Recard is live on the web. Nothing to install to try it. Open the web app
Legal

Privacy Policy

Last updated 15 September 2026. A plain-language policy for a product in active development. It reflects how Recard is built today and may be updated as the product evolves.

Open the visual data transparency guide (PDF)

1. The short version

In Standard mode, Recard securely uploads recordings for transcription and analysis by Google Cloud Vertex AI, then syncs the results to your private library. Google does not use that content to train its AI models under the applicable Vertex AI terms. In Ultra Privacy, Recard temporarily uploads the recording for the same Vertex AI processing, returns the complete transcript and analysis to the app, and then deletes and verifies deletion of the recording and derived content from Recard-managed cloud storage and databases. The durable audio, transcript, and analysis remain only inside Recard on that phone and are not synced.

2. Who we are

Recard is operated by AK FRAMES LTD, a company registered in Scotland with company number SC617144 and registered office at Unit 12, Randolph Place, Randolph Industrial Estate, Kirkcaldy, Scotland, KY1 2YX ("Recard," "we," or "us"). We provide a mobile-first AI voice and meeting recorder for iOS and Android, plus a companion web app. You can reach us at recard@akframes.cloud.

3. Data we handle

  • Account information, the email and identity you register with (including Apple or Google sign-in when selected), used to authenticate you and sync your data.
  • Standard-mode recordings and derived content, audio you record and the transcripts, summaries, notes, and Critique results generated from it. These are processed in the cloud and stored according to your plan.
  • Ultra Privacy content, audio and processing metadata are sent temporarily to Recard’s backend and Google Cloud Vertex AI to produce the transcript and analysis. The completed audio, transcript, analysis, markers, and notes are stored in the Recard app container on that phone. Recard then deletes and verifies deletion of its temporary recording document, storage objects, transcript, generated analysis and notes, search/library indexes, share tokens, and Vertex staging objects. The app associates the durable local copy with your Recard user ID so another account signed in on the same phone cannot see it.
  • Content you supply, typed notes, highlights, folder and tag names, custom note templates, and context notes for Critique.
  • Questions and Voice conversations, Standard-mode recording chat, workspace chat, library questions, and live microphone audio are sent to our backend and Google Cloud Vertex AI to generate an answer. Ultra Privacy recordings stay excluded by default. If you separately enable “Allow transient Ask & Voice” on iPhone, the app sends the minimum local transcript and analysis needed for that request; Voice sends compact meeting context plus the live microphone stream. Recard does not add that private context or its embeddings to the cloud library or retain the conversation there. The on-device chat copy clears after 24 hours of inactivity.
  • Optional nearby Voice suggestions, on iPhone you may allow a one-time approximate location lookup so the app can suggest nearby languages and accent influences. The coordinates and place lookup remain on the device and are discarded after deriving the broad administrative region. Recard receives only the language or accent style, voice and personality you select—not your coordinates, city, or inferred region. If you decline location access, the app uses your iPhone language and country settings instead and Voice remains available.
  • Optional calendar context, if you enable calendar-assisted titles, Recard reads the current event title and up to ten attendee names (or email-name labels) and sends them with that recording as title and speaker hints. Recard does not upload your whole calendar.
  • Email credentials, if you set up email summaries, your SMTP credentials are encrypted on your device and are not transmitted to or stored by us. They are sent directly to your chosen email provider only when Recard verifies the account or sends mail for you.
  • Subscription status, handled by Stripe on the web, Google Play on Android, or Apple’s App Store on iOS. We receive your plan and entitlement status, transaction identifiers, renewal state, and expiry date, but not your full payment-card details.
  • Technical service data, Firebase automatically handles your caller IP address, a per-installation Firebase ID, Firebase user/app identifiers, and limited device/app metadata such as OS version, device model, brand, form factor, installer, and SDK versions. We use this to authenticate requests, prevent abuse, operate sync, and maintain the service. The mobile releases do not include advertising, Analytics, Crashlytics, or performance-monitoring SDKs.

