Privacy Policy
Dictaro is built so your voice never leaves the EU and our servers do not keep it. This page explains exactly what data we collect, why, and how long we keep it.
1. Who we are
The data controller for Dictaro is MEDIA.COM Slovakia s.r.o., a company registered in the Slovak Republic. Operations are run from Bratislava.
| Controller | MEDIA.COM Slovakia s.r.o. |
|---|---|
| Registration (IČO) | 35 880 791 |
| Country | Slovak Republic (EU member state) |
| Privacy contact | privacy@dictaro.eu |
| General support | support@dictaro.eu |
2. What data we collect
2.1 Account data
- Email address — used as your login and to send transactional notifications.
- Display name — optional, only what you provide.
- Password — stored as a salted hash, never in plain text. If you sign in with Google or Discord we receive only your email and provider-issued ID, not the password.
- Preferred language — used to localise emails and the dashboard.
2.2 Access requests
Dictaro is currently available by invitation only. When you request access on the website we collect your name and email so we can send you an invitation, plus your IP address and browser type to spot abuse of the form. A request that does not lead to an account is deleted 12 months after you last submitted it. Once you create an account, the request becomes part of your account record.
When you accept the invitation we also record the date and the version of these Terms and this Privacy Policy you agreed to.
2.3 Service usage data
- Transcription records — one record per request: when it was made, which API key made it, and how long the audio was. Used to enforce the Free plan limits and to answer questions about your usage.
- Client name — a label you assign to each API key so you can tell devices apart in the portal.
- IP address — stored with each transcription record to detect abuse, and removed after 30 days.
2.4 Audio you dictate
Our servers do not keep your audio. When you press the hotkey, the desktop app sends the recording over HTTPS to our Whisper server in Slovakia, the server transcribes it, returns the text, and discards the audio. The audio exists on the server only while the request is being processed; temporary buffers are removed when it completes. We keep no copies of your audio.
We do not keep your transcripts either, with one exception. When our filter detects that the speech model produced text out of silence or noise (a so-called hallucination), we keep the first 200 characters of that text with the request record for 30 days, so we can improve the filter. After 30 days the text is deleted.
If you add words to your Vocabulary, the app sends that list with each recording so the speech model spells those words correctly. We do not store the list on our side.
2.5 Data kept on your own computer
The desktop app keeps some data locally, in your Windows user profile. None of it is sent to us.
- Recent recordings — the audio of your last 20 dictations, so you can play them back from the history. Older ones are deleted automatically. You can turn this off in the app settings under Keep recordings for playback; turning it off deletes the stored recordings.
- History — the text of your last 20 dictations.
- Session log — a daily log with the text you dictated, used when you ask us for help with a problem. Logs older than 14 days are deleted automatically.
- Recovery copy — if a transcription fails, the recording is kept so you can try again. Recovery copies older than 14 days are deleted automatically.
When you send us diagnostics from the app, the export contains technical logs only, without your dictated text or window titles.
2.6 Error reports from the app
When the desktop app runs into an error, it sends us a short report: your computer name, the app version, the type of error and a short technical message. Reports never contain audio, dictated text or window titles. We use them to find and fix problems, and delete them after 90 days.
3. Where your data lives
Everything stays in the European Union.
| Speech-to-text | Slovakia — Whisper large-v3 on a self-hosted GPU server |
|---|---|
| Account & auth | Supabase (Frankfurt, Germany — EU region) |
| Edge / DDoS | Cloudflare (EU edge nodes; tunnel from origin, no public origin IP) |
| Email delivery | Mailcow self-hosted in EU |
4. Legal basis for processing (GDPR Art. 6)
- Contract performance — providing the service you signed up for: account, transcription API, dashboard, billing.
- Legitimate interest — security and abuse prevention (IP logs, rate limiting, hashed audit trail).
- Consent — only for optional product update emails. You can opt out at any time.
- Legal obligation — keeping invoices for the period required by Slovak tax law (10 years), once paid plans launch.
5. How long we keep things
| Audio recordings (our servers) | Not kept, discarded as soon as the transcription completes |
|---|---|
| Transcripts | Not kept, only the requesting app receives the text; detected hallucinations: first 200 characters for 30 days |
| IP addresses | 30 days, then removed from the transcription records |
| Account data | While your account is active, plus 30 days after you request deletion |
| Transcription records | 12 months, then deleted; only monthly totals per account remain |
| Access requests | 12 months from your last request if no account was created, then deleted |
| Error reports from the app | 90 days, then deleted |
| Data on your computer | Last 20 recordings and texts; session logs and recovery copies 14 days (see 2.5) |
| Email logs | 30 days, then deleted |
| Invoices (post-monetisation) | 10 years per Slovak tax law |
6. Your rights under GDPR
You have the right to:
- Access — get a copy of all data we hold about you (Art. 15).
- Rectification — correct anything inaccurate (Art. 16).
- Erasure — delete your account and associated data, subject to the retention rules above (Art. 17).
- Portability — receive your data in a machine-readable format (Art. 20).
- Restriction — pause processing while a dispute is resolved (Art. 18).
- Objection — object to processing based on legitimate interest (Art. 21).
- Withdraw consent — for any processing that depends on consent (Art. 7).
- Lodge a complaint — with the Slovak Office for Personal Data Protection (dataprotection.gov.sk) or your local supervisory authority.
Send any request to privacy@dictaro.eu. We respond within 30 days.
7. Sub-processors
We use a small number of EU-based providers. They process data only on our instructions and under written agreements that match GDPR requirements.
| Cloudflare | CDN, DDoS protection, edge tunnel |
|---|---|
| Supabase (Frankfurt) | Authentication, account database, error reports from the app |
| Mailcow (self-hosted EU) | Transactional email delivery |
If we add or change sub-processors we will update this page.
8. Cookies
The marketing site uses no tracking cookies. Once signed in, the dashboard sets a single session cookie that is essential for keeping you logged in. There is no third-party advertising or cross-site tracking, and the website currently runs no analytics. If we add analytics, it will be a privacy-friendly, cookieless tool, and we will update this page first.
9. Children
Dictaro is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has signed up, please contact us and we will delete the account.
10. International transfers
All processing currently happens inside the EU. If we ever need to transfer personal data outside the EU we will use the European Commission's Standard Contractual Clauses and notify you in advance.
11. Changes to this policy
We may update this policy as the service grows. Material changes will be announced by email to active users at least 14 days before they take effect. The "Effective" date at the top of this page always reflects the current version.
12. Contact
Questions, requests, or complaints about privacy go to privacy@dictaro.eu.
Back