This Privacy Policy explains how Hear2Text handles your personal data when you use our website at heartotext.com and our apps for iOS and Android (together, the “Service”): what we collect, why, who we share it with, how long we keep it and which rights you have. It is written to meet the EU General Data Protection Regulation (GDPR), the UK GDPR, Türkiye’s Law No. 6698 on the Protection of Personal Data (KVKK), the California Consumer Privacy Act as amended by the CPRA (CCPA) and other applicable laws.
1. Who is responsible for your data
The Service is operated by MIA DIGITAL LLC, which is the data controller for the personal data described in this policy:
MIA DIGITAL LLC
112 Capitol Trl Ste A7751
Newark, DE 19711
United States
Email: support@heartotext.com
Recordings often contain other people’s voices and words. You decide what you record, upload and share, and you are responsible for having a lawful basis to do so. Personal data about other people that appears in your content is processed on your behalf, only to provide the Service to you.
2. The data we collect
- Account data: your name, email address and password (stored only as a salted hash), your language, and — if you sign in with Apple or Google — the account identifier and profile details that provider shares with us. Apple may give us a private relay address instead of your real email.
- Your content: audio and video you record or upload, links you import and the media we fetch from them, and everything the Service produces from them: transcripts, timestamps, speaker labels and the names you give speakers, edits, notes, translations, summaries, folders, and the questions you ask the AI assistant together with its answers.
- Workspace and sharing data: the workspaces you create or join, the names and email addresses of the people you invite or share with, and the settings of your share links.
- Subscription and payment data: your plan, your subscription status and history, and the transaction identifiers Stripe, the App Store or Google Play send us. Card details are handled by these payment providers; we never see or store your full card number.
- Support data: the messages and attachments you send to our support team or to the support assistant.
- Device and usage data: your IP address and the approximate country we derive from it, browser and device type, operating system, app version, language, push-notification token, the actions you take in the Service (such as starting a recording or opening the upgrade screen), and crash and error reports.
- Cookies and similar technologies on our website, and advertising identifiers in our apps, as described in section 8.
We collect this data from you, automatically from your devices, and from the providers you choose to use with the Service, such as Apple, Google and Stripe.
3. Why we use it, and our legal bases
- To provide the Service — creating your account, transcribing, telling speakers apart, translating, summarising, answering your questions about a transcript, syncing across your devices, sharing and exporting. Legal basis: performance of our contract with you (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)).
- To take payments and manage subscriptions, and to keep the accounting and tax records the law requires. Legal bases: contract, and legal obligation (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)).
- To keep the Service secure, prevent fraud and abuse, and apply plan limits and fair use. Legal basis: our legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).
- To understand how the Service is used and to fix errors, through analytics and crash reports. Legal basis: our legitimate interests, or your consent where the law requires consent for cookies or similar technologies.
- To measure our advertising — for example, whether an ad led to an install or a subscription. Legal basis: your consent (GDPR Art. 6(1)(a); explicit consent under KVKK Art. 5(1)).
- To email you about your account, security, billing and transcriptions (contract), and, where permitted, about new features and offers (your consent or our legitimate interests). Every marketing email has an unsubscribe link.
- To answer your support requests. Legal bases: contract and our legitimate interests.
- To comply with the law, respond to lawful requests from authorities, and establish, exercise or defend legal claims. Legal bases: legal obligation and legitimate interests (KVKK Art. 5(2)(ç) and (e)).
We do not sell your personal data, and we do not use your recordings or transcripts for advertising or to train AI models.
4. How transcription and AI features handle your content
- Transcription and speaker separation run on speech-recognition servers we operate ourselves. Your audio is not sent to a third-party transcription service.
- Speaker labels come from telling apart the voices within a single recording. We do not create voiceprints, and we do not use voices to identify people across recordings.
- To give a transcript its title and summary, detect its language, translate it and answer your questions about it, we send the relevant transcript text — never the audio — to OpenAI. OpenAI processes it as our service provider and does not use it to train its models.
- Nobody at Hear2Text listens to your recordings or reads your transcripts, unless you ask us to look at a specific one to help you, or we have to in order to investigate abuse or comply with the law.
- We do not make decisions that have legal or similarly significant effects on you based solely on automated processing.
5. Who we share data with
We share personal data only as far as each purpose requires:
- Hetzner Online GmbH (Germany) — the servers, databases and file storage that hold your account and content, located in the European Union.
- OpenAI (United States) — the AI features described in section 4.
- Stripe — payments made on our website.
- Apple and Google — App Store and Google Play purchases, Sign in with Apple and Google Sign-In, and push notifications (Apple Push Notification service and Firebase Cloud Messaging).
- Google — usage analytics on our website (Google Analytics, loaded through Google Tag Manager) and in our apps (Google Analytics for Firebase).
- Microsoft — Microsoft Clarity, which records how visitors use our website (clicks, scrolling and page views, including session replays) so that we can improve it.
- Meta Platforms — measuring the app installs and purchases that follow our ads (Meta App Events), subject to the choices described in section 8.
- Sentry (Functional Software, Inc., United States) — crash and error reports from our apps, with email addresses removed.
- Email delivery providers — sending account, billing and service emails.
