Privacy Policy

Effective September 6, 2026 · version 4.2

PRIVACY POLICY

1. INTRODUCTION

1.1. This Privacy Policy ("Policy") describes how HedyOS, operated by Individual Entrepreneur Boldyrev Andrei Pavlovich ("Operator", "HedyOS", "we", "us", "our"), collects, uses, and protects your personal data when you use the HedyOS service ("Service").

1.2. This Policy is designed to comply with:

  • General Data Protection Regulation (EU) 2016/679 ("GDPR")
  • California Consumer Privacy Act of 2018 ("CCPA") and California Privacy Rights Act ("CPRA")
  • Other applicable data protection laws

1.3. This Policy applies to all personal data collected through the HedyOS website (hedyos.com) and desktop applications.

1.4. By registering for or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, please do not use the Service.


2. DATA CONTROLLER

Individual Entrepreneur Boldyrev Andrei Pavlovich

  • Registration number: 003-2026-169-2970 (Tax Service of the Kyrgyz Republic, Sverdlovsky district office, Bishkek; TIN 22703198640030)
  • Registered address: Michurina St. 167a, Sverdlovsky district, Bishkek, Kyrgyz Republic
  • Email: hello@hedyos.com
  • Website: https://hedyos.com

For data protection inquiries, please contact: hello@hedyos.com


2.1. OUR ROLES IN DATA PROCESSING

HedyOS acts in two distinct roles depending on the type of data being processed:

2.1.1. HedyOS as DATA CONTROLLER of User Account Data:

HedyOS is the data controller for the following categories of data:

  • User's email address
  • Password (hashed)
  • Name (optional)
  • Subscription information
  • User settings and preferences
  • IP address and User-Agent (when accepting legal documents — for consent verification)

Legal Basis for Processing:

  • Your consent (GDPR Art. 6(1)(a))
  • Performance of a contract (GDPR Art. 6(1)(b))
  • Legitimate interests (GDPR Art. 6(1)(f))

Purpose: Providing access to the Service, managing your account, processing payments, technical support, and security.

2.1.2. HedyOS as DATA PROCESSOR of User-Provided Content:

HedyOS processes content (transcription texts) provided by Users, which MAY contain personal data of third parties.

If content contains personal data of third parties:

  • YOU (the User) are the DATA CONTROLLER of such personal data
  • HedyOS acts as a DATA PROCESSOR on your behalf (GDPR Art. 28)

Processing is carried out based on the Terms of Service for the purposes of:

  • Synchronizing text between your devices
  • Providing public access to transcription sessions (at your request)
  • Automatic text translation
  • Processing text with AI language models (LLM)

HedyOS's Obligations as Processor:

  • Process content ONLY in accordance with your instructions
  • Ensure confidentiality and security of data
  • Not disclose personal data to third parties except subprocessors
  • Notify you of security incidents within 24 hours
  • Delete data upon your request within 30 days

2.1.3. Allocation of Responsibility:

This Privacy Policy governs the processing of Users' personal data (category 2.1.1).

Processing of content that may contain personal data of third parties (category 2.1.2) is performed by HedyOS as a processor on behalf of the User. Requirements and User responsibilities are described in Sections 6.2 and 6.3.


3. PURPOSES OF PROCESSING

HedyOS processes personal data for the following purposes:

3.1. Providing Access to the Service:

  • User registration and authentication
  • User identification when accessing Service features
  • Linking license to user's device

3.2. Providing Functionality:

  • Audio-to-text transcription
  • Translation of transcribed text
  • Processing text with AI language models (LLM): summarization, Q&A, text analysis
  • Synchronization of data between devices (optional)
  • Public sharing of transcription sessions (optional)

3.3. Payment Processing:

  • Managing licenses and subscriptions
  • Processing payments through Paddle, which sells the Service as our authorised reseller
  • Invoicing and storing transaction information

3.4. Technical Support and Service Improvement:

  • Providing technical support to users
  • Analyzing Service usage to improve functionality
  • Ensuring security and preventing abuse

