Privacy Policy
How Oudden handles personal data across the website, desktop application and related services.
- Version
- 1.2
- Last updated
This policy explains how Oudden handles personal data across its website, desktop app and related services. The operator and contact details are in section 7.
- Audio stays on your computer. Speech is transcribed locally.
- Text can be synchronized. Notes, transcripts and chat use Oudden's servers.
- AI processes text online. A request includes the text needed to answer it.
- Sharing gives others access. Choose recipients and link settings carefully.
1. What data we use and why
- Account: name, email and sign-in information, to identify you and protect access.
- Content: notes, transcripts, chat, prompts and responses, to save, synchronize, search and process your work. Content may include information about other people.
- Meetings and sharing: event details, participants, recipients and permissions, to prepare meeting notes and provide the access you choose. Calendar access is optional.
- Payments: subscription status and transaction details from Paddle, to manage paid access. Oudden does not receive your full payment-card number.
- Support and operation: messages you send us, IP address, app/device information and technical logs, to answer questions, diagnose problems and prevent misuse.
Where applicable, we process data to fulfil our agreement with you, meet legal obligations, pursue legitimate interests in operating and securing the service, or with consent when required. Without the data needed for an account or a chosen feature, we cannot provide that account or feature.
2. What stays local and what is sent
Transcription runs on your computer. Raw audio is not uploaded to Oudden or a transcription provider. Audio storage on your device depends on the app's settings.
Notes, transcripts, meeting information, sharing settings and chat can be stored on Oudden's servers to support synchronization and online features.
When you use AI, Oudden sends OpenAI your request and the relevant text available to you. We have disabled optional sharing of these requests and responses for model training. Our requests also disable ordinary response storage. This does not eliminate all provider retention: OpenAI's abuse-monitoring logs may contain requests and responses and are normally kept for up to 30 days, with exceptions for legal and safety needs. Encrypted prompt caches may be kept for up to 24 hours. See OpenAI's data controls.
Google Calendar credentials and the calendar cache stay on your device. Event information added to an Oudden note can be synchronized with that note.
3. Who receives data
- Hetzner hosts Oudden's server and database in Helsinki, Finland.
- OpenAI processes text for AI features.
- Google provides sign-in and optional calendar access.
- Paddle handles payments and subscriptions.
- Resend delivers service emails.
Providers receive the data needed for their role. Their processing may take place outside Finland and your country, including in the United States. Their linked terms describe applicable transfer safeguards, including standard contractual clauses and adequacy frameworks where applicable. You can contact us for information about the safeguards relevant to your data or a copy of them.
When you share a note, the people allowed by its access settings can read it. Anyone receiving a public link can forward it. Audio is not included in the shared note. Restricting access or replacing a link does not remove copies that others have already saved.
We may also disclose data to meet legal requirements, protect rights and safety, or as part of a business transfer with appropriate safeguards.
4. Storage, deletion and protection
Account information and synchronized content are stored to provide your account. Deleting a note removes it from normal access once the deletion synchronizes. Its server content is scheduled for permanent removal after 30 days.
To close your account, write to the contact below. After verifying your request, we remove your personal workspace's notes, transcripts, chats and sharing access, and disable sign-in. Uninstalling or resetting the app does not delete the account or synchronized data. Local audio and files are managed on your device.
Security audit and email-delivery records are scheduled for deletion after 90 days, and AI usage and cost records after 365 days. Synchronization and operation-replay records have retention periods of 30 to 520 days. During account erasure, content-bearing operation results and AI metadata are cleared; necessary minimal technical records and cost totals may remain for their applicable periods.
We retain necessary payment records and minimal account identifiers for record-keeping obligations, payment reconciliation, security and disputes. Support records are retained while needed to handle the request or meet those obligations. Records linked to an identifier are not automatically anonymous. Account deletion does not erase past payments or necessarily remove the account from historical counts; this does not justify keeping its note or chat content.
Recovery backups expire 30 days after their creation. Deleting data from the active system does not rewrite an existing backup. The note and backup periods are separate: an ordinarily deleted note may remain in recovery copies for approximately 60 days from synchronized deletion. Completed account erasures are reapplied before a restored service is reopened. Copies independently saved by recipients and records retained by payment providers are handled separately.
We use access controls, account separation and encrypted connections to protect data. No system is completely secure; protect your device, account and shared links.
5. Cookies and website settings
The site stores:
- your selected language, for up to one year;
- your cookie-notice choice, used for 180 days; the stored entry remains until replaced or cleared in your browser;
- a marker to help offer “Open” or “Download” when returning to the app, for 90 days; it contains no account identifier;
- sign-in and security cookies, for the relevant session or verification process.
On the public pages of oudden.com, we use Google Analytics to measure visits, pages viewed, traffic sources and browser/device characteristics. Google receives this information. The _ga and _ga_31WTP5DGC3 cookies distinguish browsers and maintain session information; they are set for up to two years and their expiry may be renewed on visits. They do not identify a person by name. We do not send account identifiers or note content to Analytics. Google Signals and advertising personalization are disabled. Analytics is not loaded on sign-in, payment or shared-note pages.
Analytics starts automatically unless this browser has a saved rejection. Choose “Reject” in the banner or reopen “Cookie settings” in the footer to stop further sending and delete these Analytics cookies. Choosing “Accept” enables Analytics again; visits made while it was disabled are not replayed. Previously sent data is not deleted by this action. The choice is used for 180 days; after it expires or browser storage is cleared, the banner and automatic collection return. Necessary service cookies remain available. Advertising tags are not connected in this release.
We also use Microsoft Clarity on public pages to understand clicks, scrolling and page interactions through session replays and heatmaps, so we can improve the site. Microsoft receives interaction, page and browser/device data under its Privacy Statement. Input values are masked by default; we do not send account IDs or note content or load Clarity on sign-in, payment or shared-note pages. Its _clck cookie remembers a browser for up to one year, and _clsk links page views for up to one day; expiry can renew. Clarity follows the same banner choice. Reject ends recording, deletes these cookies and refreshes the page to fully unload it. A final packet may contain interactions collected before stopping. Previously sent recordings are not deleted by rejection. We send Clarity an advertising-storage denial.
Clearing browser storage may reset preferences or sign you out. Paddle handles checkout data under its own privacy policy.
6. Your choices and rights
Depending on applicable law, you may request access, correction, deletion or a copy of your data, restrict or object to processing, withdraw consent, and complain to a data-protection authority. Contact us below; we may need to verify your identity. If an organization controls the information, its use of that data may require a request to that organization.
Oudden is not intended for children under 13 or below the applicable minimum age for consent to online services in their country, if higher. Users under 18 or otherwise below the age of legal adulthood need a parent's or legal guardian's permission and involvement, as described in the Terms. Contact us if you believe a child has provided data contrary to these rules.
7. Operator, contact and updates
- Operator responsible for personal data: Ruslan Aliyarau, an individual.
- Correspondence address: Manasa 16, Bishkek, Kyrgyzstan.
- Email: ruslan@oudden.com.
We update this policy when our practices or requirements change. The published version shows when it was last updated. We will notify you of material changes where required.