Effective date: 1 September 2026. Version 4.0.
ai-coustics GmbH ("ai-coustics", "we", "us") builds speech enhancement technology. This notice explains what personal data we process, why, on what legal basis, who we share it with and how long we keep it.
The short version: our SDK processes audio on your own infrastructure. That audio never reaches us. What we do process is the data needed to run your account, meter your usage, bill you and keep the product working.
Questions, or to exercise any right in this notice: privacy@ai-coustics.com.
Who we are
Controller:
ai-coustics GmbH Rosenthaler Str. 38/4 10178 Berlin, Germany privacy@ai-coustics.com
We have not appointed a data protection officer. If that changes we will name them here.
Our roles
We are a controller for data about your account, your use of the developer portal and our websites, your billing relationship with us, and the telemetry the SDK reports.
We are a processor for any personal data contained in audio your own application processes with our SDK. That audio stays on your infrastructure. Where you use a feature that sends it onward - the playground described below - we process it on your instructions and only to return the result. Business customers processing third-party personal data can request a data processing agreement at privacy@ai-coustics.com.
What we collect, why, and on what basis
When you use the SDK
Audio and any other content the SDK processes stays on your infrastructure. We do not receive it, store it or have access to it.
The SDK reports the following to our backend so we can license it and meter usage: the key id or short-lived token authenticating the session, SDK version and wrapper type, model identifier, operating system, CPU architecture, a session identifier linking the session to your account, and per-session processing durations including how much audio was processed and how much was not permitted. Whether a voice activity detector was instantiated. Technical metadata inherent to any network request, including source IP address.
Purpose: authorizing the license, metering usage for billing, and diagnosing reliability and performance problems. Basis: Art. 6(1)(b) performance of the contract for licensing and metering. Art. 6(1)(f) legitimate interest in a working, secure product for reliability diagnostics.
The SDK needs model files to run. Your application downloads them once from artifacts.ai-coustics.io and then uses the local copy on every subsequent invocation. We publish a hash for each file so you can confirm that what you downloaded is what we published. Checking it is your side of the integration. We do not receive audio through any of this, but the download is an ordinary network request, so the device that makes it reaches us with its IP address and user agent.
Purpose: distributing the model files the SDK needs. Basis: Art. 6(1)(b) performance of the contract.
The SDK can also export operational metrics over OpenTelemetry when you set AIC_SDK_OTEL_ENABLE=1. Those metrics include audio-derived values such as signal-to-noise ratios and speech duration. They go to the OTLP endpoint you configure, on your own infrastructure. ai-coustics is not a recipient. The API key attribute attached to them is a SHA-256 hash, not the key.
When you use the playground
The playground on our developer portal, and its embedded version on ai-coustics.com, enhances audio in your browser. The enhancement itself runs locally in WebAssembly and the audio does not reach our servers for processing.
If you use the transcription view, your audio is sent to Soniox, Inc. to produce a transcript. Both the original and the enhanced audio are sent. For live microphone use, your browser streams directly to Soniox using a short-lived key we mint. For file uploads, the audio passes through our server on the way. In both cases the audio is transcribed as it streams - it is processed in transit and is not written to disk on either side.
Under our data processing agreement with Soniox, audio is processed transiently to produce the transcript and is not stored. Soniox does not use it to train models that serve other customers. Soniox processes it in the United States under the Standard Contractual Clauses at §7 of that agreement. We store no playground audio at all.
Purpose: producing the transcript you asked for. Basis: Art. 6(1)(b) where you have an account, Art. 6(1)(f) legitimate interest in offering a working public demo otherwise.
When you use the call analysis demo
The demo at call-analysis.ai-coustics.com analyzes a call recording you upload. The audio is sent to our compute provider Modal, Inc. in the United States, analyzed in transit and returned to you. Neither we nor Modal write it to disk, and we keep no copy of the recording or the analysis once you leave the page.
A call recording usually contains other people's voices. Only upload a recording you have the right to share with us. If you do not have that right, do not upload it.
Purpose: producing the analysis you asked for. Basis: Art. 6(1)(f) legitimate interest in offering a working public demo.
