Privacy Notice — Secretary42
This Privacy Notice explains how insight 42 UG (haftungsbeschränkt) processes personal data in connection with the Secretary42 desktop application. It covers the product and the product website at secretary42.de.
The short version. Secretary42 transcribes your speech on your device. The app does not transmit your microphone audio, transcript text, prompt text, local transcription history, app settings, or activation key to insight 42. There is no user account, and diagnostics are off by default. Separate network flows do occur for purchase and payment (through Paddle), licence delivery, licence activation and periodic licence checks, model and software downloads, updates, optional diagnostics, support, and website/checkout operation, and the website uses Google Analytics only if you accept it on the consent banner. Those are described below.
1. Controller and contact
insight 42 UG (haftungsbeschränkt), Barellistraße 6, 85049 Ingolstadt, Germany. Privacy / data-protection requests: privacy@insight42.com. General contact and full company details: see the Impressum.
We have not appointed a Data Protection Officer, as we are not legally required to do so under Art. 37 GDPR / § 38 BDSG.
2. What stays on your device
The following are processed locally and are not transmitted to insight 42 by the app:
- Your microphone audio (processed by the bundled on-device whisper.cpp engine; temporary files are deleted after transcription).
- Your transcribed text and any prompt text.
- Your local transcription history (stored in a local database on your device; by default the most recent entries are kept; you can view, copy, and delete them).
- Your app settings, your activation key and the signed licence lease it is exchanged for. The lease payload carries no personal data — only a version, plan, issue/expiry timestamps and a random value — no email, name, Paddle IDs, device identifier, or IP. Your licence is bound to the installation, and the private key the app generates for that binding stays on your device and is never transmitted; only a signature and random identifiers are sent (see §3).
- A local diagnostics/telemetry log file the app writes on your device for troubleshooting; it is not uploaded unless you choose to share it with support.
There is no cloud transcription and no cloud-transcription fallback under the current release configuration, and no user account — so there is no insight 42 server-side profile of you tied to the dictation product.
3. Processing that does involve personal data
| Activity | Personal data | Purpose | Legal basis |
|---|---|---|---|
| Purchase & payment (via Paddle) | Email, billing & payment data, transaction data | Sell the subscription; take payment; tax/invoicing | Paddle's own bases as merchant of record / independent controller (Art. 6(1)(b)/(f) and tax-law obligations) |
| Licence delivery (our minter emails your activation key) | Your buyer email, received from Paddle | Deliver your purchased licence by email | Art. 6(1)(b) GDPR |
| Webhook handling & idempotency (minter) | Pseudonymous HMAC digests + operational metadata | Verify the purchase event; avoid duplicate licence emails; security | Art. 6(1)(f) GDPR |
| Diagnostics (Sentry) — opt-in, off by default | A random local install ID + sanitized technical metadata | Diagnose crashes / performance | Art. 6(1)(a) GDPR (consent) |
| Website analytics (Google Analytics 4 on secretary42.de) — only after you accept the consent banner | Pseudonymous cookie identifiers, pages viewed, referrer, browser, device and OS type, approximate location derived from your IP address, and website events: clicks on a download, a started checkout, and a completed purchase's amount and currency | Count visits and see which pages help people decide | Art. 6(1)(a) GDPR and § 25(1) TDDDG (consent) |
| Whisper-model download | Connection metadata (e.g. IP, user agent) to the model host | Deliver the model you chose | Art. 6(1)(b) and/or (f) GDPR |
| App updates | Connection metadata to the update host: our update feed at secretary42.de, which redirects to our Hetzner Object Storage in Falkenstein, Germany (installer downloads take the same route) | Provide updates / security fixes | Art. 6(1)(f) GDPR (and (b) where part of the paid licence) |
| Support | What you send us (email or shared logs) | Handle your request | Art. 6(1)(b)/(f) GDPR |
| Licence activation & periodic licence check (our EU licensing service) | A random installation identifier, a random one-time value, a timestamp and a cryptographic signature; your activation key on first activation; connection metadata. On our side: a keyed digest of your licence reference, plan and validity dates, and one record per installation (random identifier, its public key, a short random display suffix, and a date-rounded last-seen) | Activate your licence, apply the device limit, confirm your entitlement, and process cancellations and refunds | Art. 6(1)(b) GDPR; Art. 6(1)(f) for abuse protection and administrative audit |
| Pending licence delivery record | Manual delivery: encrypted email + activation key. Paddle delivery: encrypted Paddle customer ID + activation key; email is read into memory on each attempt | Send you the activation key | Art. 6(1)(b) GDPR |
3a / 3b. Payment (Paddle) and licence delivery
Payment is processed by Paddle, which acts as merchant of record / authorised reseller and as an independent controller for the purchase, payment, tax, billing, invoicing and related buyer data, under its own privacy policy.
We receive your buyer email address from Paddle after purchase so that we can deliver your Secretary42 activation key and provide purchase-related support. We receive this data from Paddle, not from the desktop app.
