Privacy policy

Privacy policy

Effective date: 1 September 2026. Version 4.0.

ai-coustics GmbH ("ai-coustics", "we", "us") builds speech enhancement technology. This notice explains what personal data we process, why, on what legal basis, who we share it with and how long we keep it.

The short version: our SDK processes audio on your own infrastructure. That audio never reaches us. What we do process is the data needed to run your account, meter your usage, bill you and keep the product working.

Questions, or to exercise any right in this notice: privacy@ai-coustics.com.

Who we are

Controller:

ai-coustics GmbH Rosenthaler Str. 38/4 10178 Berlin, Germany privacy@ai-coustics.com

We have not appointed a data protection officer. If that changes we will name them here.

Our roles

We are a controller for data about your account, your use of the developer portal and our websites, your billing relationship with us, and the telemetry the SDK reports.

We are a processor for any personal data contained in audio your own application processes with our SDK. That audio stays on your infrastructure. Where you use a feature that sends it onward - the playground described below - we process it on your instructions and only to return the result. Business customers processing third-party personal data can request a data processing agreement at privacy@ai-coustics.com.

What we collect, why, and on what basis

When you use the SDK

Audio and any other content the SDK processes stays on your infrastructure. We do not receive it, store it or have access to it.

The SDK reports the following to our backend so we can license it and meter usage: the key id or short-lived token authenticating the session, SDK version and wrapper type, model identifier, operating system, CPU architecture, a session identifier linking the session to your account, and per-session processing durations including how much audio was processed and how much was not permitted. Whether a voice activity detector was instantiated. Technical metadata inherent to any network request, including source IP address.

Purpose: authorizing the license, metering usage for billing, and diagnosing reliability and performance problems. Basis: Art. 6(1)(b) performance of the contract for licensing and metering. Art. 6(1)(f) legitimate interest in a working, secure product for reliability diagnostics.

The SDK needs model files to run. Your application downloads them once from artifacts.ai-coustics.io and then uses the local copy on every subsequent invocation. We publish a hash for each file so you can confirm that what you downloaded is what we published. Checking it is your side of the integration. We do not receive audio through any of this, but the download is an ordinary network request, so the device that makes it reaches us with its IP address and user agent.

Purpose: distributing the model files the SDK needs. Basis: Art. 6(1)(b) performance of the contract.

The SDK can also export operational metrics over OpenTelemetry when you set AIC_SDK_OTEL_ENABLE=1. Those metrics include audio-derived values such as signal-to-noise ratios and speech duration. They go to the OTLP endpoint you configure, on your own infrastructure. ai-coustics is not a recipient. The API key attribute attached to them is a SHA-256 hash, not the key.

When you use the playground

The playground on our developer portal, and its embedded version on ai-coustics.com, enhances audio in your browser. The enhancement itself runs locally in WebAssembly and the audio does not reach our servers for processing.

If you use the transcription view, your audio is sent to Soniox, Inc. to produce a transcript. Both the original and the enhanced audio are sent. For live microphone use, your browser streams directly to Soniox using a short-lived key we mint. For file uploads, the audio passes through our server on the way. In both cases the audio is transcribed as it streams - it is processed in transit and is not written to disk on either side.

Under our data processing agreement with Soniox, audio is processed transiently to produce the transcript and is not stored. Soniox does not use it to train models that serve other customers. Soniox processes it in the United States under the Standard Contractual Clauses at §7 of that agreement. We store no playground audio at all.

Purpose: producing the transcript you asked for. Basis: Art. 6(1)(b) where you have an account, Art. 6(1)(f) legitimate interest in offering a working public demo otherwise.

When you use the call analysis demo

The demo at call-analysis.ai-coustics.com analyzes a call recording you upload. The audio is sent to our compute provider Modal, Inc. in the United States, analyzed in transit and returned to you. Neither we nor Modal write it to disk, and we keep no copy of the recording or the analysis once you leave the page.

A call recording usually contains other people's voices. Only upload a recording you have the right to share with us. If you do not have that right, do not upload it.

Purpose: producing the analysis you asked for. Basis: Art. 6(1)(f) legitimate interest in offering a working public demo.

