Privacy Policy
- Effective
- Effective August 31, 2026
- Last updated
- Last updated September 19, 2026
This policy explains how SoriGamis handles information across its mobile app, website, support channels, and connected services, including biometric information, the voices of people in recordings, and location information you choose to attach to a recording.
This summary is provided for convenience. The complete policy controls. See below.
Who we are and what this policy covers
BEH Labs LLC provides SoriGamis and is responsible for the personal information described in this Privacy Policy.
This policy covers the SoriGamis mobile application, the SoriGamis website, customer support and contact communications, and related services that link to this policy. It describes information about account holders, website visitors, people who contact us, and people whose voices or information are included in content submitted to SoriGamis.
Information we collect
The information we handle may include:
- Account and profile information, such as a name, email address, authentication identifiers, preferences, and workspace details.
- Recordings and customer content, including audio, speech, transcripts, speaker labels and the voice characteristics analyzed to produce them, summaries, action items, decisions, notes, and other output generated from submitted content. The Biometric information section describes how voice-derived data is limited, retained, and destroyed.
- Product and technical information, such as app activity, device and operating-system details, timestamps, logs, diagnostics, crash information, and information needed to secure and operate the service.
- Location information, including approximate or precise location from your device, when you choose to tag a recording or work record with a location. This is collected only if you enable location for that feature and grant the device permission it requires; it is not collected otherwise.
- Subscription and transaction information, such as product, entitlement, renewal, and purchase-status details. Payment stores and payment providers handle full payment credentials under their own terms.
- Communications, including support requests, feedback, contact-form entries, and launch-notification requests.
- Connected-service information, including authorization details, file metadata, and files or work records you choose to transfer to or from a connected storage service.
- Website preference and analytics information described below when you choose to allow optional analytics.
Where information comes from
We receive information:
- directly from you when you create an account, record or upload content, connect storage, make a request, or contact us;
- automatically from the app, website, device, and browser when you use SoriGamis;
- from app stores, subscription services, authentication providers, and connected services involved in a feature you choose; and
- from another SoriGamis user when that user records, uploads, or shares content that includes information about you.
How we use information
We use information to:
- provide, maintain, and personalize SoriGamis;
- measure how the service performs in aggregate — counts, durations, error rates, and latency — to maintain and improve it, without using recordings, transcripts, prompts, or generated records for that purpose;
- transcribe recordings and generate summaries, action items, decisions, and other requested work records;
- tag a recording or work record with a location, only when you choose to enable that feature;
- authenticate users, synchronize data, connect user-selected storage, and manage subscriptions and entitlements;
- respond to support, feedback, privacy, and contact requests;
- send you product news, tips, and offers about SoriGamis, where the law allows or you have asked for them — these come from us, not from anyone who wants to market to you separately, and every such message carries an unsubscribe link. Declining them does not affect the service, and we still send the operational messages an account needs, such as sign-in codes and billing notices;
- protect the service, users, and others; prevent fraud and abuse; debug problems; and enforce our terms;
- meet legal obligations and resolve disputes; and
- measure website use and performance only when the visitor has consented to optional analytics.
Service providers and connected services
We use providers to perform specific functions for SoriGamis. Their access is limited to information involved in those functions:
- Anthropic provides language-model processing used to generate structured outputs from transcripts and other submitted customer content.
- Deepgram provides speech-to-text processing for recording audio.
- Supabase provides backend database, data-storage, and authentication infrastructure.
- Fly.io provides application hosting and processing infrastructure.
- RevenueCat provides subscription and entitlement management.
- Resend delivers contact and launch-notification emails.
- Vercel hosts the public website and, with consent, provides website analytics and performance measurement.
- Google Drive, Microsoft OneDrive, and Dropbox receive or provide files and work records when you choose to connect and use one of those services.
Connected-storage providers process data under the user's relationship with them, including their own terms and privacy practices. You control whether to connect a supported storage service and which available files or records to transfer.
Vercel Analytics and Speed Insights load only after you consent to optional website analytics. The website analytics integration does not send recording or transcript content to Vercel. You can change the analytics choice through the Analytics control in the website footer.
AI processing: speech-to-text and language-model providers
Two categories of provider do the AI work: a speech-to-text provider, which turns recording audio into transcripts and speaker labels, and a language-model provider, which turns transcript content into the summaries, action items, and other records you ask for. The providers filling those roles today are named below. If we change or add one, we will update this policy.
SoriGamis sends recording audio to Deepgram's commercial speech-to-text API to produce transcripts and speaker labels. That audio is processed to return the results for your recording, and BEH Labs LLC does not authorize Deepgram to use recording audio or transcripts to train Deepgram's models.
