Privacy Policy

Last Updated: 2026-07-10

This policy explains what data Alt processes across the website, desktop app, and iOS app, when external transfer can occur, and what controls users have. This policy applies equally to all platforms (web, desktop, and iOS).

At A Glance

  • This policy applies equally to the website, desktop app, and iOS app.
  • Speech recognition (STT) is processed locally via the on-device Whisper model.
  • Summarization, chat, AI scribe, translation, and title generation support LocalLLM or API modes.
  • With LocalLLM or when API mode is not selected, no data is transmitted externally and the app can operate fully offline.
  • Before using API mode, the app displays a consent prompt detailing the data recipient, data transmitted, and purpose. Data is only transmitted after you explicitly consent.
  • With API mode, which requires your explicit consent, transcript text and memo content may be sent to third-party AI providers (OpenAI, Anthropic, Google) to provide the requested AI features. The audio recording files themselves are not transmitted to these third-party AI providers for external AI features.
  • Our server acts solely as a relay — it does not store transmitted data or retain any logs.
  • The website processes account, billing, download, feedback, and analytics data.
  • Analytics tools include Google Analytics (GA4), PostHog, and Vercel Analytics.

1. Scope and Definitions

This policy applies equally to all platforms listed below.

  • Desktop App: Alt application running on macOS and Windows
  • iOS App: Alt application running on iPhone and iPad
  • Website: altalt.io features including account, billing, download, and sharing
  • LocalLLM Mode: AI processing handled on-device
  • API Mode: AI processing handled through our servers and integrated API providers

2. App (Desktop and iOS) Data Processing

The following applies equally to both the desktop app and iOS app.

2.1 Always Local Processing

  • Speech recognition (STT) runs locally using the on-device Whisper model.
  • Recordings, transcripts, and generated outputs are primarily stored on your device.

2.2 Optional AI Processing (LocalLLM/API)

  • AI features include summarization, chat, AI scribe, translation, and note title generation.
  • LocalLLM: Processing remains local and can be fully offline. When using LocalLLM mode or when API mode is not selected, no data is transmitted externally.
  • API: Only when you choose to use API-based AI features and complete the necessary consent process, transcript text and memo content may be transmitted to OpenAI, Anthropic, and Google to perform your requested features such as summarization, translation, AI scribe, note title generation, and chat. The audio recording files themselves are not transmitted to these third-party AI providers.

2.3 Prior Consent Process

  • Before using API mode, the app displays an in-app consent prompt that clearly states: (1) what data is transmitted (transcript text and memo content), (2) who receives it (OpenAI, Anthropic, Google), and (3) for what purpose (performing the AI feature you requested, such as summarization, translation, or title generation).
  • Data transmission begins only after you explicitly consent through the in-app prompt.
  • You may disable API mode at any time to stop data transmission.

2.4 Server Processing and Retention

  • Our server acts solely as a relay — it forwards your request to the third-party AI service provider and returns the response.
  • User input data (transcript text, memo content) is not stored long-term on our servers and is discarded once the request is processed. However, minimal technical logs may be temporarily generated for service operation, security, and troubleshooting. We ensure these logs do not contain the full content of your AI feature inputs.
  • Each AI service provider maintains equivalent levels of data protection consistent with industry standards.

3. Google API User Data (Google Calendar)

Connecting Google Calendar is optional and occurs only after you explicitly grant permission on Google's OAuth consent screen.

3.1 Google User Data We Access

  • Your Google Account email address, OAuth access and refresh tokens, and granted scopes
  • Calendar-list data such as calendar IDs, names, primary-calendar status, and display colors
  • Calendar-event data such as event IDs, titles, start and end times, all-day status, location, meeting or conference links, and your attendance response status when available

3.2 How We Use Google User Data

  • Link the Google Account you choose to your Alt account and display its connection status
  • Display your calendars and upcoming events inside Alt
  • Exclude events you declined and let you create or link an Alt note from an event you select

We use Google user data only to provide or improve these user-facing features. We do not use it for advertising, ad targeting, credit assessment, or unrelated profiling.

3.3 Google User Data Retention Periods

We retain Google user data only for the periods stated below. When each retention period ends, we delete or destroy the applicable data unless a longer retention period is required by law.

