dicted dicted / Legal

Privacy Policy

Effective date: 2026-04-19 Last updated: 2026-06-06

1. Summary

Dicted turns speech into text. To do that, audio you record gets sent to a speech-to-text provider, transcribed, and returned. We take privacy seriously:

  • Dictation audio is deleted the moment it is transcribed. Nothing is kept on our servers.
  • Meeting uploads are stored only so you can replay them. You can delete any meeting at any time from your dashboard.
  • We never train AI models on your voice, dictation, or meeting content. Not now, not in the future — full stop. Your recordings, transcripts, and meeting content are never used for training.
  • We do not sell your personal data. We have no advertising business.
  • Dictation transcription primarily runs on infrastructure under Dicted's direct operational control. Meeting transcription, diarization, and AI artifact generation use named cloud sub-processors listed in our DPA — none of whom retain or train on your content.

The rest of this page is the detail required by GDPR, CCPA, the Australian Privacy Act, and other privacy laws. It tells you what we collect, why we collect it, how to access or delete it, and who to contact.

2. Who we are and where we operate

The service known as dicted (accessed at dicted.ai and app.dicted.ai, and via the desktop/mobile apps of the same name) is operated by M37 Tech Pty Ltd (ABN 88 696 420 363) ("we", "us", "our"), registered in Victoria, Australia.

  • Privacy contact: [email protected]
  • General contact: [email protected]

We design and market the Service for residents of Australia, New Zealand, the United States, and Canada. The applicable regimes for our marketed regions are:

  • Australia — Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs)
  • New Zealand — Privacy Act 2020
  • United States — applicable state laws, including CCPA/CPRA (California), CTDPA (Connecticut), ColoPA (Colorado), VCDPA (Virginia), UCPA (Utah), and the HIPAA framework if we ever handle PHI (we do not)
  • Canada — PIPEDA federally, plus provincial laws (Québec Law 25, BC PIPA, Alberta PIPA)

Terminology drawn from the UK/EU (data controller, data processor, subprocessor) is used in this policy as widely-understood shorthand — the substance applies under each regime above.

We are the data controller for account-level information and the data processor when business customers upload meeting content containing their own employees' or clients' voices.

2.A If you are outside our marketed regions

Residents of the European Economic Area, Switzerland, the United Kingdom, or any other region we do not actively market to may sign up at their own initiative. If you do, you should know the following:

  • EU GDPR / UK GDPR do not structurally govern our relationship. We operate under the Australian privacy framework. We do not maintain a GDPR Article 27 representative, a GDPR-specific Data Processing Agreement, or the EU-US Data Privacy Framework / SCC / IDTA contractual mechanisms for your data.
  • We still apply the same clean privacy practices to you as we do to users in our marketed regions: audio deleted immediately after transcription, no training on your content, explicit marketing opt-in, no tracking cookies, no advertising business, prompt response to deletion and export requests. In substance these are consistent with GDPR standards — they are simply not documented in the GDPR-specific manner that regulated EU/UK processing requires.
  • You still have the rights listed in §8 of this policy (access, rectification, deletion, export, objection). You can email [email protected] at any time to exercise them.
  • Your personal information is stored and processed in the United States and Australia, via the subprocessors listed in §6. By signing up outside our marketed regions you acknowledge and accept this international processing.
  • If you are a data-protection regulator with a question about a user in your jurisdiction, email [email protected] — we will cooperate in good faith.

If you believe we should not be processing your personal information without a GDPR-compliant framework, the simplest remedy is to delete your account — doing so removes all of your data per §7. We will also honour any specific deletion / access request under this section promptly.

When we actively market the Service in the EEA, Switzerland, or the UK, we will add a GDPR-compliant section to this policy, appoint Article 27 representatives, and publish a GDPR-specific DPA. Until then, the framework above is what you are accepting.

2.1 No voiceprinting, no biometric identification

We want to be completely explicit about what we do NOT do with your voice:

  • We do not generate voiceprints (voice embeddings or biometric templates derived from the acoustic characteristics of an individual's voice).
  • We do not use voice to identify individuals. Speaker diarisation in meeting transcripts clusters voices within a single recording as "Speaker 1", "Speaker 2", etc. — this does not match a voice to a named person and does not carry across separate meetings.
  • We do not retain voice embeddings after transcription. Whatever internal representations a speech-to-text model computes are discarded with the rest of the audio once the transcript returns.
  • We do not use voice for authentication, fraud-detection, or account security.

