Recordstead
Privacy Policy
In short
- Recordstead records and transcribes meetings on your Mac. The app does not automatically send us recordings, transcripts, summaries or saved voices. If you choose to send meeting content or a diagnostic archive to support, we receive what you send.
- The app has no analytics, no telemetry, no crash reporting, no account and no sync. The website counts page views without cookies, and section 7 says what that counts.
- Audio stays on your Mac unless you send it somewhere yourself. By default a recording never leaves your Mac, and neither does a saved voice. You can turn on offload to a destination you configure, an external disk or your own S3-compatible or SFTP storage, and then a recording is uploaded to your storage, already encrypted, so the destination only ever holds ciphertext. We are never the destination and never hold your credentials. If you connect an AI service yourself, transcript text goes to the service you chose, under your own agreement with them.
- Recognizing people across meetings is off until you turn it on. It stores a numeric voice template; that is biometric data, and it has its own schedule on this page.
- Deleting a meeting removes it from Recordstead permanently. Files you exported and your own backups are not touched.
- Your meetings are encrypted on disk, with a key held in your Mac’s keychain. A copy of the folder on another Mac cannot be read without a transfer code you get from this one. Three things are deliberately not encrypted, and section 2 says which and why.
- What we do hold includes website request data, pseudonymous trial and licensing records, billing and delivery records for completed purchases, and messages you send us. Public purchases are not yet available.
- If you record other people, telling them and having the right to record is your responsibility. The app asks you to confirm that before the first recording.
1. Who we are and who is responsible for what
Recordstead provides this software and website. Privacy questions and requests about your data: privacy@recordstead.app. Support: support@recordstead.app.
Two different worlds, kept apart on purpose.
Your meeting data: you decide. For recordings, transcripts, summaries, meeting titles, speaker names and voice data handled on your Mac, Recordstead is neither a controller nor a processor. The app does not send this content to us; you decide why it exists, who is in the room and how long it is kept. We provide a tool and do not determine the purposes or means of that local processing. That stays true when a bundled language model runs on your Mac. If you choose to send content to support, we handle that copy as part of your support correspondence, described in sections 6 and 7.
Our own service data: we are the controller. Recordstead is the controller for the website, licensing and support correspondence. For purchases, Paddle handles checkout and payment as the seller, while Recordstead handles license delivery and access. Sections 6 to 10 describe these activities.
2. Meeting content on your Mac
The audio of a call, your microphone track, the transcript, the summary, the title, the speaker names and the search index live in app-managed files and one database under your user account’s Application Support folder. They are readable only by your macOS user, and they are encrypted: the database is encrypted, and each stored recording is an encrypted file that also detects tampering rather than a playable one. The key is held in your Mac’s keychain and is tied to your macOS account, so copying the folder elsewhere is not enough to read it. That copy asks for a transfer code, which you get from the Mac the meetings came from, and which we never see and cannot reproduce.
If you turn on offload, a finished recording is moved off your Mac to a destination you configure, an external volume or your own S3-compatible or SFTP storage, to keep the internal disk from filling. It is the same encrypted file that is uploaded, so the destination holds only ciphertext; the key stays on your Mac. The transcript, summary and everything else stay on your Mac, so search and reading a meeting still work with the audio away. Offload is off by default, you choose the destination and supply its credentials (kept in your Mac’s keychain), and switching the active destination never moves recordings already stored elsewhere. We are never a destination.
External recordings remain in your storage until you remove them yourself. Deleting a meeting or disconnecting a destination does not delete those files. Downloaded local copies expire six hours after their last use; playback, export and processing protect a copy until the operation finishes. Expired copies are cleaned while the app runs or when it next opens. Reconnecting an archive restores access only to verified files for meetings still in the app, not deleted meetings.
Three things are deliberately not encrypted:
- A recording while it is still being made. It is written to a staging area in the clear and encrypted when the finished recording is filed. A stream that is still being written cannot be both encrypted and recoverable if the Mac loses power, and we chose recoverable.
- The app’s operational log, which holds the processing queue, timings and a record of what the app did. It contains no meeting content: meetings appear in it under an opaque handle, never by title. It stays readable so the app can tell you why it cannot open your meetings when something is wrong with the key.
