Privacy Policy
Last updated: August 13, 2026
Dicta ("we", "our") operates the meeting service at dicta.uz. This page explains what we collect, how we collect it, what we use it for, and every third party we share it with.
Data we collect
- Account info. Email address, full name, and (when you sign in with Google) the Google profile picture URL. Collected when you create an account.
- Meetings. Meeting titles, participants, timestamps, and short codes you generate. Collected as you use the service.
- Audio and transcripts. When transcription is enabled, your meeting audio is captured by the app and sent to the AI providers listed below to produce a transcript, a summary, decisions and action items. The audio itself is not retained by us after processing unless recording is also on — only the resulting text is kept.
- Recordings. When the host starts recording, video and audio are uploaded to our private object store and accessible only to the host. We do not sell or publish recordings.
- Voiceprints (optional). If you opt in to voice enrollment, we derive a mathematical signature of your voice from a short sample and store it on our own servers so we can label you automatically in transcripts. This is optional, is asked for separately, and can be deleted at any time.
- Location (optional). If you allow it, an offline recording is tagged once, at the moment it starts, with the place you made it. Declining leaves recordings unlabelled and changes nothing else.
- Operational logs and diagnostics. IP address, user agent, request timing and crash reports, for debugging and abuse prevention.
How we collect it
Directly from you when you create an account or type into the app; automatically from your device when you record or join a meeting (microphone and, if you turn it on, camera and location); and from our servers as you use the service (logs and diagnostics). We do not buy personal data and we do not track you across other companies' apps or websites.
How we use it
To run the service, produce transcripts and AI summaries, support hosts after a meeting, process payments, and prevent abuse. We do not sell your data, we do not show advertising, and we do not use your meetings to train AI models.
AI processing and your consent
Turning a meeting into a transcript and a summary requires sending your data to AI processing providers outside Dicta. Specifically: your meeting audio goes to Google (Gemini API) to convert speech into text, and to RunPod or Replicate to determine who spoke when; the resulting transcript, meeting title and participant names go to Google (Gemini API) to generate summaries, decisions and action items and to answer your questions in AI chat.
We ask for your permission before any of this happens. In the Dicta apps the disclosure appears before you can record, upload or transcribe anything, and you can withdraw consent at any time under Settings → Data & AI. Without consent you can still sign in, create and join meetings and hold audio/video calls — recording, transcription and AI features stay off.
Third parties we share data with
We share personal data only with the providers below, only for the purpose named, and only to deliver the service. Each is bound by a contract that requires them to protect your data to a standard equivalent to this policy, to process it solely on our instructions, and not to use it to train their own models or for their own purposes.
- Google (Gemini API). Speech-to-text transcription, summaries, decisions, action items, AI chat answers and search indexing. Receives meeting audio, transcript text, meeting titles and participant display names.
- RunPod. GPU capacity for speaker separation, running software we build and control. Receives a short-lived link to the meeting audio, and nothing else — no names, titles or account data.
- Replicate. Backup speaker separation and voiceprint processing, used when our own service is unavailable. Receives a short-lived link to the meeting audio, or the voice-enrollment clip.
- Recall.ai. Only if you send the Dicta notetaker into an external Zoom, Google Meet or Microsoft Teams call. Receives that meeting's link, and returns its audio, video and attendee names. Processed in the European Union.
- Google (Sign-In) and Apple (Sign in with Apple). Authentication, if you choose those sign-in methods.
- LiveKit. Real-time audio and video during a call. Runs on our own servers in Uzbekistan.
- Cloudflare. Encrypted storage of recordings, content delivery, and sending transactional email.
- Sentry. Crash and error diagnostics, which may include your account identifier and request details.
- Firebase and Google Analytics. Product usage analytics. You can switch this off in Settings; it is never used for advertising.
- Apple Push Notification service and Firebase Cloud Messaging. Delivering push notifications, which may contain meeting titles.
- OpenStreetMap (Nominatim). Turning the coordinates of an offline recording into a place name, if you enabled location.
- Telegram. Sending you meeting summaries, if you link your Telegram account.
- Multicard and RevenueCat. Processing payments and subscriptions.
- Trello, Jira, ClickUp, Asana and Hisobot. Only if you connect them. Receives the meeting title, action items, decisions, a summary excerpt and a recap link. Anyone holding that link can open the recap, so connect these only to boards your participants would accept.
How long we keep it
Account data is kept while your account exists. Transcripts, summaries and recordings are kept until you delete them or delete your account. Voiceprints are kept until you remove them or turn voice enrollment off. Operational logs and diagnostics are kept for up to 90 days. After you delete your account we remove your account, transcripts and recordings within 30 days.
Where your data is processed
Our meeting servers are in Uzbekistan, on the TAS-IX network, and live call traffic stays on them. The AI providers listed above process data outside Uzbekistan — Google, RunPod and Replicate in their own regions, and Recall.ai in the European Union. Where data leaves Uzbekistan we rely on contractual protections equivalent to this policy.
Security
Traffic is encrypted in transit. Recordings are stored in a private object store that is not publicly listable, and are reachable only through short-lived signed links. Access to production systems is limited to staff who need it. No system is perfectly secure, so we also give you the tools to delete your data yourself.
Children
Dicta is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has given us data, write to us and we will delete it.
Your rights
You can access, correct, export or delete your data, and withdraw consent to AI processing at any time. You can delete your account by emailing support@dicta.uz. We will remove your account, transcripts, and recordings within 30 days.
You can also do it yourself, from inside the app, without contacting us — see how to delete your Dicta account.
Contact
Questions or requests: support@dicta.uz.