Privacy Policy
Last updated 23 July 2026
Who we are
Crimble is a meeting recording and transcription tool. This policy explains what we collect when you use the desktop app and this website, why we collect it, and the choices you have. If anything here is unclear, email us at [email protected].
What we collect
Account information: your name, email address, and the credentials you use to sign in.
Recordings and derived data: the audio you record, along with the transcripts, summaries, and speaker labels the pipeline produces from it.
Voice data: to recognize speakers, we compute a mathematical representation (a voice embedding) of each speaker's audio and match it against the people you have named. This is biometric data and we treat it as sensitive.
Google Calendar data (optional): if you choose to connect a Google account, we request read-only access to your calendar and store your upcoming events (such as titles, times, and attendees) so we can show them in the app. We only read this data; we never create, edit, or delete your calendar events.
Team data: if you create or join a Team, we store the organization name, your membership and role, invitations, and the email addresses needed to send and manage those invitations.
Billing data: we store your plan, subscription status and dates, provisioned seat count, voucher redemptions, and identifiers that connect your Crimble account or Team to Stripe. Stripe collects and processes your billing name and address, tax information, payment method, invoices, and payment history. Crimble does not receive or store your complete card number.
Usage and diagnostic data: basic logs needed to operate the service, diagnose errors, and keep your account secure.
How we use your data
We use your recordings and derived data to provide the core product: transcribing meetings, attributing speech to speakers, recognizing people you have confirmed, and generating summaries.
We use voice embeddings only to match and recognize speakers within your own account. A person's voice data is enrolled only when you explicitly confirm a match.
We use account and diagnostic data to authenticate you, operate the service, and troubleshoot problems.
We use Team and billing data to provide organization membership, determine access to paid features, calculate seat capacity, apply vouchers, administer subscriptions, support customers, prevent abuse, and meet accounting, tax, and legal obligations.
We do not sell your data, and we do not use your recordings or voice data to train third-party models.
Google user data
If you connect a Google account, Crimble requests only the read-only Google Calendar scope (calendar.readonly). We use the calendar data you share for a single purpose: to show your upcoming meetings in the app and remind you to record when one is about to start.
Crimble's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell your Google data, do not use it for advertising, and do not use it to train generalized or third-party AI or machine-learning models. We do not share it with third parties except as needed to provide these features or as required by law.
We protect Google user data with the safeguards set out in the section below on how we protect your data. In short: it is encrypted in transit, it is readable only by your own account, it is held on infrastructure that is not reachable from the internet, and the OAuth tokens that let us read your calendar stay on our server and are never sent to your device.
You can disconnect a Google account at any time from the app's settings. When you disconnect, we delete the stored access and refresh tokens and remove the calendar events we synced for that account. You can also request deletion of this data by emailing [email protected].
Teams and invitations
People in the same Team can see member names, email addresses, and roles. Team owners and administrators can also see pending invitations, invite and remove members, and manage the Team's subscription and seats.
Joining a Team gives you paid access through that Team, but it does not give other members access to your private meetings, transcripts, saved people, recordings, or connected calendars. Those remain scoped to your own account.
Invitation emails contain the Team name and a link needed to review and accept the invitation. We use the invitee's email address to deliver and manage that invitation and related account access.
How we protect your data
We treat your recordings, transcripts, voice data, and connected Google Calendar data as sensitive, and protect all of it with the following measures.
Encryption in transit: every connection between the desktop app, this website, and our API is encrypted with TLS (HTTPS). Sensitive data is never transmitted over an unencrypted connection.
Encryption at rest: audio files are stored in object storage that encrypts every object at rest (Cloudflare R2), and our database backups are encrypted before they leave our server and are held offsite in that encrypted form. Our primary database runs on dedicated hardware that is not reachable from the internet, protected by the access controls and network isolation described here.
Access control and isolation: every product record carries the identifier of the user it belongs to, and every query is filtered by it, so no account can read another account's meetings, transcripts, saved people, or calendar events. The channel that syncs your library to the app for offline reading is scoped on the server: the app can only narrow what it is already entitled to, and can never widen that scope, request a different table, or ask for extra columns. Voice embeddings, payment identifiers, and internal storage keys are excluded from that channel entirely.
