Privacy Policy — MeetingVoice
Developed and operated by RMTracker S.L.
1. Responsible for the treatment
- Responsible: RMTracker S.L. ("RMTracker)
- Tax ID: B88803085
- Activity (NACE): 6210 - Computer programming activities
- Registration data and address: those that are in Terms and Conditions of RMTracker Solutions.
- Privacy email:
legal@rmtrackersolutions.com
2. To whom does it apply
This policy describes how we treat RMTracker personal data in the application MeetingVoice for Android, iOS, macOS and Windows, and for the associated backup services.
What does it do? MeetingVoice, in terms of data
MeetingVoice records meetings using the device's microphone and generates transcriptions with identification of who is speaking. Three features determine everything else:
- The processing takes place on the device. Transcription, speaker separation, and translation are performed locally using downloaded models at the user's request. The audio and transcripts are not sent to our servers.
- Biometric data is being processed. To identify a speaker, a mathematical representation of their voice is calculated.embedding). When it is used to unequivocally identify a person, it is a biometric data and belongs to the special categories of Article 9 of the GDPR.
- It is recorded on third parties. In a meeting, people are present who have not installed the application. Section 8 explains the distribution of responsibilities.
MeetingVoice does not record phone calls nor does it intervene in them.
4. Data processed, purpose and legal basis
4.1 On the device
They are stored in the application's private area. Sensitive content – audio, transcripts, translations, names of people and voice profiles – is stored encrypted., with the key protected by the operating system's secure storage. Some technical metadata (timestamps, duration, detected language or confidence indices) are stored unencrypted because they do not reveal the content of the conversation on their own. Automatic backup of the operating system is disabled, so nothing of this leaves the device through that method.
| Data | Purpose | Legal basis |
|---|---|---|
| Audio recordings of meetings | Providing the service: transcribing and enabling playback | Execution of the contract (art. 6.1.b) |
| Transcriptions, turn-taking and markers | Providing the service | Execution of the contract (art. 6.1.b) |
| Voice embeddings and names of people | Identifying who is speaking in each intervention | Explicit consent (art. 9.2.a) |
| Consent and information recording per meeting | Demonstrating compliance | Legal obligation (art. 6.1.c) and art. 5.2 |
| Device capability and model performance | Choosing the appropriate transcription model | Legitimate interest (art. 6.1.f): that the app works on the device |
| Application preferences | Remembering settings | Contract execution (art. 6.1.b) |
4.2 On our servers
| Data | Purpose | Legal basis |
|---|---|---|
| Account: identifier and email address | Authenticate and link the subscription | Contract execution (art. 6.1.b) |
| Subscription rights and plan status | Grant access to payment features | Contract execution (art. 6.1.b) |
| Synchronized voice profiles (optional): embeddings, encrypted name and profile metadata | Reuse profiles on other user devices | Explicit consent (art. 9.2.a), revocable |
| Linked devices: a random identifier generated by the application, the operating system, a label with the device model and the linking and last activity dates | Limit how many devices use the same subscription simultaneously | Contract execution (art. 6.1.b) |
Audio and transcripts are never uploaded. Voice profile synchronization is disabled by default: only works if explicitly enabled, and consent is recorded with your version.
4.3 About the encryption of synchronized profiles — accurately
Voice profiles are encrypted on the device before uploading. However, the key is stored in our own infrastructure, associated with the account, so that they can be decrypted on a new device. Not end-to-end encryption: technically we can access those data. We say this explicitly because stating otherwise would be inaccurate. Access is restricted to the necessary operations to provide the service and comply with legal obligations.
4.4 Diagnostics
The application logs errors in order to fix them. By design, a diagnostic event contains only the operation identifier and the type of error: never audio, transcriptions, names, emails, file paths or credentials. MeetingVoice does not incorporate any analytics, advertising or tracking SDK, and does not
5. Device permissions
- Microphone: essential for recording. Without it, the application cannot perform its function.
- Notifications and foreground service: to display the permanent notification while recording and prevent the system from interrupting the recording.
- Screen recording (only macOS): the only way the system offers to capture audio from other applications in desktop subtitles. The screen image is not captured or saved.
