1. Introduction
Welcome to Conversophy. We are committed to protecting your personal data and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App").
Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the App.
2. Data Controller
The data controller responsible for your personal data is:
Thrive-in Collaboration SRL (operating Conversophy)
Email: privacy@conversophy.com
Address: 27-33 Nerva Traian Street, office 6, entrance B, Floor 1, Bucharest, Sector 3, 031044, Romania
Register of Commerce No. J2018002517235
Data Protection Officer (DPO): For GDPR-related requests, complaints, or to exercise your rights, you may contact our Data Protection Officer at privacy@conversophy.com. We will respond within 30 days as required by GDPR.
General inquiries: connect@conversophy.com
For any questions about this policy or your personal data, please contact us using the information above.
3. Information We Collect
3.1 Personal Data You Provide
We collect information that you voluntarily provide when using the App:
- Account Information: Email address, name, and password (if you create an account)
- Security and account protection: If you enable two-factor authentication, we store hashed recovery codes and rely on AWS Cognito to manage your authenticator app setup. We do not store your TOTP secret or recovery codes in plain text. We may log sign-in attempts (success/failure, timestamp) for security purposes, retained for up to 90 days.
- Audio Recordings: Voice recordings you choose to record or upload through the App
- Transcripts: Text transcriptions of your audio recordings
- Session Metadata: Session titles, participant names, timestamps, duration, and tags
- Analysis Configuration: Speaker roles, conversation focus, interaction tags, and analysis preferences
- Communication Data: If you contact us, we may keep a record of that correspondence
3.2 Automatically Collected Data
When you use the App, we automatically collect:
- Device Information: Device type, operating system version, app version
- Usage Data: Features accessed, session processing status, error logs, timestamped activity records (e.g. session creation, analysis generation, app access events)
- Audio Metadata: Sample rate, file format, recording quality settings
3.3 Cookies, Trackers, and Analytics
Conversophy does not use cookies (first-party or third-party). We do not load any third-party analytics, advertising, retargeting, or tracking scripts. No data about your browsing behaviour is shared with advertisers, analytics platforms, or data brokers.
Authentication tokens and user preferences are stored in your browser's local storage (localStorage). This data remains on your device and is never transmitted to third parties. Because we set no cookies, no cookie consent banner is required under the ePrivacy Directive.
If you submit the waitlist form on our public /beta page, the email address and optional first name you enter are sent to our email provider, MailerLite, to manage the private-beta waitlist (see §6.5). That form loads no MailerLite script and sets no cookies or trackers on conversophy.com — only the details you type are transmitted when you submit — so the no-cookies commitment above continues to hold.
3.4 Data We Do NOT Collect
We do NOT collect:
- Location data
- Contacts or address book information
- Photos or camera access (except for audio recording)
- Social media information
- Financial information or payment details (currently)
- Cookie-based identifiers, advertising IDs, or cross-site tracking data
4. How We Use Your Information
We only process your personal data when we have a valid legal basis. Under GDPR Article 6, we rely on the following legal bases:
4.1 Core Functionality (Legal Basis: Contract Performance - GDPR Art. 6(1)(b))
When you use our app, we need to process certain data to provide the service you've requested:
- Audio Recordings: Store your recordings in your library
- Transcripts: Convert audio to text (with your consent for AssemblyAI processing)
- Speaker Diarization: Identify different speakers (required for core features)
- Session Metadata: Manage titles, dates, participants, and tags
- Account Data: Enable authentication and session management
- Transcript Editing: Allow you to review and correct transcriptions
- Audio Playback: Enable review of your recordings
We may offer LLM-assisted suggestions for analysis configuration; these are optional and you can accept, modify, or ignore them.
4.2 With Your Explicit Consent (Legal Basis: Consent - GDPR Art. 6(1)(a))
We only process the following data when you explicitly opt-in:
- AssemblyAI Transcription: Sending audio to AssemblyAI for speech-to-text (required, but you can provide written transcripts instead)
- AI Analysis (Amazon Bedrock / Anthropic Claude): Sending transcripts to Amazon Bedrock for AI-powered conversation insights (optional, consent-gated)
- Service Communications: Sending you updates and notifications (you can opt-out anytime)
Important: You must provide explicit consent before we share any data with third-party processors. Consent can be withdrawn at any time through Settings > Privacy & Data > Third-Party Services.