3.5. Communications:

3.5.1. Essential Technical Notifications (cannot opt out):

  • Registration confirmation and account recovery
  • Critical security notifications

Legal basis: Performance of contract (GDPR Art. 6(1)(b))

3.5.2. Service Notifications (can opt out):

  • Payment confirmations, subscription status
  • Changes to Service functionality

Legal basis: Consent (GDPR Art. 6(1)(a)), can be withdrawn in profile settings

3.5.3. Marketing Communications (requires separate consent):

  • News about new features
  • Special offers and promotions
  • Educational content

Legal basis: Consent (GDPR Art. 6(1)(a)), can be withdrawn at any time


4. CATEGORIES OF PERSONAL DATA

4.1. Required Data (necessary for Service use):

  • Email address — for registration, authentication, and communication
  • Password — stored in encrypted form (hashing)

4.2. Optional Data:

  • Username — if provided during registration
  • Transcribed text — stored only if you enable device synchronization or create a public link
  • Settings and preferences — for personalization

4.3. Automatically Collected Technical Data:

  • IP address — for geolocation and security purposes
  • Cookies — for web interface functionality
  • Browser and device information — for Service optimization
  • Usage statistics — transcription counts and durations for license management

4.4. Payment Data:

  • Transaction information — date, amount, payment status
  • Payment details are processed by payment systems and NOT stored on our servers

4.5. IMPORTANT: Data NOT Processed by HedyOS:

Audio Files for Transcription: Audio files are NOT processed or stored by HedyOS:

  • You independently register with a third-party speech recognition service and obtain your personal API key
  • You enter your API key in HedyOS settings
  • Audio files are transmitted DIRECTLY from your device to the speech recognition service, bypassing HedyOS servers
  • HedyOS does NOT have access to your audio files

Local Storage: By default, transcription text is stored ONLY locally on your device and is not transmitted to HedyOS servers.

Transcription text is transmitted to HedyOS servers ONLY when:

  • You enable synchronization between devices; OR
  • You create a public link to a transcription session; OR
  • You use the automatic translation feature; OR
  • You use AI language model (LLM) features

5. LEGAL BASES FOR PROCESSING

5.1. Consent (GDPR Art. 6(1)(a), CCPA):

By using the Service, you confirm that you have:

  • Read this Privacy Policy
  • Consent to the processing of your personal data in accordance with this Policy

For California residents: You have the right to opt out of the sale of your personal information. HedyOS does NOT sell personal information.

5.2. Performance of Contract (GDPR Art. 6(1)(b)): Processing is necessary for the performance of the Terms of Service between you and HedyOS.

5.3. Legitimate Interests (GDPR Art. 6(1)(f)):

Processing for legitimate interests includes:

  • Security (analyzing access logs, blocking malicious IPs, fraud prevention)
  • Service improvement (error statistics, performance analysis, feature usage)
  • Legal compliance (data retention for accounting requirements)

5.4. AGE REQUIREMENTS

5.4.1. The Service is intended exclusively for persons aged 18 years or older.

5.4.2. By registering, you confirm that you have reached this age.

5.4.3. If we become aware that a user is under 18:

  • The account will be immediately suspended
  • Personal data will be deleted within 3 business days

6. CONTENT PROCESSING FOR TRANSCRIPTION, TRANSLATION, AND LLM

Audio transcription works in one way only: you use your own API key, and audio is sent from your device directly to the speech recognition service you chose. Audio never reaches HedyOS servers, and HedyOS has no access to it.

6.1. BYOK Scenario: Audio Transcription Using Your API Key

6.1.1. Self-Service Connection: To use audio transcription, you INDEPENDENTLY:

  • Register with a third-party speech recognition service
  • Obtain your personal API key
  • Enter your API key in HedyOS application settings

6.1.2. Direct API Interaction: When using transcription:

  • Audio files are transmitted DIRECTLY from your device to the speech recognition service
  • Audio files DO NOT pass through HedyOS servers
  • HedyOS does NOT have access to your audio files

6.1.3. Legal Relationships:

  • Contractual relationships for audio processing arise DIRECTLY between you and the speech recognition service
  • HedyOS is NOT a party to these relationships
  • You are responsible for compliance with the terms of use of chosen services

6.1.4. Supported Transcription Services:

HedyOS supports integration with various speech recognition services.

