Legal
Privacy policy
What we hold, why we hold it, how long we hold it for, and the things we never receive at all. Written to be read once and understood, not to be skipped.
- Effective
- 22 August 2026
- Last updated
- 22 August 2026
- Applies to
- the Speechfy application, the Speechfy service and this website
1. Who we are
Speechfy is operated by Gabriel Anhaia da Silva, trading as Speechfy — a sole trader (Einzelunternehmen) established in Berlin, Germany. For everything described below, that business is the controller of your personal data within the meaning of Article 4(7) of the General Data Protection Regulation (Regulation (EU) 2016/679).
- Operator
- Gabriel Anhaia da Silva, trading as Speechfy
- Registered address
- Wilhelm-Caspar-Wegely-Platz 6, 10623 Berlin, Germany
- Legal form
- Sole trader (Einzelunternehmen)
- Established in
- Germany, European Union
- Privacy contact
- hello@speechfy.io
- Everything else
- hello@speechfy.io
Write to hello@speechfy.io about anything on this page, including a request under any of the rights in section 8. You do not need a particular form of words, and you will not be passed between departments.
2. What we collect, and what we never receive
Speechfy needs an account, because dictation is metered against a plan. That account is the reason almost everything in this policy exists. Four things are collected:
- Account data. The email address you sign up with, a hash of your password, your plan, and the state of your account.
- Billing data. The details needed to charge you and to issue a valid invoice — plan, billing period, amounts, VAT status, and any billing name or address you give. Card numbers are handled entirely by Stripe Payments Europe, Ltd. and never reach us; see section 6.
- Usage counts. How much of your plan's allowance you have used, and when. These are numbers and dates. They do not contain anything you said, and they do not record which applications you dictated into.
- Diagnostics. Ordinary server and application records — timestamps, request outcomes, error codes, IP address, application version — used to keep the service working and to spot abuse of it.
And four things we want to be equally plain about not having:
- Your dictation audio and the transcripts made from it are not retained. They exist for the length of the request that produced them and no longer. See section 4.
- The contents of your notes never leave your machine. We have never had a copy of one. See section 5.
- No profiling and no advertising. We do not build a profile of you, we do not sell or share personal data with anyone for their own purposes, and there is no advertising identifier anywhere in the product.
- No special category data is sought. We do not ask for, and have no use for, the data described in Article 9 — health, beliefs, biometrics and the rest. Because dictation audio is not retained, whatever you happen to say is not stored either.
3. Why we hold it, and for how long
One row per kind of data: what it is, what it is for, the lawful basis under Article 6 that permits it, and how long it survives.
| Data | What it is for | Lawful basis | How long we keep it |
|---|---|---|---|
| Account | Creating your account, signing you in, telling you about the service you are paying for. | Article 6(1)(b) — performance of the contract you entered when you signed up. | For as long as the account exists, then erased within 30 days of you closing it. |
| Billing | Taking payment, issuing invoices, handling refunds and chargebacks, meeting our tax and accounting duties. | Article 6(1)(b) for taking payment; Article 6(1)(c) — legal obligation — for keeping the invoice afterwards. | 10 years, being the period German tax and accounting law requires. This one we cannot shorten on request. |
| Usage counts | Measuring what you have used against your plan's allowance, and showing you the same number we bill from. | Article 6(1)(b) — a metered plan cannot be provided without counting. | 24 months. |
| Dictation audio and transcripts | Turning what you said into text and polishing that text, for the length of the request and no longer. | Article 6(1)(b) — this is the service itself. | Not retained. Discarded once the request has been served. Not reviewed by a human. Not used to train models. |
| Diagnostics and security logs | Keeping the service up, finding faults, and detecting abuse of the service. | Article 6(1)(f) — our legitimate interest in running a service that works and is not abused. The records are minimal and are not used to learn anything about you as a person. | 30 days. |
| Support correspondence | Answering you, and being able to look up what was said last time. | Article 6(1)(b) where it concerns your subscription; otherwise Article 6(1)(f) — our legitimate interest in answering people who write to us. | 12 months from the end of the conversation. |
| The contents of your notes | Nothing. They are files in a folder on your own machine and Speechfy does not upload them. | None needed — we are not a controller of data we never receive. | Never collected. |
Where a period above ends, the data is deleted or irreversibly anonymised. Backups are on their own cycle and are overwritten in turn, so a record can survive in a backup for a short time after it has gone from the live service; it is not restored to the live service and is not used for anything.
Automated decisions
There is no automated decision-making producing legal or similarly significant effects, within the meaning of Article 22. Models transform your words; they do not make decisions about you. Nobody's account is suspended, priced or refused by an algorithm alone.
4. What happens to your voice
You hold a key and speak. The audio is sent over an encrypted connection to Speechfy's own service. Speechfy has the audio transcribed and the text polished by advanced models, and returns the finished text to the application you were already in. The application talks to Speechfy; Speechfy talks to the models.
Once that response has been served, the audio and the transcript are not retained. They are not kept for quality review, they are not read by anyone at this company, and they are not used to train, fine-tune or evaluate any model. That last point is a contract term with our sub-processors and not merely our own policy.
Two consequences worth stating plainly. First, we cannot show you a history of your dictations on the server, because there is not one. Second, if you dictate something you should not have — a password, a colleague's medical detail — there is nothing on our side to delete, though you should still check whatever application received the text.
You are responsible for having the right to record what you dictate. If you dictate other people's words, that is your call to make under your own law.
5. Your notes stay on your machine
Notes written in Speechfy are plain Markdown files in a folder you chose on your own computer. Speechfy writes them there and reads them back from there. It does not upload them, sync them, index them on a server or copy them anywhere.
This is unusual enough to be worth spelling out: if you uninstall Speechfy, your notes are still sitting in that folder, still plain text, still openable by any editor you like. There is no export step because there is nothing to export from. If that folder happens to be inside a cloud drive you already use, then it syncs under your account with that provider and under their privacy terms, not ours.
Because we never receive them, your notes are outside the scope of the rights in section 8 — there is nothing here for us to give you a copy of, correct or erase. They are yours in the most literal sense available.
6. Sub-processors
We do not run every part of this ourselves. Speechfy uses a small number of sub-processors — other companies that process personal data on our instructions — in these categories:
- hosting and infrastructure, on which the service runs;
- the providers of the transcription and text models the service calls;
- payment processing, carried out by Stripe Payments Europe, Ltd.;
- transactional email, for receipts, password resets and service notices.
Each is bound by a written contract meeting Article 28 of the GDPR: they process only on our documented instructions, they are held to confidentiality and to appropriate security, and — for the model providers specifically — they are contractually barred from retaining your content or using it to train.
The current list of sub-processors, naming each company, what it does and the country it processes in, is available on request. Write to hello@speechfy.io and we will send it. We do not publish it on this page because it would go stale between revisions, and a stale list is worse than an honest offer to send the current one.
Stripe Payments Europe, Ltd. acts as an independent controller for parts of what it does — fraud prevention and its own regulatory duties — and its own privacy notice governs that part. Speechfy never sees or stores your card number.
7. Where your data is
The company is established in the European Union and runs on European Union infrastructure. Your account, your billing records and every log we hold stay in the European Union. They are not sent to a parent company, and not to a support desk in another time zone.
One thing does leave: the dictation itself. To turn your speech into a written sentence we send the audio, and the text made from it, to the model providers we have chosen. Some of those providers operate outside the European Economic Area, principally in the United States. The transfer lasts as long as the request does. Nothing is stored at the other end, nothing is used to train a model, and no human at the provider reads it.
That is a restricted transfer under Chapter V of the GDPR and we treat it as one. It is made on the European Commission’s Standard Contractual Clauses under Article 46(2)(c), supported by a transfer impact assessment and by contractual terms that forbid retention and training. You may ask us for a copy of the clauses relied on for any given provider; write to hello@speechfy.io and we will send it.
If you need this not to happen, it does not have to. Speechfy offers processing pinned entirely to the European Union as part of Enterprise: every model that touches your words stays inside the EU, there is no restricted transfer to assess, and the commitment is written into your data processing agreement rather than left as a statement on a web page.
Which providers we use, and where each one runs, is a decision we make rather than one you configure — see section 4. The GDPR and AI Act page sets out the safeguard in full, and what is still outstanding on it. Changing the countries involved is a material change to this policy and section 13 applies: you would be told before it happened.
8. Your rights
Under Articles 15 to 22 of the GDPR you have the following rights over the personal data described in section 3.
- Access (Article 15). To be told whether we hold data about you, and to receive a copy of it together with the information on this page.
- Rectification (Article 16). To have inaccurate data corrected and incomplete data completed. Your email address and billing details can also be changed yourself in your account.
- Erasure (Article 17). To have your data deleted — in practice, to close your account. The one thing that survives is the invoice record we are legally required to keep, as noted in the table.
- Restriction (Article 18). To have us stop doing anything with your data except storing it, while a dispute about its accuracy or our basis for holding it is resolved.
- Portability (Article 20). To receive the data you gave us in a structured, commonly used, machine-readable format, and to have it sent directly to another controller where that is technically feasible.
- Objection (Article 21). To object, on grounds relating to your situation, to processing based on legitimate interests — which here means the diagnostics row and some support correspondence. There is no direct marketing to object to.
- Automated decisions (Article 22). Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. As stated in section 3, we make none.
Where we ever rely on consent, you may withdraw it at any time under Article 7(3), and withdrawing it does not affect what was done before you did.
How to exercise them
Write to hello@speechfy.io from the address on your account, or from another address if you tell us which account you mean. Say what you want; you do not need to cite an article number.
We answer within one month, as Article 12(3) requires. If a request is genuinely complex we may extend that by up to two further months, and we will tell you why within the first month. It is free, unless a request is manifestly unfounded or excessive, in which case we will say so rather than quietly ignore it. We may ask for enough information to be sure you are who you say you are, and we will not ask for more than that.
9. Complaining about us
If you think we have handled your personal data wrongly, please write to hello@speechfy.io first — most of it will be something we can fix the same week.
You do not have to, though. Under Article 77 you have the right to lodge a complaint with a supervisory authority at any time. Complain to the authority in the member state where you live, where you work, or where you think the problem happened, and it will be handled from there. Nothing on this page takes that right away, and nothing you agree to elsewhere can.
You also have the right to an effective judicial remedy against a supervisory authority or against us, under Articles 78 and 79.
10. How we protect it
The measures below are named rather than described in adjectives, because "industry-standard encryption" is a phrase and AES-256-GCM is a fact you can hold us to.
- In transit: TLS 1.3. Everything between the application and the service, and everything between the service and its sub-processors, travels inside it.
- At rest: AES-256-GCM. An authenticated cipher, so stored data cannot be tampered with undetected.
- Passwords: Argon2id. Memory-hard hashing, which means we do not hold your password and cannot recover it for you — only reset it.
- Access on a need-to-have basis. Administrative access to systems holding personal data is limited to the people who need it to do their job.
- Nothing to leak on the dictation path. The strongest security measure here is the one in section 4: audio and transcripts are not retained, so a breach of our systems cannot expose what you said.
No system is perfect and we will not pretend otherwise. If a personal data breach occurs we will notify the supervisory authority within 72 hours as Article 33 requires, and if the breach is likely to result in a high risk to you we will tell you directly and without undue delay under Article 34 — in plain words, saying what happened and what to do about it.
12. Children
Speechfy is not designed for or directed at children. You must be at least 16 to hold an account, and we do not knowingly collect personal data from anyone younger.
If you believe a child has created an account, write to hello@speechfy.io and we will close it and delete the data.
13. Changes to this policy
The date at the top of this page is the date of the version you are reading, and it changes whenever the text does.
For a material change — a new purpose, a new category of data, a change of lawful basis, a longer retention period, or a change to the countries your dictation is processed in (section 7) — we will email every account holder at least 30 days before it takes effect, so that you can read it and close your account first if you would rather not continue. For a correction of a typo or a clearer sentence, we simply change the date.
Previous versions are kept and are available on request from hello@speechfy.io. See also the terms of service, which govern the subscription itself.