SSARvent — Privacy Policy
This Privacy Policy explains how the SSARvent application for Windows, Android and iOS (the "App") handles information. The App is published by Solution Area Software SRL, a Romanian limited liability company with its registered office at Str. Eugen Ionesco nr. 67, Cluj-Napoca, Cluj, Romania, registered with the Trade Register under no. J2024033375002, CUI (tax ID) 50742006 ("we", "us", the "Publisher").
SSARvent is a personal assistant that helps you remember and review conversations you take part in (transcript, notes) and suggests possible replies. It is intended for personal, non-professional use. It is not a medical device and is not intended for any medical or health-care purpose.
Summary
- We collect nothing. The App has no server, no analytics, no advertising, no tracking and no crash-reporting services. Accounts you create in the App exist only on your device (see section 1A). We never receive your audio, transcripts, notes, evaluations, exports or API keys.
- Your data stays on your device, except the text the App sends directly from your device to the AI provider you choose, using your own API key, so that it can suggest answers and evaluate the conversation.
- You are in control: you choose the provider, you can delete sessions at any time, sessions are deleted automatically after a number of days you choose (30 by default), and "Delete all data" wipes everything.
- You are responsible for telling the people you talk to and getting their consent. See section 4.
1. What the App processes, and where
| Data | Where it is processed | Leaves your device? |
|---|---|---|
| Audio of the conversation | On your device. Windows: headset playback ("loopback") and your microphone, transcribed locally by an open-source Whisper speech model. Android/iOS: microphone only, transcribed by the operating system's speech recognizer. Audio is not saved to disk by default. | Normally no (see 1.1 for exceptions you control) |
| Transcript text | Shown in the App and saved on your device | Recent transcript excerpts are sent to your chosen AI provider to suggest answers and to create the evaluation |
| "About me" notes you type in Settings | Saved on your device | Sent to your chosen AI provider together with the transcript, as context |
| Suggested answers, summary, evaluation, scores | Received from your AI provider, saved on your device | No |
| Exports (Markdown/text files) | Created on your device | Only if you share them (e.g. by email or cloud drive) |
| API key | Android: encrypted with an Android Keystore key. iOS: Keychain, this device only, accessible only when unlocked. Windows: the .env configuration file in your per-user installation folder. |
Sent only to your chosen AI provider, to authenticate your requests. Never in logs, exports or backups. |
| Settings (language, provider, model, auto-delete, app lock, terms acceptance version) | On your device | No |
1.1 Exceptions you control.
- Operating-system speech recognition (Android/iOS). The App asks the operating system to recognise speech on the device when your device supports it. If on-device recognition is not available for the selected language, the operating system may use its own online speech service (Google on Android, Apple on iOS), under Google's or Apple's privacy policies. You can usually avoid this by downloading the offline speech/language pack for your meeting language in your device settings (see the User Guide).
- Windows optional features. If you enable cloud transcription, audio is sent to your chosen provider for transcription instead of being transcribed locally. If you use the option to open a question in ChatGPT or Claude in your browser, the text is passed to that website under your own account there.
- First-run model download (Windows). On first use, the Windows App downloads the Whisper speech model from Hugging Face (huggingface.co). This is a normal file download; Hugging Face receives the technical information that any website receives (such as your IP address), but no meeting content.
- Opening links. Buttons such as "Get a key" open your provider's website in your browser.
1A. Accounts and sign-in
The App lets you create an account so that several people can use it on the same device, each with a role (the first account is the administrator). On iOS you can also continue without an account.
- Where accounts are stored: only on your device, encrypted (Windows: DPAPI; Android: Android Keystore; iOS: Keychain and iOS Data Protection). Account data is your email address, display name, role, the sign-in method used, and, for email accounts, a salted password hash (never the password itself). We never receive it.
- Sign in with Google, Microsoft or Apple: the provider's own sign-in page opens in your browser or the system sign-in sheet. The App receives only your account identifier, name and email address from that provider, to create or find your local account. The provider's privacy policy applies to the sign-in itself. The App does not keep the provider's access tokens.
- Deleting your account: use Settings › Account › Delete account in the App (on Android the option is called "Delete my account"). This removes the account, and the sessions that belong to it, from the device. "Delete all data" (section 6) removes every account and all data of the App on that device. A web page describing the steps for each platform is at https://www.ssarvent.com/account-deletion.html.
