Legal
Privacy Policy
Last updated: June 23, 2026
Dragon Notes ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Dragon Notes iOS application and related services (collectively, the "Service").
Please read this Privacy Policy carefully. By using the Service, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
We may collect the following types of information:
- Account Information: When you create an account, we collect your email address and display name. Subscription billing is handled by the App Store; we do not receive your payment card details.
- Audio Recordings: Audio files are written to your device while you record. What happens next depends on the transcription mode you pick for each meeting:
- Standard and High Accuracy modes process audio entirely on your device. The audio bytes never leave your device.
- Cloud mode uploads the audio directly from your device to our third-party transcription partner over an encrypted connection — processed and dropped, never stored by them. Dragon Notes servers never receive or store the audio. The transcription partner is AssemblyAI (see Section 4, Data Sharing and Disclosure).
- Voice Recognition Data (Speaker Recognition): If you turn on speaker recognition, Dragon Notes computes voice embeddings on your device and stores them encrypted in the iOS Keychain, excluded from iCloud backup. These embeddings never leave your device.
- Transcripts, Notes, and Summaries: Text generated from your audio (transcripts, AI-generated summaries, and your own notes) is synced to your Dragon Notes account so you can access it across devices. To generate the AI summaries and action items, your transcript is sent to Anthropic (Claude); see Section 4.
- Calendar Data: If you connect Apple Calendar or Google Calendar, Dragon Notes reads upcoming events on-device only, to prefill meeting titles and surface video-call links. Calendar event content is not transmitted to Dragon Notes servers.
- Usage Data & Diagnostics: Aggregate product analytics (which screens were opened, which features were used) and crash reports. Transcript content, audio, and voiceprints are explicitly excluded from analytics and crash payloads.
- Device Information: Device type, operating system version, and general diagnostic data sent alongside crash reports.
2. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, maintain, and improve the Dragon Notes Service
- To process audio recordings and generate transcriptions, notes, and action items
- To sync your data across devices when cloud sync is enabled
- To process payments and manage your subscription
- To send you important updates about the Service
- To respond to your requests, comments, or questions
- To detect, prevent, and address technical issues or security breaches
3. Audio Data — Where It Lives
Audio recordings are written to your device while you record. What happens to that audio after a meeting ends depends on which transcription mode you chose for that meeting.
- Standard and High Accuracy modes (on-device): Audio is processed locally using Apple's Speech engine (Standard) or an on-device transcription model (High Accuracy). The audio bytes never leave your device. Dragon Notes servers do not receive a copy.
- Cloud mode (third-party transcription): Audio is uploaded directly from your device, over TLS, to AssemblyAI, our third-party transcription partner. AssemblyAI is the sole recipient and processes the audio according to its data-handling policies. Dragon Notes servers never see or store the audio — we receive only the resulting text transcript. See Section 4 (Data Sharing and Disclosure).
- Transcripts, summaries, and your written notes are synced to your Dragon Notes account (Supabase Postgres), encrypted in transit (TLS) and at rest. They are accessible only to the authenticated account holder.
- You can delete any meeting at any time from within the app. Deletion removes the on-device audio, the transcript, the summary, and any voice embeddings linked to that meeting.
- We do not listen to, read, or otherwise review your audio, transcripts, or notes. Crash and analytics payloads are filtered before transmission to exclude transcript content, audio paths, and biometric embeddings.
4. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information. We do share specific data with the following named sub-processors so that the app can do what it does:
- AssemblyAI (transcription) — when you pick Cloud transcription, your audio is uploaded directly from your device to AssemblyAI, then returned to your device as text. Not used in Standard or High Accuracy modes. AssemblyAI is contractually bound to protect your data to an equivalent standard and does not use it to train its models. Privacy policy: https://www.assemblyai.com/legal/privacy-policy
- Anthropic / Claude (summarization) — your transcript (not your audio) is sent to Anthropic to generate AI summaries and action items. Anthropic is contractually bound to protect your data to an equivalent standard and does not use it to train its models. Privacy policy: https://www.anthropic.com/legal/privacy
- Third-party meeting-bot service — when you (Pro) send a Dragon bot to join a Zoom, Google Meet, or Microsoft Teams call, a third-party service operates the bot on our behalf and returns recording metadata to Dragon Notes. The meeting link you provide is sent to this service; your calendar is not forwarded. The current bot service is identified by name on request to privacy@dragonnotes.com.
- Supabase — our hosting provider for the account database (email, display name, transcripts, summaries, and notes) and authentication.
- Apple App Store — handles all subscription billing and renewals. We never receive your payment card details.
- Sentry & PostHog — first-party crash diagnostics and product analytics respectively. Transcript content, audio, voiceprints, and calendar events are scrubbed from these payloads before transmission. PostHog session-replay text inputs are masked.
- Legal Requirements: We may disclose information if required by law, regulation, legal process, or governmental request.
- With Your Consent: When you share meeting notes or transcriptions via the PDF or auto-share features, you choose the recipients.
5. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Locally stored recordings remain on your device until you delete them. Cloud-synced data is retained until you delete it or close your account. Upon account deletion, we will remove your data from our servers within 30 days, except where retention is required by law.
6. Data Security
We implement industry-standard security measures to protect your information, including encryption, access controls, regular security audits, and secure development practices. However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
7. Your Rights and Choices
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Request that we correct inaccurate data
- Deletion: Request deletion of your personal data
- Portability: Request your data in a portable format
- Opt-out: Disable cloud sync at any time to keep all data local to your device
8. Children's Privacy
Dragon Notes is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete that information promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy within the app and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
10. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at: