Privacy Policy
Last updated: July 2026 · Applies to UK GDPR & DPA 2018
1. Who we are
FutureName ("we", "us") operates a voice transcription service. For the purposes of the UK GDPR and the Data Protection Act 2018, we are the data controller for the personal data described in this policy.
2. Data we collect
Account data: name, email address, and a securely hashed password (we never store plain-text passwords).
Content data: audio files you upload or record, and the transcripts produced from them, so the service can function.
Usage data: transcription counts, minutes processed, and timestamps, used to enforce plan limits and improve the product.
Payment data: none. Card details are entered directly into Stripe's hosted checkout, so card numbers never touch our servers. We store only Stripe customer and subscription identifiers.
3. Lawful bases
Contract: processing your account, audio, and transcripts is necessary to provide the service you signed up for.
Legitimate interests: security logging, abuse prevention, and product improvement.
Consent: where required (e.g., optional cookies), we ask first.
4. Third-party processors
Stripe, Inc.: payment processing (PCI-DSS Level 1). Stripe acts as an independent controller for payment data.
Upstash, Inc.: rate-limiting infrastructure (IP addresses, short-lived).
Hosting providers: servers located in regions we select; where data leaves the UK/EEA, transfers rely on adequacy regulations or standard contractual clauses.
5. Retention
Account data is kept while your account is active. Transcripts remain until you delete them or your account. Security and audit logs are retained for up to 12 months. When you delete your account, personal data is erased or anonymised within 30 days, except where the law requires us to keep it.
6. Your rights
Under the UK GDPR you have the right to access, rectify, erase, restrict, or port your personal data, and to object to processing based on legitimate interests. You can exercise most rights directly from Account settings, or by contacting us.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
7. Cookies
We use only strictly necessary cookies: the session cookie that keeps you signed in. We do not use analytics, advertising, or other third-party tracking cookies. If that changes, we will ask for your consent first and update this policy.
8. Security
Passwords are stored using strong one-way hashing. Sessions use signed, httpOnly cookies. Optional two-factor authentication is available in Account settings. Server-to-server traffic is authenticated, and access to production data is restricted.
9. Changes & contact
We may update this policy; material changes will be announced in the app. Questions about this policy or your data: [email protected].