Privacy Policy
The short version: your audio and meeting content stay on your own devices. On the desktop app, everything is processed locally using on-device AI and never leaves your machine. On the iOS app, your recording is transcribed on-device using local speech models, and can optionally be sent to your own paired computer over an encrypted connection for desktop transcription (see the iOS section below). In both cases we (the developer) never receive your audio, transcripts, or meeting content. For desktop Pro we hold the minimum account data needed to operate the subscription (email and a licence identifier); for iOS Pro we hold none: Apple is the merchant and holds the transaction record.
1. Who we are
Clearminutes (the desktop and iOS applications) is operated by DevBytesUK, a trading name of James Gibbard ("we", "us", "our"), an individual based in the United Kingdom. For all data protection enquiries, please contact us at support.clearminutes.app.
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the data controller of personal data collected in connection with your use of Clearminutes is James Gibbard (trading as DevBytesUK).
2. The core privacy principle: local-first by design
On the desktop app, Clearminutes is built around a local-first architecture. All audio capture, transcription, and AI summarisation runs entirely on your own machine. At no point is your audio, your transcripts, or any meeting content transmitted to our servers or any third-party server operated by us.
The iOS app works differently and is covered separately in the next section.
On the desktop app, your meeting data lives only on your device, under your control. If you delete the app or its data, that information is gone. We have no copy of it and no ability to recover it.
2a. The Clearminutes iOS app
The Clearminutes iOS app records meetings on your iPhone and transcribes them on-device using local speech models (WhisperKit, Parakeet, or Apple Speech as fallback). The audio and transcript are stored on your iPhone; Clearminutes (the developer) has no access to either. The app can also send audio to your own paired computer (the Clearminutes desktop app on your Mac, Windows, or Linux machine) over an encrypted peer-to-peer connection for transcription on your desktop; the transcript is then sent back to your iPhone. You choose which path to use.
On-device meeting summaries. The iOS app can generate a structured meeting summary (summary text, key decisions, action items) from the transcript, entirely on-device. On devices with Apple Intelligence (iOS 18+), it uses Apple's Foundation Models; on older devices, it falls back to an extractive summary (frequency-based keyword extraction). No transcript text ever leaves your iPhone for summary generation. The free tier allows 5 summaries per month; Pro users get unlimited summaries.
To pair your devices, the iOS app contacts signal.clearminutes.app to exchange the short SDP/ICE pairing messages. If a direct peer-to-peer connection is unavailable, it also uses Cloudflare's STUN/TURN servers to relay the encrypted bytes. None of these servers store your audio or the pairing messages, and the relay cannot read the content. The connection is end-to-end encrypted with DTLS-SRTP, so only your iPhone and your own computer can decrypt it. The pairing messages are transient and are discarded once your devices are connected (the pairing room is deleted within minutes).
Pro subscription (Apple In-App Purchase). The iOS app sells Pro via Apple's In-App Purchase (StoreKit 2). Apple is the Merchant of Record and handles all payment, billing, and subscription management; DevBytesUK never sees your card details or billing information. Plans are $4.99/month or $39.99/year, with a 2-week free trial on the annual plan. Your purchase and subscription status are verified on-device by Apple (StoreKit Transaction.currentEntitlements): the app makes no call to any Clearminutes server for entitlement. The app generates no machine ID, stores no JWT, and sends no identifier to api.clearminutes.app for iOS Pro. Apple holds your transaction record under Apple's own terms; the iOS app itself collects no account data from you for the subscription. (The desktop app, by contrast, sells Pro through Paddle: see section 3.) Manage or cancel anytime in Settings > Apple ID > Subscriptions.
Pairing is not tied to your account. The 6-digit pairing code shown on your computer is a temporary secret that lives only for the pairing session (a few minutes). It is not tied to your account or your Pro subscription.