When you create or manage an account

Email address, and the name and authentication details held by our identity provider. Your subscription plan, billing history and payment status. The names you give your API keys - we store a hashed reference to each key, never the key itself. Your usage records.

If you complete the onboarding questionnaire: your name, company, intended use case, platform, expected volume, how you found us, and anything you type into the free-text fields.

If you arrive through a marketing link: the campaign parameters in that link, kept for up to 30 days so they can be attached to your record if you sign up.

Purpose: creating and running your account, billing you, supporting you, and understanding which marketing works. Basis: Art. 6(1)(b) for the account and billing. Art. 6(1)(c) for statutory invoice retention. Art. 6(1)(f) for support and marketing attribution.

Providing this data is a contractual requirement. Without an email address and the authentication details our identity provider needs, we cannot create an account for you.

When you visit our websites

Server and edge logs, including IP address, user agent and request metadata, are processed to serve the site and to defend against abuse. Basis: Art. 6(1)(f) legitimate interest in security and availability.

Product analytics and error reports, using PostHog. These are pseudonymous until you sign in, at which point we link them to your account. Linking back-dates activity recorded before sign-up to your account. PostHog also records session replays across all our sites: mouse movement, clicks, scrolling and page navigation. Basis: Art. 6(1)(a) consent, collected through our consent banner and withdrawable at any time from the Privacy Settings control on our cookie policy.

Error reports include stack traces and the page path, and can incidentally contain data present at the moment of the error.

When you sign up for news and updates

If you tick the optional box at signup, we use your email address to send product news and updates. Basis: Art. 6(1)(a) consent. You can withdraw it from the unsubscribe link in any message or at privacy@ai-coustics.com, without affecting anything sent before you withdrew.

We do not send marketing by SMS.

What we do not collect

We do not process special categories of personal data under Art. 9. We do not sell personal data. We do not use automated decision-making or profiling that produces legal or similarly significant effects.

Some fields are free text and reach us as you type them: API key names, and the SDK metadata your integration reports. Do not put personal data in them.

Who we share it with

We use the sub-processors below. Each is bound by a data processing agreement. Transfers outside the EEA are covered by the European Commission's Standard Contractual Clauses.

Sub-processor

What for

Data

Location

Amazon Web Services

Hosting, database, queues

All backend data

Frankfurt, Germany (eu-central-1)

Usercentrics

Consent management

Consent choices, IP address, user agent

Germany

Cloudflare

CDN, DDoS and bot protection

Request metadata, IP

Global edge

Clerk

Authentication and user directory

Email, name, sign-in metadata

United States (SCCs)

Stripe

Payments and invoicing

Billing name, email, address, card metadata

United States and Ireland (SCCs)

Metronome

Usage metering and invoicing

Account identifiers, usage records

United States (SCCs)

PostHog

Product analytics, error tracking, session replay, usage reporting

Pseudonymous and account-linked usage, account and billing records

EU Cloud, Frankfurt

HubSpot

Customer relationship management

Contact and onboarding details

EU data region

Soniox

Speech-to-text in the playground

Playground audio, transcripts

United States (SCCs)

Modal

Compute for the call analysis demo

Uploaded call audio, in transit only

United States (SCCs)

Mintlify

Documentation hosting and docs assistant

Site usage, assistant questions

United States (SCCs)

Framer

Marketing website hosting

Site usage

United States (SCCs)

Vimeo

Embedded video

Playback requests, IP address

United States (SCCs)

YouTube

Embedded video

Playback requests, IP address

United States, loaded by your browser only after you consent

We publish changes to this list on our sub-processor page. Customers with a data processing agreement are notified before a new sub-processor starts processing, and can object.

The two video services are different in kind from the rest. We do not send them anything: when a page contains an embedded player, your browser contacts them directly, which is enough for them to see your IP address. They load only after you consent.

Our sites also load fonts and script libraries from public content delivery networks. Those providers do not process anything on our behalf, so they are not listed above, but your browser does contact them and they can see your IP address. Every one of them is named in our cookie policy, with what it stores and for how long.

Beyond these, we disclose personal data only to employees and contractors who need it and are bound to confidentiality, and where a court order, subpoena or other legal obligation requires it.

Where your data is stored

Our own infrastructure runs in AWS eu-central-1 in Frankfurt, Germany. Application logs and metrics stay within that environment.

Personal data reaches the United States through the sub-processors marked above. Those transfers rely on the European Commission's Standard Contractual Clauses, with transfer impact assessments on file. You can request a copy of the clauses at privacy@ai-coustics.com.

How long we keep it

Data

Retention

Account record

For the life of the account, then 30 days

Usage and session records

10 years

Invoices and payment records

10 years, German statutory retention

API key references

Hashed reference only, never the key. Kept for 10 years so usage and invoices stay traceable.

Server and application logs

90 days

Product analytics

24 months

Error reports

90 days

Session replays

30 days

CRM contact records

36 months after the relationship ends, or 24 months after last engagement if you never became a customer

Playground audio

Not retained

Call analysis demo audio

Not retained

Marketing attribution

30 days

Backups

Up to 35 days

Delete your account and we delete the personal data associated with it, except where we are legally required to keep it - invoices being the main case, and the usage records the invoices are built from. Deletion propagates to our sub-processors. Backups age out on their own schedule, which can leave a copy for up to 35 days.

Cookies and consent

We use Usercentrics as our consent management platform. Nothing that is not strictly necessary is set until you have agreed to it, and you can change or withdraw that agreement at any time from our cookie policy, which carries the Privacy Settings control.

Withdrawing consent is as easy as giving it, and it does not affect anything processed before you withdrew.

We use four categories. Essential storage makes the site work at all - signing you in, keeping your session, remembering your consent choice - and needs no consent. Functional storage supports features you asked for, like embedded video and content delivery. Analytics storage tells us which pages get used and where the product breaks. Marketing storage links your visit to your record in our customer system, so we can tell which of our own content brought you here. We run no advertising cookies and no cross-site advertising trackers.

Every cookie and storage item we set, with its purpose and duration, is listed on our cookie policy. That page is generated from our consent management platform, so it is always current.

Your rights

Under the GDPR you have the right to access your personal data (Art. 15), to have inaccurate data corrected (Art. 16), to have your data erased (Art. 17), to restrict processing (Art. 18), to data portability (Art. 20), and to object to processing based on our legitimate interests (Art. 21), including profiling and direct marketing.

Where processing rests on consent, you can withdraw it at any time from the Privacy Settings control on our cookie policy, or at privacy@ai-coustics.com (Art. 7(3)). Withdrawal does not affect processing carried out before you withdrew.

Exercise any of these at privacy@ai-coustics.com. We respond within one month. We may need to verify your identity first, and will ask for no more than we need to do that.

You also have the right to complain to a supervisory authority (Art. 77). Ours is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin.

Security and breaches

We apply technical and organizational measures appropriate to the risk, including encryption in transit and at rest, least-privilege access control and audit logging. Credentials and tokens are redacted from application logs.

If a breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it (Art. 33), and we notify you without undue delay where the risk to you is high (Art. 34).

Children

Our services are not intended for anyone under 16, and we do not knowingly collect their personal data. If we learn that we have, we delete it. If you believe a child has given us personal data, tell us at privacy@ai-coustics.com.

Third-party links

Our sites link to other sites. A link is not an endorsement of their privacy practices. Read their notices before giving them anything.

Business transfers

If ai-coustics is acquired in whole or in part, or enters insolvency, personal data may transfer as a business asset. An acquirer would remain bound by this notice until it gives you notice of a change.

Changes

We update this notice as the product changes. The version number and effective date at the top change with it. Material changes are announced by email to account holders at least 30 days before taking effect. Where a change moves a purpose onto consent as its basis, we ask for that consent before the change applies to you.

Contact

ai-coustics GmbH Rosenthaler Str. 38/4 10178 Berlin, Germany privacy@ai-coustics.com

Final logo

Bring real-time audio intelligence into your voice AI stack

Bring real-time audio intelligence into your voice AI stack

Bring real-time audio intelligence into your voice AI stack