Mr.SpeechMr.Speech
How to useDocsPrivacyChangelog
Download
Legal

Mr.Speech Privacy Policy

Last updated and effective: 3 August 2026

Plain-English summary

Mr.Speech is local-first. Core dictation, notes, meeting recording, dictionaries, and local AI run on your device without a Mr.Speech account. We only receive personal data when you sign in, use optional cloud features, ask for support, or visit pages that necessarily contact our servers. We do not sell your personal data, we do not use your content to train our own models, and we do not track you across other websites.

1. Who is responsible (Controller)

The controller responsible for processing personal data in connection with the Mr.Speech desktop app, website, cloud services, and support channels is Ullin Noe Yanou, 47057 Duisburg, Germany. Further contact details are in the Impressum.

Privacy contact: [email protected] General support: [email protected]

(A data protection officer (Datenschutzbeauftragter) is not appointed, as the statutory thresholds in Art. 37 GDPR / § 38 BDSG are not met. This will be reassessed as the operation grows.)

2. Local-only use

When you use Mr.Speech without signing in and without enabling cloud features, your content stays on your device. This includes audio transcribed locally, transcripts, notes, dictionaries, meeting recordings, and local AI processing. We do not receive this content.

3. What we process, why, and on what legal basis

We process the following personal data only in the situations described, on the following legal bases under Art. 6 GDPR:

Data Purpose Legal basis Typical retention
Account identifiers (email, authentication ID) Sign-in and support Art. 6(1)(b) — contract Until account deletion, or as required by law (e.g., dispute resolution or security)
Synced notes, transcripts, folders, conversation history (if cloud sync enabled) Provide sync and retrieval across your devices Art. 6(1)(b) — contract Until you delete the content or your account
Audio sent for managed cloud transcription Provide the cloud speech-to-text you requested Art. 6(1)(b) — contract; Art. 9(2)(a) — explicit consent for any special-category content in speech Not retained after the request completes
Cloud usage metadata (duration, timestamp, account, meter, result status) Enforce quotas and operate the service Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interest in preventing abuse As needed to operate the service
Crash reports and diagnostics Detect and fix reliability issues Art. 6(1)(f) — legitimate interest in a stable, secure product Limited period, then deleted
Support messages Answer requests, investigate problems Art. 6(1)(b)/(f) As long as needed for support history and legal records
Google Calendar authorisation and event data (if connected) Meeting detection, upcoming-meeting display, meeting context/labels Art. 6(1)(a) — consent (you connect it) Clerk keeps and refreshes the provider authorisation until it is revoked; event data is processed transiently by our cloud service and kept only in a bounded local cache on your device
Website analytics (aggregate, cookie-free — see §9) Understand aggregate traffic and performance Art. 6(1)(f) — legitimate interest in operating the website Aggregate only; no individual profiles

We do not store your account password. Sign-in is handled by our identity provider (see §7).

You can object to processing based on legitimate interest (Art. 6(1)(f)) at any time — see §11.

4. Optional cloud features

Cloud speech-to-text. If you choose managed cloud transcription, the audio needed for that request is sent securely to us and then to a managed transcription provider. We do not keep the audio after the request completes. Dictation transcription uses Mistral by default. Providers process content transiently on our instructions. Retention differs by provider; some retain inputs for a short abuse-monitoring window under their data processing agreements (for example, Mistral for up to 30 days). Our agreements with these providers require that your content is not used to train their models. We keep limited usage metadata (see §3). The transcript is returned to your app and stored in your cloud storage only if cloud sync is enabled.

Cloud sync. If enabled, your synced notes, folders, transcripts, and related metadata are stored in our cloud so the app can retrieve them across your devices. Data is encrypted in transit. Cloud sync should not be treated as end-to-end encrypted unless a feature is expressly labelled that way.

Google Calendar. If you choose to connect Google Calendar, the system browser shows Google's consent flow. For Calendar access, Mr.Speech requests only calendar.events.readonly and calendar.calendarlist.readonly. The authorisation flow also includes the standard openid, userinfo.email, and userinfo.profile scopes used by Clerk to authenticate you and identify the connected Google account. Mr.Speech does not request Gmail or other mailbox access. Clerk manages the resulting Google authorisation and refresh token; the desktop app does not receive or store the Google provider token. When you request a sync, the authenticated Mr.Speech cloud service obtains a short-lived access token from Clerk, requests the selected calendar and event data from Google, and returns normalised results to the desktop app. Calendar and event content passes transiently through Google Cloud for that request but is not written to the Mr.Speech cloud database. The app stores selected-calendar identifiers, sync metadata, and a bounded event cache locally on your device. Mr.Speech does not request permission to create, edit, or delete events. You can stop using the integration and revoke its access through your Google account; revocation stops future access. Google's own terms and privacy policy also apply to your use of Google services.

Google API Limited Use. Mr.Speech's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google Calendar data only to provide and improve the user-facing calendar and meeting features you request. We do not sell it, use it for advertising or creditworthiness decisions, or use it to train general-purpose AI models. We transfer it only where necessary to provide the feature through the service providers identified below, to comply with law, or to protect users and the service.

Crash reports and diagnostics. Production builds may send limited crash and error diagnostics to our error-monitoring provider so we can fix reliability issues. These reports can include technical context about the error and the app state, and are kept for a limited period.

