Privacy Policy
Your thoughts are yours. Here is exactly how we handle them, who else touches them, and how to take all of it back.
Last updated 4 August 2026
UTTER IN turns something you say or type into a plan you approve. That means we handle the things you tell it, and this page says what happens to them. It is written to be read, not to be survived.
1. Who we are
UTTER IN is operated from Kuwait. We decide what happens to the personal data described on this page, which under the GDPR makes us the data controller for it. You can reach us through the contact form, which is the only contact route we publish.
2. What we collect
What you capture. The text you type and the voice recordings you make, the transcript produced from a recording, and the structured results you approve — dates, times, names you mention, categories, reminders, and links you save.
Your account. Your email address, a display name if you set one, your language and your timezone. Your timezone is load-bearing rather than cosmetic: every date in the product is resolved against it.
Your plan. Which plan you are on, how many captures and voice minutes you have used in the current period, and a payment reference from PayPal. We never see or store your card or bank details — those stay with PayPal.
Running the service. The devices you have allowed to receive notifications, and the ordinary server records our hosting produces while serving a request. We do not run analytics, tracking or advertising code of any kind — there is none on this site and none in the app. If you joined the waiting list before signing up, your IP address was stored only as a salted one-way hash, to stop the same person submitting a thousand times; the original address is not kept.
3. Why we use it, and on what legal basis
The GDPR requires us to name a lawful basis for each purpose rather than one for everything. Ours:
Running your account, understanding your captures, and delivering the reminders you approved
Performance of our contract with you
This is the service you signed up for. Without this data there is no product to deliver.
Taking payment and keeping the records tax law requires
Contract, and legal obligation
Keeping the service secure, preventing abuse, and fixing faults
Our legitimate interests
Our interest is in a service that stays up and is not abused. You can object to this at any time and we will consider it against that interest.
We do not use what you capture to train AI models, ours or anyone else’s, and our agreements with the providers in section 5 say the same. If that ever changes it will be something you opt into, and it will not be buried in an update to this page.
4. How the AI part works
When you record something, the audio is sent to a speech-to-text provider and comes back as a transcript. The transcript is then sent to an AI provider that proposes a structure for it — what the action is, when it is, who is involved. If you typed instead of speaking, only the second step happens.
The AI never acts. It proposes, and nothing is saved, scheduled or sent until you approve it on screen. That is the central rule of how this product is built, and it is the reason an AI mistake costs you a tap rather than a missed appointment.
We do not use AI to make decisions about you that have legal or similarly significant effects, and there is no profiling of you as a person. The AI reads the sentence in front of it and nothing else about you.
5. Who else receives your data
We use other companies to run the service. Each one is contractually bound to process your data only on our instructions, and none of them may use it for their own purposes.
That is the whole list. There is no analytics provider, no advertising network and no tracking company on it, because we do not use any.
If you turn on notifications in a browser, your browser’s own push service — Google, Mozilla or Apple, depending on the browser — delivers the notification. We cannot see or choose that route; it is part of how your browser works.
If you turn on reminders in the iPhone app, your phone gives us a notification token for that device. It identifies the phone, not you, and it is the only thing we hold about the device. We hand each reminder to Expo, which passes it to Apple’s notification service, which delivers it. Turning the switch off in the app removes the token.
We do not sell your personal data, and we do not share it for advertising. We never have.
6. Where your data goes
We are based in Kuwait and the companies above are in the United States, India and the European Union. Kuwait does not have an adequacy decision from the European Commission, and neither do some of the countries listed.
Where we send data from the European Economic Area or the United Kingdom to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses with each provider, and on the EU–US Data Privacy Framework where that provider is certified under it. You can ask us for a copy of the safeguards that apply to any particular provider through the contact form.
7. How long we keep things
Voice recordings: at most 24 hours, and usually minutes. The recording is deleted the moment you have finished reviewing what came out of it. If you never come back to it, a job that runs every hour deletes it once it is 24 hours old. The transcript stays, because the transcript is what you asked us to keep. This is the promise we take most seriously — keep the meaning, not the recording.
Everything else: until you delete it. Your captures, plans and reminders stay until you remove them or close your account. Something you delete goes to a trash you can restore from for 30 days, and is then gone for good.
Payment records: as long as tax law requires. Records of what you paid and when are kept after you close your account, because we are required to keep them. They contain no capture content.
Support messages: up to 24 months after your question is resolved.
8. Nobody here reads your captures
The database refuses it. There is an internal administration screen — it exists so we can answer billing questions and see whether the service is healthy. It connects to our database as a restricted account that has no permission to read the tables holding your captures, transcripts, plans, reminders, people or saved links. Not restricted by a setting someone could change on a screen: the permission was never granted, so a request for that data comes back refused.
That includes the founder. There is no administrator override, no “view as this user”, and no consent-gated exception — because an exception that exists is an exception that gets used. What the account is — your plan, your payments, how much of your monthly allowance you have used — is a different question from what you said, and only the first is visible.
It has a real cost and we accept it deliberately: if you write to support about a specific capture, we can only work from what you choose to tell us or paste to us, because we cannot look it up. We would rather be slower at support than able to read your life.
9. Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, object to processing we base on our legitimate interests, or hand it to another service in a portable form. If we ever rely on your consent for something, you can withdraw it at any time without affecting what happened before.
Most of these do not need us at all. You can edit or delete any capture, plan or reminder yourself, and you can delete your entire account from Settings — which removes your captures, plans, reminders, saved links and any recording still held, not just your login.
For anything else, write to us through the contact form. We answer within one month. We do not charge for this and we will not treat you differently for asking.
If you are in the European Economic Area or the United Kingdom and you think we have handled your data badly, you can complain to your national data protection authority. We would rather you told us first, but you do not have to.
10. If you record other people
A recording may capture someone else’s voice. Whether you may record another person depends on where you both are, and in some places everyone present has to agree. That is your responsibility rather than ours, and the fastest way to keep it simple is what the product already does — the recording is deleted within hours, and only the meaning is kept.
11. Children
UTTER IN is not for under-16s and we do not knowingly collect their data. If you believe a child has an account, tell us and we will delete it.
12. Security
Your data is encrypted in transit and at rest. Voice recordings are held in private storage that is never served publicly. Access to your rows is enforced by the database on every single query, so a mistake in our code cannot show your data to someone else. If a breach ever puts you at risk, we will tell you.
13. Changes to this page
If we change how we handle your data in a way that matters, we will say so here and update the date at the top, and we will email you before it takes effect rather than after.