Processing stages (with AI analysis consent): Depending on your settings, analysis may include: transcript structuring and chunking; expert-engine analysis; final report generation; narrative timeline; development plans; and trait-related insights where configured. Each stage uses only the data needed for that step.
4.3 Service Improvement (Legal Basis: Legitimate Interest - GDPR Art. 6(1)(f))
To improve app functionality and fix bugs:
- Analyse anonymised usage patterns to improve features
- Collect error logs and crash reports (device info only, no personal data)
- Monitor app performance and stability
- Improve AI model accuracy (only with your consent)
You can object to this processing at any time in Settings.
4.4 Legal Compliance (Legal Basis: Legal Obligation - GDPR Art. 6(1)(c))
To comply with legal requirements:
- Maintain audit logs of consent acceptance and withdrawal (3 years)
- Respond to valid legal requests from authorities
- Prevent fraud and enforce our Terms of Service
- Comply with data protection regulations
5. Data Retention
We retain your personal data only as long as necessary:
| Data Type | Retention Period | Reason |
|---|---|---|
| Audio Recordings | User-configurable (default: 90 days) | You control retention via Settings |
| Transcripts | Same as audio | Tied to audio recording lifecycle |
| Analysis Reports | Same as audio | Derived from transcripts |
| Account Data | Until account deletion | Required for app functionality |
| 2FA status | Until account deletion | AWS Cognito user attribute |
| Recovery code hashes | Until you disable 2FA, regenerate codes, or delete account | One-way hashes to verify recovery codes |
| Recovery attempt logs | Automatically purged after 1 hour | Rate-limiting to prevent brute-force attacks |
| Consent Logs | 3 years after withdrawal | Legal compliance requirement |
| Error Logs | 265 days (prod), archived for 10 years | Service improvement |
| Usage Activity Logs | Same as your data retention setting (default: 90 days) | Service improvement and account usage visibility |
You can configure your data retention period in Settings > Privacy & Data > Data Retention.
Sessions older than your retention period are automatically deleted by our systems. You may export your data at any time via Settings > Account > Export My Data or the in-app Privacy Centre before the retention period ends.
6. Third-Party Data Processing
We never sell your personal data. We do not sell, rent, lease, or trade your conversations, transcripts, analysis, or any other personal data, and we never share it with third parties for their own commercial purposes. The services below are processors that act solely on our instructions under data-processing agreements.
We use the following third-party services to process your data:
6.1 AssemblyAI (Transcription & Speaker Diarization)
- Legal Basis: Consent (GDPR Art. 6(1)(a))
- Purpose: Convert audio to text transcripts and identify different speakers
- Data Shared: Audio recordings, duration, language setting
- Location: European Union (Dublin, Ireland) - GDPR-compliant EU data residency
- Data Processing Agreement: Yes - Standard Contractual Clauses in place
- Their Privacy Policy: https://www.assemblyai.com/legal/privacy-policy
- Retention: Automatically deleted after processing (typically within hours)
- Your Control: Required for audio upload transcription, but you can provide written transcripts instead
Consent is required before uploading audio. This consent can be managed in Settings > Privacy & Data > Third-Party Services.
6.2 Amazon Bedrock (AI Analysis)
- Legal Basis: Consent (GDPR Art. 6(1)(a))
- Purpose: AI-powered conversation insights and analysis
- Data Shared: Transcripts (text only, no audio), speaker roles, analysis configuration
- Location: European Union (eu-west-1, Ireland) — all processing stays within the EU
- AI Model Provider: Anthropic Claude, accessed through Amazon Bedrock. Under Bedrock's architecture, Anthropic does not receive or retain personal data and is not a GDPR subprocessor.
- Data Retention: Zero — Amazon Bedrock does not retain input or output data. Your data is not used for model training.
- Data Processing Agreement: Covered under the existing AWS DPA
- Your Control: Completely optional — analysis features work only when consent is granted
Consent is opt-in and can be withdrawn at any time. Withdrawing consent prevents future processing but cannot "unprocess" existing analyzed sessions.
