Privacy Policy

Last updated: August 6, 2026 | Effective: August 6, 2026

1. Data Controller

The data controller for personal data processed by Pepitt is:

Paul Haardt
SIREN 105832190 - see our Mentions légales
Email: [email protected]
Data protection contact: [email protected]

We do not currently have a designated Data Protection Officer (DPO) as our core activities do not meet the GDPR Art. 37 thresholds, but you can reach us about any privacy concern at the address above.

When you record other people, you act as the data controller for their personal data and we act as your processor for that content (we process it only to deliver the Service, on your instructions). We are an independent controller for your account, billing, and service-operation data.

2. What Data We Collect

2.1 Data you provide

2.2 Data we collect automatically

2.3 Anonymous / guest usage

You can use Pepitt without creating an account ("Get started" as a guest, no email required). Guest usage is not un-identified: it is tied to a server-issued anonymous authentication identifier and your device identifier, which we use to apply your one-time free quota per device. Your audio, transcripts, and notes as a guest are processed and stored on our servers the same way as for a registered account (§2.1-2.2 above; the same sub-processors in §4 apply). If you do not create an account, this guest data (and the guest identity itself) is automatically and permanently deleted after 30 days of inactivity. We keep only an aggregate record of quota already used against your device (no audio, transcript, or note content) indefinitely, solely to prevent re-granting the same free quota via reinstall. If you create an account, your guest content is transferred to it and the guest identity is later deleted the same way.

2.4 Optional data

3. Legal Basis (GDPR Art. 6)

PurposeLegal basis
Provide the core service (recording, transcription, notes)Performance of contract (Art. 6(1)(b))
Account creation & authenticationPerformance of contract (Art. 6(1)(b))
Anonymous / guest usage (before you create an account)Legitimate interest (Art. 6(1)(f)); pre-contractual trial use at your request
Billing & subscriptionsPerformance of contract (Art. 6(1)(b))
Security, fraud prevention, abuse detectionLegitimate interest (Art. 6(1)(f))
Product analytics (pseudonymous events, opt-in)Consent (Art. 6(1)(a)), opt-in; revocable in Settings → Privacy
Crash reports (first-party, no account link)Legitimate interest (Art. 6(1)(f)) - service diagnostics
Anonymous screen counts (first-party, no identifier)Anonymous data - not personal data under GDPR
Service operation, debugging & improvement (detailed generation logs)Legitimate interest (Art. 6(1)(f)); object / opt out by email
Optional features (location, phone verification)Consent (Art. 6(1)(a)), revocable in settings
Product-news emails (optional)Consent (Art. 6(1)(a)), revocable any time

4. Third-party Processors (Sub-processors)

We share specific data with the processors below strictly to deliver the Service. We put a data processing agreement in place with each as required by GDPR Art. 28, and each operates under its own privacy policy:

Each row below shows exactly what data leaves us, who receives it, why, and the legal basis. Read each row on its own: a processor only ever receives the data listed in its own row.

Data shared Who receives it Why (purpose) Legal basis
Your transcripts (the text of your recordings) Mistral AI (EU) · policy Generate your notes from your transcripts. Processed within the EU; Mistral does not train on this data. Contract
Your audio recordings Soniox (Soniox Inc., via its EU endpoint) · policy Transcribe your audio into text. Contract
Your email address and account identifier Firebase Authentication (Google, DPF certified) · policy Authenticate you and manage your account identity. Contract
An app user ID and your subscription state RevenueCat (RevenueCat Inc., USA, DPF certified) · policy Track your subscription and entitlements. Contract
Purchase and subscription data Apple / Google · Apple | Google Process your in-app purchases. Contract
All request traffic, including your IP address, as it transits the network Cloudflare (Cloudflare, Inc., USA, DPF certified) · policy Edge proxy / CDN - all traffic to and from Pepitt passes through it. Legitimate interest (security & delivery)
A pseudonymous device identifier and product-analytics event names (screen and feature usage). No email, no name, and no recordings, transcripts or notes. Vexo Analytics (Vexo Analytics Inc., USA, transfers under Standard Contractual Clauses) · policy Understand which features are used so we can improve the app. Opt-in only: nothing is sent until you consent, and you can stop it any time in Settings → Privacy. Consent (Art. 6(1)(a))
Your email address (marketing list only) Brevo / Sendinblue (Sendinblue SAS, France, EU) · policy Send optional product-news emails, only to addresses you gave with consent on our website. Consent (Art. 6(1)(a))
All data stored server-side (audio, transcripts, notes, account and billing data) Hetzner (Hetzner Online GmbH, Germany, EU) · policy Host and store the Service's data. Contract
Your device's IP address and browser/font request (no account data) Google Fonts (Google LLC/Google Ireland) · policy Deliver web fonts on our marketing and legal pages. This request fires on every page load, including this one, and is not gated behind cookie consent because no cookie is set and no persistent identifier is stored. Legitimate interest (Art. 6(1)(f))

The "no email, no name, no content" assurance applies to Vexo Analytics only. Every other processor necessarily receives the data listed in its own row so that the Service can work - for example, Mistral receives your transcripts and Soniox receives your audio. The opt-in Vexo analytics is also entirely separate from the server-side generation & debugging logs described in §2.2 and §6, which may contain your transcript text and are kept under legitimate interest with an email opt-out.

We process your transcripts and notes only on EU-based providers. We may introduce a new note-generation provider in future; if a change would send your content to a different provider or region, we will update this list and notify you in advance.

5. International Transfers

Some of our processors are located outside the European Economic Area (EEA), primarily in the United States. Transfers rely on the EU-US Data Privacy Framework (DPF) where the processor is certified, and on Standard Contractual Clauses (SCCs) otherwise.

6. Retention

7. Your Rights (GDPR Art. 12-22)

You have the following rights regarding your personal data:

To exercise any right, email [email protected]. We respond within 30 days (extendable to 90 days for complex requests under Art. 12(3)).

8. Security

We protect your data with industry-standard safeguards:

No system is perfectly secure. If you suspect a vulnerability or breach, email [email protected].

9. Cookies & Tracking

The Pepitt mobile app and our web-served legal pages do not set cookies. Our website loads web fonts from Google Fonts on every page (see §4); this sends your IP address to Google but sets no cookie and stores no persistent identifier, so it is not gated behind a consent banner. If our marketing website introduces any other non-essential cookies or trackers, we will ask for your consent first via a cookie banner. Analytics events are sent via Vexo only if you opt in (see §2); they do not use cross-app identifiers and are not used for advertising.

10. Children's Privacy

Pepitt is not intended for users under 16. We do not knowingly collect data from children under 16. If you believe a minor has created an account, contact us and we will delete the account.

11. Automated Decision-Making

We do not perform any automated decision-making with legal or similarly significant effects on you (GDPR Art. 22). AI-generated transcripts and notes are informational outputs subject to your review.

12. Marketing Communications

If you give consent (for example by ticking the box on our website), we may send you occasional product-news emails via Brevo. We rely on your consent (GDPR Art. 6(1)(a)). You can withdraw consent at any time using the unsubscribe link in every email or by emailing [email protected]; withdrawal does not affect sending that happened before you withdrew.

13. Changes to this Policy

We may update this Privacy Policy. Material changes will be notified via the app at least 30 days before they take effect, with the option to object.

14. Contact

General contact: [email protected]
Privacy / data protection requests: [email protected]
Security reports: [email protected]