4. Why we use data and our lawful bases

  • Contract, to create and secure your account; record, process, store, sync, export, and share content as you direct; operate workspaces; provide support; enforce plan allowances; and verify subscription entitlements.
  • Legitimate interests, to keep the Service reliable and secure, prevent fraud and abuse, diagnose failures, deliver essential account and workspace-invitation messages, and understand service capacity. Our interests are operating and protecting a service users expect; we limit the data used and do not run advertising or behavioural profiling.
  • Consent, where required for optional device permissions, notifications, calendar-assisted context, or marketing communications. You can withdraw a device permission in system Settings and unsubscribe from marketing without affecting essential service messages.
  • Legal obligation, where we must retain billing, tax, fraud-prevention, or compliance records or respond to a lawful request.

Creating an account requires an authentication identifier such as an email address. If you do not provide it, we cannot create or sync a Standard-mode Recard account. Recording content is optional and supplied only when you choose to record or import it.

5. How your data flows

Standard mode

Audio and/or transcript is sent over an encrypted connection to Google’s Vertex AI (Google Cloud’s enterprise AI platform) for transcription and analysis. Your recordings are processed under Google Cloud’s Vertex AI terms and are not used to train AI models. Processing memory is wiped after the job completes. Results are synced back and retained according to your plan.

Ultra Privacy: transient processing, local retention

Ultra Privacy is available on mobile plans and uses the normal plan allowance and duration limit. The app keeps the original audio in its protected local container, sends a temporary encrypted copy to Recard’s backend and Google Cloud Vertex AI, and receives the same complete transcript and structured analysis as Standard mode. Google does not use the content to train or fine-tune AI models without permission under the applicable Vertex AI terms.

Before the app marks processing complete, Recard deletes and checks for the absence of its temporary audio objects, transcript, analysis, notes, recording document, search and library indexes, share tokens, and Vertex staging objects. If the deletion cannot be verified, the app does not present the job as successfully completed and retains the original local audio for retry. Ultra-private items stay under “Only on this iPhone”; they do not sync, appear on the web or another phone, enter a workspace, or support public links. You can export the original audio yourself.

The separate “Allow transient Ask & Voice” switch is off by default. When you turn it on, per-recording Ask sends that recording’s timestamped transcript, analysis, speakers, and saved Critique for the interaction. Overall Ask may send a bounded set of local recording transcripts and analysis for transient ranking and an answer; those local embeddings exist only in memory for that request and are not written to Recard’s search index. Voice sends compact summaries, decisions, actions, and Critique context rather than full private transcripts, plus the live microphone audio required for the conversation. Responses and the chat transcript stay on the iPhone and clear after 24 hours of inactivity. These interactions use the normal Ask and Voice allowance. Turning the switch off excludes Ultra recordings again; it does not delete them.

This is a zero-retention application mode, not on-device AI. Both initial analysis and any optional Ask or Voice interaction still use cloud AI over an encrypted connection. Google Cloud may process limited service data under its own terms, including abuse-prevention or security data where applicable. Recard does not enable search grounding for Ultra Privacy processing. Google states that Vertex AI customer data is not used to train models without permission; its published retention controls and exceptions are described in Google Cloud’s Vertex AI documentation.

6. What we never do

  • We never train AI models on your recordings.
  • We never sell your data or use your content for advertising.
  • We never route your summary emails through our servers, own-SMTP means they leave your account directly.
  • We never send a bot into your meetings; there is no bot.

7. Subprocessors and international transfers

We use a small, named set of providers: Google Cloud Vertex AI (transcription, analysis, Critique, Ask, and Voice), Google Firebase (authentication, backend, Standard-mode sync, and transient Ultra Privacy requests), a transactional email provider (account and system emails), Stripe (web subscription billing), Google Play (Android subscription billing), and Apple (iOS sign-in and App Store billing). Summary emails you send through Android use your own SMTP server. Ultra Privacy content passes through Firebase and Vertex AI for the initial processing job and, only if you enable the separate switch, for an Ask or Voice interaction. Recard deletes and verifies deletion of the Recard-managed application copies after initial processing and does not persist or index the private context supplied for Ask or Voice.