Opt-in usage analytics. The iOS app sends anonymous usage analytics only if you opt in. You are asked during onboarding (Allow or No thanks), and you can change your choice at any time in Settings. When opted in, the app sends events recording which buttons you tap, the app version, device model, OS version, timezone, and anonymous device and session identifiers. These events never include audio, transcripts, or meeting names. The events go to Clearminutes' EU-hosted PostHog account via the t.clearminutes.app proxy, the same proxy the website and desktop app use. Opting out turns off new events. When opted in, the app's on-device audit log records each telemetry event, so you can see every event in the app's Privacy screen. The app sends no crash reports and contains no advertising SDK. Its other network calls are: (1) signal.clearminutes.app for pairing (transient SDP/ICE exchange), (2) Cloudflare STUN/TURN for relay (encrypted bytes only), and (3) Apple's App Store servers for In-App Purchase (StoreKit; Apple's own terms apply, not ours). The app makes no call to api.clearminutes.app: iOS Pro entitlement is verified on-device by Apple.
An on-device audit log. The iOS app keeps a log of the connections it makes for pairing and transfer, a record-start/record-stop entry whenever a recording starts or stops, and, when you have opted in to usage analytics, an entry for each telemetry event it sends, so you can read it yourself in the app's Privacy screen. It stores metadata only: for connections, the kind of connection, the time, and the server host; for record-start/stop, a non-identifying source field with values "app" (started from inside the app) or "intent" (started from the Lock Screen widget, Siri, Shortcuts, or the Action Button; the system does not expose which surface, so both share one label). It never stores your audio, transcript text, meeting names, or the recording identifier, and it never leaves your iPhone. It is a transparency record, not a cryptographic guarantee; like any app, trust ultimately rests on the app itself and on Apple's app review.
Validate it yourself. You don't have to take these claims on trust. Open the app's Privacy screen to read the audit log of every network connection Clearminutes makes: it shows signal.clearminutes.app (pairing), Cloudflare STUN/TURN (relay), Apple's App Store (In-App Purchase), and, if you have opted in to usage analytics, t.clearminutes.app (anonymous telemetry events), and never your audio, transcript, or meeting content. The log lives on your device, so it reflects exactly what the app did, not what we assert.
Data retention on iOS. The on-device audit log is bounded (it keeps only the most recent entries and rotates). Your audio and transcripts stay on your iPhone and your own computer until you delete them in the app or remove the app.
For the avoidance of doubt: the iOS app declares three App Store privacy label data types: Audio Data used for App Functionality, not linked to you (your audio is sent only to your own paired desktop via encrypted P2P/TURN; the developer never receives it, and it is not linked to any account or identifier); and, for the opt-in analytics described above, Identifiers (Device ID) and Usage Data (Product Interaction), both used for Analytics and not linked to you (the device and session identifiers are anonymous, generated on-device, and never tied to your name, email, or account). The app collects no Contact Info, no Diagnostics, and no Location. No other data types are collected.
Apple Watch
Clearminutes offers an optional Apple Watch app that records audio from your wrist. Watch recordings are stored locally on the watch as encrypted-at-rest files, then transferred to your paired iPhone via Apple's encrypted WatchConnectivity protocol (end-to-end between paired devices, no server involved). No watch data touches any server. Once on the iPhone, recordings are transcribed on-device using the same local pipeline as iPhone recordings.
- Microphone access: the watch app requires its own microphone permission, separate from your iPhone. The first time you tap Record on the watch, the system asks for permission. You can change this in Watch settings.
- Background recording: the watch can continue recording with the screen off, up to 2 hours. While recording in the background, watchOS shows a microphone indicator in the status area so bystanders can see a recording is in progress.
- Data retention: once a recording is successfully transferred to your iPhone, the audio file is deleted from the watch. If the transfer fails, the recording stays on the watch until the next sync attempt.
- No telemetry: the watch app sends no usage analytics or crash reports.
- Audit log: watch-originated recordings appear in the iPhone's on-device Privacy audit log with a
"watch"source label.
3. What personal data we collect and why
3.1 Account data (desktop Pro subscribers)
If you purchase a Clearminutes Pro subscription on the desktop app (sold through Paddle), we collect and process the following. The iOS app sells Pro through Apple In-App Purchase and collects none of this: see the iOS section above; Apple is the merchant and holds the transaction record.
- Email address: used to create your account, send your licence activation email, and communicate subscription-related updates. The activation email is delivered via Resend, a transactional email service.
- Subscription status: whether your Pro subscription is active, trialling, cancelled, or lapsed. This is provided to us by Paddle, our payment processor, and is used solely to gate access to Pro features within the app.
