Privacy Policy
1. Who we are and our roles
This policy describes how Vetromar, a sole proprietorship operated by Leo Dries (“Vetromar,” “we,” “us”), handles personal data in connection with the Vetromar desktop application, cloud services, and the vetromar.com website (together, the “Service”). Contact: leo@vetromar.com.
We act in two distinct roles:
- Controller (in GDPR terms) for the data we need to run the business relationship: your account information, workspace administration data, billing records, service usage metering, emails we send you, and website interactions.
- Processor for Workspace Content — the meeting transcripts, ingested source content, and extracted knowledge your workspace stores through the Service. Our customer (the organization operating the workspace) is the controller of that content, including any personal data of meeting participants inside it. We process it only on the customer’s instructions, as described in this policy and our Terms of Service. If your personal data appears inside a customer’s Workspace Content (for example, you were a participant in a recorded meeting), please direct requests to that organization first; we will support them in responding.
2. Information we collect
Account and workspace data (we are controller)
- Account information: your name, email address, and password. Passwords are stored only as salted argon2id hashes — we never store or see your actual password.
- Workspace administration: workspace name, membership and roles, invites (stored as hashed tokens), and trial/subscription status.
- Billing: payments are processed by Stripe. Your card details go directly to Stripe and never touch our servers; we store only Stripe customer and subscription identifiers and the subscription status.
- Devices: a registry of the devices signed in to your workspace (an app-generated device identifier, a device name, and last-seen timestamps), used to replicate your workspace between your own devices.
- Usage metering: for the managed AI tier we record, per request, the workspace, provider, model, token counts, and audio duration. This is internal accounting for fair-use limits and cost — we do not log the content of AI requests for metering.
- Emails and logs: transactional emails we send (invites, password resets, billing notices) and standard operational server logs (timestamps, IP addresses, request metadata) kept for security and debugging.
Workspace Content (we are processor)
- Transcripts and derived knowledge: when your workspace syncs, the text of transcripts, content ingested from sources your team connected, and the structured knowledge extracted from them (units, entities, links, evidence quotes) are replicated to our cloud so your teammates’ devices can receive them.
- Audio: meeting audio stays on the device where it was recorded or imported — we do not store audio recordings on our servers. If cloud transcription is used, audio is streamed to the transcription provider, transcribed, and not retained by us.
Website
- The website collects only what you type into its forms (signup, invite acceptance, password reset). It sets no cookies and runs no analytics or advertising trackers (see Section 15).
3. How we use information
- To provide the Service: authenticate you, replicate Workspace Content between your team’s devices, transcribe and extract knowledge from content you submit, and operate team features. Legal basis: performance of a contract.
- To bill you: manage trials, subscriptions, and seats through Stripe. Legal basis: performance of a contract; legal obligations.
- To communicate: transactional email such as invites, password resets, trial reminders, and important service or terms updates. Legal basis: performance of a contract; legitimate interests.
- To secure and improve the Service: operational logs, abuse and fair-use limits, debugging. Legal basis: legitimate interests in securing and operating the Service.
- To comply with law where required. Legal basis: legal obligation.
We do not use your data for advertising, and we do not sell it (Section 7).
4. AI processing
The Service’s core function is processing your content with AI: speech-to-text transcription and language-model extraction and linking of knowledge. In the managed cloud tier this processing is performed through our AI subprocessors (Anthropic for language-model processing, Deepgram for transcription), under agreements that prohibit them from using your content to train their models. Content sent for processing is used to produce your results and is not retained by us beyond what Section 2 describes. The desktop application also offers a fully local mode in which transcription and extraction run entirely on your own machine and content is not sent to AI providers at all.
5. Service providers and subprocessors
We use a small set of providers to run the Service. Where they touch Workspace Content they act as subprocessors under data-protection law:
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Anthropic | Language-model processing (knowledge extraction and linking) in the managed AI tier | Text content submitted for processing | USA |
| Deepgram | Cloud speech-to-text transcription | Audio streamed for transcription; resulting transcripts | USA |
| Railway | Cloud hosting and database for the workspace service | Account data, workspace administration data, replicated Workspace Content | USA |
| Stripe | Payment processing and billing portal | Payment details (held by Stripe), billing identifiers | USA |
| Resend | Transactional email delivery | Email addresses and message content of service emails | USA |
| Vercel | Website hosting (vetromar.com) | Standard web-server request data | USA |
| GitHub | Distribution of app downloads and updates | Standard web-server request data when downloading | USA |
We will update this table when providers change; for notice of subprocessor changes under a DPA, contact leo@vetromar.com.
6. Local-first: what stays on your device
- Every device keeps its own local knowledge store; the app works against that local copy.