- Other users, at your direction — the people you share a transcript with, the members of your workspaces, and anyone who has a public link you created.
- Authorities and advisers — where the law requires it or to protect our rights; and a buyer or successor in a merger, acquisition or sale of assets, in which case this policy continues to apply to your data.
Our service providers process personal data only on our instructions. Apple, Google and Meta also act as independent controllers for some processing in their own services, which their privacy policies explain.
6. International transfers
MIA DIGITAL LLC is based in the United States, and the servers that store your account and content are in the European Union. Some of our providers process data in the United States or other countries. When personal data from the European Economic Area, the United Kingdom or Switzerland goes to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum), or on the EU–U.S. Data Privacy Framework where the recipient is certified, together with additional safeguards where needed. For transfers from Türkiye, we rely on the safeguards provided for in Article 9 of the KVKK, such as standard contracts notified to the Personal Data Protection Authority, or on your explicit consent where the law allows it.
7. How long we keep data
- Account data: for as long as your account exists.
- Recordings, transcripts and related content: until you delete them or your account. When you delete a recording, its audio, transcript and assistant index are removed from our systems straight away; copies in routine backups are deleted as those backups expire.
- After you delete your account: it is closed at once, and we delete or anonymise your personal data and content within 90 days, except records the law requires us to keep.
- Working copies made during processing: deleted as soon as processing ends.
- Server logs, error reports and link-import logs: up to 90 days.
- Analytics data: up to 14 months, in pseudonymous form.
- Billing and tax records: 10 years, or longer where the law requires.
- Marketing preferences: until you unsubscribe or withdraw your consent.
When a retention period ends, we delete the data or anonymise it so that it can no longer be linked to you.
8. Cookies, SDKs and tracking
On our website
We use cookies that are strictly necessary for the site to work — to keep you signed in, protect forms against forgery and remember your language — and analytics cookies from Google Analytics and Microsoft Clarity. Google Tag Manager may also load measurement tags from our advertising partners. You can block or delete cookies in your browser settings; blocking the necessary ones will stop sign-in from working.
In our apps
- Google Analytics for Firebase measures how the apps are used. It identifies an installation of the app rather than you, and does not use your advertising identifier unless you allow tracking.
- Sentry collects crash reports. Session replay and screenshots are switched off, so your transcripts never reach it.
- Meta App Events receives a small set of events — for example, that a subscription was bought — to measure our ads. It never receives the content of your recordings or transcripts. On iOS, Meta receives your advertising identifier only if you allow tracking when the app asks; you can change this at any time in Settings › Privacy & Security › Tracking. On Android, you can reset or delete your advertising ID in your device’s settings.
- Push notifications are sent only if you allow them, and can be turned off in your device settings.
9. Your rights
Under the GDPR and the UK GDPR
You have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing (and to object to direct marketing at any time), to receive it in a portable format, and to withdraw any consent you have given, without affecting the processing carried out before.
Under the KVKK (users in Türkiye)
Under Article 11 of the KVKK, you have the right to learn whether your personal data is processed; to request information if it has been; to learn the purpose of the processing and whether the data is used for that purpose; to know the third parties, in Türkiye or abroad, to whom it is transferred; to request its correction if it is incomplete or inaccurate; to request its deletion or destruction under the conditions of Article 7; to request that such corrections and deletions be notified to the third parties it was transferred to; to object to a result against you that arises solely from automated analysis; and to claim compensation for damage caused by unlawful processing.
Under California law
California residents have the right to know what personal information we collect, use and disclose, and to request its deletion or correction. We do not sell personal information. Measuring our ads with Meta or Google may count as “sharing” for cross-context behavioural advertising under California law; you can opt out by declining tracking in the app or by emailing us. We will not treat you differently for exercising these rights.
How to exercise your rights
You can delete your account at any time in your account settings, on the web or in the app, and download your transcripts with the export feature. For any other request, email support@heartotext.com. We may ask you to confirm your identity, and we reply within the time the law sets — one month under the GDPR and 30 days under the KVKK.
10. Children
The Service is not directed to children under 13, and we do not knowingly collect personal data from them. Where the law of your country sets a higher age for consenting to online services — 16 in some EU countries — that age applies. If you believe a child has given us personal data, contact us and we will delete it.
11. Security
We protect your data with encryption in transit (HTTPS) and at rest, access limited to the staff who need it, and monitoring of our systems. No system is completely secure, however, and we cannot guarantee that data will never be accessed without authorisation. Hear2Text holds no certification such as SOC 2, ISO 27001 or HIPAA; if your recordings fall under such a regime, check whether it allows them to be uploaded here.
12. Changes to this policy
We may update this policy from time to time. If a change is material, we will tell you by email or in the app before it takes effect. The date at the top of this page shows when the policy last changed.
13. Contact and complaints
To exercise your rights, or with any question or complaint about how we handle your data, contact:
MIA DIGITAL LLC
112 Capitol Trl Ste A7751
Newark, DE 19711
United States
Email: support@heartotext.com
You also have the right to lodge a complaint with a data protection authority: in Türkiye, the Personal Data Protection Authority (KVKK); in the EU and EEA, the supervisory authority where you live or work; in the United Kingdom, the Information Commissioner’s Office.