Some providers operate outside the United Kingdom. Where a restricted transfer applies, we rely on an applicable UK adequacy regulation or contractual safeguards approved under UK data-protection law, such as the UK International Data Transfer Agreement or UK Addendum, together with the provider’s data-processing terms. Contact us if you want more information about the safeguard relevant to your data.

8. Retention & deletion

Standard-mode cloud retention follows your plan: 30 days (Free), 365 days (Pro), or permanent (Unlimited). If your effective plan changes to a lower tier, its new usage limits apply at that time, but Recard gives existing cloud recordings a safety window of at least 30 days from the change before the lower retention policy can remove them, even when an earlier plan-based deletion date was closer. A recording whose normal lower-plan retention ends later keeps that later date. Recard shows the change and safety deadline in Plans & billing and may send a subscription notification, giving you time to export or renew. Re-upgrading extends plan-based retention again, and Unlimited removes plan expiry. Deleted cloud items go to Trash with a separate 30-day restore window before purge. Ultra Privacy application content exists in Recard’s cloud only for the processing job and is deleted and verified before successful completion is shown. The durable copy remains only on that phone until you delete the item, delete your account from that phone, uninstall Recard, or erase or lose the device. It is excluded from device backups and has no Recard or iCloud restore copy. A normal sign-out hides it from other accounts; signing back into the same account on that phone reveals it again. In-app account deletion removes the signed-in account’s local ultra-private content as well as requesting deletion of its cloud data. A remote account deletion request cannot erase content that only exists on an offline or unavailable phone, so you must delete the app or its private items on that phone.

Account information is kept while your account is active and then deleted or anonymised, except for limited records we must keep for legal, tax, fraud-prevention, dispute, or security purposes. Operational and provider logs are retained only for the period reasonably needed for security, troubleshooting, and legal obligations. When a fixed period is not stated, we decide it from the data’s purpose, sensitivity, contractual requirements, and applicable law.

9. Security

Data in transit between the app and our backend is protected with TLS. Ultra Privacy files use device file protection, are excluded from backup, and are kept outside the synced recording model after processing. Temporary cloud objects use the same protected Google Cloud infrastructure as Standard mode and are subject to verified application-level deletion. On Android, your local library can be protected with biometric app lock. SMTP email credentials are encrypted on-device. We do not currently hold SOC 2, ISO 27001, or HIPAA attestations; see our Trust Center for an honest account of what we have and what is on the roadmap.

10. Your rights and complaints

Depending on where you live and the lawful basis involved, you may have rights to access, correct, erase, restrict, object to our use of, or receive a portable copy of personal data we control. Where we rely on consent, you can withdraw it at any time without affecting earlier lawful processing. You have the right to object to processing based on our legitimate interests. Recard supports export and in-app account deletion directly. After an Ultra Privacy processing job is wiped, Recard cannot access or recover the durable phone-only content, so you exercise control over that copy on the phone itself.

To exercise a right, contact recard@akframes.cloud. We may need to verify your identity. You may also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint, or to the data-protection authority where you live where applicable.

11. Data supplied by other people and automated decisions

A workspace owner or administrator may give us your email address to invite you. We use it to deliver and display that invitation and identify the inviter and workspace in the message. A recording may also contain the voices or personal information of participants who do not have a Recard account; the person making or sharing the recording is responsible for having permission to do so.

Recard automatically checks subscription status and usage against published plan allowances. Its AI also produces transcripts and analysis at your request. Recard does not use these systems to make decisions about you that have legal or similarly significant effects; you should review AI output before using it to make your own decisions.

12. Recording responsibly

You are responsible for complying with the recording and consent laws that apply where you are. Some jurisdictions require all parties' consent to record a conversation, and call-recording rules can be stricter. Please let people know when you're recording.

13. Changes to this policy

If we make privacy-relevant changes to how data flows, we'll update this page and note the change. Continued use after an update means you accept the revised policy.

Read the Terms of Service →