Privacy Notice
Last updated: 15 August 2026. ConversationToText is operated by Norra Vilan AB.
1. Who we are
Norra Vilan AB (Swedish company registration number 559561-0584), trading as ConversationToText, is the data controller for the personal data described in this notice.
2. What we collect and why
- Your audio and the resulting text — processed in the memory of our servers and the memory of our transcription provider solely to produce your transcript and optional summary. It is never written to a disk, bucket or database by us, and is discarded as soon as the response is returned. Legal basis: performance of the contract.
- Email address — only if you choose to email a transcript. Used once to deliver that message. We store a one-way hash of the address for anti-abuse and delivery statistics, not the address itself. Legal basis: performance of the contract and legitimate interests.
- Usage metadata — timestamp, recording length, file type, price, payment status, transaction id, success or error code, and a one-way hash of your IP address. Used for accounting, rate limiting and fraud prevention. Legal basis: legitimate interests and legal obligation.
- Activity log — which steps happened during a visit (page opened, recording started or stopped, file selected, transcription started, finished or failed, summary created, transcript copied, downloaded or emailed), together with a random session id stored in your browser, your browser type, file size and length. No conversation content is included. Used to support you, to verify refund requests, and to detect abuse. Legal basis: legitimate interests and, for refunds, performance of the contract.
- Refund requests — the e-mail address, order reference and reason you submit on the refund page, so we can handle and answer your claim. Legal basis: performance of the contract and legal obligation.
We do not require an account, we do not ask for a name or password, and we do not keep the content of your conversations.
3. Data stored on your own device
To protect you against a lost connection or a browser crash, your recording, transcript and summary can be kept temporarily in your own browser (IndexedDB and local storage) for up to 24 hours, after which they are removed automatically. This data stays on your device, is not sent to us, and can be deleted at any time with the "Clear from this device" button.
4. Who we share data with
- Paddle.com Market Limited — our reseller and Merchant of Record, for the sale, payment processing, tax compliance, invoicing and refunds. Paddle acts as its own controller for payment data; we never see your card details.
- Groq — speech-to-text and summarisation provider, operating under zero data retention for our requests.
- Resend — email delivery, only when you ask us to email a transcript.
- Hosting and database providers — for running the site and storing the usage metadata described above.
- Professional advisers and authorities — where legally required.
5. International transfers
Some of our providers process data outside the EU/EEA. Where that happens, transfers are covered by the European Commission's Standard Contractual Clauses or an adequacy decision.
6. Retention
We keep each category of data only for as long as stated below. Deletion of the activity log, rate-limit counters and refund requests is automated; nothing needs to be requested manually.
- Audio, transcript, summary — not stored at all — deleted the moment the request ends.
- Copies in your own browser — 24 hours, then auto-deleted.
- Activity log (metadata only) — 90 days, then auto-deleted.
- Refund requests — 3 years, to handle and evidence your claim.
- Payment records — 7 years (statutory bookkeeping).
Payment and invoice records are kept for 7 years because Swedish bookkeeping law requires it. After the periods above, data is permanently deleted; nothing is archived elsewhere.
7. Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent, as well as the right to lodge a complaint with your supervisory authority (in Sweden, Integritetsskyddsmyn digheten). We respond within one month. Note that because usage metadata is pseudonymised (hashed) and contains no content, we may be unable to link it to you.
8. Security
We use appropriate technical and organisational measures, including encryption in transit, access controls, in-memory-only processing of your audio, and rate limiting against abuse.
9. Cookies
We do not use advertising or tracking cookies. The site uses only local browser storage that is strictly necessary for the features described above and for your payment session; you can clear it at any time in the app or in your browser settings.
10. Contact
Norra Vilan AB — privacy questions can be sent to the support address published on this site or through the contact details on your Paddle receipt.