Skip to content
Temlo
Product Pricing Download
Open Temlo ↗

Temlo Privacy Policy

Document version: 0.2 (draft)

Backend current Terms version: 0.2 (Terms only; this Privacy Policy is not a consent or acceptance record)

Effective version: none — no final/effective Privacy Policy has been approved or published.

Last reviewed: August 23, 2026

Planned stable URL: https://temlo.app/privacy

Publication status — current draft, not effective. This document is an implementation-based draft. The 0.2 identifier is aligned with the repository's current Terms version for release tracking only; Privacy is not accepted through the Terms acceptance record and is not treated as consent. Before this document is used as the final privacy notice, the operator must confirm the provider settings and retention periods, international-transfer safeguards, regional disclosures, cookie and consent requirements, and the final legal review.

1. Who is responsible for your personal data?

The final operator/controller identity and legal details are not finalized in this draft. They must be inserted and verified before publication. For processing where the operator decides why and how personal data is used, the operator may be the data controller, subject to the final legal assessment.

For privacy questions or requests, contact hello@temlo.app. Whether a data protection officer or representative is required, and the identity of any appointed contact, remain open launch decisions.

This Policy applies to the Temlo website, web application, desktop and mobile applications, authenticated gateways, notes, voice-note features, account and billing features, and related support and collaboration features (together, the “Services”). The Terms of Service govern your use of the Services and should be read with this Policy.

2. What data do we process?

The data we process depends on the features you use and the choices you make.

Account and authentication data

We process the account information needed to create and protect your account, which may include your email address, name or username, Clerk user and session identifiers, verification state, account status, device or sign-in metadata, and records of account deletion or recovery. Clerk handles authentication credentials and authentication infrastructure; Temlo does not receive or store your Clerk password.

Audio, transcripts, notes, and AI content

When you use dictation or voice-note features, we may process microphone recordings, audio metadata, partial and final transcripts, language selections, key terms, cleanup mode, raw transcript text, cleaned transcript text, recording duration, and error or fallback information.

On iOS, when you enable background-ready keyboard dictation, Temlo may keep a local microphone capture session active for up to five minutes while the app is in the background. Audio from that idle session is discarded on the device and is not sent to our services until you tap Dictate; the microphone indicator may remain visible while the session is armed. You can close the local capture immediately with Stop keyboard microphone in Temlo or Stop Mic in the Temlo keyboard.

When you use notes or the AI note assistant, we may process note titles, groups, documents, blocks, persistent voice-note audio, transcripts, prompts, instructions, relevant note context, proposed operations, generated responses, and the result of applying or undoing an operation. If you share a note or group, we also process sharing permissions, membership records, share links, invitation addresses, and related collaboration events.

Your content may contain personal data about you or other people. Do not record or submit another person’s voice or information unless you have the notice, consent, authorization, or other lawful basis required where you and that person are located.

Usage, quota, and billing data

We process usage and entitlement data needed to operate the Services, including audio duration, monthly allowance usage, plan, subscription state, rate-limit state, feature settings, and timestamps.

Paid transactions are processed through Paddle, our payment provider and merchant of record. Paddle may process your name, email, billing address, location, payment method information, transaction and subscription identifiers, currency, tax, invoice, refund, and chargeback information. Temlo does not receive or store full payment-card numbers. We receive the billing and entitlement records needed to provide the purchased plan, reconcile webhooks, handle support, and comply with legal obligations.

Technical, security, and support data

Depending on the request, we and our infrastructure providers may process IP address, request headers, browser or device type, operating system, application version, network and language settings, timestamps, URL or route, correlation identifiers, error details, abuse-prevention signals, and other diagnostic data. Our application logs are designed to use privacy-safe correlation and abuse signals rather than recording audio, transcripts, provider keys, or authentication tokens.

The applications may also use local device storage for preferences and operating-system integrations. This includes desktop shortcut and microphone identifiers, Clerk session tokens held through the platform’s secure token cache, the Android keyboard’s encrypted gateway-token storage, and the iOS keyboard extension’s App Group storage for a pending dictation request or transcript handoff. The iOS keyboard handoff is designed to retain pending transcript text for no more than approximately ten minutes. Local storage is controlled in part by your device and operating system; removing the application or clearing its storage may be needed to remove client-side data.