5. Meeting recordings and other people

When you record a meeting, Mr.Speech may capture the voices and words of other participants, which is their personal data. You are responsible for having a lawful basis to record and for informing the other participants where the law requires it. In Germany, recording the confidential spoken word without consent can be unlawful (cf. § 201 StGB), so please obtain consent before recording. For meeting audio you process locally, we do not receive it; for meeting audio you send to our cloud features, we act on your behalf as described in §4.

6. What we do not do

We do not sell personal data. We do not use your content to train our own models. We do not use advertising cookies or third-party behavioural/cross-site tracking.

7. Recipients and sub-processors

We use carefully selected service providers ("processors") who process personal data only on our instructions and under data processing agreements (Art. 28 GDPR). Representative providers and categories of recipients include:

Role Provider(s) Purpose
Identity / authentication and connected-account authorisation Clerk Sign-in, account management, and storage/refresh of the Google authorisation for connected Calendar accounts
Cloud infrastructure & database Google Cloud and Neon Operating the cloud service, transiently processing Calendar requests in Google Cloud, and storing synced data in Neon
Website hosting, downloads & updates, file storage Cloudflare (including R2 object storage) Serving the website and app downloads/updates; storing note attachments and support diagnostic bundles
Document OCR Mistral Extracting text from documents you import
Speech-to-text — dictation Mistral (primary); Groq, OpenAI, OpenRouter (failover) Cloud transcription of dictation audio
Speech-to-text — meetings ElevenLabs (live meetings); Mistral (recorded meetings); Groq, OpenAI, OpenRouter (failover) Live and post-meeting transcription
Text AI (cleanup, rewrites, summaries, notes AI) Cerebras, Nebius and OpenAI (primary); Groq, OpenRouter (failover) AI processing of transcribed/entered text
Calendar integration Google (Google Calendar API) Optional upcoming-meeting display and meeting context
Error monitoring & service metrics Sentry, Datadog Crash/error diagnostics and service health
Feature configuration ConfigCat Feature flags (no content data)
Account & service emails HighLevel Service and account lifecycle emails (e.g., quota notices)
Website analytics Simple Analytics Cookie-free aggregate website statistics

The table above identifies the published production providers. If this list changes materially, we update this policy. For questions about the sub-processors that apply to your account, email [email protected].

8. International data transfers

Some providers in §7 may process data outside the EU/EEA, including in the United States. Where this happens, we rely on appropriate safeguards under Chapter V GDPR — an EU adequacy decision (including the EU-US Data Privacy Framework where a provider is certified) and/or the EU Standard Contractual Clauses (SCCs) with supplementary measures. You can request information about the safeguards in place by emailing [email protected].

9. Cookies and website analytics

The Mr.Speech desktop app does not use browser cookies.

The public website uses Simple Analytics, configured without cookies and without storing information on your device. Because no information is stored in or read from your terminal device, no consent under § 25 TDDDG is required, and no cookie banner is shown. Simple Analytics' documentation states it does not store IP addresses, create device identifiers, or build advertising profiles. The website may record aggregate page-view metadata, referrers, campaign tags, anonymised device/browser categories, country-level location, time on page, and scroll depth. We count visits even when a "Do Not Track" signal is sent, because these statistics are aggregate, cookie-free, and never used for advertising or cross-site profiling.

10. Data security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and storage of cloud files through short-lived signed links rather than public access. No method of transmission or storage is completely secure, but we work to protect your data and to fix issues promptly.

11. Your rights

Under the GDPR you have the right to: access your data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing based on legitimate interest (Art. 21). Where processing is based on consent, you may withdraw consent at any time (Art. 7(3)); withdrawal does not affect the lawfulness of processing before withdrawal.

To exercise any right, email [email protected]. We may ask for information needed to verify your identity, and we will respond within the period required by law (generally one month).

You also have the right to lodge a complaint with a supervisory authority. The authority competent for the controller is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW) Kavalleriestraße 2–4, 40213 Düsseldorf, Germany (You may also contact the supervisory authority in your own EU country of residence.)

12. Automated decision-making

We do not use solely automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). AI features (transcription, rewrites, summaries) are tools you operate, not automated decisions about you.

13. Account deletion

Account deletion removes your Mr.Speech cloud account data and the cloud-stored content associated with that account, except limited records we are legally required or permitted to keep. Local data on your devices is not deleted automatically, because it is under your control on those devices. To request deletion, email [email protected] from the email associated with your account, or include enough information for us to verify the account.

14. Children

Mr.Speech is not directed to children. In the EU, we do not knowingly process the personal data of children under 16 without the consent of a holder of parental responsibility (Art. 8 GDPR; 16 is the relevant age in Germany). If you believe a child has provided personal data to us, contact [email protected] and we will take appropriate steps to delete it.

15. Changes to this policy

We may update this policy as Mr.Speech changes or as legal requirements change. We will update the date above and, for material changes, provide notice through the app, website, email, or another reasonable channel.

16. Contact

General support: [email protected] Privacy and data rights: [email protected] Postal address: see the Impressum.

Mr.SpeechMr.Speech

The unified voice-to-text, meeting recorder, and notes database for desktop. Local-first, made in Europe.

Product
  • Download
  • Try the demo
  • Changelog
  • Pricing
Features
  • Dictation
  • Meetings
  • Notes and plans
  • AI connector
Built for
  • Consultants
  • Legal
  • Healthcare
  • Developers
  • Sales teams
Resources
  • Documentation
  • How to use
  • Use cases
  • Compare
  • Support
© 2026 Mr.Speech. All voices reserved.PrivacyTermsImpressumSecurityEU AI Act
v1.6.8 · Local-first desktop app