- A technical log of what the app did, kept in your Mac’s own logs folder
at
~/Library/Logs/Recordstead/for 7 days and then deleted. It is the app writing down its own steps: timings, errors, which processing stage ran, the names and formats of the audio devices in use, and a loudness reading every few seconds while recording, so that a fault can be explained afterwards. It holds no meeting content. Titles and people’s names are withheld by macOS itself, which is why they appear in it as<private>.
The app sends none of this to us automatically. There is no automatic server-side copy, diagnostic upload or “help us improve” channel. The app contains no analytics or crash-reporting library. The technical log reaches us only if you decide to send it: the Diagnostic log row in Settings > Advanced has an Export button that writes the last seven days of it into a zip file in your export folder, and what happens to that file is then yours to choose.
3. AI services you connect yourself
Summaries, suggested titles and Ask answers are produced by a language model. Four paths exist, and all of them are your choice:
| Path | What is sent | Where |
|---|---|---|
| Built-in (default) | Transcript text, speaker names, meeting date | Nowhere. A model that ships with the app, running on your Mac |
| OpenAI-compatible endpoint | The same text, plus each transcript chunk if you enable Ask over your archive | The address you type. We do not choose it, host it or see the traffic |
| Claude Code | The same prompt text | Your own Claude Code installation, under your own account and Anthropic’s terms |
| Codex | The same prompt text | Your own Codex installation, under your own account and OpenAI’s terms |
If you use one of the two assistant tools, the app runs the copy already on your Mac and sends the text to its standard input. It signs you in to nothing, holds no account of yours, and each tool is confirmed separately: confirming Claude Code does not turn on Codex. It also narrows what that tool may do while it writes your summary, so your own configured extensions do not receive the text and the tool keeps no copy of the conversation in its own history.
Never sent on any path: audio, voice templates, or the numbers derived from a voice. Each remote path is off until you confirm it for a specific destination, and the app tells you what will be sent before you do. If you point the app at a remote endpoint, that endpoint’s operator decides what happens to the text and their policy governs, not this one. A remote address must use HTTPS; the app refuses a non-local address over plain HTTP.
4. Saved voices and the retention schedule
If you turn on recognizing people across meetings, the app stores a numeric voice template per named person so it can label them in later meetings. This is biometric data (special-category data under the GDPR, a voiceprint under Illinois law and similar statutes). Consequences:
- The feature is off in every fresh installation and stays off until you explicitly enable it and confirm a description of what it does.
- Even then, nothing is saved for a new person until you confirm, for that person and by name, that you told them and may keep a record of their voice. Decline, and they are still named in that meeting’s notes; nothing about their voice is kept.
- Templates never leave your Mac and are never sent to any AI service.
- They are deleted when you use Forget Person, when you delete the meetings that produced them, and automatically after 90 days without a confirmation.
A template is not stored for a meeting you merely transcribe. When recognition is off, nothing voice-derived survives the run at all.
Who holds the voice data
Nobody but you. Recordstead never receives a saved voice, never transmits one, and has no means of obtaining one. No voice template is sent to any AI service on any processing path, and none is sold, licensed or otherwise profited from, because we do not have it. Where a law requires the person holding voiceprints to publish a retention and destruction schedule, that person is the user of the app, and the schedule their installation enforces is the one below.
The schedule the software enforces
| Data | Where it is | Destroyed |
|---|---|---|
| Saved voice (template, samples, usage counters) | Your Mac, in the app’s database, scoped to one workspace | On Forget Person; when the meetings that produced it are permanently deleted; automatically after 90 days with no confirmation |
| A speaker question you have not answered yet, which keeps that run’s voice numbers so the question can be reopened | Same database, one row per open question | On answering, skipping or cancelling it; automatically after 7 days |
| Per-meeting voice numbers computed while separating speakers | Not stored anywhere | At the end of the operation that computed them |
Two properties of the 90-day rule, and the first is easy to get backwards. “Without a confirmation” means nobody has vouched for the voice, not that the app has stopped using it: recognizing somebody is a read and changes nothing, so a person the app labels automatically for three months, without you ever confirming their name again, is deleted at 90 days. And 90 days is a hard ceiling in the code, not a setting; nothing can widen any window in this table.