If you contact us or receive a collaboration invitation, we process the email address, message or invitation content, target note or group, and the information needed to respond or deliver the message.

Cookies, local storage, and similar technologies

The current Temlo marketing pages do not set or read Temlo advertising, analytics, or cross-site tracking cookies. They do not load third-party fonts, analytics or advertising scripts, tracking pixels, or other non-essential third-party resources. We do not currently operate a separate product-analytics, crash-reporting, advertising, or cross-site behavioral-telemetry SDK in the marketing pages or application. Because the current public-site posture uses only essential functionality, Temlo does not show a separate cookie-consent banner for these pages.

Essential or feature-required storage may still be used by the following components:

  • Temlo desktop preferences: the desktop client uses browser local storage for the selected dictation shortcut and microphone identifier when it runs in a web-compatible desktop shell.
  • Clerk authentication: Clerk may use session cookies, local storage, or related browser artifacts to authenticate and protect an account. These are controlled partly by Clerk and the browser, and Clerk’s own notices apply to its authentication components.
  • Paddle checkout and subscription management: Paddle may use cookies, local storage, or similar storage on its hosted checkout and customer-portal pages to provide payment, subscription, fraud-prevention, and support functionality. Paddle’s own notices apply to those pages.
  • Device and operating-system integrations: browsers, app stores, and operating systems may use their own storage or permissions for authentication, microphone access, app distribution, and native features.

The application also records limited server-side note-operation analytics, such as operation type, counts, duration, and success or error state, to operate and improve reliability. These are account-linked service records rather than browser tracking or advertising analytics and are currently scheduled for deletion after approximately 30 days. Essential operational telemetry may also include bounded CSP-violation metadata, correlation IDs, provider or route names, status or error codes, timing, and abuse-prevention signals; it excludes audio, transcripts, note content, prompts, responses, credentials, cookies, and full URLs.

If we introduce non-essential cookies, analytics, advertising, or similar technologies, they must be loaded through an explicit consent gate and we will provide the notice and consent controls required by applicable law before using them. The current marketing pages do not invoke that loader.

3. Why do we use personal data?

We use personal data for the following purposes and legal bases. The applicable basis depends on the user, feature, and law that applies.

Providing the Services — performance of a contract

We use account, content, usage, and technical data to authenticate you, transcribe and process requested audio, provide Smart Cleanup, operate the AI note assistant, save and synchronize notes and transcripts, maintain voice notes, apply sharing permissions, enforce the shared monthly audio allowance, provide desktop and mobile features, and deliver support or service messages.

Billing and administration — performance of a contract and legal obligation

We use account and billing records to start and administer subscriptions, reconcile Paddle transactions and webhooks, calculate entitlements, prevent duplicate or unauthorized billing, issue or respond to invoices and refunds, and meet tax, accounting, fraud-prevention, and other legal obligations. Paddle separately processes the payment transaction under its own buyer terms and privacy notice.

Security, reliability, and abuse prevention — legitimate interests and legal obligation

We use technical, usage, and derived security signals to protect accounts, enforce authentication and rate limits, detect abuse or fraud, investigate incidents, troubleshoot errors, maintain availability, recover failed work, and defend or exercise legal claims. We balance these interests against the rights and expectations of users and limit access to what is reasonably needed.

Collaboration and communications — performance of a contract and legitimate interests

We use email addresses and collaboration records to send invitations that you request, notify you about sharing, help recipients access content, and respond to support requests. We do not use collaboration invitations as permission to send unrelated marketing.

Service improvement — legitimate interests, consent where required, and legal obligation

We may use aggregated or de-identified information that cannot reasonably identify you or reveal the substance of your content to understand reliability, capacity, feature use, and service performance. We do not sell your personal data, rent it to advertisers, or use Temlo content for cross-context behavioral advertising.

Consent-based processing

Some processing may rely on your consent, such as microphone or operating-system permissions, optional communications, or non-essential cookies. You can withdraw consent through the relevant device, product, or communication control. Withdrawal does not affect processing that was lawful before withdrawal or processing required for another legal basis.

4. How audio, transcription, Smart Cleanup, and the AI note assistant work

Ordinary dictation

For realtime dictation, audio is sent through an authenticated Temlo gateway to the speech-to-text service used for the requested feature. The gateway returns transcript text and Temlo stores the resulting transcript and related usage metadata in your account when the operation completes. Temlo does not intentionally store ordinary dictation source audio in its application database after processing. Temporary handling, infrastructure logs, and provider-side retention are controlled by the relevant hosting and speech provider's current standard terms and settings.

For batch dictation, the uploaded PCM WAV audio is bounded, validated, sent to the speech-to-text provider, and then discarded from the application request path after processing. The final transcript may remain in your transcript history until you delete it or delete your account.

Persistent voice notes

A persistent voice note is different from ordinary dictation. The recorded MP4/AAC or WebM/Opus source is uploaded to Temlo storage, validated, transcribed, and converted to MP3 for consistent playback. After successful finalization, the temporary source upload is deleted and the MP3, transcript, duration, and related metadata remain attached to the voice note until you delete the note or account. Unfinished voice-note uploads are removed by the cleanup job after approximately two hours, subject to processing failures and recovery state.

Smart Cleanup

Smart Cleanup sends the transcript text and the feature settings needed for the cleanup request to Mistral AI through a server-side API. Mistral returns a proposed cleaned version; Temlo stores the raw and cleaned transcript and the selected cleanup metadata when the operation completes. Smart Cleanup is an assistive transformation and may change meaning, omit information, or introduce errors, so you should review its output.

AI note assistant

The AI note assistant sends the instruction and the relevant note context required to interpret the requested note operation to Mistral AI through a server-side API. It returns a proposed response or structured note operation. Depending on your approval, the operation may be applied, revised, undone, canceled, or retained in assistant-run records for a limited period. The assistant is not a human editor and is not used by Temlo to make decisions about eligibility, employment, credit, insurance, housing, education, or other legal or similarly significant outcomes.

Provider relationship and limitations

The repository indicates standard API integrations for Mistral AI and ElevenLabs. The actual account tier, DPA or other contract, region, transfer mechanism, training setting, and provider retention setting are not verified here. Provider public materials may describe default or optional controls, but those materials are not evidence that a particular Temlo account has enabled them. Provider privacy controls, retention rules, and terms can change; this Policy does not create a separate contractual promise about a provider's processing. The internal subprocessor and vendor register records the verification fields that remain open; each field must be checked against the applicable account and contract before publication. Accordingly, this Policy does not promise enterprise-only retention, data residency, zero-retention, or training controls that are not evidenced for the actual account and API configuration.

5. Who receives personal data?

We disclose personal data only as reasonably necessary for the purposes described in this Policy, to people you authorize, or where law permits or requires it. Our main service providers and their roles are:

  • Clerk provides authentication, account identity, session management, and related security services. See Clerk’s Privacy Policy and standard Data Processing Addendum.
  • OVHcloud hosts the web application, server-side PHP API/WebSocket gateway, PostgreSQL application database, user-content object storage, and public desktop release files. It may process account content, transcripts, notes, voice-note files, request and infrastructure data, logs, IP data, telemetry, transient content while a request is running, and versioned installer/updater artifacts. Temlo's application logs retain only bounded, allowlisted operational metadata; infrastructure settings, access, backups, and the production contract must be confirmed for the applicable account. See OVHcloud's privacy policy.
  • Vercel hosts the separate public marketing site and may process marketing-page request, infrastructure, and deployment-log data. It does not host the Temlo speech gateway. See Vercel’s Privacy Notice and Data Processing Addendum, where applicable.
  • ElevenLabs provides speech-to-text through the authenticated gateway. The actual account tier, processing region, DPA or other contract, and retention or zero-retention settings must be verified in the provider console; the repository does not establish those facts. See ElevenLabs’ Privacy Policy and API zero-retention documentation.
  • Mistral AI provides Smart Cleanup and AI note-assistant processing. Text prompts, relevant note context, and model outputs may be processed under the account's applicable Mistral API terms and privacy practices. The actual account tier, DPA or other contract, processing region, transfer mechanism, and privacy controls must be verified. See Mistral AI’s Privacy Policy and API privacy controls.
  • Paddle acts as payment provider and merchant of record. Paddle processes checkout, payment, tax, subscription, refund, fraud, and customer-support data under its Buyer Terms and Privacy Policy.
  • Resend sends collaboration and invitation emails. It may receive recipient addresses, sender information, message content, and delivery metadata. The actual account region, DPA or other contract, transfer mechanism, and provider retention settings must be verified; the application’s 90-day cleanup of terminal delivery records is not a promise about Resend’s own retention. See Resend’s Privacy Policy and Data Processing Addendum.
  • RevenueCat receives native-store entitlement and purchase-event data for mobile billing synchronization and may also receive the configured app-user identifier. The actual account region, DPA or other contract, transfer mechanism, and retention settings must be verified in the RevenueCat console. See RevenueCat’s Privacy Policy.
  • App stores, device, and operating-system providers may process app-distribution, purchase, permission, crash, and device data under their own policies when you download or use a native application. Temlo does not control those independent practices.

