This Privacy Policy describes how Verity Software Inc. ("Verity", "we", "us") collects, uses, stores, shares, and protects your information when you use the Verity voice-transcription and dictation product (the "Service"). It applies to all users of the desktop, iOS, and web applications, regardless of location.
Defined terms (Service, Your Content, Personal Data, Sub-processor, etc.) have the meanings given in /legal/definitions.
We collect only what is necessary to provide and improve the Service. We group Personal Data into four categories:
Information you provide at registration: email address, display name, and authentication tokens (OAuth or magic link). During the launch period all features are free; no billing data is collected. When paid plans are introduced, billing will be handled by a third-party payment processor acting as Merchant of Record — Verity will not store payment card numbers.
Audio recordings you capture through the Service, the transcripts and polished outputs the Service produces, and any metadata you add (titles, tags, notes). You own Your Content; we process it solely to deliver the Service to you.
We do not use Your Content to train, fine-tune, or improve AI models — not now, and not in the future. This commitment is irrevocable and repeated in Terms of Service §6. Our fine-tuning pipeline uses only benchmark datasets, synthetic data, and publicly licensed corpora.
We do not collect precise geolocation, contacts, camera data, or any sensor data beyond the microphone during an active recording session.
Verity processes your voice to produce transcripts. Depending on the jurisdiction, voice recordings and derived voiceprints may constitute biometric data. We treat all voice data as sensitive personal data regardless of where you are located.
We use your information for these purposes only:
| Purpose | Data used | Lawful basis (GDPR / Law 25) |
|---|---|---|
| Provide the Service (capture, transcribe, polish, store) | Your Content, Account data | Contract performance (Art. 6(1)(b)) |
| Authenticate your account | Account data, OAuth tokens | Contract performance |
| Process payments and refunds (when paid plans are introduced) | Billing identifiers (via designated payment processor) | Contract performance |
| Sanctions and fraud screening | IP address at signup, billing country | Legal obligation (Art. 6(1)(c)); legitimate interest (Art. 6(1)(f)) |
| Send transactional emails (receipts, renewal reminders, security alerts) | Email address | Contract performance; legal obligation |
| Detect abuse and enforce the AUP | Usage events, Account data | Legitimate interest (security) |
| Comply with legal obligations (tax, law enforcement, court orders) | As required | Legal obligation |
We do not use your information for:
We share Personal Data only with the Sub-processors listed at /legal/sub-processors and only to the extent necessary to deliver the Service.
During the launch period, Verity has no payment processor — all features are free. When paid plans are introduced, a designated payment processor will act as Merchant of Record (collecting payment, remitting applicable taxes, and handling refunds). The sub-processors list will be updated with 30 days' advance notice per Terms §7.
All processing — speech-to-text, LLM polish, database, authentication — runs on Verity-provisioned infrastructure on AWS. We do not send your audio, transcripts, or account data to third-party AI API providers. AWS provides the underlying compute, storage, and networking, but Verity operates and controls the software stack, models, and data.
Material additions to this list trigger a 30-day advance notice per Terms §7.
We may also disclose Personal Data when required by law, court order, or regulatory request — and only to the extent legally required. We will notify you of such disclosures unless prohibited from doing so.
We do not sell Personal Data. We do not share Personal Data for cross-context behavioral advertising.
| Data type | Free tier | Paid tier | After account deletion |
|---|---|---|---|
| Your Content (audio, transcripts, polished outputs) | 30-day rolling window; older content auto-purged | Kept until you delete; 30-day soft-delete trash, then permanent purge | 30 days to export, then permanent deletion |
| Transcript (server, E2EE sync — opt-in) | Not available (free tier) | Encrypted ciphertext stored until you delete; 30-day soft-delete trash, then permanent purge | Purged within 30 days of account closure |
| Account data (email, profile, auth tokens) | Duration of account | Duration of account | Deleted within 30 days of account closure |
| Billing records | N/A (no billing at launch) | When paid plans are introduced: retained as required by tax law (7 years under CRA/IRS rules), then deleted | Retained per tax-law obligation |
| Biometric data (voice, voiceprints) | Destroyed when the audio recording is purged (30-day window) | Destroyed when you delete the recording (after 30-day trash) | Destroyed within 30 days of account closure or within 3 years of last interaction, whichever is sooner |
| Usage and device data | 90 days | 90 days | Deleted within 90 days |
| Abuse/fraud logs | 1 year | 1 year | Retained up to 1 year for legal-defense purposes |
End-to-end encrypted sync (opt-in). Verity offers an optional device-sync feature that stores an encrypted copy of your transcripts on Verity servers so you can access them across devices. This feature is OFF by default; you must explicitly enable it in Settings. When enabled, transcript text is encrypted on your device before transmission using an encryption key generated on your device. Verity stores only ciphertext — we cannot read your synced transcripts because we never possess your decryption key. The key is held in your device's system keyring and is never transmitted to Verity servers; to use sync on another device you add that device by entering a short code, which transfers the key directly between your devices without Verity being able to read it. If you lose access to every device you have added, the synced copies cannot be recovered — by you, by Verity, or by anyone else. There is no recovery phrase, backup key, or escrow, because any of those would require Verity to hold something that could unlock your data. You may disable sync at any time; previously synced ciphertext is then subject to the retention schedule above (30-day soft-delete trash, then permanent purge).