  • We store your Google Account email, granted scopes, connection status, and encrypted refresh token on our server only while your calendar remains connected. We delete this data and the connection record when you disconnect Google Calendar, delete your Alt account, or we detect that you revoked Alt's access through Google.
  • Google access tokens are not stored in a database or other persistent storage. An access token is held only in server memory while processing each Google API request and is discarded when the request completes.
  • Calendar-list and event data is retrieved from Google on demand and is not stored in a database or other persistent storage on Alt's server. The desktop app holds the latest calendar snapshot only in memory, replaces it when refreshed, and discards it when you disconnect, sign out, or close the app.
  • If you create an Alt note from an event, the event title, event ID, and start and end times become part of that Alt note. Like other note data, this information may be stored on your device and in your cloud-sync storage until you delete the note or your Alt account.

3.4 Sharing, Transfer, and Disclosure

Google user data is transferred only between Google APIs, Alt's server, and your authenticated Alt desktop app to provide the calendar integration. Our infrastructure providers, including Supabase, Cloudflare, and AWS-hosted synchronization infrastructure, may process encrypted connection records and synchronized note data solely to operate and secure the service on our behalf.

We do not sell Google user data or share or transfer it to advertising platforms, data brokers, or information resellers. We also do not send Google user data to analytics services for advertising or advertising measurement.

Alt's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. See the Google API Services User Data Policy.

3.5 Data Protection

  • We use HTTPS/TLS to protect data in transit.
  • Google refresh tokens are encrypted at rest using AES-256-GCM.
  • Tokens are protected by server-side access controls and database row-level security and are never exposed to the desktop app.
  • We request only the minimum read-only Google Calendar scopes needed for the integration.

3.6 How to Delete Google User Data

  • You can disconnect Google Calendar from Alt at any time. On disconnect, we revoke the Google token and delete the stored Google email, token, scopes, and connection record from our server.
  • If we detect that you revoked access in your Google Account, we delete the stored connection record.
  • Deleting your Alt account also deletes the stored Google connection record.
  • Disconnecting does not automatically delete Alt notes you previously chose to create from calendar events. You can delete those notes, including the copied event information, by deleting the note or your Alt account.
  • You may also request deletion of Google user data by emailing [email protected]. After verifying your identity, we delete the applicable data without undue delay unless retention is required by law.

4. Information We Collect on the Website

CategoryDataPurpose
AccountEmail address (OTP auth)Account creation, login, verification
BillingStripe customer ID, subscription status, payment historyBilling and subscription management
Game/LeaderboardEmail, nickname, organization, scoreLeaderboard operations
FeedbackEmail, feedback type/contentSupport and product improvement
DownloadEmail (optional), platform, user agent, IPDownload delivery and operational stats
Shared NotesNote content, share settings, user IDSharing features
AnalyticsPage views, click events, device/browser infoService improvement and UX optimization
Support ChannelEmail support dataCustomer support

5. How We Use Information

  • Provide and operate the service
  • Authenticate users and maintain security
  • Process billing/subscription and related accounting
  • Handle customer support requests
  • Improve product quality and build new features
  • Comply with legal obligations

6. Third-Party Processors

ProviderUseRelated Data
SupabaseAuthentication, databaseAccount/service data
StripePayment processingSubscription/payment metadata
Google Analytics (GA4)Web analyticsPage/click events, device info
PostHogProduct analyticsEvent and usage behavior data
Vercel AnalyticsWeb performance and usage analyticsTraffic and visit stats
ResendEmail deliveryEmail address and message metadata
OpenAI (openai.com)AI processing in API mode (GPT models)Transcript text, memo content
Anthropic (anthropic.com)AI processing in API mode (Claude models)Transcript text, memo content
Google (ai.google)AI processing in API mode (Gemini models)Transcript text, memo content

We do not sell personal data.

7. International Transfers

Data may be processed in countries where our infrastructure/providers operate (for example Supabase, Stripe, Google Analytics, PostHog, and Resend). When API mode is selected in the desktop or iOS app, AI requests may also involve international processing by integrated API providers.

8. Retention

  • Account data: until account deletion
  • Payment records: retained as required by applicable law (for example up to 5 years)
  • Leaderboard data: until deletion request or while required for service operation
  • Feedback/support data: deleted or de-identified after purpose fulfillment
  • Analytics data: retained within operational needs, then deleted or de-identified

9. Your Rights

  • Access your personal data
  • Request correction, deletion, or restriction of your data
  • Withdraw consent and make privacy inquiries
  • Control data transfer in the desktop or iOS app by choosing LocalLLM or API mode

To exercise these rights, contact [email protected].

10. Children's Privacy

Our services are not intended for children under 14. We do not knowingly collect personal information from children under 14 and will delete such data if identified.

11. Policy Changes

This policy may be updated due to legal, product, or operational changes.

12. Contact

Privacy Officer: Alt Team

Email: [email protected]