We may also disclose information to professional advisers, auditors, insurers, successor operators, courts, regulators, law-enforcement authorities, or other recipients where needed to comply with law, protect people or property, investigate fraud or security incidents, enforce agreements, or establish, exercise, or defend legal claims. If you intentionally share a note or group, the selected recipients can access that content while the share remains active.

Provider lists, subprocessors, endpoints, and privacy practices can change. We will update this section or provide another notice when a change is material and notice is required.

6. International transfers

Temlo and the providers above may process personal data in countries where the configured services or their subprocessors operate. The actual account/product regions and subprocessor locations have not been verified in this repository, and we do not promise that all data stays in the European Union or that every feature uses EU-only processing.

Where applicable law requires a transfer mechanism, the operator and counsel must identify and document the lawful mechanism for each relevant provider. The exact mechanism, subprocessor location, and retention setting can depend on the provider, product, account tier, and request. Review the linked provider terms, the register, and current account configuration before submitting highly sensitive content; this draft does not assert that a particular transfer mechanism or contract is in place.

7. How long do we keep personal data?

We retain personal data only for as long as reasonably needed for the purposes in this Policy, unless a longer period is required for law, security, dispute resolution, fraud prevention, accounting, or provider reconciliation. The following describes the current application behavior; it is not a promise that a provider’s own retention period is identical.

  • Account and active-service data is retained while your account is active and until it is deleted, subject to legal, security, billing, backup, and recovery records. Temlo does not currently publish a single universal maximum retention period for all active user content.
  • Transcripts, notes, blocks, groups, assistant state, and voice notes remain available until you delete them, delete your account, or the feature’s lifecycle removes them. Deleting access to a shared item does not erase copies that another person made outside Temlo.
  • Ordinary dictation source audio is not intentionally stored in the Temlo application database after processing. Speech and hosting providers may retain request data for their own documented periods under their standard terms and settings.
  • Persistent voice-note audio remains with the voice note until the note or account is deleted. Temporary unfinished voice-note uploads are targeted for deletion after approximately two hours. After successful finalization, the original source upload is deleted while the converted MP3 remains with the voice note.
  • Note analytics events are currently scheduled for deletion after approximately 30 days. Terminal AI assistant runs are currently scheduled for deletion after approximately 90 days. Rate-limit records are currently scheduled for cleanup after approximately one day. These periods may be affected by a pending operation, recovery, legal hold, or failed cleanup.
  • Account deletion records remain while billing cancellation and bounded cleanup are pending. After a completed deletion, the application’s deletion coordinator record is scheduled for removal after approximately 30 days. Paddle customer and subscription records may remain as limited tombstones needed to prevent delayed billing webhooks from recreating ownership or entitlement, and Paddle or other providers may retain records required by law.
  • Billing and delivery reconciliation records have additional implementation windows: terminal Paddle webhook-delivery records and their stored payloads are cleaned after approximately 90 days, retryable-failed deliveries after approximately 30 days, RevenueCat webhook events after approximately 90 days, and terminal collaboration invitation delivery records plus Resend webhook events after approximately 90 days. Other billing ledgers, reconciliation findings, deduplication records, acceptance records, and release records have no fixed application deletion period proven by the repository and require an accounting, security, and legal decision.
  • Invoices, transaction records, support records, security records, backups, and provider logs may be retained for the period required to meet legal, accounting, fraud-prevention, dispute, or recovery needs. PostgreSQL and object-storage backups, Clerk records, OVH infrastructure logs, Vercel marketing logs, Resend email data, Mistral abuse-monitoring data, ElevenLabs logs, and Paddle records may follow provider-specific retention periods that are not controlled by Temlo. Backup and provider deletion timing is controlled by the relevant provider.