When you create or manage an account
Email address, and the name and authentication details held by our identity provider. Your subscription plan, billing history and payment status. The names you give your API keys - we store a hashed reference to each key, never the key itself. Your usage records.
If you complete the onboarding questionnaire: your name, company, intended use case, platform, expected volume, how you found us, and anything you type into the free-text fields.
If you arrive through a marketing link: the campaign parameters in that link, kept for up to 30 days so they can be attached to your record if you sign up.
Purpose: creating and running your account, billing you, supporting you, and understanding which marketing works. Basis: Art. 6(1)(b) for the account and billing. Art. 6(1)(c) for statutory invoice retention. Art. 6(1)(f) for support and marketing attribution.
Providing this data is a contractual requirement. Without an email address and the authentication details our identity provider needs, we cannot create an account for you.
When you visit our websites
Server and edge logs, including IP address, user agent and request metadata, are processed to serve the site and to defend against abuse. Basis: Art. 6(1)(f) legitimate interest in security and availability.
Product analytics and error reports, using PostHog. These are pseudonymous until you sign in, at which point we link them to your account. Linking back-dates activity recorded before sign-up to your account. PostHog also records session replays across all our sites: mouse movement, clicks, scrolling and page navigation. Basis: Art. 6(1)(a) consent, collected through our consent banner and withdrawable at any time from the Privacy Settings control on our cookie policy.
Error reports include stack traces and the page path, and can incidentally contain data present at the moment of the error.
When you sign up for news and updates
If you tick the optional box at signup, we use your email address to send product news and updates. Basis: Art. 6(1)(a) consent. You can withdraw it from the unsubscribe link in any message or at privacy@ai-coustics.com, without affecting anything sent before you withdrew.
We do not send marketing by SMS.
What we do not collect
We do not process special categories of personal data under Art. 9. We do not sell personal data. We do not use automated decision-making or profiling that produces legal or similarly significant effects.
Some fields are free text and reach us as you type them: API key names, and the SDK metadata your integration reports. Do not put personal data in them.
Who we share it with
We use the sub-processors below. Each is bound by a data processing agreement. Transfers outside the EEA are covered by the European Commission's Standard Contractual Clauses.
Sub-processor | What for | Data | Location |
|---|---|---|---|
Amazon Web Services | Hosting, database, queues | All backend data | Frankfurt, Germany (eu-central-1) |
Usercentrics | Consent management | Consent choices, IP address, user agent | Germany |
Cloudflare | CDN, DDoS and bot protection | Request metadata, IP | Global edge |
Clerk | Authentication and user directory | Email, name, sign-in metadata | United States (SCCs) |
Stripe | Payments and invoicing | Billing name, email, address, card metadata | United States and Ireland (SCCs) |
Metronome | Usage metering and invoicing | Account identifiers, usage records | United States (SCCs) |
PostHog | Product analytics, error tracking, session replay, usage reporting | Pseudonymous and account-linked usage, account and billing records | EU Cloud, Frankfurt |
HubSpot | Customer relationship management | Contact and onboarding details | EU data region |
Soniox | Speech-to-text in the playground | Playground audio, transcripts | United States (SCCs) |
Modal | Compute for the call analysis demo | Uploaded call audio, in transit only | United States (SCCs) |
Mintlify | Documentation hosting and docs assistant | Site usage, assistant questions | United States (SCCs) |
Framer | Marketing website hosting | Site usage | United States (SCCs) |
Vimeo | Embedded video | Playback requests, IP address | United States (SCCs) |
YouTube | Embedded video | Playback requests, IP address | United States, loaded by your browser only after you consent |
We publish changes to this list on our sub-processor page. Customers with a data processing agreement are notified before a new sub-processor starts processing, and can object.
The two video services are different in kind from the rest. We do not send them anything: when a page contains an embedded player, your browser contacts them directly, which is enough for them to see your IP address. They load only after you consent.
Our sites also load fonts and script libraries from public content delivery networks. Those providers do not process anything on our behalf, so they are not listed above, but your browser does contact them and they can see your IP address. Every one of them is named in our cookie policy, with what it stores and for how long.
