Formal DPA: This page serves as Cleft’s official Data Processing Agreement for all customers and compliance teams, while also providing transparent information for all users.
Last Updated: September 10, 2025
Effective: September 10, 2025
Effective: September 10, 2025
Data Processing Agreement
This document serves as both our user-friendly data transparency guide and our formal Data Processing Agreement (DPA) for customers requiring compliance documentation.Data Controller/Processor Relationship
Roles & Responsibilities
You (Data Controller): You control the personal data in your notes, recordings, and accountCleft (Data Processor): We process your data solely to provide voice-to-text services as instructed by youLegal Basis: Processing based on legitimate interests (service provision) and consent where applicable
Key Principle: We only collect and process data that’s essential for delivering our service. Your content is never used for training AI models or shared with advertisers.Complete Vendor List: This DPA covers our key data processors. For our complete list of all 37 vendors (including business operations vendors that handle no personal data), see our Vendor Transparency page.
Data Categories & Usage
Audio Recordings
Your Voice Recordings
What We Collect: Audio files when you press recordHow It’s Processed:
- Local Storage: Audio stays on your device during recording
- Device Transcription: Processed locally using OpenAI’s Whisper model
- Cloud Backup: Audio files uploaded to AWS for 1-hour temporary access
- Permanent Storage: Moved to secure AWS storage after 1 hour
- Download Access: Available for download anytime via the app
- AWS (hosting only - no content access)
- You (full ownership and download rights)
Transcripts & Text
Transcribed Text
What We Collect: Text versions of your audio recordingsHow It’s Processed:
- Device Creation: Generated locally on your device
- AI Enhancement: Text sent to AI providers for note processing
- Cloud Sync: Stored on AWS for cross-device access
- User Access: Available in-app and via export
- OpenAI (primary AI processing - text only, never audio)
- Groq (backup AI processing - text only)
- Anthropic (additional AI processing - text only)
- AWS (hosting only - no content access)
Account Information
Profile & Settings
What We Collect:
- Email address (for authentication)
- Display name
- App preferences and settings
- Device information (for sync)
- Authentication: Secure login via email
- Sync: Cross-device note synchronization
- Support: Customer service assistance
- Communications: Service updates and newsletters (opt-in)
- AWS (secure hosting)
- HubSpot (customer support interactions only)
- Mailerlite (newsletter delivery - opt-in only)
- 1Password (internal team password management only)
Website & Forms
Contact Forms & Website
What We Collect:
- Form submissions on our website
- Contact requests and support inquiries
- Scheduling information for consultations
- Customer Support: Responding to inquiries and requests
- Scheduling: Coordinating onboarding calls and consultations
- Website Hosting: Maintaining our public-facing website
- Webflow (website hosting and form submissions)
- Fillout (form building and data collection)
- Namecheap (domain registration and DNS management)
- Cloudflare (CDN and website performance)
Integration & Automation
Workflow Automation
What We Collect:
- Integration data flows you configure
- Automated workflow triggers
- Connected app permissions
- User Integrations: Connecting Cleft with your other tools
- Automation: Streamlining workflows as configured by you
- Data Export: Sending your notes to destinations you choose
- Zapier (workflow automation - only data flows you configure)
Usage Analytics
App Performance Data
What We Collect:
- Feature usage patterns (anonymous)
- App performance metrics
- Crash reports (no personal content)
- Documentation page views
- Product Improvement: Understanding which features are most valuable
- Bug Fixes: Identifying and resolving technical issues
- Performance: Optimizing app speed and reliability
- Fathom Analytics (website analytics only - privacy-focused)
- TelemetryDeck (in-app anonymous analytics - no PII collected)
- Sentry (crash reporting - no personal data)
- Metabase (internal analytics - aggregated data only)
Payment Information
Billing & Subscriptions
What We Collect:
- Subscription status
- Purchase history
