Privacy notice
Typeglot Privacy Policy.
This policy distinguishes dictated content from the limited operational information needed to provide, secure and support Typeglot.
1. Controller
Who is responsible for Typeglot data.
The Typeglot data controller operates under the ERGON LABS brand. The legally registered Polish sole proprietorship is ERGON LABS Francescantonio Addario, at ul. Józefa Jedynaka 16, 32-020 Wieliczka, Poland, NIP 6751423224, REGON 22515827. Email: hello@typeglot.com. Telephone: +48 790 379 791.
Creem separately acts as merchant of record and data controller for checkout, payment, invoicing, fraud prevention and its customer portal. See Creem's Privacy Notice.
2. Data categories
What Typeglot processes.
Request content
Audio for the current dictation, the temporary transcript, the formatting or translation request and the returned text.
Access information
Verified email, licence-key hash, merchant references, plan and subscription state, random installation identifier, protected instance token and version eligibility.
Usage and security
Request identifiers, audio duration, counters, timing, success or error category, short-retention network hashes, coarse country and abuse decisions.
Optional diagnostics
App version, language setting, timing and non-content recovery events. Diagnostics are On by default with a clear Off switch and do not include audio, transcript, output or custom-rule content.
Support and consumer rights
Your email address, message, attachments you choose to send, order reference, withdrawal or complaint record, delivery receipt and the evidence needed to answer or investigate the request.
Website information
Ordinary server and security logs, Turnstile security results and form-rate controls. Website fonts are hosted by Typeglot and do not require the browser to contact Google Fonts.
3. Dictation content
Processing is not the same as building a content archive.
The desktop keeps the current audio buffer in memory and is designed not to write dictation audio to disk. The current request is transmitted through Typeglot's protected processing chain to produce the requested text. Typeglot does not intentionally log audio, transcripts, final output or custom-rule content in its commercial database or diagnostics.
Typeglot's public disclosure conservatively assumes that its request-content processor may retain inference data for reliability and abuse monitoring for up to 30 days. Typeglot does not promise unconditional zero data retention. A stricter provider-account setting, if enabled and verified, would reduce this period without weakening this disclosure.
Local history is different. If local history is enabled, recent results may be stored on the user's own computer and can be disabled or deleted by the user.
4. Purposes and legal bases
Why the data is used.
| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide dictation, trial, free and paid access | Request content, verified email, licence and instance data, counters | Performance of the service contract and steps requested before a contract |
| Secure the service and prevent abuse | Hashed identifiers, request IDs, short-retention network state, risk events | Legitimate interests in service security and proportionate cost control |
| Handle withdrawal, complaints and legal duties | Contact details, order reference, statement, receipt and case record | Legal obligation, performance of the contract and establishment, exercise or defence of legal claims where applicable |
| Optional diagnostics | Approved non-content diagnostic fields | Legitimate interests in product reliability under the documented balancing assessment, with a user opt-out |
| Marketing | Email and consent evidence | Separate, optional consent. Trial or paid access is not conditioned on marketing consent |
5. Service providers and recipients
Who may receive information.
- Creem: merchant of record and independent controller for purchases, payments, invoicing, fraud controls and the customer portal.
- Cloudflare: processor for protected edge processing, Worker execution, database, Turnstile and security infrastructure. Its Customer DPA includes Article 28 terms and EU Standard Contractual Clauses.
- Groq: processor for the temporary speech and language work needed to return the current result. Both primary and fallback routes use Groq. Its Customer DPA includes Article 28 terms and EU Standard Contractual Clauses. Groq states that inference data may be retained for reliability and abuse monitoring for up to 30 days unless Zero Data Retention is enabled. Typeglot's public disclosure uses the standard maximum until a stricter account setting is independently verified.
- Brevo: processor for transactional trial, security and consumer-rights email. Its service terms incorporate its DPA and transfer safeguards.
- Hostinger: provider for hosting and delivery of messages sent to or from the Typeglot support address. Its public DPA supplies processor terms and subprocessor safeguards.
- Authorities and dispute bodies: only where required by law, needed to handle a complaint or claim, or requested by the consumer in an eligible dispute process.
Typeglot does not sell dictated content or personal data.
6. Retention
Approved retention periods.
- Verification and activation tokens: until used or expired, followed by routine cleanup.
- Trial-recipient and trial records: while trial or free access is active, then review 12 months after closure or last activity.
- Full verified email: only while needed for trial delivery, recovery, support and active free access, then deletion or anonymisation.
- Server-keyed email lookup hash: the same period as the associated recipient and abuse decision.
- Licence and instance history: while active, then review 12 months after expiry or revocation.
- Detailed daily usage counters: 35 days.