If a future version stores accounts on a server operated by the Publisher, this policy will be updated before that happens, and you will be asked to agree.
2. What the Publisher collects
Nothing. Specifically, the Publisher:
- does not operate any server that the App talks to;
- does not create user accounts or ask for your name, email or phone number;
- does not use analytics, telemetry, advertising identifiers, tracking pixels, fingerprinting or crash-reporting SDKs;
- does not sell, rent or share any data, because it does not have any.
If you contact us by email (for example for support), we receive your email address and whatever you write. We use it only to reply, keep it only as long as needed for that purpose (and any legal obligations), and do not use it for marketing. Please do not send us transcripts or API keys.
App stores and download sites (Apple App Store, Google Play, Microsoft Store, or the website you download from) process data about your download and purchases under their own privacy policies. We may receive aggregated, anonymous statistics from them (such as the number of installs per country), which do not identify you.
3. Legal roles (who is responsible for what)
3.1 You. The App is a tool that runs on your device under your control. When you use it to transcribe a conversation, you decide whether, when and why personal data of other people (their voices and words) is processed, and which AI provider receives it. Where data-protection laws such as the GDPR apply, you are the controller of that data, unless your use is purely personal or household activity, in which case the GDPR may not apply to you (Article 2(2)(c) GDPR, interpreted narrowly). The App is intended for personal, non-professional use; if you use it for professional or business purposes (for example meetings at work or calls with clients), you, or the organisation you act for, are the controller of the other participants' personal data and bear sole responsibility for complying with the GDPR (see section 4A of the Terms of Use). You are responsible for informing the other participants, having a lawful basis (usually consent), honouring their rights, and deleting the data when it is no longer needed.
3.2 The Publisher. Because the Publisher never receives, stores or has access to meeting content or API keys, the Publisher is neither a controller nor a processor of that content. The Publisher only provides software. (If you email us, we are the controller of your email for the purpose of replying.)
3.3 Your AI provider. The AI provider you choose receives the text you send under your own account and its own terms. It acts as an independent controller, or as your processor where its terms say so (for example under a data processing addendum that you accept with that provider). Its privacy policy applies:
- OpenAI — https://openai.com/policies/privacy-policy/ (API data: https://openai.com/enterprise-privacy/)
- Anthropic — https://www.anthropic.com/legal/privacy
- Google (Gemini API) — https://policies.google.com/privacy and the Gemini API Additional Terms https://ai.google.dev/gemini-api/terms. Note: according to Google's terms, on the Gemini API free tier Google may use the content you submit (prompts and responses) to provide, improve and develop its products, and human reviewers may read it. The free tier is not available to users in the European Economic Area, Switzerland and the United Kingdom; there, only the paid (billing-enabled) tier may be used. Wherever you are, do not send confidential or personal information through a free-tier key.
- DeepSeek — https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html. Warning: DeepSeek states that it processes and stores data on servers in the People's Republic of China. China is not recognised by the European Commission as providing an adequate level of data protection. Do not use DeepSeek for conversations involving other people's personal data, work information or anything confidential unless you have assessed this transfer and have a lawful basis.
- Custom/other providers (for example Groq, OpenRouter, or a self-hosted model): the privacy policy of that service applies; a self-hosted model on your own computer or network keeps data under your control.
We encourage you to check your provider's data-retention and training settings (for example, whether API data is used for training, and how long it is kept for abuse monitoring) before you use it.
4. Other people in your conversations
The App processes the voices and words of other people. Before you use the App, tell everyone that the conversation is being transcribed by an AI assistant and that text is sent to an AI provider, and obtain their consent where required. The App reminds you before every session and you must confirm the reminder to start. A ready-to-use notice in 9 languages is provided in consent notice. If someone objects, stop the session. People who were recorded can ask you to access or delete what you captured; you can do this by deleting the session in History.
5. Children
The App is not intended for children. You must be at least 18 years old to use it. We do not knowingly process any children's data — we do not process users' data at all. Do not use the App to transcribe conversations with children unless you have the consent of their parents or guardians and the law allows it.
