YOTEXT

Privacy Policy

Version 2026.10.02.1

This policy explains what data YOTEXT processes, why, on which legal basis, where it is sent, how long it is kept, and how you can use your rights. It is written with reference to Indonesian Law Number 27 of 2022 on Personal Data Protection (UU PDP), the EU General Data Protection Regulation (GDPR), and the Personal Information Protection Law of the People's Republic of China (PIPL).

1. Who is responsible

YOTEXT is the controller of personal data for personal accounts and the YOTEXT website. You can reach us at support@yotext.app for any privacy question.

For team workspaces, the organization that owns the workspace is the controller of the meetings, transcripts, and tasks in that workspace, and YOTEXT acts as a processor that handles the data on that organization's instructions.

2. Data we process

We only process the data needed to run the service:

  • Account data: the name, email address, and Google account identity you sign in with, plus the display name, name variations, and extra email addresses you add yourself.
  • Meeting content: audio recordings, transcripts, captions from Google Meet, Zoom, or Microsoft Teams, speaker names, and attendance lists.
  • AI output: summaries, decisions, and tasks generated from transcripts.
  • Workspace data: members, roles, invitations, and workspace settings.
  • Usage and billing data: quota, subscription status, and the customer identifier at the payment provider. We do not store payment card numbers.
  • Security data: login sessions, the activity log (audit log), and IP addresses pseudonymized with a hash function so they are not stored in their original form.
  • Analytics data: an anonymous identifier in your browser, the visit source, and product events. We do not use advertising trackers or third party trackers.
  • Admin editorial data: article source material, images, AI drafts, and the messaging account identity linked to an admin account.

3. Browser extension

The YOTEXT extension only captures tab audio and meeting captions after you press Start recording. It keeps a temporary copy in your browser so a recording is not lost when the connection drops, then sends it to the YOTEXT servers. The extension does not read pages outside the supported meeting platforms.

4. Purposes and legal bases

We process data for these purposes, on the legal bases set out in UU PDP Article 20, GDPR Article 6, and PIPL Article 13:

  • Running the service you request, including transcription, summaries, tasks, sharing, and workspaces: performance of our contract with you.
  • Transferring data abroad and processing recordings that may contain sensitive information: the separate consent you give in the app.
  • Security, abuse prevention, and the audit log: legitimate interests in protecting users and the service.
  • Anonymous product analytics to improve the service: legitimate interests.
  • Billing and tax records: compliance with legal obligations.

5. Meeting recordings and other participants

Meetings usually involve other people. You must tell every participant that the meeting is being recorded and transcribed, and ask for their consent where the applicable law requires it. The extension provides a notice you can copy into the meeting chat.

Participants who are not YOTEXT users can exercise their privacy rights through the organization that owns the workspace or through support@yotext.app.

We do not create voiceprints to identify anyone. Speaker separation is only used to structure the transcript.

6. AI processing

Transcripts, summaries, and tasks are produced by AI models and labeled as AI output, following the transparency principles of the Chinese rules on labeling AI generated content and Article 50 of the EU AI Act. AI output can be wrong, so review it before using it for important decisions.

We do not make automated decisions that produce legal effects for you. We do not use meeting content to train our own models. Content is sent to AI providers through business API services, and the data use terms of those providers also apply.

If an admin uses the article generator or messaging bot, source material is processed by an AI provider to prepare a draft. The messaging service provider also processes messages and images sent through the bot. Review the draft before publishing it.

7. Service providers (subprocessors)

We do not sell personal data. We only share data with providers that help run the service, and only as far as needed. The providers currently active are listed below and update automatically from the server configuration.

ProviderPurposeDataLocationTransfer safeguards
Application hosting providerApplication hosting and storageAudio, Transcript, Meeting details, Account identity, Email, Task content, Billing dataWhere the server is locatedData processing agreement
AI transcription and language model providerAudio transcription and AI image readingAudio, Transcript, Meeting details, Blog contentSingaporeData processing agreement, Standard contractual clauses, Separate consent
AI language model providerAI summaries, tasks, and translationTranscript, Meeting details, Task content, Blog contentSeveral countriesData processing agreement, Standard contractual clauses, Separate consent
Audio transcription providerAudio transcriptionAudio, TranscriptUnited StatesData processing agreement, Standard contractual clauses, Separate consent
Google Firebase AuthenticationSign inAccount identity, EmailSeveral countriesData processing agreement, Standard contractual clauses
ResendService emailEmail, Task content, Meeting detailsUnited StatesData processing agreement, Standard contractual clauses
PaddleSubscriptions and paymentsBilling data, EmailSeveral countriesData processing agreement, Standard contractual clauses

8. International transfers

Some providers process data outside the country you are in, including Singapore and the United States. We protect these transfers with data processing agreements, standard contractual clauses under GDPR Article 46, and your separate consent under UU PDP Article 56 and PIPL Articles 38 and 39.

You can withdraw your transfer consent at any time. Because the service cannot run without these transfers, withdrawing consent means you stop using the service and can delete your account.

9. How long we keep data

  • Account: until you delete your account.
  • Meetings, transcripts, and audio: until you or the workspace delete them, or until the retention limit set by the workspace.
  • Audit log: 365 days, then deleted automatically.
  • Billing data: as long as tax and accounting laws require.
  • Temporary data such as processing status and sessions: removed automatically when it expires.
  • Article generation requests: removed 30 days after completion or failure. Messaging account links remain until unlinked or the account is deleted.

10. Security

Each workspace is kept separate and only active members can access it. Connections are served over HTTPS, login sessions are stored as hashes, and sensitive actions are recorded in the audit log. Details are on the Security page.

11. Your rights

Under UU PDP Articles 5 to 13, GDPR Articles 15 to 22, and PIPL Articles 44 to 50, you have the right to:

  • Know about and receive information on how your data is processed.
  • Access and get a copy of your data, including in a machine readable format (portability).
  • Correct or complete inaccurate data.
  • Erase your data and end its processing.
  • Withdraw consent, suspend or restrict processing, and object to processing.
  • Object to decisions based solely on automated processing.
  • Lodge a complaint with a data protection authority and claim compensation as provided by law.

12. How to use your rights

You can download all your data and delete your account yourself in Settings, on the Account tab. For other requests, email support@yotext.app. We respond within the deadline the law requires, for example within 3 x 24 hours for certain requests under UU PDP and within one month under GDPR.

When an account is deleted, meetings in the personal workspace are deleted, while meetings you recorded in a team workspace move to the workspace owner because they belong to the organization, except private meetings, which are deleted.

13. If a data breach happens

If personal data protection fails, we notify you and the relevant authority in writing within 3 x 24 hours under UU PDP Article 46, notify the supervisory authority within 72 hours under GDPR Article 33 where it applies, and take remedial measures immediately under PIPL Article 57.

14. Age limit

The service is only for users aged 18 or older. We do not knowingly process children's data.

15. Changes to this policy

Policy version: 2026.10.02.1. If there is a material change, we ask for your consent again in the app before you can create new data.

This policy is available in Indonesian, English, and Chinese. If the versions differ in interpretation, the Indonesian version prevails.

16. Contact and authorities

Privacy questions: support@yotext.app. You can also contact the personal data protection agency in Indonesia, the data protection authority of the EU country where you live, or the Cyberspace Administration of China if you are in China.