Privacy Policy
Hum Memo ("Hum", "we") is a voice-first note-taking app for iPhone. This page is a straightforward account of what data the app handles, why, who touches it, and the control you keep. The short version: your recordings and notes are processed only to build your own notes — never for advertising, never sold, never used to train AI models, and we embed no third-party analytics or advertising trackers and never track your behavior across apps or the web.
1. Data we collect
Each category lists what it covers, why we use it, and who receives it (every recipient is detailed in Section 4).
| Category | Examples | Purposes | Recipients |
|---|---|---|---|
| Account data | Email address, account identifier, sign-in provider, display name and profile photo you set | Create and authenticate your account; show your identity in the app | Supabase (auth); Apple or Google (if you use them to sign in) |
| Audio recordings | Voice notes you record or audio files you import | Store your recordings; transcribe them; power the voice features you request | Supabase (storage); pyannoteAI (enhanced transcription & speaker features) |
| Documents & scans | PDFs, Word documents, and photos you import; pages you scan with the camera; the text extracted from them | Turn documents into notes; recognize their text (OCR) | None for the files themselves — originals stay on your device; the extracted text follows the "Transcripts & AI outputs" row |
| Transcripts & AI outputs | Transcripts, titles, summaries, tags, insights, extracted tasks and events, "Ask your notes" answers | Display and organize your notes; power search and chat over your own content | Supabase; Anthropic (and OpenAI or Google, depending on configuration) |
| Voice profiles | A short enrollment sample converted to a voiceprint, a name you assign, optional photo/emoji | Recognize enrolled voices in your future recordings — only within your account | pyannoteAI (matching under a random identifier, never a name) |
| Organization data | Folders, tags, favorites, chat history with your notes | Organize your library; keep your conversations with your notes | Supabase |
| Purchase state | Subscription tier, Apple transaction identifiers | Unlock paid features; enforce fair-use quotas | Apple (billing — we never see payment details) |
| Usage counts | Monthly tallies of paid AI operations you run — structuring, chat, transcription seconds, voiceprints, knowledge graph | Enforce fair-use quotas and keep provider costs sustainable | Supabase; our server (Google Cloud) |
| First-party product analytics | A random installation identifier; app and iOS version; device-region country code; allowlisted events such as app launch, sign-in, note creation, paywall, subscription, search/filter interactions, and content-free processing outcomes | Measure aggregate adoption and reliability; understand which product surfaces are useful; improve Hum | Supabase; our server (Google Cloud) |
| Technical logs | IP address, request timestamps, error information | Operate the service, prevent abuse, debug issues | Our server (Google Cloud infrastructure) |
Hum's product analytics are built in-house: the app embeds no third-party analytics or advertising SDK, uses no advertising identifier, and does not track you across apps or websites. The random installation identifier is not your account ID or email, and analytics never contain note text, transcript text, audio, search terms, names, or other free text. The country code comes from the device-region setting (for example, "US"), not GPS or IP geolocation. We collect no GPS/device location and no contacts. Calendar access, when you grant it, is used only to add events you create from a note and to check for scheduling conflicts; this happens entirely on your device through Apple's EventKit, and your calendar is never sent to our servers or any subprocessor. The camera is used only when you choose to scan a document, and photos or files you import are read only to turn them into notes. All text recognition (OCR) of scans, photos, PDFs, and documents happens entirely on your device through Apple's Vision framework — the original files are stored only on your device and are never uploaded to our servers or any subprocessor. Because Hum lets you record whatever you choose, your content may itself contain sensitive information; we process it only to provide the features you invoke.
2. Purposes of use
- Deliver the service — store, transcribe, structure, and sync your notes; power search, tasks, calendar events, speaker recognition, and "Ask your notes".
- Operate responsibly — authenticate you, enforce quotas, prevent abuse, debug failures.
- Understand aggregate usage — non-content counts and totals, such as how many notes exist and how heavily paid features are used, to operate and improve the service. This never involves reading your notes' content.
- Process payments — via Apple, when you subscribe.
- Comply with law where genuinely required.
We do not use your notes, recordings, or transcripts to train AI models (ours or anyone's), profile you, sell your data, or share anything with advertisers or data brokers.
3. AI & voice processing
- On your device: standard transcription runs locally through Apple's speech framework.
- Document scanning & OCR: text recognition of scanned pages, imported photos, PDFs, and Word documents runs entirely on your device through Apple's Vision framework. The original files never leave your device; only the extracted text participates in AI structuring, exactly like a transcript.
- AI structuring, chat, and knowledge features: the relevant text is sent to our AI provider — Anthropic by default (OpenAI or Google depending on configuration) — through paid commercial APIs. We send only what the feature you invoked needs. Hum has not opted into provider data sharing or model training.
