Privacy Policy
Last updated: April 2026
1. Data Controller
Sanftware
Stefan Riedelsberger
Email: privacy@sanftware.com
2. Data We Collect
When you use echosync.me, we process the following data:
- Waitlist: Email address, signup timestamp, language preference
- Demo: Audio recordings are used solely for processing and deleted immediately
- Server logs: IP address (anonymized via SHA-256 hash), timestamp, user agent
3. AI Processing
Default (Privacy-by-Default): All AI processing (speech recognition and text processing) runs through Mistral AI SAS, Paris (France). No third-country data transfer occurs in standard operation — your data stays in the EU.
Optional (with consent): In the app, users can optionally choose OpenAI (USA) as an alternative AI provider. This requires explicit, informed consent regarding the associated risks (FISA 702, CLOUD Act). This option is not available in the website demo.
4. Hosting & Sub-processors
Website: Vercel Inc. (USA) — Content Delivery Network with global edge locations.
API servers: Vercel Serverless Functions, Frankfurt region (EU).
Database: Supabase (Frankfurt, EU) — PostgreSQL with Row-Level Security.
AI (Default): Mistral AI SAS (Paris, France) — speech recognition (Voxtral) and text processing.
AI (Optional): OpenAI Inc. (USA) — only with explicit user consent.
5. Cookies
This website does not use tracking cookies or analytics tools. Only technically necessary cookies are set.
6. Age Requirement
Using EchoSync requires a minimum age of 16 years (Art. 8 GDPR). Age confirmation is collected during app registration.
7. Your Rights
You have the right to access, rectify, delete, and restrict the processing of your personal data. Contact us at privacy@sanftware.com.
8. Audio Processing
Audio recordings are transcribed via Mistral Voxtral (EU) and immediately deleted afterward. No permanent storage of audio data takes place. Processing occurs on EU servers (Frankfurt and Paris).