Privacy Policy
Effective 26 July 2026
Canto is a voice recording and AI transcription app for iOS, Android, and the web. You record conversations; we transcribe them, and offer AI features like summaries, chat, and search over what you recorded. This policy explains, in plain language, what data Canto collects, what happens to it, and the choices you have.
Who we are
Canto is operated by Tessa Labs d.o.o., Kolodvorska 12b, 71000 Sarajevo, Bosnia and Herzegovina. For the personal data described in this policy, Tessa Labs d.o.o. is the data controller — we decide what is collected and why.
For anything to do with your data, including the rights set out below, write to hello@tessa.ba.
When you use Canto as a member of an organization, that organization decides who may see the recordings shared with it; we handle that data on the terms agreed with them.
What we collect
Account information. When you sign in with Apple, Google, or Microsoft we receive your email address and name (Apple lets you hide your real email behind a relay address). We use this to identify your account and to match folder or organization invitations sent to your email.
Calendar data (optional). If you connect a Google Calendar or Microsoft 365 calendar, we read your upcoming events to show them in the app — see "Calendar data" below for exactly what that involves.
Your content. The audio recordings you make or import, the transcripts produced from them, and anything you add on top: titles, notes, tags, speaker names, AI-generated summaries and documents, and your chat messages with the AI.
Meeting records (optional). If you turn on the meeting notetaker, we store the upcoming meetings it is scheduled to join and the status of each of those sessions — see "Meeting notetaker" below.
Sharing metadata. If you use folders or organizations, we store who is a member of what, invitations by email address, and which recordings live in which folders.
Usage metrics. Counts of feature usage (for example transcription minutes and AI token usage) to enforce plan quotas, plus product analytics events such as "recording started" or "chat sent" so we can understand which features matter. Analytics are tied to your account id, not to advertising identifiers.
Cookies and consent. On the web we ask before storing anything for analytics. Until you choose, no analytics cookie or browser storage is written and no events are sent. If you decline, we still count the visit through a privacy-preserving server-side hash that cannot be traced back to you, and nothing is stored on your device. You can change the choice at any time under Settings → Preferences → Cookies & analytics.
Session replay. With your consent we record anonymised playback of web sessions to find broken flows. All text and all form input is masked before it leaves your browser, and the areas that show transcripts, notes, and chat are excluded from capture entirely — the replay shows layout and interaction, never your content.
Device and crash data. Crash reports and error diagnostics (device model, OS version, stack traces) so we can fix bugs.
We do not collect your precise location, your contacts, or your browsing history outside Canto. Like any internet service we receive your IP address, from which our analytics and crash-reporting providers derive an approximate region.
How your audio is processed
Recordings are uploaded to Firebase Storage (Google Cloud, hosted in the europe-central2 region in Poland). A server function sends the audio to a specialist speech-to-text provider, which produces the transcript; we keep the provider's raw transcript output alongside your recording so features can be re-run without re-transcribing. AI features — automatic titles, summaries, chat, semantic search, and document templates — are powered by the Google Gemini API. To make search work, transcript passages are converted into numerical embeddings and stored alongside your data in Firestore.
These providers process your content to deliver the service to you. Canto does not use your recordings or transcripts to train AI models, and we never sell them or license them to anyone. Where a provider’s standard terms would let it train on customer content, we are moving onto plans that turn that off; we will tell you the current position for any individual provider on request.
Service providers we rely on
Canto is built on a small set of sub-processors:
- Google Cloud / Firebase — hosting, storage, database, authentication, and push notifications (europe-central2).
- A speech-to-text provider — automated transcription of your audio.
- Google Gemini API — AI summaries, chat, search, and templates.
- A meeting-bot provider (EU region) — joins and records meetings when you use the notetaker.
- PostHog (EU-hosted) — product analytics, session replay, and error reporting.
- Google Crashlytics — crash reporting on the mobile apps.
- Langfuse (EU-hosted) — tracing of AI requests to debug quality issues; traces may include the prompts and responses of your AI interactions.
We will name the specific providers behind these categories on request — email hello@tessa.ba — and we notify customers before we add or replace one.
Where your data is processed
Your recordings, transcripts, and database records live in the EU: audio and server functions in Google Cloud's europe-central2 (Warsaw) region, the database in Google's EU multi-region. Analytics and AI tracing are EU-hosted, and the meeting bot runs in an EU region.
Some processing still happens outside the EEA: the Gemini API is not region-pinned, and authentication and crash reporting run on Google's global infrastructure. Those transfers rely on the European Commission's Standard Contractual Clauses in our providers' terms.
