Privacy Policy
Last updated: July 28, 2026
This Privacy Policy explains what personal data we handle when you visit recorderdesk.com, use the RecorderDesk desktop app, or buy a RecorderDesk Pro license. The data controller is Yusaku Yamaguchi, the sole proprietor who develops and sells RecorderDesk, based in Japan. You can reach us any time at [email protected].
The short version
- Your recordings, transcripts, and summaries stay on your device. We never receive them.
- The app has no telemetry, no analytics, and no crash-reporting server. You can record without an account.
- Data leaves your device only for features you turn on yourself — and the app logs each of those events so you can check.
- What we actually hold is small: your email and license record if you buy, plus website analytics.
- We do not sell your personal data, and we never use your meeting content to train AI models.
1. What stays on your device
RecorderDesk is a desktop app that runs on your own machine. The following are created and stored locally on your computer, and are never sent to us:
- audio recordings, transcripts, speaker labels, summaries, translations, and notes;
- your vocabulary lists, project context, templates, automations, and app settings;
- the Activity Log (audit log) that records what the app did and what data left your device;
- crash and error information — uncaught exceptions are written to the local Activity Log only; there is no crash-reporting server to send them to.
We operate no server that receives meeting content, and we have no technical means to read it. Deleting a recording in the app, or deleting the app's data folder, removes it — there is no copy on our side to request the deletion of.
2. When data leaves your device
Transcription and AI run on your device by default. Data leaves your machine only through features you deliberately enable, and in every case it goes to the service you chose — not to us:
- Cloud transcription, AI, or translation providers you configure yourself. What you send is then governed by that provider's own terms and privacy policy.
- Calendar connections and MCP tools, if you connect them.
- Update checks, which reach GitHub Releases on launch, every few hours, and whenever you ask — never in Offline Mode, and never if you turn auto-check off.
- License checks against our entitlement service, described in section 4.
Offline Mode blocks every outbound network call at the network boundary, with no silent fallback. Whether or not it is on, each egress event is written to the Activity Log, which you can filter and export as CSV or JSON. See the privacy documentation for how to verify this yourself.
3. This website
When you visit recorderdesk.com:
- Analytics. We use Microsoft Clarity to see which pages people read and where they get stuck. Clarity records page views, clicks, scrolling, and session replays of your interaction with the site, and sets cookies to do so. It is subject to the Microsoft Privacy Statement. Nothing loads until you accept it. We ask on your first visit; if you decline, the Clarity script is never fetched and no analytics cookie is set. You can change your answer at any time through Cookie settings in the site footer, and the site works exactly the same either way. Analytics runs only on the live site, never in local development.
- Hosting logs. Our hosting provider, Cloudflare, processes standard server request data (IP address, user agent, requested URL, timestamp) to serve the site and protect it from abuse. This is subject to the Cloudflare Privacy Policy.
- Local storage. We store one item in your browser,
rd-lang, to remember whether you chose English or Japanese. It is not a tracking identifier and never leaves your browser.
We do not run advertising, and we do not build profiles of visitors across other websites.
4. Purchases and the optional account
You can download, install, and use RecorderDesk without giving us anything. If you buy a RecorderDesk Pro license, we handle the following:
- Payment data. Payments are processed by Stripe, which collects your payment details and billing information directly. We never receive or store your full card number. We receive the transaction record we need to issue and support your license (such as the purchase amount, date, and the last four digits and card brand). Stripe processes this data as an independent controller under the Stripe Privacy Policy.
- Your email and license record. The optional account is email-only. It exists for one purpose: to restore your Pro entitlement on your devices. The record is stored with Supabase, our hosted database provider, and holds your email address and your entitlement status. It never stores your meeting content — no recordings, no transcripts, no summaries.
- Support email. If you write to us, we keep the correspondence so we can answer you and handle refunds and warranty questions.
5. Why we process it
- To perform our contract with you — selling you a license, activating and restoring your entitlement, providing updates, and handling refunds.
- To comply with legal obligations — tax and accounting records for your purchase.
- For our legitimate interests — keeping the website and the app secure and working, and understanding in aggregate how the site is used.
- With your consent — website analytics. We ask before loading it, and you can withdraw your consent at any time through Cookie settings in the site footer. Withdrawing is as easy as giving it, and costs you nothing.
We do not sell your personal data, we do not share it for cross-context behavioral advertising, and we do not use your content to train AI models.
6. Who we share data with
We do not sell or rent personal data. We share it only with the service providers we need to run the business, and only for that purpose:
- Stripe — payment processing.
- Supabase — storing the license entitlement record.
- Microsoft Clarity — website analytics, only if you accept it.
- GitHub — hosting the app downloads and release feed the update checker reads.
- Cloudflare — website hosting.
Any cloud AI, transcription, or translation provider you configure inside the app is a service you chose and connected. Your data goes to it directly from your device, not through us, and their handling of it is governed by their own policies. We may also disclose data if we are legally required to, or to establish or defend legal claims.
7. International transfers
We are based in Japan, and the providers listed above operate internationally, including in the United States and the European Union. Where personal data is transferred out of your region, that transfer relies on the safeguards those providers offer — such as the European Commission's Standard Contractual Clauses — or on an adequacy decision covering Japan.
8. How long we keep it
- License and entitlement records — for as long as your license is valid, so we can restore it; a perpetual license means we keep the record indefinitely unless you ask us to delete it.
- Purchase and tax records — for the period Japanese tax law requires (generally seven years).
- Support email — usually up to two years after the conversation ends.
- Website analytics — for the retention period Microsoft Clarity applies, which is currently up to one year.
- Anything on your device — for as long as you keep it. You control that retention entirely, including the Activity Log's own retention setting (30 / 90 / 180 days or forever).
9. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to restrict or object to how we use it, to receive a portable copy, and to withdraw consent. Residents of the EEA and the UK have these rights under the GDPR; residents of Japan under the APPI; residents of California under the CCPA/CPRA — including the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined under the CCPA.
To exercise any of these, email [email protected]. We will respond within the time the applicable law allows. Because we hold so little — essentially your email and license record — most requests are quick to handle. You also have the right to complain to your local data-protection authority.
10. Recordings you make of other people
When you record a meeting, you — not we — are responsible for that recording and for the participants' personal data in it. You are responsible for complying with the laws on recording conversations where you are, including obtaining any consent that is required. The app can display an optional on-screen recording-consent notice, and writes it to the Activity Log when shown.
11. Children
RecorderDesk is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, email us and we will delete it.
12. Security
On your device, sensitive values such as API keys are stored in the operating system's secure store, and the app ships with Electron security hardening. On our side, the data we hold is limited by design — the less we have, the less there is to lose. Traffic to this website and to our providers is encrypted in transit. No system is perfectly secure, but keeping your content on your own machine is the strongest protection we can offer, and it is the default.
13. Changes to this policy
We may update this policy as the app and the business change. When we make material changes, we will update the “Last updated” date at the top of this page. Continued use of the app or the site after a change takes effect means you accept the updated policy.
14. Contact
Questions about privacy, or a request about your data, can be sent to [email protected]. Our full seller identity and statutory contact details are in the Legal disclosure (特定商取引法に基づく表記).