Legal

Privacy Policy

Last updated: September 13, 2026

Overview

This Privacy Policy explains how NOBULLSHIT CONSEIL (SIREN: 989 598 727, SIRET: 989 598 727 00018), located at 11 avenue de la Promenade, 85140 Essarts-en-Bocage, France, processes personal data in relation to Recapro.ai (the "Service"). We act as the data controller for the data described below.

We do not sell personal data and we do not share it with third parties for marketing or advertising purposes. We will never sell your personal data.


1. What we collect

Account data : email address, phone number and basic identifiers provided during registration and authentication.

Usage data : basic device/browser information to improve service reliability.

Content data : voice recordings, transcriptions, meeting reports, debrief notes and documents you submit. Do not include sensitive personal data unless strictly necessary and legal.

Calendar data : if you connect Google Calendar or Microsoft Outlook: your events for the next 7 days, read-only (see section 5).

Organizational data : all business data (projects, meetings, summaries) is associated with your organization and isolated from other organizations.

2. Sources and purposes

We collect data directly from you (forms, recordings, reports) and automatically (cookies or similar). We use data to operate the Service, secure accounts, detect abuse, improve quality and provide support.

Local storage vs upload: Audio recordings are stored locally on your mobile device. A copy is uploaded to our servers only for transcription and report generation. Local audio files remain on your device and constitute the source of truth for audio playback.

3. Legal bases (GDPR)

Contract : to provide the Service (authentication, recording, report generation).

Legitimate interests : to improve reliability, prevent abuse, and send you a few updates a year about the Service you already use. This is direct marketing to an existing customer under Article 6(1)(f) and recital 47 GDPR; you can object at any time, from your settings or the unsubscribe link in every message.

Consent : for connecting your Google or Microsoft calendar and for meeting reminders (section 5), and for cookies that require it. Because a calendar can reveal sensitive information (a medical appointment, a union meeting, a religious event), this consent counts as explicit consent under Article 9(2)(a) GDPR. You withdraw it at any time by disconnecting the calendar, without affecting processing already carried out.

Legal obligations : records and compliance obligations.

4. Providers and transfers

Data infrastructure : authentication, database and storage hosted in France/EU.

File storage : storage of transcription files, reports and temporary audio. Hosted in France/EU.

Voice transcription service : audio recordings are processed by our transcription service, hosted on our own infrastructure in France and operated by Recapro. No third-party AI provider is involved. Audio files are deleted after processing.

Artificial intelligence service : transcriptions and contexts are processed by our artificial intelligence service (self-hosted open-source models), running on our own infrastructure in France and operated by Recapro, to generate structured reports. Your data is never transmitted to any third-party AI provider (OpenAI, Google, Mistral or any other) and is never used to train models.

Email delivery : Brevo (Sendinblue SAS, France) delivers our service emails and product updates, and processes your address, first name and delivery indicators (open, click, unsubscribe) for that purpose.

When providers are outside the EEA, we rely on appropriate safeguards (e.g., Standard Contractual Clauses) where applicable.

5. Calendar data (Google Calendar, Microsoft Outlook)

If you connect your calendar, Recapro reminds you to record your upcoming meetings. This feature is optional: you turn it on from your settings and turn it off whenever you want.

This section overrides sections 2, 3 and 4 for anything concerning calendar data: it is used only to remind you to record your meetings, and for nothing else.

What we request : read-only access to your events (Google: the calendar.events.readonly scope; Microsoft: Calendars.Read) and the email address of the connected account, shown in your settings. We cannot create, edit or delete events, and we do not access any other data from your Google or Microsoft account.

What we store : a rolling copy of your events for the next 7 days: title, beginning of the description, location, video-call link, times, attendee count and your response status. We do not keep the list of attendees, only how many there are. An automatic purge runs every hour and removes from our servers every event that ended more than 24 hours ago. Access and refresh tokens are encrypted (AES-256-GCM), stored in the European Union (Frankfurt) and never sent to your devices.

What we do with it : determine whether an event is a meeting worth recording, then send you a reminder before it starts. This classification uses simple rules first and, where needed, our self-hosted AI model described in section 4: your calendar data stays on our infrastructure, is never sent to any third-party AI provider, and is never used to create, train or improve any AI or machine-learning model, whether general-purpose or specialized.

What the reminder contains : to send you that reminder, the event title, its time and the video-call link are passed to our delivery processors: Brevo (Sendinblue SAS, France) for email, and the Expo notification service then Apple or Google for push. They use them only to deliver the message. If you would rather the real title did not appear on your lock screen or in your inbox, turn off the matching option in your settings: the reminder then uses a generic label.

What we do not do : we do not sell this data, do not share it with anyone for advertising, marketing or profiling, and do not pass it to any third party other than the delivery processors named above, which act on our instructions alone. Human access does not happen in the normal course of the service: it is technically restricted to a small number of administrators, logged, and exercised only with your explicit agreement for a support request, to handle a security incident, or to comply with a legal obligation.

Disconnecting : from your settings, in one click. We then delete the connection, the tokens and every copied event, and access stops immediately. For Google we additionally ask the provider to revoke the token; Microsoft offers no equivalent, so you can withdraw the authorization from your Microsoft account. Deleting your Recapro account removes the connection, the tokens and the events in the same way; the authorization held at Google or Microsoft is withdrawn from that account’s own settings.

Recapro’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. This applies to raw data and to anything derived from it.

6. Retention

Account data: retained until you request account deletion.

Audio recordings and associated data: uploaded audio recordings, transcriptions and reports are retained according to an automatic retention policy configured by organization (90 days by default, minimum 30 days). After this period, data is automatically deleted from our servers. Local audio files on your device are not affected by this policy.

Temporary data: audio files used for transcription are deleted or archived after processing according to our retention policy.

We may retain aggregated or anonymized data that does not identify you.

Calendar data: an hourly purge deletes each copied event once it ended more than 24 hours ago; everything is deleted as soon as you disconnect the calendar or delete your account.

7. Your rights

Subject to conditions under applicable law, you may have rights of access, rectification, erasure, restriction or objection to processing, and data portability. You also have the right to file a complaint with a supervisory authority (in France, the CNIL). Where processing relies on your consent, you may withdraw it at any time with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal. You may object at any time, and without giving a reason, to the use of your data for direct marketing (Article 21(2) GDPR): a switch in your settings, and an unsubscribe link in every message.

8. Security

We implement technical and organizational measures appropriate to the risk. No method of transmission or storage is perfectly secure.

9. Children

The Service is not intended for children. Do not use the Service if you are below the age required to consent to data processing in your jurisdiction.

10. Changes

We may update this Policy from time to time. If the changes are significant, we will provide reasonable notice via the Service. Continued use after the effective date means you accept the changes.

11. Contact

NOBULLSHIT CONSEIL, 11 avenue de la Promenade, 85140 Essarts-en-Bocage, France. Email: [email protected]