- Enhanced transcription & speaker recognition (paid features): audio is processed by pyannoteAI. Voiceprint matching uses random identifiers — the provider never learns whose voice a print belongs to.
- All content is encrypted in transit. True end-to-end encryption is not possible for AI features — the provider must be able to read content to process it. This is the same trade-off every AI note app makes; we minimize it by sending only what each request needs.
Recording others: you are responsible for obtaining the consent of people you record or whose voices you enroll, as required by the laws that apply to you.
4. Recipients (subprocessors)
We share personal data only with vendors that need it to run Hum:
| Recipient | Role | Data categories |
|---|---|---|
| Supabase | Database, file storage, authentication (including emailing your one-time sign-in code) | All content in your account; account data; first-party product analytics |
| Google Cloud | Hosting for our backend server | Content in transit; technical logs; first-party product analytics in transit |
| Anthropic | AI features (commercial API) | Transcripts/prompts relevant to each request |
| OpenAI / Google AI | Alternative AI providers (configuration-dependent) | Transcripts/prompts relevant to each request |
| pyannoteAI | Enhanced transcription, speaker recognition | Audio; voiceprints (random identifiers only) |
| Apple | Sign in with Apple, subscriptions, App Store | Sign-in identifier; purchase state |
| Sign in with Google | Sign-in identifier; email |
We may disclose data if legally compelled (for example, a valid court order) or to prevent imminent harm; where the law permits, we will tell you about such requests. We do not sell personal data.
5. Storage & who can access it
Your notes live in your own protected space: every database row is guarded by row-level security bound to your authenticated account, and audio files sit in a private bucket readable only by you. There is no dashboard or tool for reading, browsing, or searching your notes' content — we never monitor, review, or analyze your notes for keywords, advertising, or any other purpose. Access to the underlying infrastructure is limited to authorized operations personnel, for maintenance, under confidentiality.
6. Retention & deletion
- Your content is kept until you delete it. Document and scan originals exist only on your device and are removed when you delete the note or the app.
- Deleted notes go to Trash and are permanently erased after 30 days — or immediately, if you empty the Trash.
- First-party product analytics are automatically deleted after 90 days. They use a random installation identifier that resets when the app is deleted and is deliberately never connected to your Hum account, email, notes, or recordings.
- AI providers: Anthropic's standard commercial API and OpenAI's default API abuse-monitoring logs may retain request content for up to 30 days. Google's paid Gemini API does not use prompts or responses to improve its products; if optional project logging is enabled, its configurable retention can be up to 55 days. pyannoteAI deletes URL-delivered audio immediately after processing and retains job output for 24 hours. Hum does not enable provider data sharing for model improvement.
- Deleting your account (Settings → Account → Delete Account) permanently and immediately erases your active account record, private files, and durable account-linked data: notes, transcripts, audio, folders, chats, voice profiles and voiceprints, and Hum purchase/usage state. Short-lived transcription retry state (an expiring audio link and, when a repair is needed, intermediate transcript output) can remain on Hum's processing server for up to 48 hours before automatic deletion. Apple's purchase history and the AI-provider retention periods above are controlled by those providers. Because anonymous analytics are never linked to an account, they cannot be located from an account-deletion request and instead expire automatically within 90 days.
7. Your rights & controls
We honor these for everyone, regardless of location, to the extent practical:
- Access & export — your notes are always visible in-app and exportable (share, markdown, PDF).
- Correct — edit any note, transcript, speaker name, or your account details in-app.
- Delete — individual notes, voice profiles, or your entire account — all in-app, no email required.
- EU/UK (GDPR) — you additionally have rights to portability, restriction, objection, and complaint to your supervisory authority.
- US state laws (CCPA/CPRA and similar) — rights to know, delete, and correct. We do not "sell" or "share" personal information as those laws define it, so there is nothing to opt out of.
For any request the app doesn't cover, email support@hummemo.com — we respond within 30 days, and we will never discriminate against you for exercising your rights.
8. Security
Encryption in transit (TLS with HSTS) everywhere; per-account isolation via database row-level security and owner-scoped private storage; API keys and processing credentials live only on our servers, never inside the app; purchases are verified against Apple's cryptographic signatures. If a security incident ever affects your personal data, we will notify you and applicable regulators as the law requires.
9. Children
Hum Memo is not directed at children under 13 (or the higher minimum age of your jurisdiction), and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.
10. Changes
If this policy changes materially, we will update it here with a new effective date and, where appropriate, note it in the app.
11. Contact
Hum Memo
support@hummemo.com