Summary of Our Security & AI Promise:
Intexting is built for confidential boardrooms, executive consultations, and legal deliberations.
We never sell your data, we never monetize your conversations, and we never use your audio, transcripts, or notes to train AI models.
1. Introduction & Scope
This Privacy Policy explains how Intexting ("Intexting", "we", "us", or "our") collects, protects, uses, and shares personal data and user content when you visit our website at intexting.com, create an account, or access our cloud application at app.intexting.com (collectively, the "Service").
This policy applies to all registered subscribers, team members, invited participants, and visitors who access or interact with the Intexting platform. If you represent an organization, corporation, or government department, this policy forms an integral part of your service agreement with us.
2. Core Privacy Commitments
We govern our operations around four non-negotiable principles:
- Complete Data Ownership: You retain 100% intellectual property ownership of all uploaded audio files, video streams, documents, transcripts, summaries, and synthesized outputs.
- Zero Model Training: Your confidential discussions, trade secrets, and meeting minutes are never fed into machine learning training datasets.
- End-to-End Cryptographic Security: All data is encrypted both in transit (TLS 1.3) and at rest (AES-256).
- Granular User Control: You have the absolute right to export, download, or permanently purge any recording, transcript, or document from our systems at any moment.
3. Strict Prohibition on AI Model Training
A central concern for professionals using AI tools is ensuring that confidential conversations are not absorbed into public artificial intelligence models.
Our Contractual Guarantee: Intexting does not use your audio files, voice dictations, video links, uploaded PDFs, scanned images, generated transcripts, speaker identities, timestamps, or synthesized documents to train, retrain, improve, or fine-tune our own internal algorithms or any third-party foundation models (such as OpenAI GPT, Google Gemini, Anthropic Claude, or open-source speech models).
All speech transcription and document generation requests are routed through dedicated API instances governed by strict Zero-Data-Retention (ZDR) agreements. Once transcription, diarization, and formatting are completed and returned to your account dashboard, the upstream processing instances retain zero copies of your audio or text payloads.
4. Categories of Data We Collect
We collect only the data necessary to provide and operate the Intexting platform:
A. Account & Identity Data
- Full name, business email address, and account login password (stored using one-way cryptographic hashing);
- Organization name, team size, and role/designation;
- Subscription tier information (Free, Starter, Pro, Power), billing cycle (monthly/annual), and transaction records. Raw credit card numbers are handled directly by PCI-DSS Level 1 certified payment processors and are never stored on Intexting servers.
B. Customer Uploads & Audio Payloads
- Audio Files: Uploaded audio recordings in formats including MP3, WAV, M4A, AAC, and FLAC;
- Live Microphone Feeds: Live voice audio streamed through your web browser during live dictation sessions;
- Video & Links: Video files (MP4, MOV) and public YouTube URLs submitted for audio extraction;
- Scanned Images & Photos: Uploaded images (PNG, JPG, WEBP) of handwritten whiteboard notes, paper documents, and receipts submitted for OCR extraction;
- PDF Documents: Scanned or digital PDF files submitted for text extraction and document synthesis;
- Metadata: Meeting titles, scheduled dates, physical locations, attendee names, and designated chairpersons/inspectors.
C. Generated Artifacts & Work Product
- Verbatim and cleaned transcripts with sentence-level timestamps;
- Speaker diarization labels and custom speaker names assigned by the user;
- Synthesized document outputs across our 6 specialized formats:
- Minutes of Meeting (MoM)
- Client Meeting Reports
- Interview Reports & Scorecards
- Legal Case Consultation Reports
- Field Visit & Safety Audit Reports
- Media Articles & Editorial Notes
- Exported files generated in PDF, Microsoft Word (.docx), Microsoft Excel (.xlsx), and subtitle formats (.srt, .vtt).
D. Technical Telemetry & System Logs
- Browser type, operating system, IP address, and network latency;
- Session timestamps, feature usage frequency, audio processing duration, and error reports necessary for system monitoring and debugging.
5. Lawful Basis for Processing (GDPR Article 6)
| Processing Activity |
Category of Data |
Lawful Basis under GDPR |
| Account creation & service delivery |
Identity & billing details |
Performance of a contract (Art. 6(1)(b)) |
| Speech transcription & document synthesis |
User audio, text & media uploads |
Performance of a contract (Art. 6(1)(b)) |
| Infrastructure security & fraud prevention |
IP address, system telemetry |
Legitimate interests (Art. 6(1)(f)) |
| Invoicing, tax & financial compliance |
Billing transactions & receipts |
Legal obligation (Art. 6(1)(c)) |
6. Recording Consent Obligations
Audio recording laws vary by state, country, and jurisdiction. Some jurisdictions permit recording with the consent of one party ("one-party consent"), while others strictly require the affirmative consent of all participants ("all-party" or "two-party consent").