To email you your licence, our backend licence-minter temporarily holds your
Paddle customer identifier together with the activation key in an encrypted pending
delivery record. On each delivery attempt it uses the customer.read
permission to read your current buyer email from Paddle. The email exists in memory only: it
is never written to our database or logs. The encrypted customer identifier and key are
destroyed when the mail provider accepts the message, and in every case within
seven days. The desktop app contains no Paddle API key.
Apart from that pending delivery record, the licence-minter datastore is designed not to retain direct identifiers: no buyer email address, no raw Paddle customer, subscription or transaction IDs, no raw webhook bodies, and no plaintext licence credential once delivery has been accepted. What it does retain is keyed digests of those identifiers together with limited operational metadata, on the retention periods set out in §5. We treat these records as pseudonymous operational data where GDPR applies — not as anonymous or non-personal data.
3c. Diagnostics (Sentry) — opt-in only
Diagnostics are off by default, and the diagnostics service is not initialised until you explicitly opt in (Settings → License). On a fresh or opted-out install there is zero diagnostics egress. If you opt in, we send sanitized crash and performance metadata — app version, release channel, build identifier, OS, CPU architecture, local engine/model, language, a duration bucket, latency, real-time factor, and outcome — identified only by a random local install ID generated on your device. We do not receive your name, email, account ID (none exists), audio, transcript text, prompts, API keys, or local file paths. You can opt out at any time, which clears the diagnostics state and rotates the install ID.
3d. Website analytics (Google Analytics) — opt-in only
The website at secretary42.de uses Google Analytics 4, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, only if you click Accept analytics on the consent banner. Until then, and if you click Reject, the site loads nothing from Google. Google processes this data on our behalf under its data-processing terms. We have switched Google signals, advertising features and ad personalisation off; we run no advertising. Google Analytics 4 does not log or store IP addresses; Google uses the address in transit only to derive an approximate location. We do not send Google your name, email, licence or activation key, or Paddle's transaction identifiers, and the desktop app never contains Google Analytics. You can withdraw your consent at any time under Cookie settings in the footer of every page (see §10).
3e. Whisper-model downloads
When you choose a Whisper model, the app downloads the model file from Hugging Face. The model host receives connection metadata (such as your IP address and user agent). Hugging Face, Inc. is US-based (with an EU establishment, Hugging Face SAS, France); public model repositories are stored in the US by default and US transfers rely on Standard Contractual Clauses.
4. Recipients and their roles
| Recipient | Role | Location & transfer basis |
|---|---|---|
| Paddle | Independent controller / merchant of record for checkout, payment, tax, billing; discloses buyer email to us for licence delivery | UK (UK adequacy decision); controller-to-controller SCCs for relevant transfers |
| Sentry (Functional Software, Inc.) | Processor for opt-in diagnostics (Art. 28) | EU storage (GCP); US transfers under EU-U.S. DPF (DPF-certified, participant 5869) with SCC fallback. DPA signed; 30-day retention |
| Brevo (Sendinblue SAS, Paris) | Processor for licence-token email delivery (Art. 28) | EU hosting (France/Belgium); non-EEA subprocessing under SCCs/DPF. AVV signed; open/click tracking disabled |
| Hetzner (Hetzner Online GmbH) | Processor for minter and licensing-service hosting (compute, database, Redis) and for app-update and installer downloads (Object Storage) (Art. 28) | Germany (Nuremberg/Falkenstein). AVV concluded |
| Hugging Face, Inc. | Model-download host; recipient of connection metadata | US-based (EU establishment HF SAS, France); US transfer under SCCs |
| GitHub (GitHub, Inc. / Microsoft) | Public issue tracker if you file one | US + international; EU-U.S. DPF (DPF-certified, participant 6174) + SCCs |
| Google (Google Ireland Limited; Google LLC) | Processor for website analytics (Google Analytics 4), only after your consent (Art. 28) | Ireland / EU; access from and transfers to the US under the EU-U.S. DPF (Google LLC is DPF-certified) with SCCs. Google's data-processing terms accepted; Google signals and advertising features off |
We do not sell personal data or use it for advertising. Where a service provider processes personal data on our behalf, we use the data-processing terms required by Art. 28 GDPR. Paddle acts as an independent controller for checkout and payment and is not our subprocessor for that purpose.
Support channel
Support is private email only — support@insight42.com. We do not operate a public support forum. When you email support, please send only what is needed; avoid sharing audio, full transcripts, activation keys, payment details, or secrets unless we specifically ask. If you ever reach us through any public channel, do not post personal data there.