Deepgram's handling and retention of submitted audio are governed by its commercial terms. Its retention is its practice and is not a separate deletion guarantee by BEH Labs LLC.
SoriGamis sends relevant transcript or other customer content to Anthropic's commercial API to produce requested language-model output. That processing is governed by Anthropic's commercial terms and data-processing terms, not Anthropic's consumer Privacy Policy.
Anthropic states that it does not use commercial customer content to train its models.
BEH Labs LLC does not authorize any provider named above to use customer content to train its models, and does not use customer content to train models of its own.
Anthropic generally deletes standard API inputs and outputs from its backend within 30 days, but Anthropic may retain information longer for safety enforcement, legal compliance, or services with different retention behavior.
Anthropic's retention is its published practice and is not a separate deletion guarantee by BEH Labs LLC.
Connecting SoriGamis to an AI app
You can connect SoriGamis to an AI app you already use, such as Claude, so that it can read the recordings in your account and answer questions about them. This is off unless you turn it on, and it is the only way content in your account reaches a service we do not operate without you sending it there yourself.
What the AI app receives. Only what it asks for, and only from your own account: transcripts and who said what, summaries and action items produced for your recordings, the dates and titles of recordings, the names you have given speakers, and a link to the audio in your own cloud storage. Requests are answered one at a time, as the AI app makes them; nothing is exported in bulk and nothing is sent on a schedule.
What it never receives. Audio. The connector hands the AI app a link into your own cloud folder, which opens with your credentials rather than ours, so no recording is transferred through the connection. The connector is also read-only: an AI app cannot change, delete or export anything in your account through it, and cannot reach another person's account through it.
Who then holds it. Once your AI app receives an answer, that content is in that app, under its provider's privacy policy and retention rules, not this one. We do not control how long it is kept there, whether it is used to train a model, or who else in your organisation can see that conversation. Read your AI provider's policy before connecting, particularly if your recordings include other people.
What we keep. We record that a connection was authorised, and we log that a request was made, which tool it called and how long it took. We do not log transcript or summary content in those records.
Turning it off. Revoke the connection in the AI app at any time and it stops answering immediately. Revoking does not delete anything in your SoriGamis account, and it does not reach back into content the AI app has already received.
Other people in your recordings. Connecting an AI app means the voices and words of people in your recordings can be read by that app when you ask it to. The People included in recordings section applies to that disclosure as it does to any other, and the responsibility for having authority to record, and to share what was recorded, remains yours.
International processing
BEH Labs LLC and the providers described in this policy may process information in the United States and other countries where they operate. Those locations may have privacy laws that differ from the laws where you live. Where applicable law requires a transfer safeguard, we use a legally recognized mechanism or rely on another permitted basis for the transfer.
Retention and deletion
We retain information for as long as reasonably needed to provide the service, maintain accounts and requested records, meet legal and financial obligations, protect the service, and resolve disputes. Retention depends on the type of information, how it is used, and applicable operational or legal requirements.
A verified account-deletion request starts deletion from active SoriGamis systems and applicable processors as operationally feasible.
An account closed for another reason, including suspension or termination by BEH Labs LLC, is deleted on the same basis.
Some information may remain in backups or be retained for legal obligations, security, fraud prevention, abuse investigations, financial records, dispute resolution, or enforcement.
BEH Labs LLC does not promise that every deletion will be completed within a fixed number of days.
Biometric information is the exception: the Biometric information section of this policy publishes a fixed retention schedule and destruction guideline for voice-derived speaker-attribution data.
Content transferred to a connected service may remain with that service after deletion from SoriGamis. Manage that copy through the connected provider under your relationship with it.
Your privacy rights and choices
Depending on where you live and subject to applicable exceptions, you may have rights to request access to, correction of, deletion of, or a copy of certain personal information, or to object to or restrict certain processing. Contact us at [email protected] to make a request. We may need to verify your identity and authority before acting.
You can manage app permissions in your device settings, disconnect a connected storage service through the available product or provider controls, and change optional website analytics through the Analytics control in the website footer. These choices may affect features that depend on the information or permission.
United States state privacy rights
This section is a notice for residents of California and other U.S. states with comprehensive privacy laws. The categories of personal information we collect are listed in "Information we collect," the purposes in "How we use information," and the recipients in "Service providers and connected services" and "How information is disclosed."
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined in the California Consumer Privacy Act. We do not process personal information for targeted advertising or sell it within the meaning of other state privacy laws. We do not use or disclose sensitive personal information — including recording audio, biometric information, and precise geolocation — for purposes other than providing the features you request and the other purposes those laws permit.
Because nothing is sold or shared, a Global Privacy Control signal has no sale or sharing to stop, and optional website analytics runs only after you opt in through the Analytics control in the website footer — a visitor who does not opt in is never measured.