Countries with Adequate Data Protection (GDPR adequacy):

ProviderCountryRegions
GladiaFranceEU native
Alibaba SenseVoiceChina
iFlytekChina

Other Countries:

ProviderCompany CountryAvailable Regions
Google Cloud Speech-to-TextUSAUSA, Belgium (EU), Netherlands (EU), Germany (EU)
Microsoft Azure SpeechUSAUSA, Netherlands (EU), UK, Canada, Australia, Japan, Singapore, UAE, India, Brazil, South Africa
Amazon TranscribeUSAUSA, Ireland (EU), Germany (EU), UK, Canada, Japan, Singapore, Australia, South Korea, Brazil, South Africa, Bahrain
OpenAI Whisper APIUSAUSA, Ireland (EU), UK, Canada, Japan, South Korea, Singapore, India, Australia, UAE
DeepgramUSAUSA, Germany (EU)
AssemblyAIUSAUSA, Ireland (EU)
Rev.aiUSAUSA, Germany (EU)
Yandex SpeechKitRussiaRussia

Current list: https://hedyos.com/docs/transcription-services

6.1.5. Text Features Work Differently: Audio never passes through HedyOS servers, but text does. Translation, AI language model processing and synchronization operate through our servers, and the sections below describe each of them.


6.2. Automatic Text Translation

6.2.1. HedyOS's Role in Content Processing:

If content contains personal data of third parties:

  • HedyOS acts as a DATA PROCESSOR (GDPR Art. 28)
  • YOU (the User) are the DATA CONTROLLER of such personal data

6.2.2. Two Usage Scenarios:

SCENARIO 1: Personal Use If you use the Service for your own personal audio (lectures, podcasts, notes), no additional consents are required.

SCENARIO 2: Business Use (processing third-party data) If you transcribe content containing personal data of third parties (customer calls, meetings, interviews), you are the DATA CONTROLLER and responsible for:

  • Having a lawful basis for processing (consent, contract, legitimate interest)
  • Informing data subjects about processing
  • Compliance with GDPR/applicable data protection laws

6.2.3. How Translation Works:

When you activate automatic translation:

  1. Transcription text is transmitted from HedyOS server to a third-party machine translation service
  2. The translation service processes the text and returns the translated text
  3. Translated text is saved on HedyOS server (if synchronization is enabled) or locally

6.2.4. Translation Services Used:

Countries with Adequate Data Protection:

ProviderCountryRegions
DeepL SEGermanyEU native

Other Countries:

ProviderCompany CountryAvailable Regions
Google Cloud TranslateUSAUSA, Belgium (EU), Netherlands (EU), Germany (EU)
Microsoft Azure TranslatorUSAUSA, Netherlands (EU), UK, Canada, Australia, Japan, Singapore, UAE, India, Brazil, South Africa
Amazon TranslateUSAUSA, Ireland (EU), Germany (EU), UK, Canada, Japan, Singapore, Australia, South Korea, Brazil, South Africa, Bahrain

Current list: https://hedyos.com/docs/translation-services


6.3. Text Processing with AI Language Models (LLM)

6.3.1. Functionality:

The Service provides text processing features using Large Language Models (LLM):

  • Summarization (creating text summaries)
  • Generating answers to questions about content
  • Text analysis and structuring
  • Other text processing functions at user request

6.3.2. How It Works:

When activating LLM text processing:

  1. Selected transcription text is transmitted from HedyOS server to a third-party LLM service
  2. The service processes the request and returns a result
  3. Results are displayed to you and may be saved on HedyOS server (if synchronization is enabled) or locally

