Ellumo Privacy Policy
Draft — not yet published
This document is still being prepared and is not in effect. The final version will appear here before Ellumo launches; the highlighted parts are still to be filled in.
Effective date: {{EFFECTIVE_DATE}}
1. Who we are
Ellumo is a voice recorder that transcribes and summarizes your recordings. It is provided by {{LEGAL_NAME}}, {{ADDRESS}}, {{COUNTRY}} ("we", "us"). We are the controller of the personal data described here. Questions and requests: privacy@ellumo.app.
2. The short version
- There is no account. Your library — recordings, transcripts, summaries, chats — lives on your phone.
- Own keys: your recordings and transcripts go from your phone straight to the AI provider you chose, under your own key and your own contract with that provider. We never receive them.
- Ellumo Cloud: your recording goes through our server to Groq for transcription (with a subscription, to OpenAI instead when Groq is busy or unavailable), and the transcript and your questions go to Anthropic for summaries and answers. Our server keeps a transcript or a summary for 10 minutes and keeps no audio. You agree to this in the app before Ellumo Cloud is turned on.
- No ads, no tracking, no analytics SDK. Crash reports go to Sentry only if you turn them on. When the app starts, it asks Expo whether there is a fix to its code (section 4.4).
- Settings › Delete all data removes everything the app keeps on your phone.
3. What stays on your phone
Recordings, transcripts, summaries, bookmarks, chats with your recordings, settings and API keys are stored on your device. Keys are kept in the iOS Keychain or Android's secure storage and are readable only while the device is unlocked.
Titles and short summaries of your recordings can appear on your own screens outside the app: in widgets, the Live Activity, notifications, on your Apple Watch and in the Android widget, including on the lock screen. Notifications are scheduled on the device; we do not use push notifications.
Recording and on-device transcription work offline and send nothing anywhere.
4. What leaves your phone, and when
4.1 Own keys
When you connect your own key, the app sends data directly to that provider:
- For transcription (unless it runs on the phone): the recording's audio, to OpenAI, Google Gemini or an OpenAI-compatible server whose address you enter.
- For summaries and answers: the transcript text and your questions, to Anthropic, OpenAI, Google Gemini or your OpenAI-compatible server.
The request carries your key, so the provider processes the data under your account, its terms and its privacy policy. We do not receive this data and cannot see or delete it. Audio uploaded to Google Gemini's Files API is not deleted by the app; Google deletes it after its own retention period.
4.2 Ellumo Cloud
When you use Ellumo Cloud:
- the recording's audio is sent to our server, which passes it to Groq for transcription. If you have an Ellumo Cloud subscription and Groq is busy or unavailable, our server sends OpenAI the part of the recording Groq could not take, for transcription; during the free trial the recording waits for Groq;
- the transcript text, summary requests and your questions are sent to our server, which passes them to Anthropic (Claude) for summaries and answers.
With each request the app sends a random user ID, an install token (section 5), the app's platform and version, your language setting, and which version of the Ellumo Cloud consent you agreed to. Our server does not pass your user ID, install token or IP address to Groq, OpenAI or Anthropic. They process the data on our behalf (section 7). Groq and Anthropic keep it only for a limited time under their terms. Under the data controls OpenAI publishes for its transcription API, OpenAI does not use the audio for training and does not retain it (no copy kept for abuse monitoring, no stored application state). The app asks for your consent before Ellumo Cloud is used for the first time; if you decline, nothing is sent. When a service is added to Ellumo Cloud, it receives nothing from you until you agree to a text that names it, which the app asks for the next time you choose Ellumo Cloud.
4.3 Purchases
Subscriptions and minute packs are sold through the App Store or Google Play. We never see your payment details. We use RevenueCat to manage purchases: the RevenueCat SDK runs in every build that can sell Ellumo Cloud, in any mode, and sends RevenueCat your random user ID, store receipts and basic device and app information (such as OS version, app version, locale and IP address). Our server asks RevenueCat whether your subscription is active and receives purchase events (including store transaction IDs) from it.
4.4 Speech models and app updates
On-device transcription models are downloaded from Hugging Face (huggingface.co). As with any download, Hugging Face sees your IP address. Nothing about your recordings is sent.
Each time it starts, in every mode, Own keys included, the app asks the update server of Expo whether there is a newer version of its code for your build, and downloads it if there is one. The app works as usual when the check fails or you are offline. The request carries your IP address, a random update client ID (section 5), the platform, and which version of the app and of its code is running. If the app stopped with an error while it was starting the previous time, the request also carries the text of that error (up to 1,024 characters), so that a faulty update can be withdrawn; this does not depend on the crash reports switch (section 4.5). Nothing from your recordings, transcripts, summaries, chats or keys is sent.
4.5 Crash reports (off unless you turn them on)
If you turn on Settings › Privacy › Crash reports, the app sends a report to Sentry when it crashes or hits a serious error. A report contains the type of error and its code, where in the app's code it happened, the app version, the device model and OS version, and a random crash report ID (section 5). Before a report leaves the phone the app removes error messages, web addresses' parameters and anything that looks like a key or a token. Reports never contain recordings, transcripts, summaries, questions or keys. Turning the switch off stops new reports immediately; a report that is already being sent may still arrive, and anything still waiting on the device is deleted.
4.6 Email and the feedback form
If you write to us by email or through the feedback form at https://ellumo.app/feedback, we receive what you write and, if you give them, your email address, your device type and the app version. We use them only to reply and to fix what you report, and keep the correspondence as long as that takes. Cloudflare's email service delivers the form's messages to our inbox; the website keeps no copy and sets no cookies. To limit abuse, the website counts messages from each network address over one minute and keeps no log of the addresses.