6.3 Amazon Web Services (AWS)
We use Amazon Web Services for application hosting and infrastructure:
- Legal Basis: Legitimate interest (GDPR Art. 6(1)(f)) - required for the application to function
- Purpose: Application hosting, data storage, and infrastructure services
- Data Shared: Session metadata, audio files, transcripts, analysis data
- Location: European Union (eu-west-1, Ireland) - GDPR-compliant EU data residency
- Data Processing Agreement: Yes - AWS GDPR Data Processing Addendum
- Their Privacy Policy: https://aws.amazon.com/privacy/
- Retention: Per your data retention settings
- Your Control: Required infrastructure - cannot be disabled
6.4 Neon PostgreSQL Database
We use Neon (https://neon.tech), a serverless PostgreSQL platform, for secure data storage:
- Legal Basis: Legitimate interest (GDPR Art. 6(1)(f)) - required for the application to function
- Purpose: Secure database storage for sessions, transcripts, and analysis data
- Data Shared: All session data, transcripts, analysis results, user settings
- Location: European Union (EU data residency) - GDPR-compliant EU data residency
- Data Processing Agreement: Yes - Neon GDPR Data Processing Agreement
- Their Privacy Policy: https://neon.tech/privacy-policy
- Encryption at Rest: Your data is encrypted at rest using AES-256.
- Retention: Per your data retention settings
- Your Control: Required infrastructure - cannot be disabled
6.5 MailerLite (Private-Beta Waitlist)
We use MailerLite (UAB MailerLite), an EU-based email service provider, to run our private-beta waitlist and send the related confirmation and update emails. This applies only when you submit the waitlist form on our website; MailerLite is never used to process data inside the app.
- Legal Basis: Consent (GDPR Art. 6(1)(a)) — you opt in by submitting the form and confirming through double opt-in
- Purpose: Manage waitlist sign-ups, confirm your email address (double opt-in), and notify you when private-beta access opens
- Data Shared: The email address and optional first name you enter, plus sign-up and confirmation timestamps
- International Transfers: Where data is processed outside the EEA, it is safeguarded by Standard Contractual Clauses and/or the EU-US Data Privacy Framework under MailerLite's Data Processing Agreement
- Data Processing Agreement: Yes — MailerLite's Data Processing Agreement applies
- Their Privacy Policy: https://www.mailerlite.com/legal/privacy-policy
- No Cookies or Trackers: The waitlist form loads no MailerLite script and sets no cookies on conversophy.com — only the details you type are sent to MailerLite when you submit
- Your Control: Every MailerLite email includes an unsubscribe link, and you can ask us to remove you at any time via privacy@conversophy.com
7. Your Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), you have the following rights:
7.1 Right to Access (Art. 15)
You can request a copy of all personal data we hold about you. Use the Export My Data feature in Settings to download your data.
7.2 Right to Rectification (Art. 16)
You can correct inaccurate or incomplete data:
- Edit session titles, participant names, and timestamps
- Edit transcripts and speaker names
- Update your account information
7.3 Right to Erasure (Art. 17)
You can request deletion of your data:
- Individual Sessions: Delete from the Library screen
- All Data: Use Delete Account in Settings. Deletion is permanent and takes effect when you confirm; we recommend exporting your data first via Export My Data.
7.4 Right to Data Portability (Art. 20)
You can export your data in machine-readable formats:
- JSON (structured data)
- TXT (plain text transcripts)
- WAV (audio files)
- MD (analysis reports)
7.5 Right to Object (Art. 21)
You can object to certain processing:
- Opt-out of third-party AI processing (AssemblyAI, AI Analysis)
- Disable analytics and diagnostics
- Choose minimal data collection
7.6 Right to Restrict Processing (Art. 18)
You can request we limit how we use your data while resolving disputes.
7.7 Right to Withdraw Consent (Art. 7(3))
You can withdraw consent anytime via Settings > Privacy & Data > Manage Consents. This does not affect lawfulness of processing before withdrawal.
7.8 Right to Lodge Complaint with AI Authorities
You also have the right to lodge a complaint about AI-related matters with your national market surveillance authority under the EU AI Act (Regulation 2024/1689, Art. 85), in addition to your right to complain to a Data Protection Authority under GDPR.
