Last updated: 2 September 2026
This Privacy Policy explains what information ReadoutIQ ("the app", "we") handles, and how. ReadoutIQ is designed privacy first: your recordings and notes belong to you, live on your devices, and are never sent to servers operated by us. We operate no accounts, no analytics, and no tracking.
This policy is prepared with reference to the Singapore Personal Data Protection Act 2012 (PDPA). Where you are located elsewhere, equivalent rights (such as those under the GDPR or CCPA) are respected in the same way, because the app's design gives you direct control of all your data.
The app collects nothing about you as an account holder: no name, no email address, no location, no advertising identifier and no usage analytics. There is no account to create.
It does handle details of OTHER people, because meetings involve them: speaker names you type, attendee names and a location taken from a calendar event you linked, and, only if you turn on the RapportIQ sharing described in section 3, contacts that app has published. All of it stays on your device except where section 4 says otherwise.
Only at your instruction:
We never sell or rent personal information, and have no data to sell.
This is the only case in which the app sends anything you have created to another company over the network, so it is set out here in full. The one other place your content leaves this app is the optional Body of Knowledge feed in section 3, which stays on your own device.
What is sent. The text of the meeting transcript and your notes on it. Where they exist, also: the text of pre-reads attached to that meeting, which includes the body of a calendar invitation when the meeting was prepared from your diary; and the recording's description and keyword hints, which for a meeting linked to a calendar event contain that event's title, its location, and the names of its attendees. Those names come from your own calendar; email addresses are stripped out before anything is sent. Your audio recordings are never sent. Meetings you have marked Sensitive are never sent, without exception. Nothing about you as an account holder is sent, because there is no account: no name, no email address, no device or advertising identifier.
How it is collected. The transcript is produced on your device from a recording you chose to make, and recording begins only when you press record. The notes are typed by you. Pre-reads are files you attach yourself, or share into the app from somewhere like Mail. The description, the keyword hints, the attendee names and the location are copied from a calendar event, and only from a calendar you ticked in Settings, after you turned calendar awareness on; it is off by default. Nothing here is gathered in the background.
Who it is sent to. The single provider you select in Settings, under AI service, using an API key you supply from your own account with that company: Anthropic (the Claude models), OpenAI, or OpenRouter, which forwards the request to the model provider you name in the model field, so that onward provider receives the text too. The app has no server of its own and never receives your transcripts: the request goes from your device to your chosen provider, under your own account.
Every use made of it. The transcript text is used only to produce the thing you asked for: the written summary and its title, action items and their owners, the decision register, recognised names and terms, speaker-name suggestions, answers to questions you ask about the meeting, a translation of the transcript when you request one, and cross-meeting insights when you run them. It is not used for advertising, for profiling, or for any purpose you did not start.
One exception, which carries none of your content: when you have saved an API key, the Settings screen asks that provider for its current list of model names, so the list shown to you is never out of date. That request carries your key and nothing else, and it happens whether or not you have given permission to send transcripts.
Your permission is obtained first. Before the app sends a transcript to a provider for the first time, it shows you a screen naming that company, the data, the purpose and what is excluded, and sends nothing unless you agree. Permission is recorded separately for each provider, so agreeing to one says nothing about another, and changing provider asks again. You can withdraw it at any time in Settings, under AI service; withdrawal takes effect immediately and the next request is refused rather than sent. Until permission is given, every AI feature in the app declines to run.
Protection by the third party. Transcript text is shared only with providers whose published API terms commit to protections equivalent to those described in this policy: not training their models on data submitted through the API by default, and retaining it only as long as needed to serve the request and to meet their legal obligations. Anthropic and OpenAI both state that API data is not used to train their models by default. Because the account is yours, the retention and training settings on it are yours to inspect and control, and you should read the policy of the provider you choose: Anthropic at https://www.anthropic.com/legal/privacy, OpenAI at https://openai.com/policies/privacy-policy, OpenRouter at https://openrouter.ai/privacy. If a provider ceased to offer equivalent protection, the response would be to remove that provider from the app.
The app itself transfers nothing across borders. Where you use AI features, your chosen provider may process the transcript in other countries under its own safeguards; consult that provider's policy. iCloud data residency is managed by Apple.
Everything is retained on your device until you delete it. Deleting a meeting removes its audio, transcript, search index entries, and derived content from the device (and from your private iCloud, where sync is enabled). Removing an API key removes it from the Keychain. Uninstalling the app removes all local data.
Audio you chose to back up is the deliberate exception: those copies live in your own iCloud Drive and survive uninstalling the app, which is the point of a backup. They remain yours to keep or delete, in the Files app or from within ReadoutIQ.
Recordings and data are stored within the app's protected sandbox and covered by your device's encryption. API keys are held in the Keychain. Network calls to AI providers use HTTPS. No method of transmission is entirely secure; choose AI providers you trust.
Because your data never leaves your control, you exercise your rights (access, correction, deletion, portability, and withdrawal of consent under the PDPA or equivalent laws) directly in the app: view and edit everything, export anything, delete anything. There is no third party holding your data on our behalf to petition.
You are responsible for complying with the laws that apply to recording conversations in your location, including obtaining any consent required from meeting participants. In Singapore, you should be a party to the conversation you record or have the consent of the participants.
ReadoutIQ is intended for users aged 18 and above.
Material changes to this policy will be reflected in the app with an updated date at the top of this document.
Questions about this policy: angweeseng@hotmail.com