Privacy Policy

v1.0 · Last updated May 24, 2026

Attesta records what you ask it to, transcribes it, and gives you back a structured summary. This page describes exactly what data Attesta handles, how, and on whose servers.

We wrote this from scratch against the actual code. It is not boilerplate. If you find an inconsistency between this page and the app, write to legal@attesta.cc.


The three load-bearing promises

  1. Audio capture, on your tap — never in the background.
  2. Audible signature tone — every recording begins with a clearly audible tone so anyone nearby knows.
  3. Private to your account — recordings stay tied to your account, are never shared, and are never used to train AI.

Every claim below either reinforces or constrains these three statements. If we ever change them, this policy changes first.

What Attesta is

A paid iOS, iPadOS, and macOS app that:

  1. Records audio when you tap the Record button on your device.
  2. Uploads the recording to our backend for transcription and structured-summary generation.
  3. Returns the transcript and summary to your device.
  4. (Pro only) Keeps a server-side copy so the recording shows up on your other devices.

You sign in with Apple or Google. Sign-in is required to record because we meter usage per account.

What we collect

Account information

Recording data

Device information (technical, no extra permissions required)

We collect this to support you and to mitigate abuse. It is never shared outside the service providers listed below.

Purchase information

We do not see your credit card. Apple handles all payments.

What we don’t collect

What we never do

Service providers (sub-processors)

Attesta runs on third-party infrastructure. Each provider sees only the data it needs for its part of the work. None of them train on your data under our contracts with them.

ProviderWhat they handle
Apple Inc.Sign in with Apple, StoreKit subscriptions and in-app purchases, App Store distribution
Google LLCSign in with Google
Supabase Inc.Our backend — Postgres database, authentication, audio file storage
Deepgram Inc.Cloud speech-to-text — your audio is sent here for transcription
Anthropic PBCThe language model that turns your transcript into the structured summary
Cloudflare Inc.Domain (attesta.cc), DNS, email routing for our public addresses

If we add or change a provider, we update this list before the change goes live in the app.

Where data lives

Retention

DataHow long we keep it
Audio files (Pro)Until you delete the recording, downgrade from Pro, or delete your account
Transcripts and summaries (Pro)Same as above
Account profileUntil you delete your account
Purchase receiptsAs long as required for accounting (typically 7 years per tax law)
Free recordings (server side)Not retained

If you downgrade from Pro to free, server-side audio files are deleted within 30 days. The transcripts and insights on your device are unaffected.

Your rights

You can:

If you’re in the EU/UK (GDPR), California (CCPA), India (DPDP), or anywhere with similar rights, the rights above apply to you. You can also write to legal@attesta.cc with any specific request (data export, correction, restriction of processing). We respond within 30 days.

Children

Attesta is not designed for users under 13. We do not knowingly collect data from anyone under 13. If you believe a child is using Attesta, write to legal@attesta.cc and we will close the account and delete the data.

Changes

We will update this page when our behavior changes. The “Last updated” date at the top is the source of truth. Material changes will be announced in-app before they take effect.

Contact

legal@attesta.cc