Voice is therefore not processed by us as "biometric data" under GDPR Article 4(14) / APP special-category data definitions. We do not rely on any Article 9 basis for special-category processing because we do not engage in the kind of processing that triggers Article 9.

2.2 Third parties recorded in your meetings

When you upload a meeting recording, other people's voices are in it. We process that audio to deliver the meeting-intelligence service to you. For those third parties:

  • Legal basis: legitimate interest of the uploading customer in processing their own meeting recordings for productivity purposes, balanced against the limited intrusion and the short processing window. This is consistent with APP 3 (collection of personal information only by lawful and fair means) and equivalent doctrines in NZ, US state laws, and PIPEDA. We have documented a Legitimate Interests Assessment internally. No identification or voiceprinting is performed (see §2.1).
  • Your responsibility: you must obtain any consent required by your local recording laws — see Terms of Service §6.4. Dicted is not the party recording the conversation and cannot assess the local-law consent requirements on your behalf.
  • Rights of recorded third parties: if you are a person recorded in a meeting uploaded to Dicted by someone else and you wish to exercise access, rectification, or erasure rights over your voice content, email [email protected]. We will identify the relevant account and action the request within one month (or coordinate with the uploading customer where that's legally appropriate).

2.3 Health information and PHI

Dicted is not designed for, and does not claim HIPAA compliance for, the processing of Protected Health Information ("PHI"). We do not enter into Business Associate Agreements, do not maintain HIPAA Security Rule controls, and are not certified or audited for HIPAA compliance.

Health information that constitutes PHI under HIPAA (45 CFR §160.103), or sensitive health information under the Australian Privacy Act 1988 (Cth) APP regime, the My Health Records Act 2012 (Cth), state-level Health Records Acts, EU GDPR Article 9, or equivalent US state-level health-privacy laws, should not be uploaded to Dicted. The contractual prohibition is set out in our Terms of Service §5A.2 and Acceptable Use Policy §2.5; this is a material-breach clause, not a soft preference.

Because we contractually exclude PHI from the Service, we do not engage in the special-category processing that triggers GDPR Article 9, APP 3.3 (sensitive information), or HIPAA-equivalent obligations. If we discover that PHI has been uploaded in breach of the prohibition, we will treat the content under our incident-response process: typically suspension of the account and deletion of the offending material, coordinated with the uploading user where feasible.

3. Information we collect

3.1 Account information

  • Email address, display name, password hash (bcrypt — we never see your plaintext password)
  • Optional: avatar / profile picture
  • Signup metadata: timestamp, how you found us (if you told us during onboarding), your primary use case (if you told us)
  • Marketing email opt-in state (defaults to OFF — you must actively tick the checkbox at signup)

3.2 Content you create

  • Dictation audio — sent to a speech-to-text provider, discarded from our systems as soon as the transcript returns (typically within seconds).
  • Transcripts — retained until you delete them. You can set a custom retention schedule in Settings (from "do not save" through to a rolling window of N days/months); new accounts default to indefinite retention until you change the setting. You can delete any individual transcript immediately.
  • Meetings — audio files you upload, the resulting transcript, speaker diarisation, AI summary, minutes, and action items. Your transcript and all AI-generated outputs are kept until you delete the meeting — we never auto-delete them. Meeting audio follows a tiered retention schedule that depends on your plan (see §7): on Free, the audio file is automatically deleted 30 days after you create the meeting, and the transcript is kept; on Pro, audio is kept for as long as your subscription is active. You can export or download any meeting's audio at any time before it is deleted.
  • Voice notes — short transcripts you save as notes. Retained until you delete them.
  • Smart action output — text generated by AI transformations you apply to your dictation (rewrite, summarise, translate, etc.). Retained with the underlying note/transcript.

