privacy

Privacy, in plain words

What Whozit keeps, who else touches your audio, and how to remove any of it.

Last updated

  1. 1. What Whozit keeps, and where
  2. 2. Who else touches your audio
  3. 3. What Whozit never does
  4. 4. Consent and voiceprints
  5. 5. How long it's kept
  6. 6. Removing things
  7. 7. Taking it with you
  8. 8. Your account and signing in
  9. 9. Agents and MCP tokens
  10. 10. Cookies and browser storage
  11. 11. Contact

Each factual line on this page has an automated check. Most run Whozit's real code on a throwaway copy and measure what it does; a few (where data is hosted, how long snapshots are kept) check the deployment settings instead.

1. What Whozit keeps, and where

All of this sits in a folder that belongs to your account, with its own database. The only things kept outside it are your sign-in details, your consent record and your MCP token (see Your account).

Other accounts can't open your recordings, transcripts, voice library or exports, and you can't open theirs.

2. Who else touches your audio

ElevenLabs transcribes your audio with its Scribe service.

While ElevenLabs holds your audio, its own terms and privacy policy apply to what it does with it. Whozit can't see inside ElevenLabs' systems.

Fly.io hosts Whozit. Your folder sits on one volume attached to a single Fly.io machine, and Fly.io runs that machine.

Your data is stored in the United States: the volume is in Fly.io's Ashburn, Virginia region.

Whozit has no analytics and no ads, and loads nothing that reports back to a third party.

The site and the app load no third-party scripts, fonts, styles, images or embeds. The fonts are served by Whozit itself.

3. What Whozit never does

Like any hosted service, Whozit runs on a server that the person who runs it can reach. The list above is about what the software does.

In some places a voiceprint counts as biometric data. Illinois (under BIPA) and the EU and UK (under the GDPR) are examples. Those laws can require you to get a person's consent before you collect their voiceprint. This is general information, not legal advice.

That record is your agreement. It isn't the agreement of the people in your recordings. Tell the people you record, ask whether they're fine with it, and forget anyone who isn't.

You can have Whozit forget anyone at any time (see Removing things).

5. How long it's kept

6. Removing things

7. Taking it with you

8. Your account and signing in

9. Agents and MCP tokens

An MCP token lets an AI tool that you connect, such as Claude Code or Claude Desktop, read your meetings. (Claude.ai and ChatGPT connectors aren't supported yet.)

What an agent reads goes to the company that runs it, under that company's terms. Revoking the token stops new reads. It can't take back what was already read.

10. Cookies and browser storage

11. Contact

Questions, or something you want removed that the buttons above don't reach: hello@whozit.io

When this page changes, the date at the top changes too.