To exercise any of these rights, use the in-app Privacy Centre or contact privacy@conversophy.com.
8. Data Security
We implement appropriate technical and organisational measures to protect your data:
8.1 Encryption
- In Transit: All data transmitted using HTTPS/TLS encryption
- At Rest: Sensitive data (auth tokens, consent logs) stored in encrypted device storage (iOS Keychain, Android KeyStore)
- Audio Files: Locally cached audio files are encrypted (AES-256)
8.2 Access Controls
- Authentication required for all app features
- Role-based access controls on backend systems
- Regular security audits and penetration testing
8.3 Data Breach Response
In the event of a data breach affecting your personal data:
- We will notify you within 72 hours (GDPR requirement)
- You will receive an in-app notification and email
- We will explain what data was affected and what we're doing
- We will provide guidance on protective steps you can take
8.4 Limitations
No security system is perfect. While we strive to protect your data, we cannot guarantee absolute security. You use the App at your own risk.
8.5 Security and Two-Factor Authentication
If you enable two-factor authentication (2FA), we process the following data:
| Data | Where stored | Purpose | Retention |
|---|---|---|---|
| 2FA status (enabled/disabled) | AWS Cognito (user attribute) | To know whether to require a second factor at sign-in | Until account deletion |
| TOTP secret | AWS Cognito only (we never see or store it) | Enables authenticator app codes | Managed by AWS; deleted when you disable 2FA |
| Recovery code hashes | Our database (mfa_recovery_codes table) | One-way hashes to verify recovery codes; we cannot recover your original codes | Until you disable 2FA, regenerate codes, or delete your account |
| Recovery attempt logs | Our database (mfa_recovery_attempts table) | Rate-limiting to prevent brute-force attacks on recovery codes | Automatically purged after 1 hour |
| Security event logs (if implemented) | Logging system | Failed/successful sign-in attempts, timestamps | 90 days (align with data retention setting) |
Lawful basis: We process this data on the basis of our legitimate interests (Article 6(1)(f) GDPR) in protecting your account and the sensitive conversation data you store. Two-factor authentication is optional; you choose whether to enable it.
Your rights: You can disable 2FA at any time from Settings > Security. This will delete your recovery code hashes from our systems. The TOTP secret is managed by AWS Cognito and is removed when you disable 2FA.
9. Your Responsibilities
9.1 Recording Consent
YOU are solely responsible for obtaining consent from all participants before recording conversations. Recording laws vary by jurisdiction:
- One-Party Consent: Only one party (you) must consent
- Two-Party/All-Party Consent: ALL parties must consent before recording
Check your local laws before recording. Illegal recording may result in criminal or civil penalties.
9.2 Account Security
- Keep your password secure and confidential
- Log out from shared devices
- Notify us immediately of unauthorized access
10. Children's Privacy
10.1 Account Holders
The App is not intended for use by children under 16 as account holders. We do not knowingly create accounts for children. If you believe we have inadvertently created an account for a child, please contact us immediately and we will delete the account and associated data.
10.2 Minors as Speakers in Recorded Conversations
Conversations you choose to upload or record may include speakers under 18 (e.g. your own child, a family member, or a student). Because processing personal data of minors requires special protection under GDPR Art. 8 and is subject to heightened safeguards under EU AI Act Art. 5(1)(b), before we analyse any conversation you have flagged as including a speaker under 18, we require you to attest through an in-app modal that:
- You are the parent or legal guardian of every under-18 speaker in the conversation (or have obtained that parent/guardian's permission).
- You consent, on their behalf, to Conversophy processing the conversation for communication-analysis purposes.
- Where age-appropriate and practical, you have informed the minor speaker(s) that the conversation will be analysed.
Your attestation is recorded in a consent audit log (including the session identifier and the timestamp of your attestation). This record is retained for 3 years after withdrawal, in line with the Consent Logs row in §5.
We do not independently verify the self-reported age bands or the attestation — the attestation is an adult account holder's formal declaration. You remain responsible for ensuring you have the authority you attest to.
If you believe a conversation involving a minor has been analysed without proper parental/guardian authority, please contact us immediately at privacy@conversophy.com and we will delete the conversation and associated analysis.