- Internet: download the models requested by the user, authenticate the account and validate the subscription.
MeetingVoice no requests location, contacts, camera, calendar or phone status.
6. Recipients and data controllers
We do not sell personal data or provide them for advertising purposes. Intervene:
- Supabase — authentication, database and storage of the models. Data controller. Hosting region: Ireland (EU).
- Apple and Google — processing subscriptions and validation of receipts. Act as independent controllers in accordance with their own policies. We do not receive payment card data: only a signed receipt.
- Render — hosting of the corporate website, including this page, in the Frankfurt (EU) region.
- Authorities — solely when required by a regulation or resolution.
The data processing agreements of Supabase and Render in accordance with Article 28 of the GDPR have been subscribed to and archived by RMTracker S.L.
7. International Transfers
If any processor transfers data outside the European Economic Area, the transfer is based on a decision of adequacy or standard contractual clauses, with the supplementary measures that are necessary.
The data from your account and voice profiles do not leave the European Union: the database and storage are hosted in Ireland. Apple and Google process purchase data in accordance with their own policies and transfer mechanisms, which they publish. The corporate website is hosted in the Frankfurt region, within the European Union.
8. Recording other people: who is responsible for what
This section is important and it is advisable to read it completely.
When you record a meeting, you decide who to record, for what purpose and for how long. In this relationship, you act as the data controller towards the other participants, and RMTracker provide them with the tool.
Consequently, you commit to:
- Informing all participants before starting to record and obtaining their consent when required by applicable law.
- Obtaining explicit consent before creating a voice profile of a person: this is biometric data.
- Responding to requests for access or deletion from the participants. The application allows you to delete a person, their voice profiles and any meeting.
- Comply with the rules of your jurisdiction and your company regarding recording conversations, which in some territories require the consent of all parties involved.
To help you, the application displays a permanent notification while recording and saving a record of the notice and the legal basis of each meeting.
If you use MeetingVoice on behalf of an organization, it will be that organization who assumes the responsibility.
9. Retention periods
- On the device: the content remains until you delete it. We do not apply automatic deletion: they are your data and you decide.
- Synchronized voice profiles: as long as consent is valid. When revoked or account deleted, they are removed from the server.
- Linked devices: as long as the period is active. The recording of an inactive period is retained for one year, because it maintains the waiting period between changes and provides evidence of which devices had access; after that period, it is deleted.
- Account and subscription rights: as long as the account is active and then during legal prescription periods.
- Tax documentation for subscriptions: is retained for the periods imposed by Spanish regulations: four years according to the General Tax Law and six years for books and commercial documentation, according to the Commercial Code. These rows are retained even if the account is deleted, as it has already been disconnected from the person.
10. Their rights
They may exercise the rights of access, rectification, deletion, limitation, portability and withdrawal, as well as withdraw any consent granted at any time, without affecting the validity of previous processing.
- From the application: delete meetings, people and voice profiles; disable synchronization; delete the account.
- In writing:
legal@rmtrackersolutions.com - Deletion form: request for data deletion
We will respond within one month, extendable by two more months in complex requests. If you believe that we have not handled your request correctly, you can file a complaint with the Agencia Española de Protección de Datos (www.aepd.es).
11. Security
- Encryption of content at rest on the device, with the key protected by the system operating system's secure storage.
- Automatic system backup disabled, to prevent recordings from ending up in the manufacturer's cloud.
- All traffic via HTTPS; clear traffic prohibited by configuration.
- Server-side purchase validation: the client never decides which rights are granted to it.
- Account isolation in synchronized data.
No system is infallible. If a breach poses a high risk, we will notify you and the supervisory authority within legal deadlines.
12. Minors
MeetingVoice is a professional tool and is not intended for minors. No specific contractual minimum age is established and we do not consciously collect data from minors. Anyone who uses the application to record a minor must have the legitimacy and authorizations required by applicable regulations.
13. Changes in this policy
Will be published at this same address with their version number and effective date. If the change is substantial, we will notify you through an additional channel. The version history is available for your review.
legal@rmtrackersolutions.com.