- Machine ID hash: a one-way cryptographic hash derived from identifiers on your device. This is used for licence enforcement to verify that the app is activated on an authorised machine. The raw device identifier is never stored; only the hash is retained.
The legal basis for processing this data is the performance of a contract with you (Article 6(1)(b) UK GDPR): specifically, to fulfil your Pro subscription and provide the licensed software.
3.2 Payment data
The desktop app uses Paddle as its payment provider. Paddle acts as the Merchant of Record for all desktop transactions, meaning Paddle collects and processes all payment information including card details, billing address, and VAT information. DevBytesUK never has access to your payment card details or full billing information. Paddle's own privacy policy governs the handling of your payment data and can be found at paddle.com/legal/privacy. The iOS app uses Apple In-App Purchase instead: Apple is the Merchant of Record for iOS Pro; DevBytesUK never receives your card details or billing information, and the iOS app collects no payment data from you.
3.3 Free tier users
If you use Clearminutes on the free tier without creating an account, we do not collect any personal data. No registration is required to download or run the app.
3.4 Data we do not collect
On our own servers, we do not collect, and have never collected:
- Audio recordings or audio snippets from your meetings
- Transcripts or summaries generated by the app
- Meeting titles, participant names, or any meeting content
- Crash reports or diagnostic logs transmitted to our servers
- IP address logs linked to individual users
- Browser or device fingerprinting data
- Any data for advertising or marketing profiling
3.5 Cancel feedback (Pro subscribers who cancel)
If you cancel your Pro subscription and choose to leave a reason, we collect two separate pieces of data with different handling:
- Reason tag: a fixed category (e.g. "too expensive", "not using", "found an alternative", "technical issues", "other"). This is sent to our analytics platform (PostHog, EU) only if you have consented to analytics cookies, so we can understand why users cancel. The reason tag is not linked to your free-text message in analytics.
- Free-text message (optional): any text you write in the reason box. This is stored on our support backend (Cloudflare D1, EU region) against your account for up to 12 months, and is deleted with your account on request (contact us to request earlier deletion). It is never sent to our analytics platform or written to our server logs: only the reason tag is.
The legal basis for processing the free-text message is our legitimate interest in understanding and reducing churn (Article 6(1)(f) UK GDPR). The reason tag in PostHog is processed under your analytics consent.
4. How we use your data
We use the personal data we hold for the following purposes only:
- To activate and manage your Pro subscription licence
- To send you a licence activation email when you purchase Pro
- To verify your subscription status when the app checks for an active licence
- To handle billing-related communications passed through Paddle (e.g. payment failure notifications)
- To respond to support requests you initiate with us
- To comply with our legal obligations under UK law
We do not use your data for profiling, automated decision-making, targeted advertising, or any purpose beyond operating your subscription.
5. Data sharing and third parties
We share limited personal data with the following third parties, strictly as required to operate the service:
- Paddle: payment processing and Merchant of Record for the desktop app. Paddle receives your email address and processes all desktop payment data. Paddle is responsible for VAT collection and remittance. The iOS app uses Apple In-App Purchase: Apple is the merchant for iOS Pro; DevBytesUK receives no payment data and no email from iOS Pro purchases.
- Resend: transactional email delivery. Resend receives your email address solely for the purpose of delivering your licence activation email.
- PostHog: website analytics (only if you consent via the cookie banner). PostHog receives anonymised data about how you navigate the Clearminutes website (pages visited, buttons clicked, downloads). Data is stored on EU servers (eu.posthog.com). No audio, transcripts, or meeting content is ever included. PostHog's privacy policy is at posthog.com/privacy.
We do not sell your personal data. We do not share your data with data brokers or advertising networks. We do not use your data to train AI models.
If we are required by law to disclose your data: for example, in response to a court order or regulatory requirement, we will do so only to the extent required and will notify you where legally permitted.
6. Data retention
We retain your desktop account data (email address, subscription status, machine ID hash) for as long as your desktop Pro subscription is active. Following cancellation or expiry, we retain this data for a further 30 days to allow for reactivation, after which it is permanently deleted from our systems. The iOS app holds no such account data: iOS Pro is an Apple In-App Purchase whose transaction record is held by Apple under Apple's own terms.