6.3.3. Legal Qualification:

Similar to translation (section 6.2):

  • HedyOS acts as DATA PROCESSOR on your behalf (GDPR Art. 28)
  • LLM services act as SUB-PROCESSORS
  • If content contains personal data of third parties, YOU are the DATA CONTROLLER

6.3.4. LLM Services Used:

Countries with Adequate Data Protection:

ProviderCountryRegions
Mistral AIFranceEU native
Hugging FaceFranceEU inference
DeepSeekChinaapi.deepseek.com
Alibaba (Qwen)China
iFlytek (Spark)China
Baidu (ERNIE)China

Other Countries:

ProviderCompany CountryAvailable Regions
OpenAI (GPT-4, GPT-4o)USAUSA, Ireland (EU), UK, Canada, Japan, South Korea, Singapore, India, Australia, UAE
Anthropic (Claude)USAUSA, Ireland (AWS Bedrock EU), Germany (AWS Bedrock EU), Australia, Japan, Singapore
Google (Gemini)USAUSA, Belgium (EU), Netherlands (EU), Germany (EU)
Microsoft (Azure OpenAI)USAUSA, Netherlands (EU), UK, Canada, Australia, Japan, Singapore, UAE, India, Brazil, South Africa
Amazon (Bedrock)USAUSA, Ireland (EU), Germany (EU), UK, Canada, Japan, Singapore, Australia, South Korea, Brazil, South Africa, Bahrain
GroqUSAUSA, Canada, Finland (EU), Saudi Arabia, Australia
Together AIUSAUSA, Sweden (EU), France (EU), UK, Italy (EU), Portugal (EU)
PerplexityUSAUSA, EU servers
CohereCanada/USAUSA, Germany (SAP EU)
IBM (watsonx)USAUSA, Germany (EU)

Current list: https://hedyos.com/docs/llm-services

6.3.5. International Data Transfers:

By activating LLM features, you consent to transfer of content to the jurisdictions listed above.

When using providers with EU endpoints, data is processed within the EEA/countries with adequate protection under GDPR Art. 45.

For US providers using EU endpoints, we rely on:

  • Standard Contractual Clauses (GDPR Art. 46(2)(c))
  • EU-US Data Privacy Framework (where applicable)

6.4. Text-to-Speech (TTS) Services

Reference Information:

The following services may be used for text-to-speech synthesis:

Countries with Adequate Data Protection:

ProviderCountryEU Endpoint
KyutaiFranceEU native
Alibaba CosyVoiceChina
ByteDance Seed-TTSChina
iFlytekChina

Other Countries:

ProviderCompany CountryAvailable Regions
Google Cloud Text-to-SpeechUSAUSA, Belgium (EU), Netherlands (EU), Germany (EU)
Microsoft Azure SpeechUSAUSA, Netherlands (EU), UK, Canada, Australia, Japan, Singapore, UAE, India, Brazil, South Africa
Amazon PollyUSAUSA, Ireland (EU), Germany (EU), UK, Canada, Japan, Singapore, Australia, South Korea, Brazil, South Africa, Bahrain
OpenAI TTSUSAUSA, Ireland (EU), UK, Canada, Japan, South Korea, Singapore, India, Australia, UAE
ElevenLabsUSA/UKUSA, UK, EU (api.eu.residency.elevenlabs.io)

7. SHARING PERSONAL DATA WITH THIRD PARTIES

7.1. General Provisions:

We do not sell your personal data. We share personal data only as described in this section.

7.2. Service Providers (Processors):

7.2.1. Payment Processors:

Payment SystemLocation
PaddleUnited Kingdom

Data shared:

  • Email address
  • Transaction information (date, amount, subscription type)

Payment card details are processed directly by payment systems and NOT stored on our servers.

7.2.1a. Paddle as an Independent Controller:

Your purchase is sold by Paddle.com Market Limited, acting as our authorised reseller and Merchant of Record. Paddle is not our processor: it decides on its own how to handle the data it collects for the sale, and is therefore a separate controller with its own privacy policy at https://www.paddle.com/legal/privacy.

