Trust Center
Plain facts about what the software does.
This page is written so you can check it. Each claim points at a setting, a file or a page you can verify.
We don't store your data. We can't.
Your recordings, transcripts and notes exist only on your device. Recordist has no server that could hold them. The only thing we ever keep is the email on your receipt.
If you choose a cloud AI provider for notes, the transcript goes from your computer to that provider under your own account. That is your choice, off by default, and listed in the Privacy Ledger.
What leaves your machine
By default, nothing about your meetings. Every case that can send anything is listed here with what, where and when. The app records the same events in its Privacy Ledger, so you can compare.
| Feature | Data | Destination | When |
|---|---|---|---|
| Recording, transcription, search, Prep Briefs | Nothing | Nowhere | Never; it all stays on your machine. |
| Local AI notes | Nothing | The local model on your machine | Never leaves the machine. |
| Cloud AI notes with your own key (optional) | Transcript text of that meeting + your template | The provider you chose (Anthropic, OpenAI or a compatible endpoint), directly | When you click Generate, or on auto-notes if you enabled it. Logged in the Privacy Ledger. |
| Transcription model download | A download request; nothing about you | Public model mirror (HTTPS) | When you pick a model. Verified against a published checksum. |
| Update check | App version and platform | Our release host | At launch and every six hours while the app runs; the switch is Settings → General → Check for updates automatically. |
| Licence verify or recover (optional) | Licence id, or the email you used at checkout | Recordist licence service | Only when you click Verify online or Recover key. Keys verify offline. |
| AI assistants you connect (MCP, A2A) | Whatever the assistant asks for | A connection on your own machine only | When your assistant calls a tool. Where it sends what it read is up to that assistant. |
| This website: early-access form, support ticket | What you type: your email, your first name if you gave it, which computer you would run it on, the plan you chose if you asked from the pricing page, and the time you asked; for a ticket, the text you wrote. | Our hosting provider's storage for this site | Only when you submit a form here. Nothing from the app. |
| Wren (support assistant, AI) | Your chat messages, with anything that looks like a key removed | Anthropic's API, through this site | Only when you chat with Wren on this website. Message bodies are not logged. |
No telemetry, analytics or crash reporting exist in the app or on this site. The only diagnostic is Settings → General → Export diagnostics, which writes a file you choose whether to send. It contains no audio and no transcript text.
Permissions we ask for, and why
- Microphone
- To record your side of the call. Without it, only the other participants are captured.
- Screen & System Audio Recording (macOS 14.6 or later)
- macOS gates system-audio capture behind this permission. Recordist uses the audio part only; it never reads screen contents, and it does not request Screen Recording for video.
- Calendar (optional)
- To title meetings and build Prep Briefs from attendee names. Read-only; can be declined.
- Notifications (optional)
- To tell you when notes are ready.
- Not requested
- Accessibility, Contacts, Location, Camera, Full Disk Access, Automation. The Chrome extension is limited to the supported meeting sites and to the app on your own machine.
How it's protected
No software is perfectly secure and we don't claim Recordist is. What we can say is where the meeting lives, who can reach it, and what we did about each.
Reachable only from your own machine
The app's local connections for your AI assistants and the extension exist only on your computer. They are unreachable from your network by design and refuse requests that arrive any other way.
A token that never leaves your computer
Every local request must carry a random token created on first launch and readable by your user account only. It is personal to your machine and should never be shared; the app never asks you to.
Keys in the keychain
A cloud AI key, if you add one, lives in your operating system's keychain, never in settings files, exports, diagnostics or logs. Logs contain no transcript text.
- Data at rest: regular files under your user account; optional encryption of the database with a passphrase (Settings → Privacy → Encrypt database). We recommend turning on full-disk encryption.
- Licences: keys carry a digital signature the app checks offline; the signing secret exists only in our licence service, never on your machine.
- Builds: early builds are not yet code-signed, so every release publishes a checksum file. Builds come from our automated pipeline on tagged releases, with dependencies pinned.
- Website: static, no cookies, no analytics, security headers at the edge. Payments are hosted by Stripe; card details never touch our infrastructure.
Data retention and deletion
On your device
- Audio is deleted 30 days after a meeting by default (Free) or kept as long as you like (Pro). You can also delete audio right after transcription.
- Transcripts, notes and the search index stay until you delete them.
- Delete one meeting: removes its records and its audio.
- Delete everything: Settings → Privacy → Delete all data removes the database, audio and models, then quits. Uninstalling afterwards leaves nothing behind.
With us
- If you buy a plan: your email, the plan, the amount and a payment reference, kept for as long as tax law requires.
- If you ask for early access: your email, your first name if you gave it, which computer you chose, the plan if you chose one, and the time you asked, kept until invitations have gone out and the draw is complete, then for up to 12 months in case of a dispute.
- If you open a ticket: what you typed, kept for up to 2 years after the last message.
- If you chat with Wren: nothing is stored beyond the request; message bodies are not logged.
- Never: audio, transcripts, notes, or anything from inside the app.
Accuracy of transcripts and notes
Notes are generated by an AI model, a local one by default or a provider you choose, and may be inaccurate, incomplete or misattribute who said what. Transcripts are automatic and can contain errors. Recordist keeps the recording, for as long as you set, so you can check. The app shows this notice above every notes panel and at the top of every export. Do not rely on notes for legal, medical, financial, employment or safety decisions without verifying them.
Recording law is your responsibility
Recordist never records without your explicit confirmation, and you are always a participant in what it records. Whether you must tell or ask the other people depends on where everyone is. Before your first recording the app asks you to confirm that you understand this. We keep a plain-English summary of US, Canadian, UK, EU, Australian and Indian rules, with the caveat that it is general information and not legal advice.
This website
- No cookies, no analytics, no tracking pixels. The only third party the page loads is Google Fonts, and the privacy policy says so.
- The films on this site are served from our own domain with the browser's built-in player. No third-party video player, no tracking, no autoplay with sound.
- Wren, the support assistant, is an AI and is labelled as one everywhere it appears. A human reads every ticket.
- No testimonials, user counts or press quotes appear on this site unless they are real and attributable. There are none yet.
Vulnerability disclosure
Email [email protected] with a description, steps to reproduce and the app version. We acknowledge within 3 business days and aim to fix confirmed high-severity issues within 14 days. Please give us reasonable time before disclosing, do not test against other people's machines or data, and tell us if you want credit in the changelog. There is no paid bounty at this time.
Third-party licences
Recordist is built on open-source software and ships the full notices in the app (Settings → About → Acknowledgements). The main components:
- whisper.cpp and ggmlMIT
- OpenAI Whisper model weightsMIT
- TauriMIT / Apache-2.0
- cpal (audio capture)Apache-2.0
- RNNoise / nnnoiselessBSD-3-Clause
- SQLitePublic domain
- rusqliteMIT
- Model Context Protocol SDKMIT
- Qwen3 (default local model)Apache-2.0
- OllamaMIT
- Inter, Instrument Serif, JetBrains MonoSIL OFL 1.1
Whisper is a model released by OpenAI under the MIT licence; Qwen is released by Alibaba Cloud under Apache-2.0; Ollama is an open-source project under the MIT licence. "Powered by" statements are factual and imply no endorsement. Models with non-commercial licences are labelled in the picker.
Who we are
Recordist is made and sold by Havihi Digital Inc., an independent software studio incorporated in Canada. Our registered office is 2 McMillan Pl, Welland, Ontario L3B 0L5, Canada. Current version 0.3.0; every release is on the changelog and every open limitation on known issues.
Recordist was built in good faith by a small team who wanted meeting notes without a bot in the room or a vendor holding the recording. It is a tool for remembering your own conversations. It is not a tool for recording people who do not know, monitoring staff, or surveilling anyone. The app asks you before every recording, keeps a visible indicator while it records, and gives you notice templates because we think the people you talk to deserve to know. Use it responsibly; the recording is yours, and so is the responsibility for it.
Questions about anything here: [email protected].