Meeting audio never leaves your PC. Transcript snippets and screenshots pass through our server to the AI provider you chose and are not stored. Your provider keys are stored encrypted and used only for your requests.
This policy explains what callAssistX (the Windows app and the website at this domain, together “the service”) does with data, in plain terms. [Your company name] is the operator and data controller.
1. What stays on your PC
- Meeting audio. Both audio streams (what you hear and your microphone) are captured and transcribed on your PC by Whisper. Recordings and live transcripts are saved only in your local data folder.
- Notes, projects and the memory index. Your project notes and past meetings are stored on your PC. Embeddings for the memory index are computed through the service with your provider key, but the index itself stays local.
- Settings and usage history. Kept in your local data folder.
2. What passes through our server and is not stored
When you press Listen, Ask, Scan, Solve, Explain, Details or Ask notes, or when auto-answer or minutes run, the app sends the relevant transcript snippet, screenshot or notes excerpt to our server, which forwards it with your encrypted provider key to the AI provider you selected and streams the answer back. We do not store these texts or images. If you turn on cloud speech to text, each finished utterance is forwarded to the provider in the same way; silence is never sent.
For each request we keep an accounting record only: your account id, device id, the feature used, the provider and model, token counts, cost, duration and whether it succeeded. Never the prompt, text or image.
3. What we store
- Account. Your Google account email, name and profile picture, your plan and trial dates, and your sign-in sessions.
- Provider keys. API keys you add on the website are encrypted (AES-256-GCM) before they are saved, are decrypted only for the duration of your own requests, and are never sent to the desktop app or written to logs. Only the last four characters are shown back to you.
- Devices. The name and a fingerprint of each PC you sign in from, when it was last seen and its app version, so you can revoke a lost one.
- Usage counts as described in section 2, and an audit log of security-relevant actions (sign-ins, key changes, device revocations) with IP address and browser user agent.
- Billing. Subscription status and invoice references from Razorpay. We do not receive or store your card details.
4. Third parties
- Your AI provider (OpenRouter, OpenAI, Anthropic, Google Gemini or xAI) receives the snippets you send, under your own account and their terms. Choose a provider whose data handling you accept.
- Google for sign-in. We receive your verified email, name and picture.
- Razorpay processes payments for Pro.
- Microsoft online neural voices speak answers aloud by default; the answer text is sent to Microsoft to be synthesised. Offline Windows voices are available in Settings › Voice.
- Sentry receives crash reports from the website and, if enabled, the app. Reports contain stack traces and your account id, not meeting content.
5. Recording other people
You are responsible for using callAssistX lawfully. Recording or transcribing a conversation may require the consent of the other participants where you or they are located. The app shows a notice before a recording starts; tell the people in your meeting when you record.
6. Retention
Account data is kept while your account exists. Usage records and audit logs are kept for up to 12 months. Revoked device tokens and expired sessions are purged on a schedule. Nothing in section 2 is retained.
7. Your rights and deleting your account
You can see and remove your provider keys and devices in your account at any time. To export or delete your account and everything in section 3, email support@callassist.rovidant.com from the address you signed in with. We complete deletion within 30 days; invoice records are kept as long as tax law requires. Your local data folder is yours to delete (install.ps1 -Uninstall -RemoveData).
8. Security
Traffic is encrypted in transit (TLS). Keys are encrypted at rest with a key held separately from the database. Access to production systems is limited to the operator. If we learn of a breach affecting you, we will tell you without undue delay.
9. Changes
We will post changes here with a new effective date and, for material changes, show a notice in the app.