Meeting notetaker
The notetaker is off until you turn it on. When enabled, Canto checks your connected calendars on a schedule for upcoming Microsoft Teams, Google Meet, and Zoom meetings and stores a record of each meeting it may join — the event details (title, time, description, attendees, join link), whether it is set to join, and the resulting session status. A bot then joins the meeting under the name you choose, appears in the participant list, and is admitted by the organizer. It records the meeting audio, which enters the same pipeline as any other recording.
You are responsible for telling participants they are being recorded and for having whatever consent the law where you are requires. See our Terms of Service.
Shared meetings. If more than one Canto user is in the same meeting, a single bot joins instead of one each. The recording, transcript, and notes are then copied into each of those users' accounts, where each copy belongs to that user and stays under their control — including after you delete yours.
You can turn the notetaker off entirely, or stop it for an individual meeting, in Settings → Meeting notetaker.
Calendar data
Connecting a calendar is optional. If you do, Canto requests read-only access to your events (Google Calendar via the calendar.events.readonly scope; Microsoft 365 / Teams via Calendars.Read). We use it to show your day's meetings in the app so you can start a note for one, and — if you enable the notetaker — to know which meetings a bot should join.
We do not keep a mirror of your calendar. Events are fetched live when you open the app and displayed. We store event details in only two cases: when you explicitly start a note from a meeting, a snapshot of that single event (title, time, attendees, description, and meeting link) becomes part of that note and helps the AI name and summarize it; and, if the notetaker is enabled, the upcoming meetings it is scheduled to join, as described above. The connection tokens themselves are stored encrypted. We never write to, modify, or delete anything in your calendar, and calendar data is never used for advertising or sold.
You can disconnect a calendar at any time in Settings → Calendars, which deletes the stored tokens, or revoke Canto's access from your Google or Microsoft account settings.
Canto's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
People you record
Recordings and meeting invites contain other people's personal data — their voices, what they said, their names and email addresses. When you record, you decide why and you are responsible for the legal basis and for telling those people; Canto processes that content on your instructions, to run the service for you.
If someone you recorded asks about their data, ask them to contact you first, since we cannot identify whose voice is in whose recording. Contact us and we will help you respond.
Sharing inside Canto
Sharing is always something you do deliberately. When you place a recording in a shared folder, every member of that folder — including all current and future members of an organization attached to it — can listen to it, read its transcript, use AI features on it, and edit certain fields (title, notes, tags, speaker names, summary, and transcript corrections). Deleting the recording and choosing which folders it lives in stay under your control as the owner.
Nothing in Canto is ever public. There are no public links, and people outside your folders and organizations cannot see your content.
Cookies and local storage
The web app stores data on your device to work: your signed-in session, your language and display preferences, and a cookie and local-storage entry set by our analytics provider to recognize returning visits. We use no advertising or cross-site tracking cookies. Clearing your browser storage removes them, at the cost of signing you out.
Security
Your data is encrypted in transit (TLS) and at rest by our cloud provider. Access to recordings is enforced server-side by database and storage rules, and shared audio is served through short-lived signed links rather than public URLs. Calendar refresh tokens are additionally encrypted with a key we hold separately.
A small number of our staff can access production data where necessary to operate and support the service, including signing into an account to diagnose a problem; such access is logged. If a breach affects your personal data, we will notify you and the relevant supervisory authority without undue delay.
No ads, no selling data
Canto shows no advertising, and we do not sell or rent your personal data to anyone. We share data only with the service providers listed above, and only to run the app.
Retention and deletion
Your data is kept for as long as your account exists, so your library is there when you come back. Deleting a recording removes its audio, transcript, raw provider output, and derived AI data.
You can delete your entire account in the app (Settings → Delete account). This permanently wipes your recordings, transcripts, notes, AI artifacts, chats, sharing memberships, and account record. Folders you own are deleted; recordings other people contributed to your folders remain theirs, as do copies of shared meetings already delivered to their accounts. Any backup copies age out on a rolling basis and are never restored to undo a deletion. We keep the minimum records we are legally required to keep, and internal logs that contain no recording content for a short period.
Your rights
You can access, correct, export, or erase your data. Much of this is available directly in the app (edit anything, export transcripts and audio, delete your account). For anything else — including a full data export, objecting to a form of processing, or questions about this policy — email hello@tessa.ba and we will respond within 30 days. If you are in the EU/EEA you also have the right to lodge a complaint with your local data protection authority.
Children
Canto is not directed at children. You must be at least 13, or older where your country sets a higher age of digital consent, to use it, and we do not knowingly collect data from anyone younger. If you believe a child has created an account, contact us and we will delete it.
Changes to this policy
If we change this policy in a meaningful way, we will update this page, change the effective date at the top, and — for significant changes — notify you in the app.