When data reaches the end of its retention period, we delete or irreversibly anonymize it. Backups are purged on their next rotation cycle (maximum 30 days after primary deletion).
You have the following rights over your Personal Data. To exercise any of them, visit your Privacy Rights Portal, email [email protected], or use the in-app account settings (including in-app account deletion under Settings › Account › Delete Account). We respond within 30 days (or sooner where required by law).
PIPEDA (federal): You may file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca if you believe we have not adequately addressed your request.
Quebec Law 25: You have the right to:
We will notify you and the CAI within 72 hours of any confidentiality incident (breach) that presents a risk of serious injury, as required by Law 25.
British Columbia PIPA / Alberta PIPA: Express consent is required for collection of sensitive personal data (including audio recordings). Your consent is obtained through the in-app recording consent modal. You may withdraw consent at any time.
California (CCPA/CPRA): California residents have the right to:
We do not use or disclose sensitive Personal Data for purposes other than providing the Service. We do not sell Personal Data. We do not share Personal Data for cross-context behavioral advertising.
To exercise your CCPA/CPRA rights: visit your Privacy Rights Portal, email [email protected], or use the in-app account settings. We verify your identity through your authenticated account session. You may designate an authorized agent — provide a signed authorization letter.
Other US state privacy laws (VA, CO, CT, TX, OR, MT, DE, NH, NJ, MD, NE, RI, MN, IN, KY, IA, TN): These laws grant similar rights (access, delete, correct, opt out, appeal). The rights in §5.1 satisfy all of them. To appeal a denied request, email [email protected] with "APPEAL" in the subject line; we respond within 45 days.
Illinois BIPA: Your biometric data rights are described in §1.4 above and in our Biometric Data Policy. You consented to biometric data collection through the in-app consent modal. You may withdraw consent at any time.
If you are established in the EU, EEA, or UK:
Verity Software Inc. is incorporated in Quebec, Canada. Your Personal Data may be transferred to and processed in the United States, where Verity operates its infrastructure on AWS.
Copies of SCCs and our PIA summaries are available on request via [email protected].
We have not received, and do not anticipate receiving, any national-security orders, FISA directives, or bulk-surveillance requests. If we receive a lawful government request for Personal Data, we will (a) scrutinize it for legal validity, (b) narrow the scope to the minimum required, and (c) notify the affected user unless legally prohibited.
We protect your Personal Data with:
End-to-end encryption (device sync). When you enable the optional device-sync feature, your transcripts are encrypted client-side using AES-256-GCM before any data leaves your device. The encryption key is generated on your device, stored in your system keyring, and is never transmitted to or stored on Verity servers. Adding a second device transfers that key directly between your devices, protected by a short code you type from one screen to the other; Verity relays the exchange but cannot read the key. Synced transcripts are stored on our servers as ciphertext only. Even in the event of a server-side data breach, synced transcripts cannot be decrypted, because Verity does not possess and cannot derive the key.
No system is perfectly secure. If you suspect a security issue, contact [email protected] or [email protected].
Verity requires users to be at least 16 years old to create an account. We do not knowingly collect Personal Data from children below the most-protective applicable threshold:
If we learn we have collected data from a child below the applicable threshold without verifiable parental consent, we delete the account and associated data within 30 days and confirm deletion to the reporting party.
Parents or guardians may report a suspected underage account by emailing [email protected].
The Verity web application uses:
verity_referral cookie and localStorage entry to track referral codes. Contains only the 8-character referral code; no personal data. Cleared after account creation.We do not use:
The desktop and iOS applications do not use cookies.
Verity uses AI models (speech-to-text and large language models) to transcribe and polish your dictation. These are content-processing tools, not decision-making systems:
Under the EU AI Act, Verity is classified as a limited-risk AI system (Article 50 — transparency obligations only). We disclose AI involvement through an in-app modal and a persistent badge on polished outputs.
If Quebec Law 25's automated-decision provisions apply to any future feature, we will provide notice and a mechanism to request human review before deploying that feature.
We treat "material changes" to this Privacy Policy the same way we treat material changes to the Terms of Service: 30 days' advance notice by email and in-app notification before the change takes effect. You may object and terminate the Service before the effective date with a pro-rata refund.
Non-material changes (clarifications, expanded rights, additional transparency) take effect when posted.
The §1.2 commitment to never train on Your Content is irrevocable and cannot be weakened without your affirmative re-consent.
Verity Software Inc. 64 rue de L'Ermitage, Blainville, QC, J7B 1K3, Canada
Person responsible for the protection of personal information (Law 25): the Founder, reachable at [email protected].
| Purpose | Contact |
|---|---|
| Privacy requests, data-subject rights, DPA/SCC copies | [email protected] |
| General support | [email protected] |
| Legal notices | [email protected] |
| Abuse reports | [email protected] |
| Security incidents | [email protected] or [email protected] |
Canadian privacy regulator: Office of the Privacy Commissioner of Canada — priv.gc.ca Quebec privacy regulator: Commission d'acces a l'information du Quebec (CAI) — cai.gouv.qc.ca
This policy is maintained by Verity Software Inc. and updated as our practices evolve.