Your data
Security and data
Doctor's appointments, legal consultations and therapy sessions go through QuillHub. That is why we say this plainly instead of burying it in the terms: what we encrypt, who has access, where a recording goes and how to delete it.
In short
- TLS 1.2+
- encryption in transit
- AES-256
- encryption at rest
- 0
- of your recordings used for training
- 30 days
- to full physical deletion
Encryption
Everything between your device and the service travels over TLS 1.2 or newer. Audio, video, transcripts and database records are stored encrypted with AES-256. That covers both the files you upload and the recordings made by the desktop app.
Who can see your recordings
Only you — and the people you send a transcript link to. Engineering access to data follows the least-privilege principle, and administrative actions are logged. We do not look at user recordings, do not sell them and do not pass them to third parties. Your data is seen only by the tools listed on the subprocessors page.
Models are not trained on your data
Speech recognition and text structuring are done by external engines, and each one is bound by an agreement that prohibits using your data for training. For OpenAI language models we use the Zero Data Retention configuration: a request is processed and not stored. The full list of subprocessors, what each one does and where it is located, is on the subprocessors page.
Desktop app
- A meeting recording stays on your computer until you send it for transcription yourself. Until then you can listen to it or delete it.
- The app does not capture system audio outside a recording session you started.
- Quick Dictation streams audio to a real-time recognition engine; a local copy stays on the device in case the connection drops.
- Anonymous usage statistics are collected only if you switched them on; recording content and transcript text never go through that channel.
Deletion
Any recording can be deleted at any moment — together with its transcript, summary and everything made from it. The whole account is deleted under Settings → Privacy → Delete Account, or by emailing legal@quillhub.ai.
Deleted data is marked for destruction immediately; physical deletion from the database and object storage happens within 30 days, and backups are purged within a further 30. The only thing kept longer is what the law requires us to keep — payment records — and only for that purpose.
Payments
Payments in USD are processed by Stripe, payments in RUB by CloudPayments. The transaction happens on their side; we receive only the outcome and do not store full card details.
If something goes wrong
We notify you of a personal-data breach involving your data without undue delay and within the legal deadlines — 72 hours where the GDPR applies. Found a vulnerability? Write to legal@quillhub.ai; we will respond and will not pursue a good-faith researcher.
We do not hold ISO 27001 or SOC 2 certification yet. If your organisation needs a completed security questionnaire or a Data Processing Addendum for a contract, write to us — that is handled by email.