Privacy Policy for Srutam
Last Updated: October 2, 2026
App Name: Srutam
Contact Email: hlo.krsna@gmail.com
Account & Data Deletion: Web Deletion Request Page
1. Introduction
Welcome to Srutam — “that which is heard.” Srutam is a privacy-first voice notes app: recordings are transcribed and processed on your device, and every cloud feature is optional and off by default. This policy explains exactly what stays on your device, what moves to the cloud if you turn sync on, and which third parties are ever involved.
2. Your Audio Never Leaves Your Device
- Microphone access (RECORD_AUDIO) is used only to record your voice notes.
- Transcription happens entirely on-device using local AI speech-recognition models. Your audio is never uploaded, streamed, or sent to Srutam's servers or any third party, under any circumstance — this is true whether or not you enable cloud sync.
- Recordings are stored in your device's Music folder (
Music/Srutam/), where you can open, manage, or delete them directly at any time.
3. AI-Generated Summaries and Insights (Bring Your Own Key)
To turn a transcript into a summary, key points, next steps, ideas, decisions, and reminders, Srutam sends the TEXT TRANSCRIPT of that note (never the audio) to an AI provider you choose and authenticate with your own API key:
You control which provider is used, and your key is stored only on your device. When this feature runs, the transcript text is sent directly from your device to that provider's API to generate the summary. That provider processes it under its own privacy policy, which we encourage you to review:
- Google Gemini: https://policies.google.com/privacy
- OpenAI: https://openai.com/policies/privacy-policy
- Anthropic: https://www.anthropic.com/legal/privacy
- Groq: https://groq.com/privacy-policy/
If you don't configure an AI provider, Srutam will not generate summaries or insights, and nothing leaves your device for this purpose.
4. Optional Cloud Sync
Cloud sync is off by default. If you turn it on:
- Account Identity: You sign in with your Google account (via Google Sign-In). We store your email address to identify your cloud account.
- What Syncs: The following is uploaded to our cloud database (hosted on Supabase): your note's title, transcript, AI-generated summary and key points, next steps (and their completion status), ideas, decisions, and reminders (including the meeting/deadline/call/milestone title, time, person, and location you spoke). Your audio file is never part of this upload — see Section 2.
- Private Notes Protection: Marking a note “Private” in the app keeps it out of anything a connected AI coding agent can read (Section 5), even while cloud sync is on. A private note may still be stored in your cloud account so it stays backed up and available to you across sign-ins — it is excluded from agent access, not from sync.
- Control: You can turn cloud sync off at any time, and you can delete your cloud data entirely — see Section 7.
5. Connecting an AI Coding Agent (MCP)
Srutam can expose your synced notes to an AI coding agent (such as Claude Code, Cursor, or similar developer tools) over the Model Context Protocol (MCP), so the agent can read your voice-captured ideas and tasks directly.
- Setup & Security: This requires cloud sync to be on and requires you to generate an API key in Settings. The key is shown to you once in plain text and is never stored anywhere by us in readable form afterward — only a one-way cryptographic hash is kept, the same way a password would be.
- Agent Permissions: An agent holding your key can: read your non-private notes, insights (ideas/decisions), and reminders, and mark a next step as completed. It cannot delete your notes, change your reminders, or access anything marked Private.
- Revocation: You can have up to 3 active keys and revoke any key at any time from Settings; a revoked key stops working immediately.
6. What We Don't Do
- We do not sell your data.
- We do not run advertising or analytics trackers that profile you.
- We do not share your notes or audio with any third party beyond the providers named in Sections 3 and 4 — and those only ever receive exactly what's described there, only when you've enabled that specific feature.
7. Account and Data Deletion
You can delete your Srutam cloud account and all associated cloud data (notes, summaries, next steps, ideas, decisions, reminders, and API keys) at any time:
- In the app: Settings → Account → “Delete my account & data”
- On the web, without the app installed: via our dedicated Account & Data Deletion Page, or email hlo.krsna@gmail.com with the subject “Delete my Srutam data” from the email address associated with your account.
We process deletion requests within 7 days. Deleting your account removes your data from our cloud database; it does not touch audio recordings already stored locally on your own device, since we never had a copy of them to delete. If you've used a third-party AI provider (Section 3), any data already sent to and retained by that provider is governed by their own policy — Srutam does not control or have access to it.
8. Data Retention
- On-device recordings and transcripts are retained until you delete them or uninstall the app.
- Cloud-synced data is retained until you delete the individual note, turn off sync and clear your data, or request full account deletion (Section 7).
9. Security
- On-device data is protected by your phone's native security (biometrics, encryption, passcode).
- Cloud data is protected by Supabase's infrastructure and row-level security, so only you — and any agent you've explicitly authorized with a key — can read your data.
- API keys are never stored or transmitted in plain text after creation; only a one-way hash is kept server-side.
10. Children's Privacy
Srutam is not directed at children under 13, and we do not knowingly collect data from them.
11. Changes to This Policy
We'll update the “Last Updated” date above and post changes here. If a change is significant, we'll highlight it in the app.
12. Contact Us
Questions about this policy, or requests regarding your data: