Privacy Policy

Last updated: 22 August 2026

1. Who We Are

Just Summit Ltd (company number 15449136) is responsible for the personal data described in this policy. This policy covers the Summit mobile app, the Just Summit website, support, product updates, and Just Summit Headphones presales. Contact us at hello@justsummit.co.

2. Information We Collect

  • Account details, such as your email address, authentication identifier, name, profile image, session information, and preferences.
  • Audio you choose to record or import, plus recording titles, timestamps, duration, file size, processing state, folders, and other recording metadata.
  • User-owned results such as transcripts, summaries, highlights, Actions, speaker labels, Daily Memories, Ask Summit questions and answers, edits, and exports.
  • Subscription product, entitlement, trial, renewal, expiry, restore, quota, and usage information. Apple handles your payment details; we do not receive or store complete card details for App Store purchases.
  • App usage events and diagnostics, such as app version, device platform, feature state, error codes, performance, and crash information. Our analytics controls are designed not to send audio, transcript text, summaries, Actions, questions, answers, names, or email addresses as event properties.
  • Website contact, Founding List, presale, billing-status, analytics, device, and support information that you provide or that is generated when you use the website.

3. Local Recording and Optional Cloud Processing

Summit saves a completed recording locally before deciding whether any processing or upload is allowed. Recording does not itself authorise a cloud upload. Free accounts are local-only for automatic recording processing. Trial and paid users can choose a remembered processing preference, and cloud processing occurs only when that preference, server-verified entitlement, quota, and network state allow it.

Local audio and locally generated data remain on your device unless you choose an authorised sync, processing, sharing, export, backup, or deletion action. Device storage, operating-system backups, and anything you export or share are also subject to the controls and policies of your device and chosen destination.

4. How We Use Information

  • To create, authenticate, secure, and support your Summit account.
  • To capture, save, process, synchronise, recover, display, search, export, share, and delete the recordings and results you request.
  • To verify subscriptions and trials, enforce plan features and quotas, restore purchases, prevent fraud, and provide billing support.
  • To provide support, diagnose failures, maintain security, understand product reliability, and improve Summit.
  • To manage website enquiries, presales, product updates, tax, accounting, legal, and fraud-prevention obligations.

5. Service Providers

Depending on the feature you use, we may use:

  • Supabase for account authentication, database records, cloud storage, and server functions.
  • AssemblyAI for authorised cloud transcription and language-model processing of recordings, transcripts, or prompts.
  • Apple and RevenueCat for App Store purchases, subscription entitlement verification, trials, restores, and billing lifecycle events.
  • PostHog for product analytics and Sentry for diagnostics and crash reporting.
  • Google or Apple when you choose their sign-in service.
  • Vercel, Stripe, and email or customer-support providers for the website, presales, payment processing, messages, and product updates.

These providers process data for the service they supply and must protect it consistently with their contracts and applicable law. We do not sell your recordings, transcripts, personal information, or Google sign-in data, and we do not use them for third-party advertising.

6. Authentication

If you use Google or Apple sign-in, we receive the account information needed to authenticate you. We do not receive your Google or Apple password. Google sign-in does not request access to Gmail, Google Drive, Google Calendar, or other Google content. Summit's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

7. Retention and Deletion

  • Local recordings remain on your device until you delete them, delete the app or app data, or your device or backup settings remove them.
  • Cloud audio is retained while authorised and within the applicable plan's storage allowance. After trial or paid access expires, cloud audio has a 30-day exit period before scheduled deletion. Resubscribing during that period cancels the scheduled expiry deletion.
  • Previously generated transcripts, summaries, highlights, Actions, and other user-owned results remain readable after cancellation, downgrade, expiry, or cloud-audio deletion until you delete the recording or account.
  • Provider-side transcription artifacts and Summit cloud objects are included in the recording and account deletion lifecycle, subject to technical recovery and legal requirements.
  • Subscription, security, fraud-prevention, tax, support, and business records may be retained where reasonably necessary or legally required.

You can initiate full account and associated-data deletion in the Summit app under Settings → Account → Delete Account & Data. You can also email hello@justsummit.co. Deleting a Summit account does not itself cancel an Apple subscription; subscription management remains available in your Apple ID settings.

8. Lawful Bases and Your Choices

We process information as needed to provide the service or fulfil a purchase contract, with your consent where required, for our legitimate interests in operating, securing, supporting, and improving Summit, and to meet legal obligations. You are not required to provide optional analytics, marketing, cloud processing, or microphone access, but declining a permission may make the related feature unavailable.

You can change processing preferences in the app, stop future recordings, revoke operating-system permissions, unsubscribe from marketing email, delete individual content, or delete your account. Withdrawing consent does not affect processing that was lawful before withdrawal.

9. International Transfers

Some service providers may process information outside the United Kingdom. Where data-protection law requires it, we use an applicable adequacy decision or approved contractual and organisational safeguards. Contact us if you want more information about the safeguards relevant to your data.

10. Your Rights

Depending on your location and the applicable lawful basis, you may have rights to access, correct, erase, restrict, object to, or receive a portable copy of your personal data. You may also withdraw consent where processing relies on consent. Email hello@justsummit.co to make a request.

If you are in the UK, you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint. We would appreciate the opportunity to address your concern first.

11. Security and Automated Results

We use access controls, tenant isolation, encryption in transit, secret management, server-side entitlement checks, and deletion fencing intended to protect Summit data. No system is completely secure. Automated transcripts, summaries, speaker labels, Actions, and answers can be incomplete or wrong and should be reviewed by you. Summit does not use them to make solely automated decisions with legal or similarly significant effects about you.

12. Recording Responsibility and Children

You are responsible for having the permission or other lawful basis required to record, upload, process, or share audio involving other people. Summit is not directed to children under 13, and we do not knowingly collect personal data from them.

13. Changes and Contact

We may update this policy when Summit's features, providers, or legal obligations change. We will update the date above and provide additional notice where required. Questions, privacy requests, and deletion requests can be sent to hello@justsummit.co.