What “destroyed” means, exactly
The record is removed from the app’s database and the app cannot recover it. That is the whole of the promise, and it is deliberately narrower than it could sound:
- We do not claim the underlying disk blocks are overwritten. The database is an ordinary local file and deletion is a database delete, not a secure erase.
- The record was encrypted while it existed, and that is not a secure erase either: we do not claim the underlying ciphertext is overwritten, and the key that could read it is still on your Mac.
- Copies you made yourself, such as exports, Time Machine, iCloud or a duplicated folder, are outside the app entirely and are not touched.
One thing is kept: a record that a voice was destroyed, when, and on what basis it had been saved. It holds an identifier and dates, no name and no voice data, so it cannot say whose voice it described.
Changing this schedule
A material change here is also a change to what you agreed to in the app, so it bumps the version of the in-app description (currently version 4) and every installation is asked again before the feature keeps running.
5. If you record other people
Recordstead does not tell anyone that a recording started, and it cannot. Before your first recording the app asks you to confirm that recording lawfully and informing participants is your responsibility; before automatic call detection starts, it asks again, separately. Settings › General offers a plain-language notice you can paste into an invitation. Where you record, and where the participants are, may require their consent, and where you enable saved voices you may also need their written consent and your own retention policy.
6. Data we hold, at a glance
App operations do not send us meeting content. Support correspondence may include content or diagnostics you choose to send. Paid-purchase rows apply only when sales open.
| Activity | Data | Purpose | Legal basis | Recipients | Kept |
|---|---|---|---|---|---|
| Trial licensing | Installation public key, pseudonymous device signal, request identifiers, trial dates, invitation code where applicable, IP address in requests | Grant and check the 30-day trial and prevent repeat use | Trial terms and legitimate interest in preventing abuse | Cloudflare (hosting and database) | Trial device link until its recorded retention date, 24 months after trial expiry or registration without a start; installation and trial records have no general automatic expiry |
| Paid licensing | License reference and status, public installation keys, up to two activations, optional label sent by the app, replacement history | Activate and check the purchased right | Purchase contract and fraud prevention | Cloudflare (hosting and database) | Active entitlement and activation records have no general automatic expiry; completed replacement records are swept after 90 days |
| Purchase and delivery | Buyer email and transaction facts supplied by Paddle; a key generated by Recordstead; encrypted stored copies of the email and key; delivery status | Fulfil orders, send or resend the key, process refunds and disputes | Purchase contract and applicable legal obligations | Paddle (independent seller and source of buyer data, not a recipient of the key), Cloudflare (billing database and work queue), Resend (mail delivery) | Encrypted key and email have no automatic expiry, including after refund or revocation. Financial, event and delivery metadata also have no general automatic deletion schedule. Temporary encrypted mail envelopes are wiped after delivery or swept after 23 hours |
| Private candidate links | Browser IP address and request time | Serve an invited build | Legitimate interest in delivery | Cloudflare | Signed link expires after 24 hours; the download Worker stores nothing |
| Updates and future public stable downloads | Request data; on a signed candidate update, installation public key, timestamp and request signature | Offer and serve updates; serve a stable build only after explicit promotion | Legitimate interest in delivering working software | Cloudflare | The download Worker stores nothing; Cloudflare operational logs may remain. A promoted public stable download does not require a visitor installation key or a 24-hour token |
| Website visits | Request data including IP address, browser and page; cookieless page-view measurements | Serve and protect the site and measure pages read | Legitimate interest in running and measuring the site | Cloudflare | Provider operational logs; analytics in full for seven days, then as aggregates |
| Support and privacy mail | Your address, message, attachments you choose and the exchange | Answer and document the matter | Legitimate interest in answering and legal rights; a contract where applicable | Cloudflare Email Routing and our mailbox provider | No configured automatic deletion schedule; retained for the matter and applicable dispute or legal obligations, with deletion requests assessed individually |
We do not sell personal information or use it for cross-context advertising, and we make no automated decisions about you.
7. Website and support mail
Hosting. The website is served by Cloudflare. Cloudflare processes request data, including IP addresses, as our processor to serve and protect the site (Cloudflare privacy policy, Cloudflare customer DPA). Fonts are served from our own domain. The site sets no cookies of its own.