What Paddle receives from us: your email address and the identifier of the plan you are buying.

What comes back to us from Paddle: your name where you provided it, your email address, the country and, where required for tax, the region or postal code of your billing address, plus the purchase history — transaction identifiers, amounts, currency, dates, subscription status and the last four digits and brand of the card. Full card numbers never reach us.

Why we process it: performance of the contract with you (granting and renewing the licence) and compliance with our accounting duties.

Your requests: you may address a deletion or access request to either side. We answer for what we hold; a request about the data Paddle holds as a seller — invoices, tax records, payment disputes — is answered by Paddle, and their retention duties as the seller may keep parts of it after we delete our copy.

7.2.2. AI Services (Translation, LLM, STT, TTS):

See Sections 6.2, 6.3, and 6.4 for detailed lists.

7.2.3. Email Services:

Message delivery is entrusted to a service provider acting on the Operator's behalf. Its legal name, country and privacy policy are available on request: hello@hedyos.com

Only the recipient's email address and the content of the message are transferred to the provider.

7.2.4. Hosting Providers:

ProviderServer Location
netcup GmbH (Germany)Germany (Nuremberg data centre)

7.3. Legal Requirements:

We may disclose personal data if required by law or in response to valid requests by public authorities.

7.4. Business Transfers:

In the event of a merger, acquisition, or sale of assets, your personal data may be transferred. We will notify you of any such transfer.


8. INTERNATIONAL DATA TRANSFERS

8.1. Data Transfer Mechanisms:

When we transfer personal data outside your country of residence, we ensure appropriate safeguards:

For EEA/UK residents:

  • Standard Contractual Clauses (GDPR Art. 46(2)(c))
  • Adequacy decisions (GDPR Art. 45) for countries with adequate protection
  • EU-US Data Privacy Framework (where applicable)

For California residents: Personal data may be transferred to and processed in countries outside the United States. We ensure appropriate safeguards are in place.

8.2. Countries with Adequate Data Protection (EU adequacy decisions):

Data transfers to these countries require no additional safeguards:

  • All EU/EEA member states
  • United Kingdom
  • Switzerland
  • Canada
  • Japan
  • South Korea
  • Argentina
  • Israel
  • New Zealand
  • And other countries with EU adequacy decisions

8.3. Countries Requiring Additional Safeguards:

CountrySafeguard Used
USAStandard Contractual Clauses, EU-US Data Privacy Framework
ChinaStandard Contractual Clauses

Your account data and your texts are stored on our servers in Germany, in a Nuremberg data centre operated by netcup GmbH. The servers moved there from Malaysia on 25 August 2026; the Malaysian infrastructure is being decommissioned.


9. DATA RETENTION

Data CategoryRetention Period
Account data (email, name)Until account deletion
Transcriptions (sessions)Until deleted by user
Transaction data5 years (legal requirement)
Technical logs90 days

10. YOUR RIGHTS

10.1. Rights Under GDPR (for EEA/UK residents):

You have the right to:

  • Access your personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data ("right to be forgotten") (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing (Art. 21)
  • Withdraw consent at any time (Art. 7(3))
  • Lodge a complaint with a supervisory authority (Art. 77)

10.2. Rights Under CCPA/CPRA (for California residents):

You have the right to:

  • Know what personal information we collect, use, and disclose
  • Delete your personal information
  • Opt-out of the sale of personal information (we do NOT sell your data)
  • Non-discrimination for exercising your rights
  • Correct inaccurate personal information
  • Limit use of sensitive personal information

10.3. How to Exercise Your Rights:

To exercise any of your rights, please contact us at: hello@hedyos.com

We will respond to your request within:

  • 30 days (GDPR)
  • 45 days (CCPA), extendable by additional 45 days if necessary

We may request verification of your identity before processing requests.