3.3 Technical information

  • Device fingerprint for anti-fraud and concurrent-session limits (device name, operating system, hardware ID on Tauri desktop, cookie + user agent on web). We rely on legitimate interest for this processing, documented in an LIA summarised in §9. The fingerprint is strictly bound to preventing account compromise and enforcing the plan's device-session cap — it is never used for advertising, cross-site tracking, or profiling.
  • IP address — your IP is processed in-memory by our rate-limiting system but is not stored in our application database. Server access logs (handled by our nginx reverse proxy) may temporarily retain IP addresses for up to 14 days for security and abuse detection, after which standard log rotation removes them.
  • Client version, platform (desktop/web/mobile) for compatibility and error tracking
  • Error reports and crash logs (via Sentry — content-bearing fields are scrubbed via a beforeSend filter that strips URL query strings, request bodies, and user identifiers; we document the filter configuration internally and will provide details to any regulator or customer on request)

3.4 Billing information

Processed by Stripe. We never see your card number. Stripe returns us a customer ID, a subscription ID, and the price tier you're on. Your Stripe data is subject to Stripe's own privacy policy (stripe.com/privacy).

3.5 Usage metadata

  • Minutes of dictation per billing period
  • Meeting upload count and aggregate duration
  • Smart action counts (daily and monthly)
  • Concurrent session counts

We use this to enforce your plan's fair-use limits (see FAIR_USE.md) and to understand product usage in aggregate. Individual session patterns are logged only to the extent necessary to detect automation or abuse.

4. Why we process each type of data

Data Legal basis (GDPR) Purpose
Account + password Contract (Art. 6(1)(b)) Provide the service you signed up for
Dictation audio / transcripts Contract Deliver transcription — the core product
Meeting uploads Contract Deliver meeting intelligence
Device fingerprint Legitimate interest (Art. 6(1)(f)) Prevent account sharing + abuse; protect your account from unauthorised access
IP address Legitimate interest Security, rate limiting, abuse prevention
Billing info Contract + Legal obligation (Art. 6(1)(c)) Process payment; comply with tax/finance record-keeping
Marketing emails Consent (Art. 6(1)(a)) Send you product updates — ONLY if you explicitly ticked the opt-in at signup
Transactional emails Contract Welcome email, password reset, usage warnings, cancellation confirmation
Crash logs Legitimate interest Find and fix bugs

5. Speech-to-text processing

This is the most sensitive part of dicted, so we spell it out:

  1. You speak into the app.
  2. Your audio is captured and sent over TLS to one of our speech-to-text providers (see Subprocessors below).
  3. The provider returns a text transcript.
  4. Our server discards your audio the moment that transcript is received. We do not write dictation audio to disk or to any long-term storage on our systems.
  5. If a smart action is applied, the transcript text (never audio) is processed by a language model. The primary path runs on infrastructure operated directly by Dicted (no data leaves our network). Google Gemini Flash is a cloud fallback that fires only when the primary path is at capacity or unavailable; in that case the transcript text is sent to Google under their published API terms (zero-retention, no-training). See §6.1.
  6. The transcript and action output are returned to your client, which renders them at your cursor (in dictation mode) or saves them as a note/meeting (in other modes).

Meeting uploads are different: the audio is stored in your account so that you can replay it alongside the transcript. You can delete any meeting (audio + transcript) at any time from the meetings page, and deletion is permanent. Meeting audio is also subject to the tiered retention schedule in §7 — on Free it is deleted 30 days after upload (the transcript is kept and remains fully usable; the meeting detail view simply shows that the audio has expired), and on Pro it is kept while your subscription is active. Either way you can download the audio before it expires.

6. Subprocessors

We use the following third-party services to deliver dicted. A subprocessor is a provider we share data with in order to run the service.

We deliberately keep this list small and limit AI processing to well-known, established providers with strong privacy reputations — predominantly US-based. We do not route your content to unknown, low-profile, or jurisdictionally unclear providers.

6.1 AI processing subprocessors

These providers apply machine-learning models to your content (transcribe audio, summarise transcripts, etc.) on the paths described below.