User Warranty: As a condition of using Intexting, you represent and warrant that you have obtained all necessary legal notices and consents from all participants before recording in-person meetings, phone calls, or virtual video conferences. Intexting disclaims liability for recordings captured without proper participant consent.
7. Technical & Encryption Standards
We deploy defense-in-depth technical safeguards to protect your files against unauthorized access, disclosure, or breach:
- Encryption at Rest: All uploaded audio files, generated transcripts, synthesized documents, and database records are encrypted using Advanced Encryption Standard with 256-bit keys (AES-256).
- Encryption in Transit: All data transmitted between your web browser and our application servers is encrypted via Transport Layer Security (TLS 1.3 / HTTPS).
- Tenant Isolation: Customer accounts operate within cryptographically separated logical containers to prevent cross-tenant data leakage.
- Zero Local Device Storage: Intexting does not write persistent audio buffers to client device temp folders outside of standard browser cache controls.
- Staff Access Controls: Internal administrative access to production systems requires hardware-token multi-factor authentication (MFA) and is strictly governed by least-privilege role-based access policies (RBAC). Intexting employees cannot access your private transcripts or recordings without your express, logged support authorization.
8. Sub-processors & Cloud Infrastructure
Intexting engages trusted sub-processors for hosting, compute infrastructure, and transactional processing. Each sub-processor is bound by data processing agreements requiring standards equivalent to our own:
- Cloud Infrastructure: Enterprise cloud data centers certified under SOC 2 Type II, ISO/IEC 27001, and HIPAA compliance frameworks;
- AI Computing Gateways: High-performance speech and language inference engines operating under strict zero-retention (ZDR) commercial SLAs;
- Payment Processors: Globally recognized payment gateways compliant with Payment Card Industry Data Security Standards (PCI-DSS Level 1).
9. Public Links & Collaboration Controls
Intexting allows users to share meeting transcripts and summaries with colleagues and external clients via Public Sharable Links:
- Each public link uses a randomly generated, high-entropy cryptographic token;
- Public links are unindexed and include
noindex, nofollow headers preventing search engines from crawling or indexing the contents;
- Recipients access shared pages in read-only mode without the ability to edit or alter the underlying account records;
- You may revoke, disable, or delete a public link at any time from your dashboard, which immediately severs public access.
10. Data Retention & Deletion Lifecycle
You maintain complete authority over how long your data remains on Intexting servers:
- Manual Deletion: When you delete a speech file, transcript, or document from your dashboard, it is immediately deleted from our active database and file storage systems.
- Account Closure: If you close or delete your Intexting account, all associated recordings, documents, transcripts, and profile data are completely purged within 30 calendar days.
- Backup Purging: Routine disaster recovery backups are encrypted, isolated, and overwritten on a rolling 30-day rotation cycle.
11. International Transfers (GDPR / Cross-Border Transfers)
If you access Intexting from the European Economic Area (EEA), the United Kingdom, or Switzerland, your data may be transferred to and processed in data centers located in other jurisdictions. Where international transfers occur, Intexting relies upon the European Commission's Standard Contractual Clauses (SCCs) and robust technical safeguards to ensure a level of data protection equivalent to European standards.
12. User Privacy Rights (GDPR & CCPA/CPRA)
Depending on your geographic location, you enjoy specific legal rights regarding your personal information:
- Right to Access: You may request a complete copy of all personal information and files stored in your account.
- Right to Rectification: You may correct or update inaccurate profile data through your account settings.
- Right to Erasure ("Right to be Forgotten"): You may request the total deletion of your personal data and account records.
- Right to Data Portability: You can export your data anytime in open formats: PDF, Word (.docx), Excel (.xlsx), Text (.txt), and Subtitles (.srt).
- California Privacy Rights (CCPA / CPRA): We do NOT sell, rent, or share personal information for cross-context behavioral advertising. California residents have the right to request disclosure of categories of information collected, the right to opt out of any future sale (which we do not engage in), and the right to non-discrimination for exercising privacy rights.
13. Children's Privacy
Intexting is an enterprise and professional productivity service designed strictly for users aged 18 and older. We do not knowingly collect, process, or solicit personal information from minors. If we learn that personal data of a minor has been collected, we will immediately delete that information.
14. Updates & Contact Information
We may update this Privacy Policy from time to time to reflect technological improvements, security enhancements, or legal requirements. Material updates will be highlighted via in-app notifications or email notices prior to their effective date.
For privacy inquiries, Data Processing Agreements (DPA), or to exercise your statutory data rights, please contact our designated privacy department: