Mr.SpeechMr.Speech
For your workDocsPrivacyChangelog
Download
Legal

Mr.Speech Privacy Policy

Last updated and effective: 3 October 2026

Plain-English summary

Mr.Speech is local-first. Core dictation, notes, meeting recording, dictionaries, and local AI run on your device. We only receive personal data when you sign in, use optional cloud features, ask for support, or visit pages that necessarily contact our servers. We do not sell your personal data, we do not use your content to train our own models, and we do not track you across other websites.

Optional PostHog desktop usage analytics requires separate consent and is off by default; see §9. It sends feature events and a random device identifier, never speech or note content.

1. Who is responsible (Controller)

The controller responsible for processing personal data in connection with the Mr.Speech desktop app, website, cloud services, and support channels is Ullin Noe Yanou, 47057 Duisburg, Germany. Further contact details are in the Impressum.

Privacy contact: [email protected] General support: [email protected]

(A data protection officer (Datenschutzbeauftragter) is not appointed, as the statutory thresholds in Art. 37 GDPR / § 38 BDSG are not met. This will be reassessed as the operation grows.)

2. Local-only use

When you use Mr.Speech without signing in and without enabling cloud features, your content stays on your device. This includes audio transcribed locally, transcripts, notes, dictionaries, meeting recordings, and local AI processing. We do not receive this content.

3. What we process, why, and on what legal basis

We process the following personal data only in the situations described, on the following legal bases under Art. 6 GDPR:

Data Purpose Legal basis Typical retention
Account identifiers (email, authentication ID) Sign-in and support Art. 6(1)(b) — contract Until account deletion, or as required by law (e.g., dispute resolution or security)
Synced notes, transcripts, folders, conversation history (if cloud sync enabled) Provide sync and retrieval across your devices Art. 6(1)(b) — contract Until you delete the content or your account
Audio sent for managed cloud transcription Provide the cloud speech-to-text you requested Art. 6(1)(b) — contract; Art. 9(2)(a) — explicit consent for any special-category content in speech Not retained after the request completes
Cloud usage metadata (duration, timestamp, account, meter, result status) Enforce quotas and operate the service Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interest in preventing abuse As needed to operate the service
Crash reports and diagnostics Detect and fix reliability issues Art. 6(1)(f) — legitimate interest in a stable, secure product Limited period, then deleted
Support messages Answer requests, investigate problems Art. 6(1)(b)/(f) As long as needed for support history and legal records
Google Calendar authorisation and event data (if connected) Meeting detection, upcoming-meeting display, meeting context/labels Art. 6(1)(a) — consent (you connect it) Clerk keeps and refreshes the provider authorisation until it is revoked; event data is processed transiently by our cloud service and kept only in a bounded local cache on your device
Website analytics (aggregate, cookie-free — see §9) Understand aggregate traffic and performance Art. 6(1)(f) — legitimate interest in operating the website Aggregate only; no individual profiles
Optional desktop usage events and random device identifier (PostHog — see §9) Understand feature usage and device retention Art. 6(1)(a) — consent; § 25(1) TDDDG for the local identifier Up to one year, or earlier erasure; withdrawal stops future collection

We do not store your account password. Sign-in is handled by our identity provider (see §7).

You can object to processing based on legitimate interest (Art. 6(1)(f)) at any time — see §11.

4. Optional cloud features

Cloud speech-to-text. If you choose managed cloud transcription, the audio needed for that request is sent securely to us and then to a managed transcription provider. We do not keep the audio after the request completes. Dictation transcription uses Mistral by default. Providers process content transiently on our instructions. Retention differs by provider; some retain inputs for a short abuse-monitoring window under their data processing agreements (for example, Mistral for up to 30 days). Our agreements with these providers require that your content is not used to train their models. We keep limited usage metadata (see §3). The transcript is returned to your app and stored in your cloud storage only if cloud sync is enabled.

Cloud sync. If enabled, your synced notes, folders, transcripts, and related metadata are stored in our cloud so the app can retrieve them across your devices. Data is encrypted in transit. Cloud sync should not be treated as end-to-end encrypted unless a feature is expressly labelled that way.

Google Calendar. If you choose to connect Google Calendar, the system browser shows Google's consent flow. For Calendar access, Mr.Speech requests only calendar.events.readonly and calendar.calendarlist.readonly. The authorisation flow also includes the standard openid, userinfo.email, and userinfo.profile scopes used by Clerk to authenticate you and identify the connected Google account. Mr.Speech does not request Gmail or other mailbox access. Clerk manages the resulting Google authorisation and refresh token; the desktop app does not receive or store the Google provider token. When you request a sync, the authenticated Mr.Speech cloud service obtains a short-lived access token from Clerk, requests the selected calendar and event data from Google, and returns normalised results to the desktop app. Calendar and event content passes transiently through Google Cloud for that request but is not written to the Mr.Speech cloud database. The app stores selected-calendar identifiers, sync metadata, and a bounded event cache locally on your device. Mr.Speech does not request permission to create, edit, or delete events. You can stop using the integration and revoke its access through your Google account; revocation stops future access. Google's own terms and privacy policy also apply to your use of Google services.

