# Privacy

Last updated 10 October 2026.

Your meetings are none of our business. That is a description of how the app is built, not a promise about how we behave.

This page is also Chitmonk's privacy policy. It covers the app at chitmonk.com and these pages. "We" means the people who make and publish Chitmonk.

## What stays on the device

- **Speech is transcribed in the browser tab**, by models that were downloaded once and run locally. No audio is sent anywhere.
- **Transcripts, names and history** are stored in the browser's own database on the device.
- **Voice fingerprints**, used to suggest who is speaking, exist only in memory during a meeting and are discarded when it ends. They are never stored, never exported, and the storage layer refuses anything shaped like one.
- **Audio** is held only for the phrase being transcribed, then released, unless you ask to keep it for that meeting.

We never receive any of this. We cannot read it, lose it, sell it or hand it over, because we do not have it.

## No network during a meeting

While a meeting is recording or paused, the app makes no requests at all. The page is only allowed to talk to its own address, and after the first download it works with the network switched off.

## What can leave, and only if you choose

1. **Your email address, if you sign up for the Chitmonk+ beta.** You type it and press the button; that address, and nothing else, is sent to Chitmonk's own site. It cannot be sent while a meeting is recording. [What happens to it](#the-sign-up-list).
2. **Usage statistics, only if you say yes.** Counts such as how many meetings are started and which exports are used. Never audio, transcripts, names or titles, and nothing is sent while a meeting is recording. Off unless you turn it on. [Exactly what is sent](#how-statistics-are-collected).

That is the whole list. An exported file goes wherever you put it; the app does not send it anywhere.

## How statistics are collected

**Only if you turn it on.** The app asks once, on the home screen, and the switch is in Settings under Privacy. Until you say yes, nothing is sent and the code that sends it is not even downloaded. Turn it off and it stops at once: anything waiting is thrown away.

**Only if this copy of the app is connected to a statistics service at all.** If Settings says "Usage sharing is not set up in this build", there is nowhere for statistics to go and nothing is sent, whatever the switch says.

**Who receives them.** [PostHog](https://posthog.com), a product-analytics company, on servers in the United States. It handles them for us and on our instructions. We use them to see which parts of Chitmonk get used. We do not sell them, share them with advertisers, or use them to build a profile of you.

**What is sent.** These events and nothing else. This is the complete list.

| When | What is sent with it |
| --- | --- |
| The app is opened | Whether it is installed as an app. Whether the speech engine is installed |
| The speech engine finishes installing | Whether voice suggestions were included |
| A meeting starts | The language, as a two-letter code. How many people are on the list. Whether voice suggestions are on. Which voice detector is in use. Whether audio is being kept. Whether it is a shared-device meeting |
| A meeting ends | Its length as a range (such as 15 to 30 minutes). Its number of lines as a range (such as 50 to 200). Whether it was a shared-device meeting |
| An export finishes | The format, such as Word or Markdown |
| An import finishes | How many meetings were in it |
| A model is chosen | Which job it does and which model |
| The Chitmonk+ panel is opened | Nothing more |
| A beta sign-up goes through | Nothing more. Not the address |
| You sign in to Chitmonk+ | Nothing more |
| Usage sharing is turned on | Nothing more |

**What comes with every event.** The analytics library describes the browser it runs in. Chitmonk lets these through and removes the rest:

- the browser and its version, the operating system and its version, and the kind of device (desktop, tablet or phone);
- the size of the screen and of the window;
- the name and version of the analytics library, and the time;
- three random identifiers: one for this browser, one for this visit and one for this tab. They are random numbers made in your browser, there so that one browser is counted once. They are kept in the browser's local storage, not in a cookie.

**What is never sent.** The app can only send short code words, numbers and yes-or-no values: free text is rejected before it leaves, so a title, a name or a line of transcript cannot be sent even by mistake. Chitmonk also removes what the analytics library would otherwise add by itself: the address of the page you are on (a meeting's address identifies the meeting), the page you came from, campaign tags, the full user-agent string, your language and your time zone. There is no recording of your screen, clicks or typing.

**Your IP address.** Any server sees the address a request comes from, and PostHog's does when an event arrives. We have it set to discard that address instead of storing it, and each event asks it not to work out a location from it.

**Never during a meeting.** While a meeting is recording or paused, events wait on your device and go only after it ends.

**If you sign in to Chitmonk+**, once that exists, events from then on are linked to your Chitmonk+ account's identifier, so that we can tell how Chitmonk+ is used.

**Stopping and removing.** Turn the switch off in Settings, or use "Delete all data" there, and sending stops and the identifiers your browser was using are discarded. To have statistics already sent from your browser removed, write to us at the address at the end of this page.

## The sign-up list

If you sign up for the Chitmonk+ beta, we keep your email address and the date you signed up. Nothing else about you or the request is written down.

We use the address for one thing: to write to you about Chitmonk+. We do not sell it, share it or add it to any other list. It is stored with Cloudflare, the company that hosts the site. We keep it until you ask us to remove it or the list is no longer needed, whichever comes first. To be removed, write to the address at the end of this page.

To stop a script filling the list, sign-ups from one IP address are limited to one every two seconds. The IP address is only counted against, for ten seconds. It is not stored with your sign-up or anywhere else by us.

## Signing in to Chitmonk+

Chitmonk+ is not available yet, and the free app has no account. When sign-in exists it will be handled by [WorkOS](https://workos.com), a sign-in provider, which will hold the name and email address of your account. Nothing about sign-in is downloaded or contacted unless you choose to sign in.

## The site itself

Chitmonk's sites are delivered by [Cloudflare](https://www.cloudflare.com). To deliver a page to you, and to protect the site from abuse, Cloudflare's network necessarily handles the IP address your request comes from and basic details of the request, as every web host does. It does that under its own privacy policy.

We do not keep request logs of our own. Chitmonk's server code is small (it takes sign-ups and serves the speech models), and it is set to store no log of who asked for what.

Chitmonk sets no cookies. The app keeps its settings and your meetings in the browser's own storage on your device. These documentation pages run no script at all, load nothing from any other site, and have no statistics of any kind.

## What we share, and with whom

We do not sell personal information, and we do not share it for advertising. Three companies handle data for us, each only for the job named here:

| Company | What it handles | When |
| --- | --- | --- |
| Cloudflare | Delivering the sites. Storing the beta sign-up list | Always, for the sites. The list only if you sign up |
| PostHog | Usage statistics | Only if you turn them on |
| WorkOS | Chitmonk+ sign-in | Only if you sign in, once that exists |

We would disclose information if the law required it. For meetings, there is nothing we could disclose.

## What an export contains

A `.chit` bundle holds the meeting's complete history: every line, every edit, every name, and the audio only if you chose to include it. Treat it like the meeting itself. [What is in a bundle](/chit/).

## Other people in your meetings

A meeting holds the words and names of the people in the room, and you are the one who holds them: they are on your device, under your control. Telling people they are being recorded, and getting their consent where the law requires it, is your responsibility. The [terms of use](/terms/#5-telling-people-you-are-recording) say more.

## Your choices

- **Your meetings:** delete one from its page, or everything with "Delete all data" in Settings. Nothing needs to be asked of us, because we hold nothing.
- **Statistics:** off unless you turn them on; the switch is in Settings.
- **Your sign-up address:** write to us to see it, correct it or have it removed.

Depending on where you live, the law may give you rights over personal information about you, such as to see it, correct it, delete it or object to its use. We will honour such a request from anyone, wherever they live, and we will not treat you differently for making one.

## Children

Chitmonk is for adults. It is not directed at children, and we do not knowingly collect personal information from anyone under 13. If you believe a child has signed up for the beta, write to us and we will remove the address.

## Changes to this page

When what Chitmonk does changes, this page changes with it, and the date at the top changes too. If a change is significant we say so at the top of the page.

## Contact

Questions about privacy, or a request about your information: [legal@chitmonk.com](mailto:legal@chitmonk.com).
