Who is responsible
The controller for the data described here is Marco Müllner, Rain 1, 6642 Stanzach, Austria. For anything on this page (access, deletion, or a question), write to [email protected]. That address reaches a person, not a ticket queue.
The app: what stays on your Mac
Recording, transcription, and speaker separation happen on your Mac, using models that run on your own hardware. The results are ordinary files (Markdown and audio) in your own folder.
Recordings and transcripts never leave your Mac, and we never receive them. We could not read them if we wanted to: horch has nowhere to send them to us. We run no server that accepts meeting data and there is no account behind which it could be stored. The only ways any meeting text leaves your machine at all are the two you choose yourself, and both go to a provider you have an account with, never to us: a cloud AI provider you connect, and the iPhone Companion syncing through your own iCloud. Both are described below.
The app contains no analytics, no telemetry, and no crash reporting. It does not phone home to count launches, measure features, or report errors. The only calls horch makes to us are the license checks described below: activating a Mac, deactivating it, and revalidating the license on a slow cadence (roughly weekly) so that a refunded or revoked license stops working. Activation sends your license key, which we hash on arrival and never store, together with the machine fingerprint. Revalidation sends back the signed receipt the service issued for that Mac. Nothing about your meetings is part of any of it.
Cloud AI: the one thing you can choose to send away
horch answers questions and writes summaries with a language model. You pick which one. If you use a local model, that work happens on your Mac and nothing leaves it. That is the default posture of the product. (Downloading such a model fetches it from the model registry, which sees your IP address the way any download does.)
You can instead connect a cloud provider (Anthropic, OpenAI, or Google) by entering your own API key or signing in to your own account with that provider, in horch's AI setup. If you do, the text horch needs the model to read (excerpts of your transcripts and notes, and your questions) is sent to that provider, under your agreement with them, and is subject to their privacy policy. It still never passes through any server of ours, and we never see it. This is entirely your choice: without credentials you supply yourself, horch cannot make such a call, and it never makes one on its own initiative.
The iPhone Companion
If you use the Companion app, the small subset it needs (your todos, quick notes, and meeting summaries) is replicated through your own iCloud account (Apple's CloudKit private database). It passes through Apple's infrastructure under your Apple account, not through any server of ours; we cannot see it. Recordings and full transcripts are never part of that subset. Dictated captures on the phone are transcribed by the operating system on the device; the audio is discarded and only the text is kept.
The license service: the only server we run
We operate exactly one service, and it deals with licenses and nothing else. It never sees meeting data. This is the complete list of what it stores.
Your license
- the license id and the type of license;
- a SHA-256 fingerprint of your license key: the key itself is never stored, and we cannot recover it from the fingerprint (which is why we can only re-send the key we mailed you, never look it up);
- the email address the license was issued to, and the customer id Paddle assigned to the purchase;
- the end of the update window, the validity dates, and whether the license has been revoked (and why: refund, chargeback, or an administrative decision);
- an optional internal note, for licenses we grant by hand.
Your activations
A license runs on up to 2 Macs, so the service records one activation per Mac: the license it belongs to, a machine fingerprint, whether it is active, and when it was activated, last seen, and deactivated.
The machine fingerprint is a one-way hash: the app takes your Mac's hardware UUID and sends only the SHA-256 digest of it. The raw identifier never leaves your machine. The digest lets us recognise the same Mac again and count seats; it tells us nothing else about the computer, and it cannot be turned back into an identifier.
Your purchase
- an order record per transaction: the Paddle transaction id, the license it belongs to, whether it was a purchase, renewal, refund, or chargeback, the amount, the currency, and when it happened;
- the raw event Paddle sends us for that transaction, stored as received so a payment can be reconciled or replayed if something goes wrong. It contains what Paddle chooses to send: typically the email address, customer id, amounts, and the country used for tax.
We never see your payment details. Paddle.com Market Ltd is the merchant of record: it runs the checkout, takes the card or PayPal payment, handles the tax, and issues the invoice. Card numbers never touch our systems. Paddle is an independent controller for that payment data. Its own privacy policy applies at paddle.com.
Your license key email
After a purchase we email your key to the address on the order, over SMTP through an email delivery provider. That provider processes your address and the message on our behalf, as a processor.
IP addresses
Activation, deactivation, and revalidation requests are rate-limited by IP address to blunt key-guessing and floods. The address is counted in memory for a one-minute window and is not written to your license or activation record. Our web server, like any web server, writes request logs which include the IP address, the user agent, and the path requested; these are held by our hosting provider for a limited period and used only to operate and secure the service.
Administrative records
An append-only audit log records administrative actions on licenses (issued, revoked, extended, key re-sent) with the actor, the action, the license concerned, and the time, so that changes to a license are traceable. It never contains a license key, a password, or a token. The logins and sessions of our own administrator (including that administrator's IP address and browser) are recorded for security. This concerns us, not you.
License analytics
To run the license business — to see how many licenses are bought, renewed, refunded, and activated, and whether the purchase and key-email pipeline is healthy — the service sends a small set of pseudonymous events to PostHog on its European infrastructure. Each event is keyed to a license id and carries only counts and facts about the transaction or activation: the kind of event, the amount and currency, a seat count, an activation or revalidation. It never carries your email, your name, or the raw machine fingerprint. This is separate from the website analytics below and does not depend on the cookie banner: the legal basis is our legitimate interest in operating and securing the licensing service (Art. 6(1)(f) GDPR). PostHog processes it on our behalf as a processor.
This website
The public pages of horch.app are static HTML, served with no third-party fonts, no tracking pixels, no advertising, and no embedded third-party content. They set no cookies until you choose to allow the analytics described next. (The private administration area sets a session cookie, but only for us.)
Analytics, only if you agree
To see which pages and links are useful and improve the site, we use PostHog, a product-analytics tool, running on PostHog's European infrastructure so this data stays in the EU. It is off by default. On your first visit a banner asks: nothing loads, no event is recorded, and no analytics cookie is set unless you press Accept. Press Decline and no analytics run at all, and nothing about your visit is recorded beyond the ordinary server request log described above.
If you accept, PostHog records the pages you view and the elements you interact with, your device and browser type, how you arrived at the site, and an approximate location derived from your IP address, tied to a random identifier stored in a first-party cookie on this domain. This includes a masked session replay, a reconstruction of your visit that shows where you click and scroll but hides every input value and all on-page text, and an automatic report if a page throws a browser error. The payment form is handled by our reseller in a separate frame and is never recorded. It is used only to understand and improve the site. We do not sell it, we do not share it with advertisers, and it is never linked to your license or anything about your meetings. You can change your mind at any time through “Cookie settings” in the footer; declining or withdrawing removes the analytics cookie and stops the tracking.
The checkout, when you start one, is served by Paddle.com Market Ltd and follows Paddle's own privacy policy.
Why we are allowed to hold this
- Performance of a contract (Art. 6(1)(b) GDPR): issuing your license, delivering the key, activating your Macs, validating the license, handling support and refunds.
- Legitimate interests (Art. 6(1)(f) GDPR): preventing abuse and key sharing, rate limiting, keeping the service secure, and keeping an audit trail of administrative actions.
- Legal obligation (Art. 6(1)(c) GDPR): retaining the records of a sale for the statutory bookkeeping period.
- Consent (Art. 6(1)(a) GDPR): the optional website analytics, which run only if you accept the banner and which you can withdraw at any time.
Who else gets to see it
- Paddle.com Market Ltd: the merchant of record, which processes the payment and the tax as its own controller.
- Our hosting provider: runs the license service and its database on our behalf, as a processor.
- Our email delivery provider: sends the license key email on our behalf, as a processor.
- PostHog: our product-analytics provider, which processes website usage data on our behalf as a processor, on its EU infrastructure, and only if you have consented.
- Apple, but only if you use the iPhone Companion, and only through your iCloud account, under your agreement with Apple. We are not a party to it.
We do not sell data, we do not share it with advertisers, and we run no third-party trackers. Where an infrastructure provider processes data outside the European Economic Area, the transfer is covered by the European Commission's standard contractual clauses in that provider's data processing agreement.
How long we keep it
- License and activation records: for as long as the license exists. A perpetual license has to stay verifiable, so we keep the record unless you ask us to delete it.
- Order records and payment events: for the statutory retention period for business records under Austrian law (seven years), after which they are deleted.
- The audit log: for as long as we need it to investigate what happened to a license.
- Server request logs: for the limited period our hosting provider retains them.
- Website analytics: only while you consent. Withdrawing consent stops collection and removes the cookie; the events already gathered are retained by PostHog for a limited period and then deleted.
Your rights
Under the GDPR you have the right to access the data we hold about you, to have it corrected, to have it deleted, to restrict or object to how we use it, and to receive it in a portable machine-readable form. Write to [email protected]. No form, no account needed. We answer within one month.
One honest caveat about deletion: if we delete your license record, the license can no longer be validated or reactivated, so the app will lock on your Macs. Your files stay on your disk regardless. And we must keep the accounting record of a sale for as long as tax law requires, even after the license itself is gone.
You can also complain to a supervisory authority. Ours is the Österreichische Datenschutzbehörde (dsb.gv.at); you may equally complain to the authority where you live.
Two things we do not do
There is no automated decision-making and no profiling: nothing about you is scored, ranked, or decided by a machine. And horch is not aimed at children; we do not knowingly collect data from them.
Changes
If this policy changes, the new version appears here with a new "last updated" date. If a change materially affects existing customers, we will say so by email.