Google API Limited Use. Mr.Speech's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google Calendar data only to provide and improve the user-facing calendar and meeting features you request. We do not sell it, use it for advertising or creditworthiness decisions, or use it to train general-purpose AI models. We transfer it only where necessary to provide the feature through the service providers identified below, to comply with law, or to protect users and the service.

Crash reports and diagnostics. Production builds may send limited crash and error diagnostics to our error-monitoring provider so we can fix reliability issues. These reports can include technical context about the error and the app state, and are kept for a limited period.

5. Meeting recordings and other people

When you record a meeting, Mr.Speech may capture the voices and words of other participants, which is their personal data. You are responsible for having a lawful basis to record and for informing the other participants where the law requires it. In Germany, recording the confidential spoken word without consent can be unlawful (cf. § 201 StGB), so please obtain consent before recording. For meeting audio you process locally, we do not receive it; for meeting audio you send to our cloud features, we act on your behalf as described in §4.

Recognising the same person across your devices. So that speakers are labelled consistently, Mr.Speech keeps a directory of the people you have met: a name, an email address where one is known, a company inferred from that address, and when and how often you met. Alongside each entry the app derives a voice signature — a set of numbers describing how a voice sounds. When sync is enabled for this feature (it is on by default while you are signed in), the directory and the signatures are stored in your account so your other computers recognise the same person by the same name instead of creating a second entry for them. No meeting audio is uploaded for this feature. Because a voice signature is used to recognise a specific person, we treat it as sensitive data: it is stored only in your own account, and the signatures Mr.Speech learns about other people are never shared with other users. Separately, if you deliberately record a sample of your own voice for a team, that sample is shared with your team members so they can label you — that is your own choice and only ever your own voice. Deleting a person under Settings -> Meetings -> People removes their entry and signature from your account and from your other devices. You can turn this sync off at any time in Settings.

Contact details can be edited, including email addresses for people met outside calendar meetings. Mr. AI uses stable speaker links in saved meetings to retrieve attributed statements with meeting references. Contact sync and voice-profile sync are separate settings, both enabled by default while signed in. Turning voice sync off stops uploads and downloads on that device, but retains signatures already stored in your account. Turning contact sync off stops both types of sync on that device. Use Forget with contact sync enabled to delete the contact and linked signatures from your account; other devices apply deletion when they next sync. Meeting recordings and transcripts are managed separately.

6. What we do not do

We do not sell personal data. We do not use your content to train our own models. We do not use advertising cookies or third-party behavioural/cross-site tracking.

7. Recipients and sub-processors

We use carefully selected service providers ("processors") who process personal data only on our instructions and under data processing agreements (Art. 28 GDPR). Representative providers and categories of recipients include:

Role Provider(s) Purpose
Identity / authentication and connected-account authorisation Clerk Sign-in, account management, and storage/refresh of the Google authorisation for connected Calendar accounts
Cloud infrastructure & database Google Cloud and Neon Operating the cloud service, transiently processing Calendar requests in Google Cloud, and storing synced data in Neon
Website hosting, downloads & updates, file storage Cloudflare (including R2 object storage) Serving the website and app downloads/updates; storing note attachments and support diagnostic bundles
Document OCR Mistral Extracting text from documents you import
Speech-to-text — dictation Mistral (primary); OpenRouter and others (failover) Cloud transcription of dictation audio
Speech-to-text — meetings ElevenLabs, Mistral; others (failover) Live and post-meeting transcription
Text AI (cleanup, rewrites, summaries, notes AI) Cerebras, Nebius and OpenAI (primary); Groq, OpenRouter (failover) AI processing of transcribed/entered text
Calendar integration Google (Google Calendar API) Optional upcoming-meeting display and meeting context
Error monitoring & service metrics Sentry, Datadog Crash/error diagnostics and service health
Feature configuration ConfigCat Feature flags (no content data)
Account & service emails HighLevel Service and account lifecycle emails (e.g., quota notices)
Website analytics Simple Analytics Cookie-free aggregate website statistics
Optional desktop product analytics PostHog (EU hosting) Consented feature events linked to a random device ID; no speech or note content

The table above identifies the published production providers. If this list changes materially, we update this policy. For questions about the sub-processors that apply to your account, email [email protected].

8. International data transfers

Some providers in §7 may process data outside the EU/EEA, including in the United States. Where this happens, we rely on appropriate safeguards under Chapter V GDPR — an EU adequacy decision (including the EU-US Data Privacy Framework where a provider is certified) and/or the EU Standard Contractual Clauses (SCCs) with supplementary measures. You can request information about the safeguards in place by emailing [email protected].

9. Cookies and website analytics

The Mr.Speech desktop app does not use browser cookies.

The public website uses Simple Analytics, configured without cookies and without storing information on your device. Because no information is stored in or read from your terminal device, no consent under § 25 TDDDG is required, and no cookie banner is shown. Simple Analytics' documentation states it does not store IP addresses, create device identifiers, or build advertising profiles. The website may record aggregate page-view metadata, referrers, campaign tags, anonymised device/browser categories, country-level location, time on page, and scroll depth. We count visits even when a "Do Not Track" signal is sent, because these statistics are aggregate, cookie-free, and never used for advertising or cross-site profiling.