Subprocessor Purpose Data shared Location
OpenAI Speech-to-text fallback for dictation when the primary path is at capacity or unavailable Audio (discarded after transcription) United States
Soniox Speech-to-text + diarization fallback for meetings Audio (discarded after transcription) United States
Deepgram Speech-to-text fallback for dictation and meetings when the primary path is at capacity or unavailable Audio (discarded after transcription) United States
AssemblyAI Speech-to-text + diarization fallback for meetings when the primary path is at capacity or unavailable Audio (discarded after transcription) United States
Gladia Speech-to-text fallback for dictation and meetings when the primary path is at capacity or unavailable Audio (discarded after transcription) European Union (France)
Groq Speech-to-text fallback (dictation and meetings) and cloud language-model inference fallback for transcript processing when the primary path is at capacity or unavailable Audio for speech-to-text; transcript text (never audio) for language-model inference United States
Dicted (self-hosted Gemma 4-26B-A4B) Primary language-model processing on transcripts — meeting summaries, minutes, action items, smart actions, Smart Polish, Voice Edit. Runs on Dicted-operated infrastructure; transcript text never leaves Dicted's network. Transcripts (never audio) Australia
Google (Gemini Flash) Cloud fallback when the primary path is at capacity or unavailable. Receives transcript text only when invoked. Zero-retention, no-training under enterprise terms. Transcripts (never audio) United States

All AI subprocessors above are bound by their published API terms to:

  • Not retain your content after the response returns (or to retain it only for the minimum necessary to deliver the response)
  • Not use your content to train speech or language models
  • Not disclose your content to third parties except as required to deliver the service

For dictation specifically, the primary speech-to-text path runs on infrastructure operated directly by Dicted (see §6.2 — Oracle Cloud for application hosting and the Dicted-operated GPU node). The OpenAI fallback above only fires when this primary path is at capacity or unavailable.

For meeting transcription and diarization, the primary path runs on RunPod Secure Cloud (see §6.2) executing our self-hosted speech-recognition pipeline. RunPod is infrastructure-grade — they provide GPU compute and execute our Docker image; they do not apply their own AI models to your content. The Soniox subprocessor above only fires when the primary path is unavailable.

6.2 Infrastructure subprocessors

These providers carry, store, or compute on your data without applying AI models of their own.

Subprocessor Purpose Data shared Location
Cloudflare R2 Meeting file storage Meeting audio files (encrypted at rest) United States / global edge
RunPod (Secure Cloud) GPU compute for our self-hosted meeting transcription + diarization pipeline Meeting audio (transient — discarded after transcription) Pinned region (United States)
Stripe Payment processing Name, email, card token United States / Ireland
Oracle Cloud Infrastructure Application hosting + Dicted-operated dictation transcription compute All operational data, dictation audio (transient) United States
Amazon Web Services (SES) Transactional and opt-in marketing email delivery Email address + message United States
Sentry Crash + error reporting Technical stack traces (content redacted where feasible) United States

6.3 Cross-border data disclosure

All of our AI and infrastructure subprocessors are US-based, with the single exception of Gladia — a speech-to-text fallback provider established in the European Union (France). For Australian, New Zealand, and Canadian users (and customers whose US state law contemplates cross-border-transfer disclosure), your personal information is disclosed internationally to deliver the Service.

For Australian users (APP 8): we take reasonable steps to ensure each overseas recipient does not breach the APPs, including: (a) contractual terms requiring equivalent privacy protections, no retention of audio beyond transcription, no training on user content, and no third-party disclosure; (b) preference for providers with enterprise-grade security certifications (SOC 2, ISO 27001, PCI-DSS where applicable); (c) limiting each provider to the minimum data needed for its function; and (d) periodic review of their published security and privacy practices. We do not rely on the "substantially similar law" exception under APP 8.2(a). We remain accountable under APP 8.1 for any breach of the APPs by an overseas recipient.

For New Zealand users (Privacy Act 2020): we comply with IPP 12 by relying on equivalent contractual protections.

For Canadian users (PIPEDA + provincial laws): we rely on contractual safeguards equivalent to those required under Canadian federal and provincial privacy law for cross-border processing.

The contractual mechanism with each provider:

Provider Mechanism
OpenAI API zero-retention terms + SOC 2 Type II
Soniox Published API terms (no-retention, no-training) + SOC 2 Type II
Deepgram Published API terms (no-retention, no-training)
AssemblyAI Published API terms (no-retention, no-training)
Gladia Published API terms (no-retention, no-training)
Groq Published API terms (no-retention, no-training)
Google (Gemini) Enterprise terms for zero-retention and no-training
Cloudflare R2 Contractual privacy terms + SOC 2 / ISO 27001
RunPod (Secure Cloud) Contractual privacy terms + SOC 2 Type II (Secure Cloud tier only — RunPod's Community Cloud is not used)
Stripe PCI-DSS Level 1 + SOC 2 + contractual privacy terms
Oracle Cloud SOC 2 Type II + contractual privacy terms
AWS (SES) SOC 2 + contractual privacy terms
Sentry Contractual privacy terms + content-scrubbing filter we configure

Note: dicted is not offered in the EEA or UK, so EU-US Data Privacy Framework (DPF) certification and UK International Data Transfer Agreements (IDTA) are not relied on in this policy. When we expand to those regions, §6.3 will be updated with the applicable DPF / SCC / IDTA mechanisms and users notified in advance.