11. International Data Transfers & Hosting Location
Core processing for the App is hosted in the European Union (eu-west-1, Ireland). This includes Amazon Web Services infrastructure, Amazon Bedrock (AI analysis), and Neon PostgreSQL database storage. AssemblyAI transcription is processed via the EU endpoint (Dublin, Ireland).
Your data therefore physically remains in the EU for these services. Some providers (AWS, AssemblyAI) are headquartered in the United States; as is common in the industry, U.S. laws such as the CLOUD Act may create residual legal access risks even when data is stored in the EU. We rely on EU hosting, contracts, and safeguards to mitigate these risks.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be notified as follows:
- Minor Changes: Updated "Last Updated" date, in-app banner
- Material Changes: In-app notification requiring your explicit re-acceptance before you can continue using the App. Email notification may also be sent.
When material changes are made, you will be presented with the updated terms and asked to explicitly accept them. If you decline, the process described in the Terms and Conditions (Section 9.2) applies: a 30-day grace period for data export, followed by account deactivation. Your data will not be deleted without your explicit request. You may accept the updated terms at any time to restore full access.
You can view the policy version history in Settings > Privacy & Data > Privacy Policy > Version History.
13. Contact & Complaints
13.1 Contact Us
For privacy questions or to exercise your rights:
- Privacy / DPO: privacy@conversophy.com (for GDPR requests and complaints)
- General inquiries: connect@conversophy.com
- In-App: Settings > Privacy & Data > Contact Support
- Response Time: Within 30 days (GDPR requirement)
13.2 How We Handle Requests and Complaints
We will respond to any request to exercise your rights (access, rectification, erasure, portability, objection, restriction) or any complaint about our processing of your personal data within 30 days. If we need more time, we will inform you and explain why. You can submit requests or complaints by email to privacy@conversophy.com or via the in-app Privacy Centre.
13.3 Supervisory Authority
If you are in the EEA and believe we have not addressed your concerns, you have the right to lodge a complaint with your local data protection authority.
Our lead supervisory authority is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP): https://www.dataprotection.ro/.
- Find Your Authority: https://edpb.europa.eu/about-edpb/board/members_en
14. Legal Basis Summary
| Processing Activity | Legal Basis |
|---|---|
| Audio transcription | Your consent |
| Speaker diarization | Your consent |
| AI analysis | Your consent |
| Session storage | Contract performance |
| Account management | Contract performance |
| Error logging | Legitimate interest |
| Security monitoring | Legitimate interest |
| Usage activity tracking | Legitimate interest |
| Consent audit logs | Legal obligation |
15. Definitions
- Personal Data: Any information relating to an identified or identifiable person
- Processing: Any operation performed on personal data (collection, storage, use, deletion)
- Data Controller: The entity that determines the purposes and means of processing
- Data Processor: The entity that processes data on behalf of the controller
- Consent: Freely given, specific, informed, and unambiguous indication of your wishes
16. Additional Information
16.1 Automated Decision-Making
We do NOT use your data for: Automated decision-making that produces legal effects; Profiling for marketing, advertising, or credit scoring purposes; AI model training — Amazon Bedrock guarantees zero data retention and no training on your data. We also never sell, rent, or trade your personal data, or share it with any third party for their own commercial purposes. The system analyses communication patterns and dynamics to provide insights — this is the core service you consented to and does not produce decisions with legal effects.
16.2 Data Minimization
We are committed to collecting only the data necessary for the App's functionality. You can manage third-party data sharing (e.g. transcription and AI analysis) in Settings > Privacy & Data > Third-Party Services. Files stored only on your device (before upload) can be viewed and deleted in Settings > Privacy & Data > Manage Local Files.
16.3 Transparency
We believe in radical transparency. You can view:
- What data we store (via Data Export)
- When it will be deleted (retention settings)
- Who processes it (third-party disclosure)
- Your consent history (Manage Consents)
We document known limitations of AI analysis in our AI Transparency notice.
This privacy policy is informational and does not constitute legal advice. Consult an attorney for legal questions about recording consent or data protection.
© 2026 Conversophy. All rights reserved.
Brand Notice. Conversophy™ is a trademark of Thrive-in Collaboration SRL.