Counting page views. The site counts page views with Cloudflare Web Analytics. It stores nothing on your device and reads nothing from it: no cookie, no local storage, no device fingerprint, and no identifier that could tie one visit to another or to you. A page view reports the page you opened, the address of the site that linked you, your country, your browser, operating system and device type, how the page was loaded, and how long it took. Cloudflare processes this for us and states that it does not track individual visitors across the sites it serves. Measurements are kept in full for seven days and as aggregates after that. Because nothing is stored on or read from your device, this needs no consent banner; we rely on our legitimate interest in knowing whether the site works and which pages are read. Any content blocker that stops Cloudflare’s script stops the measurement, and the site works the same without it.
Former access requests. The waitlist and its request database have been removed. The website no longer accepts access requests. Earlier messages may remain with their recipients or in the mail provider’s delivery records under that provider’s retention practices (Resend privacy policy, Resend DPA).
Writing to us. Mail to any recordstead.app or recordstead.com address is received by Cloudflare Email Routing and forwarded to the mailbox we read. There is no automatic deletion schedule for this mailbox. We keep the exchange while handling the matter and any applicable claim or legal obligation. Ask privacy@recordstead.app for access or deletion.
8. Licensing and purchases
The app checks trial and paid access with the Recordstead service at
license.recordstead.com, hosted on Cloudflare. It sends a per-installation
public key and signature, a request identifier and, for public trial
deduplication, a SHA-256 derivative of the Mac’s platform identifier. The raw
identifier stays on your Mac; the service HMACs the derivative for lookup.
This is pseudonymous personal data, not anonymous data. The service also
sees your IP address for ordinary network delivery and rate limiting. It does
not receive meeting content. An invited build may also send the invitation
code you enter.
The trial-device link has a recorded expiry 24 months after the trial ends or registration without a start; its cleanup occurs during later licensing requests. Installation, trial and activation records do not have a general automatic expiry today. You may contact privacy@recordstead.app about these records.
Public purchases are not yet available. For a purchase, Paddle collects and handles checkout and payment information as the seller under its own Privacy Policy. Paddle supplies Recordstead with the buyer email and transaction information needed to issue and manage the license. Recordstead generates the license key and encrypts both the key and buyer email before storing them in its billing database. The app supplies any optional activation label you type; Paddle does not supply that label or the license key. We use Resend to deliver the key.
The encrypted key and email have no automatic expiry, including after a refund or revocation ends processing access. They support manual resend while a license is active, but that purpose is not an implemented deletion trigger. Financial, event and delivery metadata also have no general automatic deletion schedule. Temporary encrypted mail envelopes are removed when delivery is resolved or swept after 23 hours; that cleanup does not remove the stored key or email. You can request deletion through privacy@recordstead.app. We assess a request against any active license, purchase or refund dispute and applicable legal obligation, and explain what can be removed. We do not promise a deletion date that has not been implemented.
Updates and downloads. A build can keep itself up to date. When it starts,
and every few hours while it runs, it asks dl.recordstead.app, also on
Cloudflare, whether a newer build exists. You can also ask it to look, and
you can switch automatic checks off. The feed request carries no app-specific
identifier; Cloudflare sees your IP address, as it does for any web request.
An invited candidate download uses a signed link that expires after 24 hours.
For a candidate update download, the app sends its installation public key,
the request time and a signature proving that installation made the request.
The service verifies that installation before serving the candidate. Neither
path sends meeting content, file names, a list of apps on your Mac or a report
of how you use Recordstead. Nothing is checked or downloaded while you are
recording.
A public stable 1.x download path is prepared but is available only after explicit release promotion. Once promoted, the public route does not require a visitor installation key or an expiring invitation token. This policy does not mean a public stable build is available now.
A build compiled locally from source carries no endpoint, no update feed and contacts nothing.
9. Model downloads
Speech and language models come from Hugging Face and its content delivery network when the app needs a model that is not already on your Mac. The active transcription model may download during launch preload; a processing hold may defer that preload. Other models download when their features need them. The request is anonymous, with no token, no account and no identifier; Hugging Face sees your IP address, the time and which model was requested, under its own privacy policy. This connection carries no meeting content, and the download is verified against a pinned checksum before the model is used.