You can delete content using the controls provided in the Services. Account deletion is intended to permanently remove your owned application data, transcripts, notes, voice notes, sharing relationships, assistant state, and usage records after the deletion workflow completes. Some provider, legal, security, billing, backup, or reconciliation records may remain as described above.

8. Your choices and data-protection rights

Depending on your location and the applicable law, you may have the right to:

  • request access to personal data and information about how it is processed;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests, including direct marketing if introduced;
  • receive personal data you provided in a structured, commonly used, machine-readable format and ask us to transmit it where the right applies;
  • withdraw consent where processing is based on consent; and
  • complain to a competent data-protection supervisory authority, including the authority competent for your residence or our establishment.

To exercise a right, email hello@temlo.app with the account email, the request, and enough information for us to verify the account. We may ask for reasonable identity verification and may need to contact a provider to complete a request. We will respond within the period required by applicable law and explain any lawful reason we cannot fulfill a request in full.

Account deletion is available through the account settings where enabled. Settings also provides an authenticated Export your data flow that iterates the documented bounded export phases and cursors and assembles a machine-readable JSON file covering the profile, dictations, notes, collaboration, billing, and account records returned for the account. The client stops safely at 5,000 pages, 100,000 records, or 20 MB, and rejects malformed or repeated continuation data. Web and Tauri surfaces download the JSON file; iOS and Android use the platform share sheet for exports up to 8 MB. A larger native export must be downloaded from the web surface. A cancellation before delivery, failure, or over-limit condition does not share an export. Email remains available if you need help with an access request or a copy of information, and we will handle the request under applicable law.

Your rights may be limited where retaining or processing information is required by law, needed to establish or defend a claim, necessary to prevent fraud or abuse, or technically required to protect another person’s rights. You may also need to exercise a right directly with a provider when that provider acts as an independent controller, such as Paddle’s payment processing or a provider’s own account and security records.

9. Security

We use reasonable technical and organizational measures appropriate to the Services, including authenticated access, server-side provider credentials, bounded request and storage handling, rate and abuse controls, access checks for notes and shares, deletion workflows, and privacy-conscious structured logging. No internet transmission, device, provider, or storage system is completely secure, and we cannot guarantee absolute security.

If you believe there is a security or privacy incident, contact hello@temlo.app promptly. Do not include secrets, passwords, API keys, or unnecessary sensitive content in your first message.

10. Automated processing and profiling

Temlo uses speech recognition and generative AI to produce transcripts, cleaned text, and proposed note operations. These systems can be inaccurate and are intended to assist you. Temlo does not use these outputs to make decisions about you that produce legal or similarly significant effects, and we do not intentionally perform voice-biometric identification, emotion recognition, or behavioral profiling for those purposes.

You are responsible for reviewing output before relying on it, publishing it, sending it to another person, or using it in a consequential decision.

11. Children

The Services are not directed to children under 13, and we do not knowingly offer accounts to children under 13. If you believe a child has provided personal data to Temlo, contact hello@temlo.app. If we learn that we collected such data without an appropriate legal basis, we will take reasonable steps to delete it.

12. Changes to this Policy

We may update this Policy when the Services, providers, law, or our data practices change. Each published version will show its version number and last-updated date. For a material change, we will provide notice through the Services, by email, or by posting a prominent notice where required. If a change requires consent or renewed acceptance, we will request it.

13. Contact

For privacy requests, data-protection questions, or complaints about Temlo’s processing, contact:

Temlo — hello@temlo.app

Document history

  • Version 0.2 — August 12, 2026. Clarified essential browser, native-device, provider, and operational storage, documented the absence of non-essential marketing tracking and the future consent gate, and removed external Google Fonts requests from the public pages.
  • Draft review — August 23, 2026. Aligned the displayed draft identifier with the backend Terms version, separated Privacy from Terms acceptance, added RevenueCat and provider-verification caveats, and described the bounded Settings JSON export with its web-download and native-share limits.
  • Version 0.1 — August 12, 2026. Initial implementation-based draft covering account data, user content, audio and transcription, Smart Cleanup, the AI note assistant, Paddle billing, providers, international transfers, retention, deletion, rights, and security.
Temlo

Natural speech in. Ready-to-use text out.

Open appSupportTermsPrivacyContact© 2026 Temlo