5. Retention
| Data | Retention |
|---|---|
| Audio | Not retained — transient, deleted after transcription |
| Transcripts / local history / settings | On your device only; you control and can delete |
| Local diagnostics/telemetry file | On your device only; not uploaded unless you share it |
| Webhook event ledger (minter) | At most 100 days; HMAC event reference, closed type/outcome, and timestamps only; no email, raw Paddle IDs, or webhook body |
| Replay and rate-limit counters (Redis) | TTL-bounded operational HMACs only; Redis has no persistence or backup |
| Buyer email (minter) | Read from Paddle for each delivery attempt and held in memory only. Never persisted, logged, returned to the app, or placed in your licence |
| Licence and installation records (licensing service) | Your subscription lifetime plus 30 days. No email or name in the licence record, no raw Paddle identifiers, no IP history, and no device, operating-system, locale or time-zone data |
| Licence delivery record | Deleted as soon as delivery is accepted; hard maximum 7 days. Manual delivery encrypts email + key; purchased delivery encrypts Paddle customer ID + key and resolves email transiently |
| Licence one-time values and rate-limit counters | 10 minutes and at most 15 minutes respectively; never logged |
| Administrative audit of licence actions | 180 days |
| Diagnostics events (Sentry) | 30 days (EU project, DPA signed) |
| Website analytics (Google Analytics) | Only if you accepted: event data is kept for 2 months in Google Analytics; the _ga cookies expire after 13 months, and are deleted from your browser when you withdraw consent. Your consent choice itself stays in your browser's local storage until you change it |
| Minter / reverse-proxy logs | Licensing-service reverse proxy: the access log records no IP address, user agent or request URI; it rotates at 10 MiB, and rotated log files are deleted after 24 hours. The website (secretary42.de) keeps no access log |
| Email delivery logs (Brevo) | Open/click tracking disabled |
| Support correspondence | Kept only as long as needed to handle your request, then deleted |
| Payment / billing | Per Paddle's retention policy (Paddle is the controller) |
6. Legal bases
The legal bases per flow are set out in the table in §3. In summary: purchase and licence delivery rely primarily on contract (Art. 6(1)(b)); webhook verification/idempotency, security logging, updates and model-download logging rely on legitimate interests (Art. 6(1)(f)) with documented assessments; opt-in diagnostics and opt-in website analytics rely on consent (Art. 6(1)(a)), and storing or reading the analytics cookies on your device additionally on your consent under § 25(1) TDDDG.
7. Whether providing data is required
Providing your email at checkout is necessary to buy a subscription and receive a licence; without it we cannot deliver the licence. Diagnostics are optional and refusing them does not affect your use of the app. Website analytics are optional too: rejecting them does not affect the website, downloads or checkout. Support content is optional, but we need it to answer your request.
8. Your rights
Subject to the GDPR, you have the rights of access, rectification, erasure, restriction, portability, and objection (including the right to object to processing based on legitimate interests), and the right to withdraw consent for diagnostics (in the app) or website analytics (Cookie settings in the website footer) at any time without affecting prior processing. There is no user account, so there is no login or profile to export. Your dictation content never reaches us at all. Because a licence is bound to an installation, we do hold a pseudonymous licence record, and we can act on it: give us your activation key and we will locate, export, or delete that record. (Deleting it during an active subscription ends the licensed service — we will explain the consequence before acting.) If you no longer have the activation key, we can verify your purchase through Paddle instead. For payment data, contact Paddle (the controller for that data), and for diagnostics, contact us.
To exercise your rights, email privacy@insight42.com. You also have the right to lodge a complaint with a supervisory authority. The competent authority for insight 42 is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
9. International transfers
Some recipients may process personal data outside the EU/EEA, or their corporate group / subprocessors may have access from third countries. Where a recipient processes data outside the EU/EEA, appropriate safeguards apply, such as an EU adequacy decision, the EU-U.S. Data Privacy Framework for certified US organisations, or the EU Standard Contractual Clauses with supplementary measures where required. Sentry, GitHub/Microsoft and Google (for website analytics) are DPF-certified; Hugging Face's US transfers rely on SCCs; Brevo hosts in the EU with SCC/DPF fallback; Hetzner is EU/DE; Paddle (UK) benefits from the UK adequacy decision and uses SCCs for other transfers.
10. Cookies, the website, and the checkout (TDDDG)
Unless you accept analytics on the consent banner, a pageview on secretary42.de loads no analytics, advertising trackers, third-party scripts, third-party images, or non-essential cookies. Web-server access logging is disabled. The server must process the technical data needed to deliver each request, but does not retain it in an access log.
Google Analytics, only with your consent. If you click Accept analytics,
the site loads Google Analytics 4 from Google, which sets the _ga and
_ga_… cookies and receives the data described in §3. If you click Reject,
none of it loads. Your choice is remembered in your browser's local storage
(s42-consent-v1), which is strictly necessary for that purpose (§ 25(2) no. 2 TDDDG).
You can change or withdraw your choice at any time under Cookie settings in the
footer of every page: withdrawing stops Google Analytics on the page you are on and deletes its
cookies, and no later page loads it. How Google uses data from sites that use its services:
policies.google.com/technologies/partner-sites.
If you actively start checkout, the site loads Paddle's checkout resources and Paddle may set storage needed to run secure checkout under its own notices. We do not receive your card details.
11. Automated decision-making
insight 42 does not use automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR. Any fraud/payment risk decisions at checkout are carried out by Paddle as part of its own controller processing.
12. Children
Secretary42 is not directed to children; you must be 18+ to purchase (see the Terms).
13. Changes
We may update this Notice; the "Last updated" date reflects the current version.
14. Contact
insight 42 UG (haftungsbeschränkt), Barellistraße 6, 85049 Ingolstadt, Germany — privacy@insight42.com.