Privacy Policy
Last updated: 15 September 2026
Catchy(“we”, “the service”) records or accepts uploaded meeting audio and turns it into transcripts, notes and action items. This policy explains what we collect, why, who we share it with, and your rights.
What we collect
- Account data: your email and (optionally) display name and avatar, via Google sign-in or email/password.
- Meeting content: audio you upload or record, the resulting transcripts, notes, and any edits you make.
- Usage data: minutes transcribed per month (for quota/billing) and basic, privacy-first product analytics (no session recording, no autocapture).
- Billing data: handled by Stripe — we never see or store your card number.
How we use it
To provide the service (transcription, notes, sharing), enforce plan limits, take payment, send you transactional email you requested, and keep the service secure. We do not sell your data and do not use your meeting content to train models.
Product-update emails
Only if you tick the box (at sign-up or on your profile), we email you about new features a few times a year, using your account email. Every email has a one-click unsubscribe link, and you can switch it off on your profile at any time. We never share the list with anyone, and it is deleted with your account.
Assistant chats
By default, your conversations with the in-app assistant are saved to your account so they are there on any device you sign in on. They are stored in our database (Supabase, see below) and only your account can read them. A saved chat is deleted automatically once it has had no activity for 12 months. In the assistant's settings (Data tab) you can instead keep chats only in this browser, or not save them at all, and you can delete one chat or all of them at any time. Deleting your account deletes them too.
Sub-processors
We share data only with the providers needed to run the service:
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (eu-central-1) |
| Vercel | Application hosting / serverless functions | EU/US |
| Deepgram | Speech-to-text transcription | US |
| ElevenLabs | Speech-to-text transcription (fallback) | US |
| Groq | Speech-to-text transcription (fallback) | US |
| OpenRouter / OpenAI | Note & summary generation (LLM) | US |
| PostHog | Privacy-first product analytics (no session replay) | EU |
| Resend | Transactional email (share invites) | US |
| Stripe | Payments & subscription billing | US/EU |
Audio sent to transcription providers is processed to return text and is not used by them to train models under their API terms. Some providers are in the US; transfers rely on their standard contractual clauses.
When you turn on web search for a question in the assistant, a search query written from that question is sent through OpenRouter to Exa, a web search provider.
Retention & deletion
Your meetings, audio and transcripts are kept until you delete them. Deleting a meeting removes its transcript, notes and audio file. Deleting your account removes your meetings, audio, API keys, usage records and saved assistant chats. You can request export or deletion at any time by emailing us.
Your rights
Subject to your local law (incl. GDPR), you can access, correct, export or delete your data, and object to or restrict processing. Contact us to exercise these rights.
Security
Data is encrypted in transit (HTTPS) and at rest by our infrastructure providers. Access to your meetings is scoped to your account.
Contact
Questions or requests: phktistakis@gmail.com.
This document is a starting template and not legal advice; have it reviewed before relying on it.