Przejdź do treści
Diktavo Powrót na stronę główną
Wersje Historia zmian
English
Englishen Deutschde Françaisfr Españoles Italianoit Nederlandsnl Polskipl Portuguêspt Svenskasv Türkçetr Русскийru Українськаuk العربيةar हिन्दीhi Bahasa Indonesiaid 日本語ja 한국어ko ไทยth Tiếng Việtvi 中文zh

Privacy

Privacy Policy

Under the Swiss revDSG and the GDPR (for customers in the EU). Last updated: September 2026.

1. Data controller

Joshua Böhme, Poststrasse 4, 9443 Widnau, Switzerland. Email: support@diktavo.com.

2. Principle: local processing

Diktavo's speech recognition runs entirely on the user's device. Audio recordings themselves are never transmitted to us or to any third party and stay exclusively on the user's PC; the conversion of speech to text takes place exclusively locally. The text produced by a dictation likewise stays local, unless the user is signed in with a user account: in that case the app transmits the dictation history to synchronize it between the devices of the same account (see Section 3, "History synchronization"). Also excluded from local processing are the other connections listed in Section 3 (in particular license verification, the user account, and optional services); apart from the dictation history mentioned above, none of these transmit audio recordings or recognized text. A further exception is feedback the user actively sends themselves if they attach a screenshot to it: depending on its content, that screenshot may also show dictated text.

3. What data we process

  • License verification: On activation and at regular checks, the app transmits the email address, license key, and a pseudonymous device identifier (a hash derived from hardware characteristics, not a plain name) to our license server (Cloudflare). Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • User account: On registration and sign-in we process the email address, a password hash (never the plaintext password), session data for signed-in devices (device name, pseudonymous device identifier, and the app version installed on that device), and, if enabled, the two-factor setting. When signing in via Google, we receive the email address from Google. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Account lock for abuse: On reasonable suspicion of abuse, in particular a violation of Section 2 of the Terms, the operator can lock an account instead of deleting it; the lock is reversible at any time and affects only sign-in, not any stored dictations. We store a timestamp of the lock together with an internal note of the reason; that note is intended solely for the operator, and a locked sign-in is only told that it is locked, not why. Setting and lifting a lock are additionally recorded with a timestamp in the operator's internal action log (see "IP block for abuse" below for its retention). Legal basis: legitimate interest in preventing abuse (Art. 6(1)(f) GDPR / Art. 31 revFADP).
  • Account settings: So that Diktavo behaves the same way across several devices of the same account, we store operating settings such as keyboard shortcuts, language selection, paste behavior, and sound and theme choices. Not transmitted are the performance metrics measured on the respective device. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • History synchronization: If the user is signed in, the app transmits the dictation history (the dictated text), including entries moved to the trash, and usage statistics to our server shortly after each dictation, so that the history is available on all devices of the same account. Deleted dictations stay in the trash and are removed for good after 30 days, on the server as well. Transmission is encrypted (TLS); storage takes place server-side, not end-to-end encrypted. The transmitted text is processed exclusively for this purpose and is not shared with third parties. Synchronization is tied to being signed in to the account. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Dictionary synchronization: If the user is signed in, the app synchronizes the personal dictionary (custom replacements, learned terms, blocked words) between the devices of the same account. Transmission is encrypted (TLS); storage takes place server-side, not end-to-end encrypted. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Word count (usage volume): For signed-in users we transmit the number of dictated words (only the count, never the dictated text itself), to determine and enforce the scope of the free plan (3,000 words per week) or Pro access. This happens independently of leaderboard participation. From the IP address of that report we derive the country and store it with the account; the IP address itself is not stored. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Leaderboard (optional): If the user additionally opts into the leaderboard, we make their word count publicly visible under a self-chosen display name and their country. What is optional here is the public display, not the collection of the country (see "Word count"). Dictated text is never transmitted for this purpose. Participation can be switched off at any time in the settings; the word count is then no longer shown publicly but continues to be counted for usage determination. Legal basis: consent (Art. 6(1)(a) GDPR).
  • Feedback (optional, signed-in users only): If the user sends feedback from within the app, we transmit the text they entered, the app version, the configured language, and, if they choose to attach them in the dialog, up to three screenshots. An email address is only transmitted if the user enters it themselves in the field provided for that purpose.
    The content is already encrypted on the user's device and is readable only by the operator. It is held encrypted at Cloudflare until the operator retrieves it, for at most twelve months, after which it is automatically deleted. After retrieval, the feedback is held exclusively locally by the operator. Screenshots are re-encoded before being sent, which strips metadata such as location information. Legal basis: consent (Art. 6(1)(a) GDPR).
  • Error and usage data (optional): If a signed-in user explicitly opts in in the settings (default: off, revocable at any time, with no downside for functionality or scope), the app transmits, on an error, its exception message, and, independently of that, small usage metrics (e.g. runtimes, counters), together with the app version in either case. Dictated text, text excerpts, or word lists are never transmitted for this purpose. Legal basis: consent (Art. 6(1)(a) GDPR).
  • IP addresses (rate limiting): For technically limiting how often requests can be made, we process IP addresses briefly; for this purpose they are always hashed with a secret server key and are never stored in plaintext or shown in responses or persistent logs. For the separate, narrower exception used for a targeted block, see "IP block for abuse" below. Legal basis: legitimate interest in preventing abuse (Art. 6(1)(f) GDPR / Art. 31 revFADP).
  • IP block for abuse (optional, only on active suspicion): So that an address can be blocked in a targeted way, we log, on every sign-in and registration, the IP address together with the time and outcome (sign-in, registration, or failed attempt); this entry is automatically deleted after 30 days. Where there is active suspicion of abuse, the operator can block an address for a limited period; unlike the rate limiting above, the address is then stored in plaintext (not hashed), because a block requires a reversible address. An internal reason is optional and is not disclosed to the person affected; the response only states that access was blocked, never why or for how long. A block lasts at most one year and is then lifted automatically; an already-expired block remains visible in the database for up to 90 more days for traceability and is then deleted automatically. If the operator lifts a block explicitly beforehand, the address is deleted immediately. Setting or lifting a block is, like every operator action, additionally recorded with the address in the internal action log, which is deleted automatically after 365 days. Legal basis: legitimate interest in preventing abuse (Art. 6(1)(f) GDPR / Art. 31 revFADP).
  • Purchase/payment: Handled by our merchant of record, Polar Software Inc., which processes billing and payment data as an independent controller.
  • Website: Cookieless traffic measurement (Cloudflare Web Analytics), no cookies, no personal profiling, no IP storage. Legal basis: legitimate interest in traffic measurement (Art. 6(1)(f) GDPR / Art. 31 revFADP). For selected campaign links, we also count only daily landing-page visits and download-link clicks under a random campaign ID. We do not store IP addresses, Reddit usernames, content, cookies, or any connection to a Diktavo account for this measurement.
  • Beta waitlist: While the download is temporarily paused, you can join the beta waitlist. We then process your email address, your chosen language, and the timestamps of sign-up, confirmation (double opt-in), and any unsubscribe. The sole purpose is a one-time notification once the beta starts; after signing up you receive a confirmation email with a link, and the address stays inactive until you click it. You can unsubscribe at any time via the link in every email. Legal basis: consent (Art. 6(1)(a) GDPR / Art. 6(6) revFADP). Deletion at the latest when the beta starts, immediately on unsubscribe.

