Privacy Policy

This policy explains what data FastSpeech processes, why, who else is involved and what rights you have. Controller within the meaning of the GDPR:

1. Account data

2. Dictation: audio and text

3. Dictionary, snippets and usage

4. Payments

Payments are processed by Stripe (Stripe Payments Europe Ltd., Ireland). Your card details go directly to Stripe and never reach our servers. We store only your Stripe customer reference, your plan, your subscription status and the current period end. Legal bases: performance of a contract, Art. 6 (1)(b), and our legitimate interest in secure payment handling, Art. 6 (1)(f) GDPR.

5. Server logs

Our servers process technical data needed to deliver the Service and keep it secure, such as IP address, time of request and error messages. This data is not used to build profiles and is kept only briefly. Legal basis: legitimate interest in a secure, working service, Art. 6 (1)(f) GDPR.

6. Cookies and local storage

7. Who processes data on our behalf

We work with carefully selected providers who process data only on our instructions, under a data processing agreement:

ProviderWhat forWhere
Cloud hosting providerRunning our servers and storing account dataServers in the EU (Netherlands); provider based in the USA
GroqSpeech recognition (turning audio into text)USA
AnthropicFormatting the transcribed textUSA
OpenAIFormatting the transcribed text (alternative)USA
StripePayments and subscription managementIreland / USA
DiscordOptional sign-in and member roleUSA
Google, MicrosoftOptional sign-in, if you use itUSA
ipwho.isTurning the IP address of a sign-in into a rough area (city and country), so you can recognise your own devices in the listEU

Where a provider is outside the EU, the transfer is based on the European Commission’s standard contractual clauses or an adequacy decision (Art. 44 ff. GDPR).

8. How long we keep data

When you delete your account, the associated data is deleted or anonymised, except where we are legally required to keep it.

9. Your rights

Under the GDPR you have the right to access your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict processing (Art. 18), to data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw consent at any time with effect for the future.

To exercise your rights, write to contact e-mail. You also have the right to complain to a supervisory authority, for example the data protection authority of your federal state.

10. Data security

All connections between the apps, the website and our servers are encrypted (TLS). Passwords are stored only as salted scrypt hashes. Access to production systems is limited to the people who need it.

11. Changes to this policy

We update this policy when our processing changes. Material changes are announced in the app or by e-mail before they take effect.