10. International transfers
Cloudflare and Resend are United States companies operating global networks. Both are certified under the EU-U.S. Data Privacy Framework, including its UK Extension, and both incorporate the EU Standard Contractual Clauses in their data processing agreements linked above. Hugging Face and any AI provider you configure yourself are connections your Mac makes directly; their handling of your IP address or text is governed by their terms.
11. Your rights
For anything we hold, write to privacy@recordstead.app. You may ask for access, rectification, erasure, restriction, objection, portability, or withdraw a consent you gave us. We answer within one month; if a request is complex we may take up to two further months and will tell you why within the first month. We ask only for what is needed to be sure it is you, normally that you write from the address the record is associated with, and we do not collect more documents to try. Requests are free unless manifestly unfounded or repetitive. You may complain to the data protection authority of the country where you live.
If you asked us to forget you, we may keep a minimal entry saying that this address must not be written to again, so that the request itself is honoured.
For meeting data kept only on someone’s Mac, we cannot act on that archive: we have no access to it or a way to find out who recorded you. If someone voluntarily sent us a copy for support, you can ask us about that copy through the privacy address above. The person who made the recording answers requests about their own archive, and the app gives them the tools:
- Export Person Data in People writes a document listing every meeting you appear in, what you were recorded saying, where you are named, and whether a voice template is stored for you. It works whether or not a voice is saved.
- Forget Person removes the voice template and the app’s record of recognizing you. Deleting the whole meeting removes the recording, transcript and summary permanently.
- Renaming a speaker corrects a wrong name across their library.
If you write to us about a recording we do not hold, we will explain this and point you to the recorder; we cannot forward the request because we do not know who they are. If the recorder refuses or does not answer, you can contact a data protection authority about their handling of the recording.
If you run Recordstead and receive such a request: check that it really comes from the person, export what you hold from People, answer, then act. Deletion is Forget Person for a voice, or permanently deleting the meetings. The export covers one name as your library spells it and one installation; copies you have already exported, sent or backed up are yours to handle. The app keeps no request log; if you need one, keep it yourself.
12. How long things are kept on your Mac
| Data | Kept until |
|---|---|
| Your transcripts and summaries | You delete the meeting. There is no automatic expiry and no cap we impose |
| Your recordings | Under Settings > Storage, choose an age of 1, 3, 7, 30 or 90 days (7 by default), or keep the newest 1, 5, 10 or 20 local recordings regardless of their age. Eligible older audio is removed from this Mac or moved to a destination you configured, according to your setting; the meeting, its transcript and its summary stay. A recording of a meeting that was never transcribed is not removed this way, because it is the only copy that meeting has |
| A speaker question you have not answered | You answer it, or 7 days |
| Saved voices | Forget Person, or 90 days without a confirmation |
| Capture leftovers the app can no longer use | Swept after 7 days; an unfinished recording is recovered instead of deleted. This staging area is the one place on disk that is not encrypted, and the sweep is what empties it |
| The technical log of what the app did | 7 days, swept while the app runs. A zip you exported from it is a file of yours, and is kept until you delete it |
Deleting a meeting is permanent: it is removed from Recordstead and cannot be recovered there. Files you exported, and your own backups such as Time Machine or iCloud, are outside the app’s reach and are not touched.
13. AI-generated content
Transcripts are produced by automatic speech recognition and are labelled Automatic transcription in the app. Summaries, suggested titles and Ask answers are generated by a language model; the app labels them AI-generated. Review for accuracy. and tells you which model and destination Ask uses before your first question. They can be wrong, and they are not a verbatim record.
An exported summary carries a machine-readable provenance record at the end of the file, stating that the content was machine-generated, by which model, where, and when. An exported transcript carries no such record: it is a verbatim record of what was said, not text a model wrote for you. If you publish or circulate generated text, any duty to say it was AI-generated is yours as the one publishing it; keep the provenance record in place, or label the text yourself.
The models that run on your Mac are published by third parties under their own licences, listed in the app under Help › Third-Party Licenses. We are not the developer of those models.