The short version
- Audio is never stored.Speech is processed to produce text and then discarded — we don't keep recordings.
- History stays local. Transcripts are saved on your device, not on our servers.
- No training on your content. We never use your voice or text to train AI models.
- We collect the minimum. Account details and basic, privacy-preserving product analytics — nothing more than we need.
Data we collect
Account information
When you create an account we collect your name, email address, and authentication details. Authentication is handled through our identity provider; we store a secure user identifier, not your password.
Billing information
If you purchase a paid plan, payments are processed by our payment provider. We receive limited billing metadata (plan, status, last four digits, country) but never your full card number.
Usage & diagnostics
We collect privacy-preserving product analytics — such as feature usage counts, app version, operating system, and crash diagnostics — to improve Superlumy. These contain aggregate or technical signals, not the contents of what you dictate.
Device & log data
Our servers automatically record technical data like IP address, browser type, and timestamps for security and reliability.
Your voice & transcripts
This is the part people care about most, so we'll be specific:
- When you dictate online, audio is streamed to our speech models, converted to text, and the audio is discarded. We do not retain recordings.
- When you dictate offline, processing happens entirely on your device and nothing leaves your machine.
- Your transcript history, personal dictionary, and voice shortcuts are stored locally on your device.
- We do not use your audio or transcripts to train, fine-tune, or improve any AI models — ours or our providers'.
How we use data
- To provide, maintain, and secure the Superlumy app and website.
- To process transactions and manage subscriptions.
- To respond to support requests and communicate service updates.
- To understand aggregate usage and improve performance and reliability.
- To detect, prevent, and address fraud or abuse.
Sharing & subprocessors
We do not sell your personal data. We share data only with vendors who help us operate Superlumy (for example, cloud hosting, authentication, speech processing, payments, and analytics), each bound by contractual confidentiality and data-protection obligations. See our list of subprocessors.
We may disclose information if required by law or to protect the rights, safety, and security of our users and Superlumy.
Data retention
We keep account and billing data for as long as your account is active and as required to comply with legal obligations. Audio is not retained. Local data (history, dictionary, shortcuts) remains on your device until you delete it. When you close your account, we delete or anonymize associated personal data within a reasonable period.
Security
We protect data with encryption in transit and at rest, least-privilege access controls, and continuous monitoring. Read more on our Security page.
Your rights
Depending on where you live (e.g. under GDPR or CCPA/CPRA), you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these rights, contact us at privacy@superlumy.com. We will not discriminate against you for exercising your rights.
International transfers
We may process data in countries other than your own. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses to protect your data when it is transferred internationally.
Children
Superlumy is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. We'll post the new version here with an updated date and, for material changes, provide a more prominent notice.
Contact us
Questions about privacy? Email privacy@superlumy.com or write to [Company Name], [Company Address]. For data-protection matters in the EU/UK, you may also contact our representative at the same address.