amlistening

Privacy Policy

What the desktop app keeps on your machine, what the website collects, and who else touches it.

In effect from 20 September 2026.

The short version

Your recordings, transcripts, markers, keywords and exports are kept on your machine. The app does not automatically send them to us, and it has no telemetry; capture, transcription, review and export need no network at any tier. This website holds what an account and a licence need: a name, an email, a plan, and the ids that tie a payment to them. We run no advertising, and no analytics that identify you or follow you between sites. The sections below list the rest, including the parts that are easy to leave out.

What the desktop app does

The app writes a take to disk as plain files in a project folder, and everything derived from it — transcript, markers, keyword hits, exports — stays beside it. It sends us no recordings and no transcripts, and there is no telemetry in it.

Four things use a network, and none carries a recording: the model download, signing in, the licence refresh, and the update check. Downloading a model or an update reveals your IP address and request details to the server that serves it. What leaves your machine lists each call and what it sends.

Once you export a take, or send us a file, that copy is outside the app: it lives wherever you put it, including a synced folder or a backup service.

What the website collects

This is everything the website and the services it uses handle. We hold it to run your account and your licence, to keep the billing records the law makes us keep, and to answer you when you write to us. We do not sell it, and we do not share it for advertising.

Account
the name and email you enter at sign-up, and a password, which Supabase Auth stores as a hash — we never hold the plain text. A reset sends one email to that address.
Plan
your tier, its expiry, where it came from, and the Stripe customer and subscription ids. Card details go straight to Stripe and never reach us. Stripe also collects a billing address at checkout, because where you are is a term of the sale.
Licence
a random installation id the app generates for the machine, your account id, your plan and the token's own dates, and the email on your account. They travel in the signed licence token the app caches, and the installation id comes back to us with the token when the app refreshes it. The token carries no computer name and no user name. A token is valid for at most 30 days at a time; the file holding it stays on the machine until the app replaces or removes it.
Session
authentication cookies that keep you signed in and cover a sign-up or password reset in progress. See Cookies below.
Support
the emails you choose to send us, any attachment, and our replies. Cloudflare Email Routing carries mail sent to support@amlistening.app and forwards it to a private mailbox, where a person reads it.
Requests
the servers hosting the site and the licence API see the requests they answer: IP address, browser, URL. Sign-up confirmation carries the email address in the page URL, and the check for whether an address already has an account sends it in the request URL. We keep no request logs of our own — there is no logging code in the site — and our providers keep short operational logs under their own policies.

What the app does not send

The app does not send your recordings or transcripts to us, and we do not ask for them. We receive a file only if you choose to email one, and an export you send to another service is handled by that service. We run no advertising, and nothing on this site builds a profile of you or follows you between sites.

One measurement does run on the website: Cloudflare Web Analytics, which our host adds to the page rather than us building it into the site. It is cookieless, it stores nothing on your device, and it reports which pages were viewed and how quickly they loaded — not who viewed them. Any other measurement we add will be held to the same standard: cookieless, and it will not identify you, and this policy will say so before it runs.

Because none of that builds a profile of you in the first place, we do not act on a Do Not Track signal from your browser. We do not sell your personal information, we do not share it for advertising, and there is no advertising here to opt out of.

Cookies

The cookies on this site are for authentication, not tracking. Supabase's session client sets a session cookie when you sign in — a large value is split across chunk cookies — and code-verifier cookies while a sign-up or recovery flow is open. We pass Supabase's own cookie settings through untouched and set no lifetime of our own, so each lasts as long as that library gives it and the access token's expiry decides when a session is refreshed. Signing out clears the session. There are no analytics or advertising cookies. When you pay, Stripe's checkout page sets its own under Stripe's privacy policy.

Who processes it

These providers run the parts named below. Each handles the data as our processor, on our instructions, except where it says otherwise.

Supabase
the account and entitlement database, and the sign-up and reset emails it generates.
Resend
delivers those emails, which is why they arrive from our mail subdomain rather than from Supabase.
Stripe
checkout, subscriptions, invoices, refunds and the billing portal. Stripe also acts independently as a controller for its own purposes, including fraud prevention and its legal obligations; its privacy notice explains that role.
Cloudflare
hosting for the site and the licence API, our own release server, the mail routing behind our support address, and the Web Analytics described above.

Models are the exception, because we do not choose where they come from. The transcription engine downloads them from the repository its own catalogue names, and Settings → Models shows you that repository and the model's licence before you download anything. That server sees the connection data needed to serve the file, including your IP address, and the app sends it nothing about you or your recordings.

Where your data goes

We are in California, and the providers above are United States companies, so what we hold is processed in the United States. Cloudflare answers a web request from whichever of its locations is nearest you, so the request itself is handled where you are.

Pro is not sold in the European Union, the European Economic Area, the United Kingdom or Gibraltar — the terms say so and checkout enforces it — so this policy describes no transfer out of those places and there is no representative there to name.

How long we keep it

Account and entitlement
kept while your account exists. When the account is deleted, the entitlement row is deleted with it. Ask us by email and we do it, cancelling any Stripe subscription first so no further charge can happen; there is no self-service delete button yet.
Billing records
Stripe keeps invoices and payment records for as long as tax and accounting law requires, and the entitlement row saying what you bought lives with your account. We cannot delete what the law requires us to keep.
Licence on your machine
a file on your device. A token is valid for at most 30 days at a time; deleting your account stops new ones being minted, and the cached one stops working when it expires. Expiry is not deletion of the file, which stays until the app removes it.
Session
until it expires or you sign out.
Logs and support email
we keep no request logs ourselves, and our providers keep theirs briefly under their own policies. Support email and its attachments are deleted after two years.

Your choices

Ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete your account: email support@amlistening.app. We answer within one month, and if the law allows us longer we will say why and when. Depending on where you live you may also object to or restrict processing, take your data elsewhere, and complain to your data protection authority. We will never charge you or treat you differently for asking.

Children

amlistening is for working adults and is not intended for children. If we learn an account belongs to a child, we will close it and delete the personal data we are not required to keep.

Changes to this policy

This policy takes effect on the date at the top of this page. A change appears here with a new date, and account holders hear about the ones that matter by email.

Contact

amlistening is run from California in the United States, and its operator is the controller for what this policy describes. Questions about this policy or your data: support@amlistening.app. Questions about the product are answered in the docs.