- Payment method (handled by Apple/Stripe)
- Apple App Store: Handles all iOS subscription billing
- Stripe: Processes web payments (we don’t see card details)
- RevenueCat: Manages subscription status and analytics
- Apple (iOS subscriptions)
- Stripe (web payments - PCI compliant)
- RevenueCat (subscription management)
Data Flow Diagram
Recording to Note Process
Recording to Note Process
Step 1: You record audio → Your Device (local storage)Step 2: Audio transcribed → Your Device (using OpenAI’s Whisper model)Step 3: Audio backed up → AWS (secure cloud storage)Step 4: Transcript enhanced → OpenAI/Groq/Anthropic (text processing only)Step 5: Final note saved → AWS (encrypted storage)Step 6: Synced to your devices → Your Apps (encrypted transfer)
Data at Rest
Data at Rest
Your Device:
- Audio files (during recording)
- Transcripts and notes (local cache)
- App preferences
- Audio files (encrypted)
- Transcripts and notes (encrypted)
- Account information (encrypted)
- Sync data (encrypted)
- No data stored - processing only
- Receive text, never audio
- No training on your data
Data in Transit
Data in Transit
Device ↔ AWS: End-to-end encryption using TLS 1.3AWS ↔ AI Providers: Encrypted API calls (HTTPS/TLS)Device ↔ Payment Processors: Direct secure connection (bypasses our servers)App ↔ Analytics: Anonymous, aggregated data only
Your Data Rights
Full Ownership
You Own Everything
- All notes, transcripts, and audio files
- Complete export available anytime
- Delete individual items or entire account
- No vendor lock-in - portable data
Complete Control
Granular Permissions
- Choose which features to sync
- Control communication preferences
- Manage integration permissions
- Request specific data deletion
Transparency
Full Visibility
- Know exactly who processes your data
- See all vendor relationships
- Access data processing agreements
- Review security certifications
Privacy by Design
Built-in Protection
- No advertising or tracking
- No data sales to third parties
- No AI training on your content
- GDPR & CCPA compliant
Data Minimization
We follow strict data minimization principles:- Only Essential Data: We collect only what’s needed for core functionality
- Purpose Limitation: Data used only for stated purposes
- Retention Limits: Automatic deletion after 2 years of inactivity
- Access Controls: Vendor access limited to necessary functions only
DPA Compliance & Audit Rights
Compliance & Audit Rights
Audit Rights: Customers have the right to audit our data processing activities upon reasonable noticeCompliance Support: We assist with your GDPR, CCPA, and other regulatory compliance requirementsDocumentation: This page serves as your DPA - bookmark, download, or print for your compliance recordsUpdates: We’ll notify customers of material changes to our data processing practices
Incident Response & Security
Security Incident Response
Security Incident Response
Notification Timeline: We notify affected customers within 72 hours of discovering a security incidentResponse Process: Immediate containment, investigation, remediation, and detailed incident reportsCustomer Support: Dedicated incident response team
Technical & Organizational Measures
Technical & Organizational Measures
Encryption: All data encrypted in transit (TLS 1.3) and at rest (AES-256)Access Controls: Role-based access, multi-factor authentication, regular access reviewsInfrastructure: SOC 2 compliant cloud infrastructure with redundancy and monitoringStaff Training: Regular security awareness training for all Cleft personnel
Questions About Data Processing?
Data Protection Officer
Jonny Cosgrove
Founder, COO and Data Protection Officer📧 DPO@cleftnotes.com
📋 DPA Questions: Include “DPA” in subject line
Founder, COO and Data Protection Officer📧 DPO@cleftnotes.com
📋 DPA Questions: Include “DPA” in subject line
Privacy & Compliance
Privacy Team📧 privacy@cleftnotes.com
📋 For: DPA questions, audit requests, compliance documentation, general privacy questions
📋 For: DPA questions, audit requests, compliance documentation, general privacy questions
Related Documentation
- Privacy Policy - Complete legal privacy policy
- Vendor Transparency - Detailed vendor information
- Cookie Policy - Our no-cookie promise
- Terms of Service - Usage terms and conditions
Data Subject Access Request: To request a copy of all personal data we hold about you, submit a request here or contact our Data Protection Officer.