11. DATA SECURITY

11.1. Technical Measures:

  • TLS 1.2+ encryption for data in transit
  • Encryption for data at rest
  • Access controls and authentication
  • Regular security assessments

11.2. Organizational Measures:

  • Staff training on data protection
  • Access limited to authorized personnel
  • Processors are bound by their own terms of service and privacy policies; where a processor offers a data processing agreement, we conclude one

12. COOKIES AND ANALYTICS

We operate a self-hosted instance of PostHog on our own infrastructure (ph.hedyos.com) for anonymous product analytics. Data is not sent to PostHog Cloud or any third parties.

What we collect:

  • Anonymous device identifier (distinct_id formatted as {region}:{user_id} for authenticated users, or anonymous cookie pre-auth);
  • App / OS / browser version;
  • Region (RU/WORLD) and deployment environment (staging/production);
  • Standard PostHog session events (pageview, pageleave — only after cookie consent);
  • Server-side lifecycle events (account creation, trial start, license activation, recognition start/end).

What we do NOT collect:

  • Session audio;
  • Transcription text or phrases;
  • Plaintext email in events (person properties store only license type and is_paying flag);
  • IP address in stored events (used transiently for geolocation only, not persisted);
  • Browser autocapture of clicks, forms, and elements — disabled.

Storage: Self-hosted PostHog on our infrastructure.

Opt-out: In the macOS app — Settings → Data Privacy → Analytics toggle (invokes posthog.opt_out_capturing()). On the web — cookie consent banner; collection is opted-out by default (opt_out_capturing_by_default: true) until you give explicit consent. You may withdraw consent at any time.

Legal basis: Article 6(1)(f) of the General Data Protection Regulation — legitimate interests of the Controller in understanding product usage. Your right to object under Art. 21 GDPR is honored by the opt-out controls described above.

Browser cookie controls: You can manage cookie preferences through your browser settings.


13. CHANGES TO THIS POLICY

We may update this Policy from time to time. We will notify you of material changes:

  • By email (for registered users)
  • Through the Service interface
  • By updating the "Effective Date" at the top

Continued use after changes constitutes acceptance of the updated Policy.


14. CONTACT US

For any questions about this Privacy Policy or our data practices:

Email: hello@hedyos.com Website: https://hedyos.com


15. ADDITIONAL INFORMATION FOR CALIFORNIA RESIDENTS (CCPA/CPRA)

15.1. Categories of Personal Information Collected:

CategoryExamplesCollected
IdentifiersEmail, device IDYes
Commercial informationTransaction recordsYes
Internet activityUsage data, logsYes
GeolocationIP-based locationYes
Sensory dataAudio (NOT stored by us)No
Professional informationN/ANo

15.2. Sources of Personal Information:

  • Directly from you (registration, settings)
  • Automatically (device, usage data)

15.3. Business Purposes for Collection:

  • Providing the Service
  • Security and fraud prevention
  • Analytics and improvement
  • Legal compliance

15.4. Sharing for Business Purposes:

We share personal information with service providers (processors) as described in Section 7. We do NOT sell personal information.

15.5. Financial Incentives:

We do not offer financial incentives for personal information.


16. ADDITIONAL INFORMATION FOR EEA/UK RESIDENTS (GDPR)

16.1. Data Protection Officer:

We have not appointed a DPO as we do not meet the threshold requirements under GDPR Art. 37. For data protection inquiries, contact: hello@hedyos.com

16.2. Supervisory Authorities:

If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local supervisory authority. A list of EU supervisory authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members

16.3. Legal Basis Summary:

Processing ActivityLegal Basis
Account managementContract (Art. 6(1)(b))
Payment processingContract (Art. 6(1)(b))
Essential notificationsContract (Art. 6(1)(b))
Marketing communicationsConsent (Art. 6(1)(a))
Security measuresLegitimate interest (Art. 6(1)(f))
Service improvementLegitimate interest (Art. 6(1)(f))
Legal complianceLegal obligation (Art. 6(1)(c))