Privacy Policy
Overview
Loqi ("we", "our", "the app") is a recording and AI-powered transcription app for iOS. This privacy policy explains what data we collect, how we use it, and your rights regarding that data.
Data We Collect
Account Information
You can use Loqi without creating an account. On first launch the app creates an anonymous account — a random identifier with no name, email, or other personal information attached. Your credits, plan, and purchases are linked to that identifier.
Saving an account (signing in with Apple, Google, or email) is optional — it exists so your credits and purchases follow you to other devices or a new phone. If you sign in, we receive:
- Email address
- Display name (if provided by your sign-in provider)
- A unique user identifier
This data is managed by Firebase Authentication (Google) and stored on Google's servers. We do not store your sign-in credentials.
Audio Recordings
When you record a meeting, the audio is:
- Stored locally on your device
- Uploaded to a private cloud storage bucket only when a meeting is processed — and only after you have allowed AI processing (see Your Consent to AI Processing below) — as a temporary transit buffer
- Deleted from our servers after processing completes. If processing needs to be retried (for example during an AI service outage), the audio is kept only while those retries are pending, and a storage lifecycle rule deletes it in any case within about a day of upload (at most two). We do not retain audio server-side beyond that.
AI-Processed Content
When a recording is processed, the audio is sent to Google's Vertex AI (Gemini) service, which returns:
- A text transcript with speaker identification
- A summary of key points, a title, and a list of topics discussed
- Extracted action items
This processed content is delivered to your device and stored in an on-device database. To make sure a finished transcript still reaches you when the app was closed during processing, the result is held in a server-side delivery inbox until your device retrieves it, for at most 7 days, and is deleted from our servers as soon as it is delivered (or when the 7 days expire). After delivery, transcripts, summaries, and tasks exist only on your device.
Audio sent for processing is handled by Google Cloud’s Vertex AI under Google’s data-processing terms. Google does not use your audio or the generated text to train its models. We have disabled Google’s data caching for our project (zero data retention), so Vertex AI does not keep your audio or results after the request completes. Google may temporarily log prompts flagged by its automated abuse-detection systems, as described in Google’s Generative AI data governance documentation.
Your Consent to AI Processing
The app asks for your explicit permission before the first recording is sent to Google's AI service, and explains there what is sent and to whom. Until you allow it, nothing leaves your device — recording, playback, and sharing work regardless. You can withdraw this permission at any time in Settings → AI Processing; from that moment no further audio is transmitted.
Subscription & Usage Data
We collect:
- Your subscription plan (Free, Starter, Pro, or Max)
- Number of recordings processed and credits used per billing period (1 credit covers up to 1 minute of audio)
- Purchased credit-pack balance
This usage data is stored in Google Firestore and linked to your user ID. It is used solely for enforcing plan limits.
Purchases are processed by Apple through the App Store (StoreKit) and work without a saved account. We do not receive or store your payment details. Apple notifies our server of subscription and purchase events (App Store Server Notifications) so we can activate your plan and add purchased credit packs; these notifications are linked to your account via an anonymous token. See Apple's Privacy Policy.
Abuse Prevention
The app uses Apple's App Attest / Firebase App Check to verify that requests to our servers come from a genuine copy of the app. This involves Apple issuing a device attestation; no additional personal data is collected by us for this purpose.
What We Do NOT Collect
- We do not collect location data
- We do not collect contacts or address book data
- We do not use analytics or advertising SDKs
- We do not track you across other apps or websites
- We do not sell your data to third parties
How We Use Your Data
| Data | Purpose |
|---|---|
| Account info (anonymous identifier, or sign-in details if you save an account) | Authenticate you and link your credits and subscription |
| Audio recordings | Process with AI — with your permission — to generate transcripts and summaries |
| Transcripts & summaries | Display to you locally; held server-side only until delivered to your device (max 7 days); share/export only when you choose |
| Usage data | Enforce plan limits (recordings processed, credits used) |
| Subscription status | Determine which features you can access |
Third-Party Services
We use the following third-party services that may process your data:
| Service | Provider | Data Shared | Purpose |
|---|---|---|---|
| Firebase Authentication | Email, user ID | Sign-in and identity | |
| Cloud Functions & Cloud Storage | Audio (temporarily), user ID | Server-side AI processing | |
| Vertex AI (Gemini) | Audio (temporarily) | Transcription, summarization, task extraction | |
| Firestore | User ID, plan, usage stats | Usage tracking and plan management | |
| Apple App Store | Apple | Purchase events, anonymous account token | Payment processing and subscription lifecycle |
Audio sent to Google Vertex AI is processed according to Google's Cloud Data Processing Terms. Google does not use your data to train AI models.
Data Sharing
We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes.
Your meeting content (transcripts, summaries, tasks, recordings) is shared only when you explicitly use the app's sharing or export features (email, the iOS share sheet, or PDF export). In that case, the content goes to the recipients and apps you choose.
Data Storage & Security
- On-device data (recordings, transcripts, summaries, tasks): Stored in a local database and the device file system. Protected by your device's security (passcode, biometrics).
- Server-side data (user ID, plan, usage stats, undelivered results): Stored in Google Firestore with access restricted to your own authenticated account.
- Audio in transit: Uploaded over HTTPS (TLS) to a private storage bucket, used only as a transit buffer for processing, and deleted afterwards (see Data Retention).
Data Retention
| Data | Retention |
|---|---|
| Audio recordings (device) | Until you delete the meeting from the app |
| Audio recordings (server) | Deleted after processing; kept only while retries are pending, and removed by a lifecycle rule within about a day of upload (at most two) in every case |
| Transcripts, summaries, tasks (server) | Until delivered to your device, at most 7 days |
| Transcripts, summaries, tasks (device) | Until you delete the meeting from the app |
| Account information | Until you delete your account |
| Usage statistics | Until you delete your account |
Your Rights
You have the right to:
- Access your data: All meeting data is visible in the app. Usage data is shown on the Settings screen.
- Delete your data: Delete individual meetings from the app. Delete your account and all server-side data at any time (Settings → Delete Account, or Delete All Data for an anonymous account).
- Export your data: Use the sharing/export features to export meeting content.
- Withdraw consent: Turn off AI processing at any time in Settings → AI Processing — no further audio is transmitted. You can also delete your account at any time.
Children's Privacy
Loqi is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us.
Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes through the app or via email. Continued use of the app after changes constitutes acceptance of the updated policy.
Contact
If you have questions about this privacy policy or your data, contact us at:
Email: privacy@jdms.nl