Protection of Google tokens: the OAuth access and refresh tokens for a linked Google account are stored server-side only. They are never sent to your device, never included in the data that syncs to the app, and never returned by our API. They are deleted when you disconnect the account or delete your account.
Credentials and secrets: passwords are stored hashed, never in plain text, and sign-in endpoints are rate limited to slow down brute-force attempts. Application secrets and third-party API credentials live in a dedicated secrets manager, and are never committed to source control or baked into application images.
Network isolation: our database, job queue, and sync engine are not reachable from the internet. They listen only on an internal network behind our authenticated API, which is the sole entry point to your data. The only publicly reachable services are the TLS-terminating web edge and administrative SSH, which is key-based only with password login disabled.
Data minimization and secure disposal: we delete the full meeting recording from storage as soon as processing finishes. We keep one short voice sample per speaker so you can review speaker recognition, and that sample is deleted automatically after seven days. Deletions are permanent, not soft-deleted flags.
On your device: the copy of your library cached locally for offline reading is wiped when you sign out, and is replaced if a different account signs in on the same machine.
Operational safeguards: access to production systems is limited to the people who operate the service, is authenticated with keys rather than passwords, and is used only to run and support the product. Servers receive automatic security updates, and we keep encrypted offsite backups so your data can be restored after a failure.
Service providers
We rely on a small number of processors to run the pipeline, including hosted transcription and diarization models and cloud infrastructure for storage and compute. These providers process data on our behalf under contract and are not permitted to use it for their own purposes.
Stripe processes checkout, payment methods, subscriptions, invoices, billing addresses, and tax information for us. Stripe receives the information you enter during checkout and may process it under its own privacy policy as an independent controller where required by law. We receive subscription and payment status, limited billing details, and Stripe identifiers needed to provide and support your plan.
Cookies and analytics
On this website we use PostHog, a product analytics tool, to understand how the site is used, such as which pages are visited and which buttons (like sign up or download) are clicked. Our PostHog instance is hosted in the European Union.
Analytics starts when you visit this website and continues unless you select Decline in the cookie banner. Declining stops future analytics tracking and is remembered in your browser's storage. Selecting Accept keeps analytics enabled. You can bring the banner back at any time by clearing this site's data in your browser.
Our analytics is deliberately minimal and content free. We do not use session recording or automatic click capture, and we never send your recordings, transcripts, summaries, voice data, payment details, voucher codes, Team names, or anything you type to analytics. We collect anonymous page views and a small set of product events, such as signing up, starting a download, requesting checkout, reaching Stripe Checkout, or applying a type of voucher. We record the voucher type, never the code.
If you sign in on this website, we associate these analytics events with your account identifier, never your email address, so we can understand how signed-in people use the product.
Retention and deletion
We keep only what the product needs. The full audio recording is deleted from storage as soon as a meeting finishes processing, and the short per-speaker voice sample kept for review is deleted automatically after seven days. Your transcripts, summaries, and saved people are kept for as long as your account is active, so your library stays readable.
Google Calendar data is kept only while a Google account is connected. Disconnecting it deletes the stored tokens and the synced events. Team invitation and membership records are kept while needed to administer Team access, resolve account issues, and meet operational or legal obligations.
Subscription, invoice, payment, voucher, and related accounting records may be kept after cancellation or account deletion for the periods required by tax, accounting, fraud-prevention, dispute, and other legal obligations. Stripe retains the billing and payment data it controls under its own retention rules.
You can ask us to delete specific meetings, your Google data, or your entire account, including the associated voice data, by contacting [email protected]. Deleted product data is removed from our live systems, and encrypted backups containing it age out within six months under our backup retention schedule. We may retain the limited billing or legal records described above where deletion is not legally permitted or required.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to withdraw consent for processing your voice data. To exercise any of these, contact [email protected].
Changes to this policy
We may update this policy as the product evolves. When we make a material change, we will update the date above and, where appropriate, notify you.
Contact
Questions about privacy? Email [email protected].