Privacy Policy
This policy explains what data FastSpeech processes, why, who else is involved and what rights you have. Controller within the meaning of the GDPR:
Company / operator name
Street and number, postcode, city, country
E-mail: contact e-mail
Data protection officer, only required in specific cases (e.g. 20+ people regularly processing personal data). Otherwise delete this line.
1. Account data
- When you register directly we store your e-mail address and your password, the latter only as a salted scrypt hash, never in plain text.
- With third-party sign-in (Google, Microsoft, Discord) we receive your e-mail address and an account identifier from that provider, never your password there.
- We also store your plan, your subscription status and, if you connected Discord, your Discord ID and username.
- For every sign-in we store the device and browser description your program sends, the IP address it came from, and the times of sign-in and last use. The IP address is looked up once to derive a rough area (city and country); only that area is shown to you, never the address itself. You can see this list under Devices in your account and sign out any device you do not recognise. Purpose: letting you spot and stop unauthorised access. Legal basis: legitimate interest in the security of your account, Art. 6 (1)(f) GDPR.
- If you upload a profile picture, we store it with your account so it appears in the app and on the website. You can remove it at any time.
- Purpose: providing your account. Legal basis: performance of a contract, Art. 6 (1)(b) GDPR.
2. Dictation: audio and text
- When you dictate, the audio is sent to our servers, forwarded to our transcription provider, and the finished text is returned to your device.
- We do not store your audio. It is held in memory only for as long as the request takes and is not written to any disk on our side.
- The transcribed text is passed to an AI provider for formatting (punctuation, filler words, your dictionary) and then returned. We do not keep the content of your dictations.
- Your dictations are not used to train AI models, neither by us nor, under our agreements, by our providers.
- Your dictation history is stored locally on your device and is never uploaded to us. You can delete it there at any time, and you can switch history off entirely.
- Legal basis: performance of a contract, Art. 6 (1)(b) GDPR.
3. Dictionary, snippets and usage
- Your personal dictionary, text snippets, scratchpad and app settings are stored with your account so they follow you from one device to the next. Settings that describe the machine itself, your microphone, autostart, keyboard shortcuts, stay on that machine, as does your dictation history.
- We count the number of words you dictate per week to enforce plan limits. Only the count is stored, never the content.
- Legal basis: performance of a contract, Art. 6 (1)(b) GDPR.
4. Payments
Payments are processed by Stripe (Stripe Payments Europe Ltd., Ireland). Your card details go directly to Stripe and never reach our servers. We store only your Stripe customer reference, your plan, your subscription status and the current period end. Legal bases: performance of a contract, Art. 6 (1)(b), and our legitimate interest in secure payment handling, Art. 6 (1)(f) GDPR.
5. Server logs
Our servers process technical data needed to deliver the Service and keep it secure, such as IP address, time of request and error messages. This data is not used to build profiles and is kept only briefly. Legal basis: legitimate interest in a secure, working service, Art. 6 (1)(f) GDPR.
6. Cookies and local storage
- One session cookie (
fs_session) keeps you signed in on the website. It is technically necessary, without it, signing in would not work. - Your theme preference (light or dark) is kept in your browser’s local storage.
- No advertising cookies, no tracking, no analytics services. That is why you see no cookie banner.
7. Who processes data on our behalf
We work with carefully selected providers who process data only on our instructions, under a data processing agreement:
| Provider | What for | Where |
|---|---|---|
| Cloud hosting provider | Running our servers and storing account data | Servers in the EU (Netherlands); provider based in the USA |
| Groq | Speech recognition (turning audio into text) | USA |
| Anthropic | Formatting the transcribed text | USA |
| OpenAI | Formatting the transcribed text (alternative) | USA |
| Stripe | Payments and subscription management | Ireland / USA |
| Discord | Optional sign-in and member role | USA |
| Google, Microsoft | Optional sign-in, if you use it | USA |
| ipwho.is | Turning the IP address of a sign-in into a rough area (city and country), so you can recognise your own devices in the list | EU |
Where a provider is outside the EU, the transfer is based on the European Commission’s standard contractual clauses or an adequacy decision (Art. 44 ff. GDPR).
8. How long we keep data
- Account data: for as long as your account exists.
- Audio: not stored at all.
- Dictionary and snippets: until you delete them or close your account.
- Weekly word counts: for the current and previous billing periods.
- Sign-in records (device, IP address, times): until that sign-in expires after 30 days, or immediately when you sign the device out yourself.
- Profile picture: until you remove it or close your account.
- Invoicing data: for the statutory retention periods (up to 10 years under German tax and commercial law).
When you delete your account, the associated data is deleted or anonymised, except where we are legally required to keep it.
9. Your rights
Under the GDPR you have the right to access your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict processing (Art. 18), to data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw consent at any time with effect for the future.
To exercise your rights, write to contact e-mail. You also have the right to complain to a supervisory authority, for example the data protection authority of your federal state.
10. Data security
All connections between the apps, the website and our servers are encrypted (TLS). Passwords are stored only as salted scrypt hashes. Access to production systems is limited to the people who need it.
11. Changes to this policy
We update this policy when our processing changes. Material changes are announced in the app or by e-mail before they take effect.