Cancel feedback (the free-text reason you leave when cancelling) is retained on our support backend for up to 12 months from the date you submit it, after which it is automatically purged. It is deleted earlier if you request account deletion: contact us to do so.
Any meeting data, transcripts, or recordings stored by the app remain on your local device only. This data is not subject to our retention schedule because we never hold it. You can delete this data at any time by removing the app's data directory from your device.
7. Data security
We take reasonable technical and organisational measures to protect the personal data we hold. Account data is stored securely with access controls limiting who within DevBytesUK can view it. All data in transit between your device and our licence server is encrypted using TLS.
Because meeting content is processed entirely on your device and never transmitted to us, there is no server-side exposure of your meeting data.
8. Your rights under UK GDPR
As a data subject under UK GDPR, you have the following rights regarding the personal data we hold about you:
- Right of access: you can request a copy of the personal data we hold about you.
- Right to rectification: you can ask us to correct inaccurate personal data.
- Right to erasure: you can ask us to delete your personal data, subject to our legal obligations.
- Right to data portability: you can request your data in a structured, machine-readable format.
- Right to object: you can object to processing based on legitimate interests.
- Right to restrict processing: you can ask us to limit how we use your data in certain circumstances.
To exercise any of these rights, please contact us at support.clearminutes.app. We will respond within one calendar month as required by UK GDPR.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9. Analytics
9.1 Website analytics (clearminutes.app)
We use PostHog to understand how visitors use the Clearminutes website: pages visited, buttons clicked, and downloads initiated. This analytics is only activated if you consent via the cookie banner shown on your first visit.
Website analytics data is:
- Consent-gated: not collected unless you explicitly accept analytics cookies
- Anonymised: not linked to your name, email address, or any personally identifiable information (unless you subsequently make a purchase, in which case your email may be associated with your session for subscription tracking purposes)
- EU-hosted: stored on PostHog's EU infrastructure (eu.posthog.com) in compliance with UK GDPR data transfer requirements
- Limited in scope: covers site navigation and click behaviour only; no audio, transcripts, or meeting content is ever collected
You can change your analytics preference at any time by clicking "Manage cookie preferences" in the footer, or by clearing your browser's cookies.
The legal basis for processing website analytics data is your consent (Article 6(1)(a) UK GDPR).
9.2 Desktop app analytics
The Clearminutes desktop application separately collects anonymous usage analytics and app telemetry via PostHog. This data helps us understand how the app is used and identify areas for improvement.
This analytics data is:
- Anonymous: not linked to your name, email address, or any personally identifiable information
- Aggregated: used only to understand general usage patterns, not to profile individual users
- Limited in scope: covers feature usage and app performance signals only; no meeting content, transcripts, audio, or participant data is ever included
You can opt out of app analytics at any time in the app's Settings. Opting out stops all telemetry from being sent. Your opt-out preference is stored locally on your device and respected immediately.
10. Cookies
The Clearminutes desktop application does not use cookies.
The Clearminutes website (clearminutes.app) uses the following cookies:
- Essential cookies: required for the site to function (e.g. your cookie consent preference). These are always active and cannot be disabled.
- Analytics cookies: set by PostHog only if you consent via the cookie banner. These cookies enable us to understand how visitors navigate the site. You can accept or decline these when the banner appears, and change your preference at any time.
We do not use advertising cookies, social media tracking pixels, or any third-party cookies beyond those described above.
11. Children's privacy
Clearminutes is not directed at children under the age of 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
12. International data transfers
DevBytesUK is based in the United Kingdom. Our service providers (Paddle and Resend, for the desktop app) may process data in countries outside the UK. Where such transfers occur, we rely on appropriate safeguards including standard contractual clauses or adequacy decisions to ensure your data remains protected to UK GDPR standards. The iOS app's In-App Purchase is processed by Apple under Apple's own terms; DevBytesUK holds no iOS payment data.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. Where changes are significant, we will notify active Pro subscribers by email. Continued use of Clearminutes after the effective date of any changes constitutes your acceptance of the updated policy.
14. Contact
For all privacy-related enquiries, data subject requests, or concerns, please contact us at support.clearminutes.app.