Beyond these, we disclose personal data only to employees and contractors who need it and are bound to confidentiality, and where a court order, subpoena or other legal obligation requires it.
Where your data is stored
Our own infrastructure runs in AWS eu-central-1 in Frankfurt, Germany. Application logs and metrics stay within that environment.
Personal data reaches the United States through the sub-processors marked above. Those transfers rely on the European Commission's Standard Contractual Clauses, with transfer impact assessments on file. You can request a copy of the clauses at privacy@ai-coustics.com.
How long we keep it
Data | Retention |
|---|---|
Account record | For the life of the account, then 30 days |
Usage and session records | 10 years |
Invoices and payment records | 10 years, German statutory retention |
API key references | Hashed reference only, never the key. Kept for 10 years so usage and invoices stay traceable. |
Server and application logs | 90 days |
Product analytics | 24 months |
Error reports | 90 days |
Session replays | 30 days |
CRM contact records | 36 months after the relationship ends, or 24 months after last engagement if you never became a customer |
Playground audio | Not retained |
Call analysis demo audio | Not retained |
Marketing attribution | 30 days |
Backups | Up to 35 days |
Delete your account and we delete the personal data associated with it, except where we are legally required to keep it - invoices being the main case, and the usage records the invoices are built from. Deletion propagates to our sub-processors. Backups age out on their own schedule, which can leave a copy for up to 35 days.
Cookies and consent
We use Usercentrics as our consent management platform. Nothing that is not strictly necessary is set until you have agreed to it, and you can change or withdraw that agreement at any time from our cookie policy, which carries the Privacy Settings control.
Withdrawing consent is as easy as giving it, and it does not affect anything processed before you withdrew.
We use four categories. Essential storage makes the site work at all - signing you in, keeping your session, remembering your consent choice - and needs no consent. Functional storage supports features you asked for, like embedded video and content delivery. Analytics storage tells us which pages get used and where the product breaks. Marketing storage links your visit to your record in our customer system, so we can tell which of our own content brought you here. We run no advertising cookies and no cross-site advertising trackers.
Every cookie and storage item we set, with its purpose and duration, is listed on our cookie policy. That page is generated from our consent management platform, so it is always current.
Your rights
Under the GDPR you have the right to access your personal data (Art. 15), to have inaccurate data corrected (Art. 16), to have your data erased (Art. 17), to restrict processing (Art. 18), to data portability (Art. 20), and to object to processing based on our legitimate interests (Art. 21), including profiling and direct marketing.
Where processing rests on consent, you can withdraw it at any time from the Privacy Settings control on our cookie policy, or at privacy@ai-coustics.com (Art. 7(3)). Withdrawal does not affect processing carried out before you withdrew.
Exercise any of these at privacy@ai-coustics.com. We respond within one month. We may need to verify your identity first, and will ask for no more than we need to do that.
You also have the right to complain to a supervisory authority (Art. 77). Ours is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin.
Security and breaches
We apply technical and organizational measures appropriate to the risk, including encryption in transit and at rest, least-privilege access control and audit logging. Credentials and tokens are redacted from application logs.
If a breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it (Art. 33), and we notify you without undue delay where the risk to you is high (Art. 34).
Children
Our services are not intended for anyone under 16, and we do not knowingly collect their personal data. If we learn that we have, we delete it. If you believe a child has given us personal data, tell us at privacy@ai-coustics.com.
Third-party links
Our sites link to other sites. A link is not an endorsement of their privacy practices. Read their notices before giving them anything.
Business transfers
If ai-coustics is acquired in whole or in part, or enters insolvency, personal data may transfer as a business asset. An acquirer would remain bound by this notice until it gives you notice of a change.
Changes
We update this notice as the product changes. The version number and effective date at the top change with it. Material changes are announced by email to account holders at least 30 days before taking effect. Where a change moves a purpose onto consent as its basis, we ask for that consent before the change applies to you.
Contact
ai-coustics GmbH Rosenthaler Str. 38/4 10178 Berlin, Germany privacy@ai-coustics.com