6.4 Subprocessor change notification

A complete, current list of subprocessors is available at dicted.ai/subprocessors. We will notify you by email of any new subprocessor at least 30 days before they gain access to your data, giving you time to object. If you object to a new subprocessor, you may cancel your subscription and receive a pro-rata refund of any pre-paid unused portion.

We aim to select subprocessors from established, well-known providers — predominantly US-based — with published privacy policies and enterprise-grade security practices. We do not add obscure or low-reputation providers even if they are cheaper. This is a policy statement, not an absolute contractual commitment — we reserve the right to vary providers as needed, subject to the notification-and-objection process above.

7. How long we keep your data

Data Retention
Account info Until you delete the account, then 30 days soft-delete grace period
Dictation audio Deleted immediately after transcription (seconds, not retained)
Transcripts Per your account preference (default: until you delete)
Meeting transcripts, summaries, minutes, action items Until you delete the meeting — never auto-deleted on any plan
Meeting audio (Free) Deleted automatically 30 days after upload; the transcript is kept
Meeting audio (Pro) Kept while your subscription is active; a Pro→Free downgrade triggers a 30-day grace (see below) before the Free rule applies
Voice notes Until you delete the note
IP logs 90 days
Crash / error logs 90 days
Billing records 7 years (Australian tax law requirement) — limited to invoice/payment facts, not content
Email opt-in state Lifetime of the account; timestamped so we can prove consent if asked

After you delete your account, we purge all personal data within 30 days except the 7-year billing records described above and any data we are legally required to retain (e.g. for subpoena response).

7.1 Meeting-audio retention in detail

Meeting audio is the largest part of what we store, so we apply a tiered retention schedule. In every case your transcript, summary, minutes, action items, and other AI-generated outputs are kept until you delete the meeting — these are never automatically deleted. Only the audio file itself is subject to the schedule below:

  • Free plan: the audio file is automatically deleted 30 days after you create the meeting. The transcript and all derived outputs remain. The meeting detail view shows that the audio has expired and that you can keep future audio by upgrading.
  • Pro plan: the audio file is kept for as long as your subscription is active.
  • Storage limits: Free includes 5 GB of meeting-audio storage and Pro includes 100 GB. When you reach your limit, new uploads are blocked until you free up space or upgrade — we do not delete existing audio to make room.
  • If you downgrade from Pro to Free: nothing is deleted immediately. You get a 30-day grace period from the downgrade date, during which we email you a reminder and offer to export your audio. After the grace period, audio that already exists falls under the Free 30-day-from-creation rule (so older audio may be deleted shortly after the grace ends), and any audio still within 30 days of its creation date is kept until it reaches that age.
  • Export before deletion: you can download any meeting's audio at any time before it is deleted, from the meeting detail page.

8. Your rights

8.1 Your rights (all users)

Regardless of your specific jurisdiction, we honour the following rights for every user, because they are the right default and they're required in most of our supported regions:

  • Access — you can request a copy of the personal data we hold about you
  • Rectify — you can correct inaccurate data, directly in Settings for most fields
  • Erase — you can delete your account and associated personal data (§7 above for what survives and for how long)
  • Port — you can export your data in a machine-readable format from Settings
  • Restrict / object to processing based on our legitimate interest (including the device-fingerprint processing in §3.3)
  • Withdraw consent for marketing emails at any time — via the unsubscribe link in any marketing email, or from Settings
  • Not be subject to significant automated decisions — we do not use automated decisions with legal or similarly significant effects. Account-suspension decisions for suspected abuse are always reviewed by a human before becoming final.