- Audio recordings never leave your device except transiently for cloud transcription, if enabled.
- Nothing is uploaded to our cloud until you sign in to a workspace and confirm that the device’s store should sync with it — a store previously bound to a different workspace asks before uploading anywhere new.
- In fully local mode, transcription and extraction run on your machine and content is not sent to our AI providers.
- Deleting your cloud workspace does not touch the local copies on your devices; those remain under your control (and your responsibility) to keep or delete.
7. What we don’t do
- We do not sell or rent personal data, and we do not “share” it for cross-context behavioral advertising (as those terms are defined in U.S. state privacy laws).
- We do not use Workspace Content to train AI models, and our AI providers are contractually barred from doing so.
- We do not run advertising, analytics trackers, or third-party cookies on the website or in the app.
- We do not access your Workspace Content except as needed to provide, secure, and support the Service, as you direct, or as required by law.
8. Retention
- Workspace Content: retained in the cloud for as long as the workspace exists, so it can sync to your team’s devices; deleted when the workspace is deleted (Section 9).
- Account data: retained while your account exists; deleted or anonymized when your account is deleted.
- Billing records: retained as long as required for tax, accounting, and legal purposes.
- Usage metering and operational logs: retained for a limited period for security, fair-use, and cost accounting, then deleted or aggregated.
9. Deletion and your controls
- Workspace deletion (admin): in the app (Workspace tab), a workspace admin can permanently delete the workspace. This immediately cancels the subscription and deletes the workspace’s replicated content, memberships, invites, devices, and related records from our cloud systems.
- Account deletion: any member can delete their own account from the app; this removes their account data and revokes their access. (A sole admin must first transfer or delete the workspace.)
- Member removal: admins can remove members, which immediately revokes the removed member’s access tokens.
- Password reset: available from the app and website; resetting revokes all existing sessions.
- For anything you cannot do in the app, email leo@vetromar.com.
10. Security
Measures we apply include:
- encryption in transit (TLS) for all traffic between the app, our cloud, and our providers;
- passwords stored only as salted argon2id hashes; session, invite, and reset tokens stored only as SHA-256 hashes, with expiry and single-use semantics where applicable;
- immediate token revocation when a member is removed or a password is reset;
- secrets kept out of client configuration files and stored with restrictive file permissions on your device;
- least-privilege access: our cloud service holds only the data listed in this policy, and card data never touches our servers.
No system is perfectly secure. If we learn of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
11. International data transfers
Our cloud systems and providers are located in the United States. If you use the Service from the EU, EEA, UK, or Switzerland, your data is transferred to the U.S. For such transfers we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses (and UK/Swiss equivalents) with our providers, and, where a provider is certified, the EU–U.S. Data Privacy Framework. A data processing agreement incorporating these safeguards is available on request.
12. Your rights — EU, EEA, UK, Switzerland (GDPR)
Where the GDPR (or UK/Swiss equivalents) applies and we act as controller, you have the right to access, rectify, erase, and receive a portable copy of your personal data; to restrict or object to processing (including any processing based on legitimate interests); and to withdraw consent where processing is based on consent. Exercise these rights by emailing leo@vetromar.com; we respond within one month. You also have the right to lodge a complaint with your local supervisory authority.
For personal data inside a customer’s Workspace Content, the customer is the controller — send requests to them first (Section 1); as processor, we will assist the customer in fulfilling them.
13. Your rights — U.S. states
Depending on your state (for example under the California Consumer Privacy Act as amended), you may have rights to know, access, correct, delete, and obtain a portable copy of your personal information, and to opt out of its sale or sharing. We do not sell or share personal information, and we collect only the categories described in Section 2 (identifiers, commercial information, and internet activity), for the purposes in Section 3. To exercise any right, email leo@vetromar.com. We will not discriminate against you for exercising your rights. Note that most Service data belongs to business accounts and is covered by our contract with your organization.
14. Children
The Service is for business use and is not directed to children. We do not knowingly collect personal data from anyone under 18 as a user of the Service. If you believe a child has created an account, contact us and we will delete it.
15. Cookies and tracking
The vetromar.com website sets no cookies and uses no analytics or advertising trackers. When you pay, Stripe’s checkout pages (hosted by Stripe) may use cookies as described in Stripe’s own privacy policy. The desktop application does not embed trackers.
16. Changes to this policy
We will update this policy as the Service evolves. For material changes we will give notice by email to workspace admins and/or in the app or on the website before the change takes effect. The “Last updated” date and version above identify the current policy.
17. Contact
Vetromar (operated by Leo Dries)
Email: leo@vetromar.com