6. Retention and deletion
- Sessions (transcripts, answers, evaluations) are kept on your device until you delete them, or until auto-delete removes them after the number of days you choose in Settings (default 30 days on Android and iOS).
- Delete one session: History → open the session → Delete.
- Delete everything: Settings → Delete all data. This removes all sessions, notes, settings and the stored API key from the App.
- Delete your account: Settings → Account → Delete account (see section 1A).
- Uninstalling the App removes its private storage on Android and iOS. On Windows, the uninstaller
removes the program, the local accounts database, the configuration file with your API key (
.env) and the app state; your saved meetings (themeetingsfolder) and yourcontext.mdnotes in the installation folder are kept on purpose, and you can delete them manually. - Exports you saved or shared outside the App are not deleted by the App; delete them yourself.
- Data sent to your AI provider is kept according to that provider's policy. Delete it there, or contact the provider, if needed.
- Backups: on Android, the App opts out of cloud backup and device-to-device transfer; on iOS, the API key is stored "this device only" and is not included in backups.
7. Security
The App is designed to keep your data safe on your device:
- no backend: there is no central database to breach;
- HTTPS (TLS) for all connections to AI providers; plain HTTP is not allowed on mobile (on Windows it is
allowed only for a model running on your own computer,
localhost); - API keys in the operating system's secure storage on mobile, never written to logs or exports;
- data at rest: iOS file protection "Complete" (encrypted while the device is locked); Android app-private storage encrypted with an AES-GCM key held in the Android Keystore;
- optional app lock with biometrics or device passcode;
- no hidden or background recording: a visible indicator is shown while listening, plus the operating system's microphone indicator / notification on mobile;
- minimal permissions (microphone, speech recognition on iOS, internet, notifications and a microphone foreground service on Android).
No system is completely secure. Your data is only as safe as your device: use a screen lock, keep your operating system up to date, and do not share your API key. See the SSARvent security documentation for details.
8. International transfers
The App itself does not transfer data anywhere. When you use an AI provider, you send data to that provider, which may process it in other countries (for example the United States for OpenAI, Anthropic and Google, and China for DeepSeek). The provider's terms and transfer mechanisms (such as the EU–U.S. Data Privacy Framework or Standard Contractual Clauses, where the provider offers them) govern that transfer. Choose a provider whose data locations and safeguards are acceptable for the conversation.
9. Your rights
Because the Publisher holds no data about you, most rights are exercised directly on your device:
- Access / portability: open any session in History or export it (Markdown/text).
- Rectification: edit your "About me" notes and settings at any time.
- Erasure: delete a session, use "Delete all data", or uninstall the App.
- Withdraw consent / object: stop using the App or a provider at any time; revoke your API key at the provider.
- Data held by your AI provider: contact that provider using the links in section 3.3.
If you contact us by email, you have the rights of access, rectification, erasure, restriction, objection and portability regarding that correspondence, under the GDPR where it applies. You can also lodge a complaint with a data-protection supervisory authority — in Romania, the ANSPDCP (https://www.dataprotection.ro/), or the authority in your country of residence.
10. Permissions the App asks for
| Permission | Platform | Why |
|---|---|---|
| Microphone | All | To hear the conversation, only while you have started a session |
| Speech recognition | iOS | To convert speech to text with Apple's recognizer (on-device when supported) |
| Internet | All | To send text to your AI provider |
| Notifications | Android 13+ | To show the mandatory "SSARvent is listening" notification |
| Foreground service (microphone) | Android | To keep listening while the screen is off or you switch apps, always with a visible notification |
| Biometrics / device credential | Android, iOS | Only if you turn on the optional app lock |
| Audio devices (loopback + microphone) | Windows | To capture headset playback and your microphone during a session |
The App does not request access to contacts, location, photos, calendars, phone calls or call logs.
11. Changes to this policy
We may update this policy. The version and effective date are shown at the top. If we make material changes, the App will show the new version and ask you to accept it before you continue. Because we do not have your contact details, we cannot notify you by email.
12. Contact
- Solution Area Software SRL
- Address: Str. Eugen Ionesco nr. 67, Cluj-Napoca, Cluj, Romania
- Trade Register no.: J2024033375002
- CUI (tax ID): 50742006
- Email: solutionareasoftware@gmail.com
- Website: https://www.ssarvent.com/