Privacy Policy

Last updated: July 13, 2026

1. Introduction

AndyNote ("we", "our", or "us") is operated by OLAP DATABASE PTE. LTD. This Privacy Policy explains how we collect, use, and protect your personal data when you use the AndyNote application ("the App"). We are committed to protecting your privacy and being transparent about our data practices.

2. Data We Collect

2.1 Voice & Transcription Data

  • Audio recordings: Captured by your device microphone during transcription sessions. Audio is saved in your local app library. For real-time transcription, audio is streamed over an encrypted connection to a speech service. High-accuracy transcription, recovery, and some post-recording workflows may upload audio files for asynchronous cloud processing.
  • Transcription text: The text output generated from your audio. Stored locally on your device. When transcription, translation, AI analysis, Ask Andy, search, recovery, or similar connected features run, the required text and context are sent to our backend and selected processing providers.

2.2 AI Chat Data

  • Chat messages: When you use Ask Andy, your questions, relevant note content, and conversation history are sent to our backend for processing.

2.3 Account & Authentication Data

  • Email address (via Google Sign-In or Apple Sign-In)
  • User identifier
  • Authentication provider information

2.4 Usage & Device Data

  • App version, device model, operating system version
  • Country and locale settings
  • Feature events, diagnostics, network information, and service-reliability data
  • Identifiers used for authentication, subscriptions, attribution, fraud prevention, and analytics

3. How We Use Your Data

PurposeData Used
Real-time speech-to-text transcriptionAudio stream
Real-time translationTranscription text
AI analysis (speaker identification, summaries, titles)Transcription text, related context, and audio when required by the workflow
AI chat (Ask Andy)Chat messages, conversation history
User authenticationEmail, user ID
App improvement & analyticsUsage statistics, device info

4. Third-Party Services & Data Sharing

We share your data with the following third-party services to provide the App's functionality. Each service is subject to their own privacy policies and enterprise data protection standards.

Cloudflare

Data shared: Account and request data, uploaded audio or text, processing jobs, generated results

Purpose: Networking, application infrastructure, processing, reliability, and cloud storage

Privacy policy: www.cloudflare.com

Microsoft Azure and speech providers

Data shared: Audio, transcription text, language and request metadata

Purpose: Speech-to-text, translation, and related processing

Privacy policy: privacy.microsoft.com

OpenAI

Data shared: Audio or text required for the selected transcription or AI feature

Purpose: Transcription, summaries, speaker tools, search, translation, and chat

Privacy policy: openai.com

Anthropic

Data shared: Text and context required for selected AI features

Purpose: Summaries, speaker tools, search, translation, and chat

Privacy policy: www.anthropic.com

Model-routing providers

Data shared: Audio or text required for the selected feature

Purpose: Routing requests to available transcription and AI models

Privacy policy: openrouter.ai

Firebase (Google)

Data shared: Authentication, analytics, messaging, and diagnostic data

Purpose: Authentication, product analytics, notifications, and service diagnostics

Privacy policy: firebase.google.com

RevenueCat and Apple

Data shared: Purchase identifiers, subscription status, and entitlement information

Purpose: Purchases, subscriptions, and entitlement management

Privacy policy: www.revenuecat.com

Attribution and analytics providers

Data shared: Device, campaign, purchase, and app-event identifiers

Purpose: Campaign measurement, product analytics, performance, and fraud prevention

Privacy policy: www.appsflyer.com

Important: AI Data Processing

Connected features send the content required for the request through our backend to selected speech or AI providers. Provider selection can vary by feature, region, selected model, availability, and reliability. For these workflows:

  • Data is encrypted in transit using industry-standard TLS
  • Provider retention and data use follow the applicable API or enterprise terms
  • Processing copies and results may be retained to deliver, retry, and recover requested features

Audio may be sent for real-time or high-accuracy transcription and for workflows that need to rebuild or recover a transcript. Other AI features generally process transcript text and related context.

5. Your Choices & Controls

You control when you record and which connected features you use:

  • Recording controls: AndyNote accesses the microphone only with operating-system permission and while a recording workflow is active.
  • Connected features: Starting transcription, translation, analysis, Ask Andy, recovery, or similar features submits the content required to provide that feature.
  • Local controls: You can review, export, and delete notes stored in the app. Deleting local data does not necessarily delete cloud processing copies.

To request deletion of cloud-associated personal data, contact us at [email protected]. We may need to verify your request and may retain information where required for legal, security, fraud-prevention, or technical reasons.

6. Data Storage & Retention

  • On-device storage: Voice notes, transcriptions, and chat history remain available in the app on your device. AndyNote is local-first, not local-only: connected transcription and AI features submit the content required for processing.
  • Backend storage: When AI features are enabled, transcription text, audio, job metadata, and generated results may be stored to complete requests and support retries, recovery, security, and reliability. Retention varies by data type and operational need.
  • Account data: User authentication data is managed through Firebase and our backend database.

7. Data Security

  • All data transmissions use HTTPS/TLS encryption
  • TLS is transport encryption; cloud processing is not described as end-to-end encrypted
  • Authentication tokens are generated securely and expire regularly
  • Third-party services maintain enterprise-grade security certifications
  • We do not sell your personal data to any third party

8. Children's Privacy

The App is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected data from a child under 13, please contact us so we can promptly remove it.

9. International Data Transfers

Your data may be processed in regions where our third-party service providers operate, including the United States, Europe, and Asia-Pacific. Privacy protections and legal requirements can differ from those in your home jurisdiction.

10. GDPR & EEA Users

If you are located in the European Economic Area (EEA), you have additional rights under the GDPR:

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing

Contact us to exercise an applicable right. We may need to verify your request.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting a notice in the App or on our website. Your continued use of the App after changes are posted constitutes your acceptance of the updated policy.

12. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

  • Email: [email protected]
  • Company: OLAP DATABASE PTE. LTD.
  • Address: 1 North Bridge Road, Singapore 179094