To exercise any of these rights, email [email protected] or use the Export data and Delete account buttons in your dashboard settings. We aim to respond within 30 days (one month for Australian users requesting access under APP 12, 45 days for CCPA users, sooner where possible).

You also have the right to complain about our handling of your personal information to the relevant regulator:

  • Australia: Office of the Australian Information Commissioner (OAIC) — oaic.gov.au
  • New Zealand: Office of the Privacy Commissioner — privacy.org.nz
  • United States: your state Attorney General; California: California Privacy Protection Agency (CPPA)
  • Canada: Office of the Privacy Commissioner of Canada — priv.gc.ca

8.2 CCPA / CPRA (California residents)

California residents have the right to:

  • Know what personal information we collect, disclose, and the purposes (right to know)
  • Delete personal information we hold, subject to legal retention exceptions (right to delete)
  • Correct inaccurate personal information (right to correct)
  • Opt out of the "sale" or "sharing" of personal information — we do neither, but you have the right regardless
  • Limit the Use and Disclosure of Sensitive Personal Information — we collect voice recordings, which can be treated as sensitive personal information under §1798.140(ae); we use this only to deliver the service you requested, which is an exempt purpose under CPRA §1798.121(a), so no separate "limit" action is needed. You can nonetheless email [email protected] at any time to ask us to stop any processing you consider outside the service delivery.
  • Not be discriminated against for exercising these rights
  • Designate an authorised agent to make requests on your behalf — we require written authorisation and independent verification of the agent's authority

Categories of personal information collected and retention. Disclosed per CPRA §1798.100(a)(3):

CCPA category Examples for dicted Retention
Identifiers Email, display name, account ID Until account deletion + 30-day grace
Customer records (§1798.80(e)) Payment data (via Stripe) 7 years (AU tax) for invoice facts only
Internet activity IP address, device fingerprint, client version IP addresses not stored in application DB; nginx access logs rotate at ~14 days. Active fingerprints retained for session length.
Geolocation Inferred country from IP (coarse only) Not persisted beyond session
Audio/voice (sensitive) Dictation audio (transient); meeting audio (tiered) Dictation: seconds. Meeting audio: Free deleted 30 days after upload; Pro kept while subscription active (30-day grace on downgrade). Meeting transcripts kept until you delete the meeting. See §7.1.
Professional/employment Signup-onboarding answers (optional) Until account deletion
Inferences None — we do not profile users N/A

We do not sell or share personal information for cross-context behavioural advertising as those terms are defined by the CCPA/CPRA. We have no advertising business.

Shine the Light (Cal. Civ. Code §1798.83): we do not disclose personal information to third parties for their direct marketing purposes. California residents may email [email protected] to confirm this for their records.

California "notice at collection"

This Privacy Policy is presented at, and linked from, every signup entry point and every input control where new personal information is first collected — account creation, billing, meeting upload, and voice-note creation. The categories of personal information we collect, the purposes for which each category is used, and the retention period for each are listed in the "Categories of personal information collected and retention" table above. We do not sell or share personal information for cross-context behavioural advertising as those terms are defined by the CCPA/CPRA. The notice in this Privacy Policy is the notice at collection for the purposes of CPRA §1798.100(a). California residents can exercise the rights listed in §8.2 by emailing [email protected] or using the Export data and Delete account buttons in dashboard settings.

8.3 Australian Privacy Principles (APPs)

You have the right to access and correct your personal information held by us, and to complain about our handling of personal information. We comply with the APPs under the Privacy Act 1988 (Cth). Complaints can be made to us first ([email protected]) and, if unresolved, to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Cross-border disclosure (APP 8). All of our subprocessors listed in §6 are located overseas, primarily in the United States. We take reasonable steps to ensure they do not breach the APPs, including: (a) contractual terms requiring equivalent privacy protections; (b) preferring providers certified under the EU-US Data Privacy Framework (a proxy for robust privacy practice); (c) periodic review of their published security and privacy practices; and (d) limiting each provider to the minimum data needed for its function. We do not rely on the "substantially similar law" exception under APP 8.2(a) because the US does not have a federal general-purpose privacy law substantially similar to the Privacy Act. We remain accountable under APP 8.1 for any breach of the APPs by an overseas recipient.