5. Identifiers
- User ID: a random identifier created on your phone. It is used by RevenueCat and our server to connect your purchases and Ellumo Cloud usage. Delete all data replaces it with a new one.
- Install token: a random value stored in the Keychain (iOS) or secure storage (Android). Our server uses it only to make sure the free Ellumo Cloud trial is granted once per installation. It stays after Delete all data; on iPhone it also stays after the app is deleted, because iOS keeps Keychain items; on Android it is removed when the app is uninstalled.
- Crash report ID: only if you turn crash reports on, Sentry's code in the app creates a random identifier and adds it to crash reports, so that reports from the same installation can be told apart. Turning crash reports off, or Delete all data, deletes it from the phone; if you turn them on again, a new one is used from the next time the app starts.
- Update client ID: a random identifier that Expo's code in the app creates and sends with each update check (section 4.4). Expo uses it to give an update to a share of installations and to count the installations running each update. It is not linked to your user ID or install token. It stays after Delete all data, is removed when the app is uninstalled, and can move to a new device with a backup (section 9).
We do not use the advertising identifier and do not track you across apps or websites.
6. What our server keeps, and for how long
| Data | How long |
|---|---|
| A finished transcript or summary, so a retry of the same upload or summary is not charged twice | 10 minutes, then deleted automatically |
| Audio, answers, questions | Not stored |
| Ellumo Cloud usage: minutes, summaries and questions per month | The current and the previous month |
| The number of summaries made for each recording (under the recording's random ID) | Until we add an expiry; it contains no content |
| Minute packs: store transaction ID, minutes, purchase and expiry dates | Until the pack expires (12 months) |
| Free trial usage per install token | Kept, so the trial is granted once per installation |
| Your subscription status from RevenueCat | 10 minutes (the last known status up to 7 days) |
| Cost and performance records per request (a shortened one-way hash of your user ID, the service, model, minutes, tokens, cost, duration) | The retention of Cloudflare Workers Analytics Engine (about three months) |
| Technical error logs (no content, no keys) | Cloudflare's log retention |
7. Service providers and where they are
| Provider | What for | Location |
|---|---|---|
| Cloudflare, Inc. | Runs our server and our website, stores the records in section 6 and delivers the feedback form's messages | Global network; storage location chosen by Cloudflare |
| Groq, Inc. | Transcription in Ellumo Cloud | United States |
| OpenAI, L.L.C. | Transcription in Ellumo Cloud when Groq is busy or unavailable (subscribers only) | United States |
| Anthropic, PBC | Summaries and answers in Ellumo Cloud | United States |
| RevenueCat, Inc. | Purchases and subscription status | United States |
| Functional Software, Inc. (Sentry) | Crash reports, only if you turn them on | {{SENTRY_REGION}} (EU, Germany, recommended) |
| 650 Industries, Inc. (Expo) | App updates (section 4.4) | United States |
| Apple, Google | App stores, payments, backups you turn on | Their own terms |
Where data leaves the European Economic Area, the UK or Switzerland, we rely on {{TRANSFER_MECHANISM}} (for example, the EU Standard Contractual Clauses or the EU–US Data Privacy Framework).
8. Why we process data (legal bases)
- To provide the service you ask for (contract): Ellumo Cloud transcription, summaries and answers; purchases and subscription status.
- Our legitimate interests: granting the free trial once per installation, preventing abuse, keeping costs under control, keeping the service secure, and delivering fixes to the app (app updates).
- Your consent: crash reports; and before Ellumo Cloud is first used, your agreement to send recordings to Groq (and to OpenAI when Groq is busy or unavailable) and Anthropic. You can withdraw consent at any time by turning crash reports off or switching to Own keys.
9. Backups
- iPhone and iPad: iOS includes the app's recordings and library in your iCloud Backup or computer backup if you have backups turned on. Those backups are stored by Apple under your Apple Account, or on your computer, not by us. Speech models are excluded. Your keys and identifiers never move to another device through a backup, apart from the update client ID (section 5).
- Android: the app's backup rules exclude recordings, the library, settings and keys from Google backups and device transfers; the update client ID is included in them.
10. Deleting your data
- Settings › Delete all data deletes recordings, transcripts, summaries, chats, exports, keys and settings on your phone, turns crash reports off, deletes crash reports waiting to be sent and the crash report ID, and gives you a new user ID.
- It cannot delete backups made earlier (manage them in your device's settings), keeps the install token and the update client ID (section 5), and leaves our server's records under the old user ID to expire as in section 6. To have them deleted sooner, write to privacy@ellumo.app; as there is no account, we will explain how to send us the identifier from your phone so we can find them.
- Uninstalling the app deletes its data on Android. On iPhone, iOS keeps Keychain items (your keys and the install token) after the app is deleted: use Delete all data first to remove your keys.
- Data you sent to your own provider is governed by your agreement with that provider.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict its processing, and to withdraw consent. Most of your data is on your phone and under your control. For data on our server, write to privacy@ellumo.app. You may also complain to your local data protection authority.
12. People you record
Ellumo records whatever the microphone hears. You are responsible for telling people that you are recording them and for getting their consent where the law requires it. Ellumo does not record phone calls.
13. Children
Ellumo is not directed at children under 16, and we do not knowingly process their data. If you believe a child has used Ellumo Cloud, write to us and we will delete what we can find.
14. Security
All traffic between the app, our server and our providers is encrypted (HTTPS). Keys are stored in the device's secure storage, and the app's logs mask them. Crash reports are scrubbed as described in section 4.5.
15. Changes
We will update this policy when the app's data practices change, and change the effective date above. For significant changes we will tell you in the app.
16. Contact
{{LEGAL_NAME}}, {{ADDRESS}}, {{COUNTRY}} — privacy@ellumo.app