users see in-app notices instead).
  • To comply with applicable law and respond to valid legal requests.

4. What we don’t do

We do not use your audio, transcripts, or outputs to train any AI model — ours or anyone else’s. Our subprocessors are contractually prohibited from doing so.

We do not sell your personal information for money or other consideration, and we do not share it for cross-context behavioral advertising.

We do not load third-party advertising trackers. No Google Analytics, no Facebook Pixel, no advertising cookies.

We do not access your content except as necessary to deliver the Service or, in rare cases, to investigate suspected violations of our Terms or to comply with a valid legal request.

5. Who processes data on our behalf

We use the following subprocessors. Each operates under a contract that prohibits using your data for any purpose outside delivering the Service.

SubprocessorRoleData
BytePlus (Seed ASR 2.0)Speech-to-textAudio + transcript
DifyLLM transformsTranscripts + outputs
Cloudflare R2Audio file storageAudio files
KeycloakAuthenticationEmail + password hash
GoogleOptional OAuth sign-inEmail + Google account ID
StripePayment processing (paid users only)Customer ID + subscription state

This list is current as of the effective date. We may change subprocessors over time; we will update this list and, for paid customers under a separate Data Processing Agreement, provide advance notice as required by that agreement.

6. Data retention

  • Audio files (Cloudflare R2): deleted automatically within 72 hours of upload by a bucket lifecycle policy. You cannot extend this; we cannot make exceptions.
  • Transcripts and AI-generated outputs: stored in our database. Retained until you delete them, you close your account, or your anonymous session expires.
  • Shared snapshots (links you generate at /s/…): retained until you delete or expire the share. Soft-deleted shares are permanently scrubbed within 90 days. Shared pages are marked noindex so search engines do not list them.
  • Account data (email, billing records): retained while your account is active. Deleted within 30 days of account closure, except for records we are legally required to keep (e.g., tax and accounting receipts for the period required by law).
  • Server logs: kept for up to 30 days for security and abuse investigation, then deleted or aggregated.

7. Your rights

Depending on where you live, you have some or all of these rights:

  • Access — ask for a copy of the personal information we hold about you.
  • Correction — ask us to correct inaccurate or incomplete information.
  • Deletion — ask us to delete your personal information. We comply within 30 days unless law requires us to retain it.
  • Portability — receive a copy of your transcripts and outputs in a machine-readable format (JSON).
  • Object or restrict — object to or restrict certain uses of your data (e.g., direct marketing).
  • Withdraw consent — where we rely on consent, you may withdraw it at any time.
  • Lodge a complaint with a supervisory authority — for EEA/UK users, your local data protection authority.

To exercise any of these rights, email [email protected] from the address on your account (or, for anonymous users, with enough information for us to identify the affected session). We may need to verify your identity before responding.

8. California residents (CCPA / CPRA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act and Privacy Rights Act:

  • Right to know the categories and specific pieces of personal information we have collected about you, the sources, the business purpose, and the categories of third parties with whom we share it. The categories and business purposes are described in Sections 2–5 above.
  • Right to delete your personal information, subject to limited exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of the sale or sharing of personal information. We do not sell or share personal information for cross- context behavioral advertising, so this right does not apply — but we honor it as a matter of policy.
  • Right to limit the use of sensitive personal information. We do not use sensitive personal information for any purpose other than delivering the Service.
  • Right to non-discrimination — we will not deny you service, charge different prices, or provide a different level of quality because you exercised any of these rights.

To exercise these rights, email [email protected]. We may verify your identity before responding.

9. Cookies and similar technologies

We use a small number of cookies:

  • distinct_id — an anonymous identifier we set in your browser to count unique visitors, enforce per- session quotas, and prevent abuse. Set HttpOnly with a maximum age of three years. Contains no personal information you supplied.
  • NextAuth session cookies next-auth.session-token, next-auth.csrf-token, next-auth.callback-url. HttpOnly. Used only for authentication and cleared when you sign out.
  • NEXT_LOCALE — stores your selected language preference.

We do not use Google Analytics, Facebook Pixel, advertising cookies, or third-party tracking cookies.

10. Security

We use TLS to encrypt data in transit, encryption at rest for stored audio and database content, and access controls to limit who on our team can view production data. We log administrative access for audit. No system can be perfectly secure; we will notify affected users without undue delay if we discover a breach affecting personal information, in accordance with applicable law.

11. International data transfers

Our service may transfer your data across borders — for example, audio uploaded from the European Economic Area may be processed by Cloudflare R2 in a US region, and transcripts may be processed by our LLM subprocessor outside your country of residence. Where required, transfers from the EEA, UK, or Switzerland rely on the European Commission’s Standard Contractual Clauses or an equivalent safeguard.

12. Children’s privacy

audien.to is not directed to children under 13 (or under 16 in the EEA, UK, or Switzerland). We do not knowingly collect personal information from anyone in those age groups. If you believe a minor has provided us with personal information, email [email protected] and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. For material changes, we will give at least 30 days’ advance notice by email (to paid users) or by in-app notice (to anonymous users). The effective date at the top of this page shows when the current version took effect.

14. Contact

For any privacy question or to exercise your rights, email [email protected].

audien.to
[email protected]

개인정보 처리 방침 · audien·to