9. Cookies and similar tracking

See the separate Cookie Notice (COOKIE_POLICY.md / dicted.ai/cookies). Summary: we use the minimum cookies required to keep you signed in, prevent cross-site request forgery, and (if you consent) basic product analytics. We do not use advertising or tracking cookies.

10. Security and breach notification

  • All data in transit is encrypted with TLS 1.2 or higher.
  • Passwords are hashed with bcrypt (cost factor 12) — we cannot recover your password, only reset it.
  • Access to production systems is restricted to a small number of operational staff, audited via 2FA-protected login.
  • Meeting files in R2 are encrypted at rest.
  • We maintain an internal incident response process.

Breach notification timelines:

  • Australian OAIC + affected Australian users: if we suspect an eligible data breach, we complete our assessment within 30 days — the maximum the Notifiable Data Breaches scheme (Privacy Act 1988 (Cth) Part IIIC) allows for assessment. If we conclude that an eligible data breach has occurred, we notify the OAIC and affected individuals as soon as practicable after forming that view (not 30 days later), and sooner than the assessment deadline where the risk is material and understood.
  • New Zealand Privacy Commissioner: as soon as practicable under the Privacy Act 2020's Notifiable Privacy Breach regime where the breach is assessed as causing or likely to cause serious harm.
  • Canadian Privacy Commissioner + affected users: as soon as feasible under PIPEDA's Digital Privacy Act amendments where there is a real risk of significant harm.
  • US state attorneys-general / affected US users: as required by the applicable state breach-notification law, often within 30-60 days.
  • Affected users everywhere: notified as soon as we can explain what happened and what to do about it, which is typically within a few days of confirming the breach.

No system is perfectly secure. You are responsible for keeping your own password and device access credentials safe.

10A. Government and law-enforcement requests

We treat government and law-enforcement demands for user data as exceptional, and we hold them to the following standard:

  • Valid legal process required. We disclose personal information to law enforcement or a government agency only where we are compelled by valid, properly-served legal process (such as a subpoena, court order, or warrant) appropriate to the data sought, or where the emergency exception below applies.
  • We review and push back. We review each request for validity and scope, and object to, narrow, or challenge requests that are overbroad, defective, or unlawful.
  • We notify you where we can. Where we are legally permitted, we notify the affected user before disclosing their data so they have an opportunity to respond — unless doing so is prohibited by law or the matter is a genuine emergency.
  • Emergency exception. Where we believe in good faith that disclosure is necessary to prevent imminent death or serious physical harm, we may disclose the minimum information necessary to the relevant authority without prior notice.
  • Transparency. We intend to publish a transparency report on the volume and type of requests we receive once volumes make that meaningful.

Requests should be sent to [email protected]. Nothing in this section limits the mandatory reporting duties described in our Acceptable Use Policy (for example, CSAM reporting).

11. Children

Dicted sets a minimum account age of 16. Where your local law sets a higher age for digital-service consent, that higher age applies. We do not knowingly collect data from anyone under the applicable minimum age.

We do not collect a date of birth or any age information at signup, and we do not use facial, biometric, or age-estimation technology. The minimum age is a condition of the Terms of Service you accept when you create an account: by signing up you confirm you meet it. We do not separately verify age, but we act on credible reports that an account holder is under the minimum age. If you are a parent and believe your child has created an account, email [email protected] and we will delete the account promptly. If you are building a product category for which we should apply stricter age-assurance (education, children's services), contact us first — we do not market to those categories.

12. Changes to this policy

We will notify all users by email of material changes at least 30 days before they take effect. Material changes include: new categories of data collected, new subprocessors with access to content, new purposes of processing, or any expansion of data retention. Non-material changes (typo fixes, clarifications, new contact channels) are made without notice but always dated at the top of this page.

Previous versions of this policy are archived and available on request to [email protected].

13. Contact

  • Privacy matters: [email protected]
  • General: [email protected]

© 2026 M37 Tech Pty Ltd, PO Box 1215, GREYTHORN VIC 3104, Australia. All rights reserved.

Other legal documents

Terms of Service Fair Use & Anti-Abuse Policy Cookie Policy Refund & Cancellation Policy Acceptable Use Policy Takedown Procedure Data Processing Agreement Subprocessors Subprocessor Change Log Open-Source & Model Attributions

© 2026 M37 Tech Pty Ltd. All rights reserved. · ABN 88 696 420 363