Effective: 2026-07-25 · Operator: TeKoTeK (Franck Junior Aboya Messou) · Contact: mailtoteko.tek@gmail.com
This policy explains what personal data AIReco (the "App") collects, why, who it is shared with, how long it is kept, and the rights you have over it. It is written to satisfy EU/EEA + UK GDPR, the California CCPA, and Apple App Store Review Guidelines 5.1.1(i) and 5.1.2(i). If a section conflicts with your local law, the stronger protection applies.
| Data | Purpose | Lawful basis (GDPR Art. 6) | Where it lives |
|---|---|---|---|
| Audio recordings you make in the app | Local playback + on-device transcription. Sent to Google Gemini ONLY if you have accepted Cloud AI consent and selected "AIRecoo AI" mode. | Contract (the app you installed) + Consent for the Gemini path | On your device. Optional encrypted backup to your Firestore folder if you enable Cloud Sync. |
| Transcripts, summaries, action items, tags | The core notes the app produces from your recordings. | Contract + Consent for AI processing | Same as above. |
| Email address (only if you sign in) | Authenticating you, attaching IAP / Stripe entitlements to the right account, sending a deletion confirmation if you request one. | Contract | Firebase Authentication (Google LLC) + Apple ID / Google ID provider if you use Sign in with Apple / Google. |
| Device identifier (random UUID generated locally) | Enforcing the device-count cap on your subscription (Free 1, Basic 2, Pro 4) so a single subscription cannot be shared across an unlimited number of phones. | Legitimate interest (fraud prevention) | Firestore users/{uid}/devices. Wiped when you sign out or delete your account. |
| Monthly usage counters (number of recordings, AI tokens used) | Enforcing your plan's monthly cap and showing you the meter in the app. | Contract | Firestore users/{uid}/usage/{month}. |
| In-App Purchase receipt (Apple) / Stripe customer id (web + Android) | Validating that your subscription is active. | Contract | Sent to Apple StoreKit / Stripe for verification. Their decision is stored in Firestore users/{uid}. |
| Crash reports and non-fatal error events | Fixing bugs. No transcript text or note bodies are ever sent — only stack traces, error codes, and timings. | Legitimate interest (service quality) | Firebase Crashlytics (Google LLC). You can disable in Settings. |
| App language and theme preference | Showing the app in the language and theme you picked. | Contract | On-device secure storage. Never leaves the device. |
We use the following sub-processors. We send them only the minimum data needed for the purpose listed and require them to provide protections equal to ours.
| Service | What we send | Where | Their policy |
|---|---|---|---|
| Google Cloud / Firebase (Auth, Firestore, Cloud Functions, Storage, Crashlytics, Hosting, App Check) | Account email + UID, encrypted note bodies you opt in to sync, IAP/Stripe receipts, crash traces, app check tokens. | asia-northeast1 region (Tokyo) for functions; global for the other services. EU users' data is processed under Google's Standard Contractual Clauses. | firebase.google.com/support/privacy |
| Google Gemini API (generative AI) | The single audio recording or transcript you are processing — ONLY when you have accepted Cloud AI consent. | Google processing region. Your data is NOT used to train Gemini models per Google's API terms. | ai.google.dev/terms |
| Apple Inc. (App Store, Sign in with Apple, StoreKit IAP receipt validation) | IAP transaction id + product id only. | Apple servers. | apple.com/legal/privacy |
| Stripe, Inc. (payments — used only on web and Android) | Your email + payment information you enter on the Stripe Checkout page (we never see your card number). | Stripe US / EU. | stripe.com/privacy |
We do not use any advertising network, any analytics product that tracks you across apps or websites, or any data broker. We do not implement Apple's App Tracking Transparency framework because we do not track.
AIReco is not directed at children under 13. If you become aware that a child has provided us personal data, contact us and we will delete it.
Under GDPR and similar laws you have the right to:
Some sub-processors (Google, Apple, Stripe) operate outside your country. Transfers from the EEA/UK to the US rely on the EU-US Data Privacy Framework and on Standard Contractual Clauses where applicable.
Data in transit is protected by TLS 1.3. Data at rest on Firebase uses Google's encryption at the storage layer. Authentication tokens and the device identifier are stored in iOS Keychain / Android EncryptedSharedPreferences via the platform secure-storage APIs. Server-side enforcement of plan caps, device limits, and receipt validation happens in Cloud Functions; the client cannot bypass them.
Material changes are announced via the in-app notice banner at least 14 days before they take effect, and the "Effective" date at the top of this page is updated. You can revoke consent or delete your account if you don't agree.
Questions, requests, or DPA correspondence:
mailtoteko.tek@gmail.com
Operator: Franck Junior Aboya Messou (TeKoTeK), Japan.