Optional desktop product analytics

PostHog usage analytics is off by default and requires a separate choice in onboarding or Settings → Advanced → Telemetry. It shares only screen names, feature outcome events, app version, coarse platform, event time and a random device identifier. We do not send audio, speech or note content, account identities, error text, file paths or session recordings. The identifier is created in local storage only after consent and is not linked to your account. Our existing daily usage-counter control is separate.

We use PostHog's EU hosting, with location enrichment and person-profile creation disabled for these events. PostHog and its network providers receive the source IP as part of the connection. EU hosting does not guarantee that all processing takes place in the EU; see §8 and PostHog's privacy policy.

You can withdraw consent at any time using the same Settings control. This stops future events and removes the local identifier; it does not erase events already received. Events are retained for up to one year, or erased earlier on request. Since identifiers are not linked to accounts, deleting an account does not automatically identify these events. To request access or erasure, use “Copy analytics reference” in the same Settings section and contact [email protected] before switching analytics off so we can locate the relevant events. If you have already opted out, we may be unable to identify them.

10. Data security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and storage of cloud files through short-lived signed links rather than public access. No method of transmission or storage is completely secure, but we work to protect your data and to fix issues promptly.

11. Your rights

Under the GDPR you have the right to: access your data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing based on legitimate interest (Art. 21). Where processing is based on consent, you may withdraw consent at any time (Art. 7(3)); withdrawal does not affect the lawfulness of processing before withdrawal.

To exercise any right, email [email protected]. We may ask for information needed to verify your identity, and we will respond within the period required by law (generally one month).

You also have the right to lodge a complaint with a supervisory authority. The authority competent for the controller is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW) Kavalleriestraße 2–4, 40213 Düsseldorf, Germany (You may also contact the supervisory authority in your own EU country of residence.)

12. Automated decision-making

We do not use solely automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). AI features (transcription, rewrites, summaries) are tools you operate, not automated decisions about you.

13. Account deletion

Account deletion removes your Mr.Speech cloud account data and the cloud-stored content associated with that account, except limited records we are legally required or permitted to keep, and except content you shared in a team workspace. Content you created or edited in a team owned by someone else stays with that team for its other members. It is no longer linked to your account, but your name can still appear inside it where it was written into the content itself, for example in comments, task assignments, activity history, meeting transcripts and speaker names, until the team removes it or the team is deleted. If you own a team that still has other members, you must disband it before you can delete your account. A team you own that has no other members, or that you have already disbanded, is deleted together with your account straight away; its stored files are removed within two days. A disbanded team is otherwise kept for 30 days so its owner can restore it, and is then deleted. When you leave or are removed from a team, your membership is kept for 30 days so you can rejoin; the content stays with the team. Voice signatures you shared with a team, and the voice samples you contributed to its people directory, are removed from the shared team directory when you leave, are removed, the team is disbanded, or you delete your account. A teammate's offline device can retain a roster copy until it next successfully checks its current teams. Identifiable copies that older app versions placed in a teammate's personal voice profiles or cloud account are removed when that device next successfully syncs its people directory. Some older copies cannot be identified automatically; contact [email protected] to request a review and deletion. Local data on your devices is not deleted automatically, because it is under your control on those devices. To request deletion, email [email protected] from the email associated with your account, or include enough information for us to verify the account.

14. Children

Mr.Speech is not directed to children. In the EU, we do not knowingly process the personal data of children under 16 without the consent of a holder of parental responsibility (Art. 8 GDPR; 16 is the relevant age in Germany). If you believe a child has provided personal data to us, contact [email protected] and we will take appropriate steps to delete it.

15. Changes to this policy

We may update this policy as Mr.Speech changes or as legal requirements change. We will update the date above and, for material changes, provide notice through the app, website, email, or another reasonable channel.

16. Contact

General support: [email protected] Privacy and data rights: [email protected] Postal address: see the Impressum.

Mr.SpeechMr.Speech

The unified voice-to-text, meeting recorder, and notes database for desktop. Local-first, made in Europe.

Product
  • Download
  • Team beta
  • Book a demo
  • Dictation software
  • Changelog
  • Pricing
Features
  • Dictation
  • Meetings
  • Notes and plans
  • AI connector
Built for
  • Leaders
  • Consultants
  • Legal
  • Healthcare
  • Developers
  • Sales teams
Resources
  • Documentation
  • Guides
  • All comparisons
  • vs. Wispr Flow
  • vs. superwhisper
  • vs. Dragon NaturallySpeaking
  • vs. Notion
  • vs. Granola AI
  • Use cases
  • Speech to text
  • Meeting transcription
  • Meeting minutes template
  • GDPR speech recognition
  • About us
  • Support
ASK AI ABOUT MR. SPEECH
Ask ChatGPTAsk ClaudeAsk PerplexityAsk Grok
© 2026 Mr.Speech. All voices reserved.PrivacyTermsImpressumSecurityEU AI Act
v1.7.8 · Local-first desktop app
Mr.Speech