- Monthly aggregate usage totals: 13 months.
- Diagnostics, provider-recovery events and operational alerts: 90 days.
- Network hashes and rate windows used for abuse controls: 30 days or less.
- Routine support conversations: 24 months after closure.
- Ordinary support attachments: 90 days after closure.
- Withdrawal, complaint and payment-dispute evidence: review after six years, with longer retention only for an active claim or legal duty.
- Accounting and tax records: the applicable statutory period, allocated between Typeglot and Creem according to role.
Automated cleanup applies to the operational retention periods. Identity, licence, support and legal-hold records follow a documented owner review.
7. International transfers
Safeguards follow the data.
Some providers may process information outside the European Economic Area. Typeglot uses provider agreements that include EU Standard Contractual Clauses or another lawful transfer mechanism where required. This policy will be updated if the processing chain or applicable safeguards change.
8. Your rights
Access and control.
Subject to applicable conditions, you may request access, correction, deletion, restriction, objection and portability. Where processing is based on consent, you may withdraw that consent without affecting earlier lawful processing. You may object to direct marketing at any time.
Send requests to hello@typeglot.com. Typeglot may ask for information reasonably necessary to verify identity. You may also lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office, or another competent authority.
9. Marketing and service messages
A purchase email is not automatic newsletter permission.
Typeglot may use a verified trial or buyer email for trial delivery, licence fulfilment, security, essential service messages, recovery and support. Typeglot will not automatically add every buyer or trial user to a newsletter. Marketing consent, if offered, must be separate, optional and unchecked, and can be withdrawn without affecting trial, free or paid access.
Optional product analytics and getting-started emails.
Updated 6 September 2026, consent wording version 2026-09-06-v1. The activation form offers two separate, unchecked choices. The extended-beta application records separate optional preferences under wording version 2026-09-05-beta-v1. Application preferences do not activate analytics or emails, do not affect beta selection or access, and must be confirmed during verified activation. Contact hello@typeglot.com to change or remove a beta application preference. Declining either choice has no effect on trial, free or paid access. Neither choice changes the existing diagnostics setting.
With your product-analytics consent, Typeglot may send non-content events to PostHog's EU Cloud: first verified activation, an authenticated dictation attempt, a successful or failed result, and an access limit. These use a random analytics identifier, time, app version and free, trial or paid tier. PostHog does not receive your email address, licence or installation identifiers, IP address, audio, dictated text, custom rules, or processing-provider details. We do not use website autocapture, session replay or location enrichment for this integration. PostHog retains these events for up to one year under its standard free-plan policy. A shorter dashboard reporting window does not shorten that storage period.
With your email consent, Brevo delivers five getting-started messages, planned for days 0, 2, 5, 9 and 14 after first verified activation. Typeglot may also send one check-in after seven full days without an authenticated dictation attempt. Failed attempts and plan-limit encounters count as use. We check activity across your installations, leave at least 48 hours between optional emails, and do not repeat a check-in until you have returned and become inactive again. Brevo receives the verified delivery address and message, not your dictation history. Brevo may include an invisible image to count email opens. Typeglot requests anonymized, aggregate open statistics rather than a record of your individual opens. An image loading does not prove that you read an email. Email opens do not control onboarding or inactivity reminders.
Optional choices take effect only after email ownership is verified through activation. Preferences recorded before this wording version do not start the revised integrations without a fresh choice and verified activation. Reinstalling does not restart the welcome series. You can stop optional emails or both choices through the preferences link in an email, request a replacement activation code with the optional boxes cleared, or contact hello@typeglot.com. Withdrawal stops future collection or sending; it does not affect access or essential service messages. Contact us to request deletion of previously collected data.
Pending activation-form choices expire after 24 hours. Beta application preferences remain with the application record and are removed with it; they are never copied into an active mailing list or analytics profile. Unsent analytics events expire after 24 hours. Consent audit entries are retained for up to 12 months; current choices and minimal delivery-step records remain while needed to honour your preferences and prevent repeat onboarding. Optional integrations can be paused for testing, service trouble or sending limits without affecting Typeglot access.
10. Automated controls, security and changes
Protected identifiers and limited access.
Typeglot uses automated rate, quota, version and abuse controls. They can delay or deny access where a limit or security rule is met. A network match alone is not intended to create a permanent denial. Contact support for review of a suspected error. Typeglot does not use these controls to make a decision producing legal or similarly significant effects through profiling.
Typeglot uses server-side credentials, hashed licence identifiers, random instance identity, protected local credentials, restricted operational access and metadata minimisation. No internet service can guarantee absolute security.
This policy is effective from 20 August 2026. Material changes will be dated and communicated where required.