Hum Memo

Privacy Policy

Effective August 1, 2026

Hum Memo ("Hum", "we") is a voice-first note-taking app for iPhone. This page is a straightforward account of what data the app handles, why, who touches it, and the control you keep. The short version: your recordings and notes are processed only to build your own notes — never for advertising, never sold, never used to train AI models, and we embed no third-party analytics or advertising trackers and never track your behavior across apps or the web.

CONTENTS
  1. Data we collect
  2. Purposes of use
  3. AI & voice processing
  4. Recipients (subprocessors)
  5. Storage & who can access it
  6. Retention & deletion
  7. Your rights & controls
  8. Security
  9. Children
  10. Changes
  11. Contact

1. Data we collect

Each category lists what it covers, why we use it, and who receives it (every recipient is detailed in Section 4).

CategoryExamplesPurposesRecipients
Account dataEmail address, account identifier, sign-in provider, display name and profile photo you setCreate and authenticate your account; show your identity in the appSupabase (auth); Apple or Google (if you use them to sign in)
Audio recordingsVoice notes you record or audio files you importStore your recordings; transcribe them; power the voice features you requestSupabase (storage); pyannoteAI (enhanced transcription & speaker features)
Documents & scansPDFs, Word documents, and photos you import; pages you scan with the camera; the text extracted from themTurn documents into notes; recognize their text (OCR)None for the files themselves — originals stay on your device; the extracted text follows the "Transcripts & AI outputs" row
Transcripts & AI outputsTranscripts, titles, summaries, tags, insights, extracted tasks and events, "Ask your notes" answersDisplay and organize your notes; power search and chat over your own contentSupabase; Anthropic (and OpenAI or Google, depending on configuration)
Voice profilesA short enrollment sample converted to a voiceprint, a name you assign, optional photo/emojiRecognize enrolled voices in your future recordings — only within your accountpyannoteAI (matching under a random identifier, never a name)
Organization dataFolders, tags, favorites, chat history with your notesOrganize your library; keep your conversations with your notesSupabase
Purchase stateSubscription tier, Apple transaction identifiersUnlock paid features; enforce fair-use quotasApple (billing — we never see payment details)
Usage countsMonthly tallies of paid AI operations you run — structuring, chat, transcription seconds, voiceprints, knowledge graphEnforce fair-use quotas and keep provider costs sustainableSupabase; our server (Google Cloud)
First-party product analyticsA random installation identifier; app and iOS version; device-region country code; allowlisted events such as app launch, sign-in, note creation, paywall, subscription, search/filter interactions, and content-free processing outcomesMeasure aggregate adoption and reliability; understand which product surfaces are useful; improve HumSupabase; our server (Google Cloud)
Technical logsIP address, request timestamps, error informationOperate the service, prevent abuse, debug issuesOur server (Google Cloud infrastructure)

Hum's product analytics are built in-house: the app embeds no third-party analytics or advertising SDK, uses no advertising identifier, and does not track you across apps or websites. The random installation identifier is not your account ID or email, and analytics never contain note text, transcript text, audio, search terms, names, or other free text. The country code comes from the device-region setting (for example, "US"), not GPS or IP geolocation. We collect no GPS/device location and no contacts. Calendar access, when you grant it, is used only to add events you create from a note and to check for scheduling conflicts; this happens entirely on your device through Apple's EventKit, and your calendar is never sent to our servers or any subprocessor. The camera is used only when you choose to scan a document, and photos or files you import are read only to turn them into notes. All text recognition (OCR) of scans, photos, PDFs, and documents happens entirely on your device through Apple's Vision framework — the original files are stored only on your device and are never uploaded to our servers or any subprocessor. Because Hum lets you record whatever you choose, your content may itself contain sensitive information; we process it only to provide the features you invoke.

2. Purposes of use

We do not use your notes, recordings, or transcripts to train AI models (ours or anyone's), profile you, sell your data, or share anything with advertisers or data brokers.

3. AI & voice processing

Recording others: you are responsible for obtaining the consent of people you record or whose voices you enroll, as required by the laws that apply to you.

4. Recipients (subprocessors)

We share personal data only with vendors that need it to run Hum:

RecipientRoleData categories
SupabaseDatabase, file storage, authentication (including emailing your one-time sign-in code)All content in your account; account data; first-party product analytics
Google CloudHosting for our backend serverContent in transit; technical logs; first-party product analytics in transit
AnthropicAI features (commercial API)Transcripts/prompts relevant to each request
OpenAI / Google AIAlternative AI providers (configuration-dependent)Transcripts/prompts relevant to each request
pyannoteAIEnhanced transcription, speaker recognitionAudio; voiceprints (random identifiers only)
AppleSign in with Apple, subscriptions, App StoreSign-in identifier; purchase state
GoogleSign in with GoogleSign-in identifier; email

We may disclose data if legally compelled (for example, a valid court order) or to prevent imminent harm; where the law permits, we will tell you about such requests. We do not sell personal data.

5. Storage & who can access it

Your notes live in your own protected space: every database row is guarded by row-level security bound to your authenticated account, and audio files sit in a private bucket readable only by you. There is no dashboard or tool for reading, browsing, or searching your notes' content — we never monitor, review, or analyze your notes for keywords, advertising, or any other purpose. Access to the underlying infrastructure is limited to authorized operations personnel, for maintenance, under confidentiality.

6. Retention & deletion

7. Your rights & controls

We honor these for everyone, regardless of location, to the extent practical:

For any request the app doesn't cover, email support@hummemo.com — we respond within 30 days, and we will never discriminate against you for exercising your rights.

8. Security

Encryption in transit (TLS with HSTS) everywhere; per-account isolation via database row-level security and owner-scoped private storage; API keys and processing credentials live only on our servers, never inside the app; purchases are verified against Apple's cryptographic signatures. If a security incident ever affects your personal data, we will notify you and applicable regulators as the law requires.

9. Children

Hum Memo is not directed at children under 13 (or the higher minimum age of your jurisdiction), and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.

10. Changes

If this policy changes materially, we will update it here with a new effective date and, where appropriate, note it in the app.

11. Contact

Hum Memo
support@hummemo.com