1. What's recorded and how long it lasts
When you say something out loud, the audio travels encrypted to the service that transcribes it and is deleted as soon as the thread is saved to your account. The intermediate transcript isn't kept: it's used to write the thread and discarded in the same process. There are no "just in case" audio copies, and no temporary files that outlive the session.
- Your account: your email, your hashed password and the name the app greets you by.
- Your people: the name of each person you talk about, and what you said about their life — their stories, their portrait and a summary of each conversation. It's kept in your account, under your control.
- Your usage: how many notes you record, how long they are and what they cost to process. Not one word of what you said.
- The recording: deleted the moment the note is saved. The app never plays it back.
- The transcript: not stored anywhere.
- What isn't requested or collected: your contacts, your location and any advertising identifier.
2. Data about people who don't use the app
Here's the part other apps leave out. When you record that a friend's mother is having surgery on Tuesday, you're storing information about someone who hasn't agreed to anything — sometimes health information.
We can't notify them: we don't know who they are, only a first name as you said it. GDPR anticipates that impossibility (art. 14(5)(b)) in exchange for making it public and taking safeguards, so here are ours:
- The audio is deleted straight away and the transcript isn't kept.
- Nobody else sees it. It isn't shared, isn't sold and isn't cross-referenced.
- The app doesn't investigate or infer: it only keeps what you said.
- There's no way to publish anything from here.
If you're that person and want to know whether you're in the system, or want to be removed, write to [email protected]. We'll do it.
3. Who can see your threads
Nobody but you. They aren't shared with the people they're about, aren't handed to third parties and aren't used to train models. The app has no publishing feature, no visible profile and no social export, and there are no plans to add one.
Understanding what you record takes two outside services, and neither trains its models on what we send: one transcribes the audio, the other turns that transcript into your threads. The detail on each is in section 4.
4. Who processes your data, and with what help
The data controller is Alejandro Ramón Gracia, address Calle Santa Teresa de Jesús 53, 6.º D, 50006 Zaragoza, España, contact [email protected].
To provide the service, it relies on the following data processors:
| Provider | What for | What it receives | Where | Safeguard |
|---|---|---|---|---|
| Supabase | Database, auth, storage and functions | Everything in your account | European Union | — |
| Groq | Audio transcription | The audio | United States | DPF / standard contractual clauses |
| Anthropic | Writing threads from the transcript | The transcript | United States | DPF / standard contractual clauses |
| Sentry | Technical error logging | Your account identifier and error traces, no content | United States / European Union, depending on plan | DPF / standard contractual clauses |
| PostHog | Usage analytics | Events with no content (numbers, booleans, closed categories) | European Union | — |
| Resend | Support email and waitlist confirmation | Your message and your email / the email you leave on the waitlist | United States | DPF / standard contractual clauses |
None of these providers uses your data for its own purposes, and none of them trains models on what we send.
5. Legal basis and what it's used for
- Your account and the service: to deliver what we offer you (GDPR art. 6(1)(b)).
- Sending your audio to Groq and your transcript to Anthropic: because you give explicit permission on the first screen, and you can withdraw it by deleting your account (art. 9 consent for this category of data).
- Security and usage limits: legitimate interest in keeping the service up and sustainable (art. 6(1)(f)).
The email you leave on the waitlist is processed with your consent and only to notify you at launch: it doesn't go on any newsletter list. It's stored in the service's own database (Supabase, European Union); you have to confirm it by clicking a link we send you by email, and it's deleted entirely as soon as the launch notice is sent.
6. How long it's kept
Your threads, for as long as you want. The audio, until the thread is saved. Waitlist emails, until the launch notice is sent — and if you never confirm the double opt-in email, they're deleted on their own after 14 days. Usage records and support messages are kept for 24 months.
7. Deleting your data
In the app, under Profile → Delete account. Everything you've saved is permanently deleted — people, stories, portraits, notes, files and your profile — with no grace period, no trash, and no questions asked.
You can also request it by writing to [email protected]: you'll get a response within thirty days. And if you don't have the app installed, you can request it just the same from the delete-my-data page.
8. Your rights
You can access, rectify, erase, restrict or object to the processing of your data, and ask us to hand it over in a portable format, by writing to [email protected]. If you think something hasn't been handled properly, you can complain to your data protection authority.
9. Children
AlHilo isn't aimed at anyone under 16, and we don't knowingly collect their data.
10. Changes to this page
If anything here changes, you'll be told inside the app before it takes effect, and the date of the latest version stays here. Last updated on September 8, 2026.