Privacy Policy
Effective date: July 27, 2026
1. What this policy covers
This policy explains what personal data Pictefor ("we", "us") collects when you use the Pictefor web platform, the Pictefor desktop application for Windows, and the Pictefor mobile app for Android, why we collect it, and the choices you have. The mobile app is covered in detail in section 4.
2. Data we collect
- Account data: email address, name (if provided), organization role (owner, manager, member), and authentication records. Stored with our database provider, Supabase.
- Usage data: processing-unit consumption, feature usage, device sessions (device identifier and label, used to enforce per-seat device limits), and an activity log of administrative actions within your organization.
- Billing data: handled by Paddle.com as merchant of record. We never see or store your full payment details; we receive subscription status and invoice metadata.
- Content you process: the documents, images, video, audio, and web pages you submit for extraction, and the datasets produced from them.
- Audio recordings and files sent from the mobile app: voice recordings you choose to make on your phone, the transcripts produced from them, and any photos, videos or documents you explicitly send to your workspace.
3. How AI processing works
When you run an extraction or send a recording for transcription, the relevant content (text, image regions, video frames, or an audio file) is transmitted over an encrypted connection through our relay service to third-party AI providers, currently Groq and Google (Gemini), solely to produce your result. We use these providers' API offerings, under terms which do not permit them to use API content to train their models. Source files and audio are processed transiently and are not retained by us after processing; results are stored where you choose (locally in the desktop app, or synced to your organization's cloud workspace).
4. The Pictefor mobile app (Android)
The mobile app is a companion to the desktop app for people working away from their computer. It signs in with the same Pictefor account. Specifically:
- Microphone: the app records only when you start a recording yourself. Recording runs as a foreground service so it survives the screen turning off, and Android shows a persistent notification the entire time it is active. Recordings are saved to app-private storage on your device.
- What leaves your phone, and when: nothing is uploaded automatically. When you tap "Send to Pictefor", the audio file is uploaded over an encrypted connection to our relay and forwarded to our speech-to-text provider purely to produce a transcript. The audio is not stored by us after transcription. The resulting transcript is saved to your organization's workspace so your desktop app can import it.
- Photos, videos and documents: files you explicitly pick are uploaded to a private inbox area of your workspace and are deleted from it once your desktop app downloads them.
- We do not record phone calls: Android does not permit third-party apps to capture call audio, and we do not attempt to. If you opt in to the after-call hint, the app observes only whether a call has ended, so it can offer to record a voice summary afterwards. It does not read phone numbers, contacts, call logs, SMS, or the content of any call. You can turn this hint off in the app at any time.
- Consent when recording other people: recording a conversation involving other people requires their consent, and laws on recording vary by country. You are responsible for obtaining that consent. The app states this in its interface, and we recommend telling participants before you begin.
- Permissions: microphone (recording), notifications (the recording notification and the optional after-call hint), phone state (only to detect the end of a call, optional), and internet access. You can revoke any of these in Android settings; features that depend on them stop working, and nothing else changes.
- No advertising or tracking: the mobile app contains no advertising, no analytics SDKs and no third-party trackers, and we do not sell or share your data for advertising.
5. Why we process data (legal bases)
- to provide the Service under our contract with you (accounts, extraction, transcription, sync, seat management);
- legitimate interests: securing the Service, preventing abuse, enforcing seat/device limits, and improving reliability;
- legal obligations: tax and accounting records (via Paddle);
- consent, where required (e.g. marketing emails, always optional).
6. Sharing
We share data only with the processors needed to run the Service: Supabase (database, authentication and file storage), Cloudflare (relay infrastructure), Groq and Google (AI extraction and transcription, content only), Paddle (billing, as merchant of record), and Vercel (website hosting). We do not sell personal data. Within your organization, owners and managers can see member activity and usage consistent with the seat model.
7. Retention
Account and usage data are kept while your account is active and deleted or anonymized within 90 days of account deletion, except where law requires longer retention. Synced datasets are retained for 30 days after subscription termination to allow export, then deleted. Content submitted for extraction, including audio sent for transcription, is not retained by us beyond processing. Transcripts and files sent from the mobile app remain in your workspace inbox until your desktop app imports them, or until you delete them. Recordings kept on your phone stay on your phone and are removed when you delete them in the app or uninstall it.
8. Deleting your account and your data
You can request deletion of your Pictefor account and the personal data associated with it at any time by emailing support@pictefor.com from the address registered to the account, or follow the steps on our account deletion page. We confirm the request and delete the account, its transcripts, its synced datasets and its uploaded files within 30 days, other than records we are legally required to keep, such as billing and tax records held by our payment processor for the period required by law. Deleting the mobile app from your phone removes any recordings still held on the device, but does not by itself delete your Pictefor account. Members of an organization should note that data belonging to the organization is controlled by its owner.
9. Your rights
Depending on your jurisdiction (including under the GDPR), you may have rights to access, correct, export, restrict, object to processing of, or delete your personal data. Organization members should direct requests to their account owner where the organization controls the data; otherwise contact us directly and we will respond within 30 days.
10. Security
Data in transit is encrypted with TLS. Database access is protected by row-level security and scoped service credentials; administrative operations are audit-logged. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you without undue delay.
11. Children
Pictefor is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Cookies
The platform uses strictly necessary cookies for authentication and session management. We do not use third-party advertising or tracking cookies. The mobile app does not use cookies.
13. Changes and contact
We will announce material changes to this policy on the platform or by email before they take effect. Privacy questions and requests: support@pictefor.com.