4. Disclosure / processors

Data processors (under a data processing agreement per Art. 28 GDPR): Cloudflare, Inc. (license infrastructure, downloads, website) and Resend (delivery of system emails such as confirmation, password reset, and notices; it processes the email address for that purpose). Independent controller: Polar Software Inc. (purchase/payment/billing); its privacy notices additionally apply in that respect. Insofar as data is transferred to the United States (Cloudflare, Resend, Polar), this takes place on the basis of the EU Standard Contractual Clauses or a valid adequacy mechanism.

5. Retention period

License data for the duration of the contractual relationship plus statutory retention periods. Account, settings, and leaderboard data for the duration of the account; once the account is deleted, this data is removed, including any feedback not yet retrieved by the operator. Feedback is retained for up to twelve months after being handled, to help identify recurring issues; screenshots attached to it are deleted after three months. The sign-in log kept for the IP block is deleted automatically after 30 days, error and usage data after 90 days; an IP block at the latest 90 days after it expires, or immediately if lifted explicitly. An account lock persists until it is lifted or the account is deleted; either also deletes the sign-in-log and error/usage data tied to that account. The operator's internal action log (who set or lifted an account or IP block, and when) is deleted automatically after 365 days.

6. Your rights

Access, rectification, erasure, restriction, objection, withdrawal of consent, and data portability. Requests to support@diktavo.com. Customers in the EU also have the right to lodge a complaint with a data protection supervisory authority. In Switzerland, the Federal Data Protection and Information Commissioner (FDPIC) is responsible.

Dieser Rechtstext liegt nur auf Deutsch und Englisch vor. This legal document is only available in German and English. Deutsch · English

Powrót na stronę główną
Diktavo

Dyktowanie na urządzeniu dla Windows. Twój głos, od razu zapisany i nigdy nie wysyłany dalej.

Produkt

Jak to działa Funkcje Ceny FAQ PobierzDołącz do bety Wszystkie wersje

Informacje prawne

Nota prawna Prywatność Regulamin Prawo odstąpienia Licencje

Kontakt

support@diktavo.com
Copyright Joshua Boehme · Dyktowanie na urządzeniu Diktavo · Na urządzeniu · Prywatne z założenia