Product and marketing email is first-party: we send it ourselves through our email provider, and that is neither a sale nor cross-context behavioral advertising. Recording audio, transcripts, and the records generated from them are never used to market to you, and are never disclosed to anyone for their own marketing.
If we ever decide to disclose personal information for a third party's own marketing, or to add advertising or attribution software to the apps, we will update this policy and publish a working Do Not Sell or Share My Personal Information control, honor Global Privacy Control signals, and obtain any consent the law requires — before that disclosure begins, not after. Recording content stays outside any such arrangement.
Depending on your state, you may have the right to know, access, correct, delete, or obtain a portable copy of your personal information, and the right not to receive discriminatory treatment for exercising a privacy right. Submit a request to [email protected]. An authorized agent may submit a request on your behalf with proof of authorization. If we decline a request, you may appeal by replying to our decision, and we will tell you the outcome; where your state provides it, you may then contact your state attorney general.
People included in recordings
Microphone permission from a device is not the same as permission from the people being recorded.
A voice can identify the person it belongs to. SoriGamis analyzes voice characteristics to attribute speech to speakers, and the Biometric information section explains the limits, retention schedule, and destruction that apply to that data.
A recording may contain personal information about people who do not have a SoriGamis account.
The user who records, uploads, or shares content is responsible for having the authority and providing any notice or obtaining any consent required by applicable recording, privacy, workplace, biometric, or other laws. That includes asking every participant for permission before the recording begins and obtaining written consent where a recording or biometric law requires it. If you believe SoriGamis holds information about you in another user's content, contact us. We may need information that lets us identify the relevant account or record and may need to consider the rights of the account holder and others.
Biometric information
Unlocking the app with a fingerprint or face
SoriGamis can be set to require your device's biometric authentication — such as a fingerprint or face scan — before the app opens. That check is performed by your device's operating system, which tells the app only whether it succeeded. BEH Labs LLC does not receive, collect, or store the fingerprint, face geometry, or other biometric data used to unlock your device or the app.
Voices in recordings
To label who said what, SoriGamis analyzes voice characteristics in a recording to tell speakers apart and attribute speech to them. A voice can identify the person it belongs to, and some laws treat data derived from a voice as a biometric identifier. This section applies wherever such a law does.
Speaker-attribution data is created and used only to organize the recording it comes from. We do not use it to identify people across recordings, do not enroll it in a voice database, do not use it to train models, and do not sell it. We do not disclose it except to the processors named in this policy as needed to perform speaker attribution, except where law or legal process requires disclosure, and except in a transaction described in "How information is disclosed," in which case it remains subject to this section.
Permission from the people recorded
Because a voice can identify a person, the user who records must ask for and obtain each participant's permission before recording them, and where a biometric or recording law requires written notice or a written release, must obtain it in that form before the recording begins. The Terms of Service make this a condition of using SoriGamis.
Retention schedule and destruction
Speaker-attribution data is stored only as part of the recording and work record it describes. We destroy it at the earliest of: deletion of the recording or work record it belongs to; completion of a verified deletion request or withdrawal of the consent it rests on; satisfaction of the purpose of maintaining speaker attribution in that recording's work record; three years after your last interaction with SoriGamis; or one year after the account holding the recording is closed.
Destruction removes the data from active systems, after which copies may persist in backups for a limited period until those backups are rotated. Anything retained beyond this schedule because it is needed to establish, exercise, or defend a legal claim is isolated and used only for that purpose. This fixed schedule and these destruction exceptions apply to biometric information in place of the general retention terms of this policy, which do not promise fixed deletion windows for other information.
Age requirements
You must be at least 13 years old to create or use a SoriGamis account. Where the law where you live sets a higher minimum age for consenting to the processing of your personal information — up to 16 in parts of the European Economic Area — that higher age applies to you.
If the law where you live does not allow you to agree to an online service on your own, a parent or legal guardian must authorize your use.
SoriGamis does not permit accounts for children under 13.
A parent or legal guardian who believes a child under 13 has created an account should contact us so we can investigate and take appropriate action.
Security
We use administrative, technical, and organizational measures designed to protect information based on its nature and the risks of processing it. No storage or transmission method is completely secure, so we cannot guarantee absolute security. Protect your account credentials and contact us if you believe your account or information has been compromised.
Changes and contact
We may update this policy as SoriGamis, our providers, or applicable requirements change. We will post the updated policy and revise the updated date. If a change is material, we may provide additional notice when appropriate.
For questions or requests about this policy or SoriGamis privacy, contact BEH Labs LLC at [email protected].
Questions about this policy?
Contact BEH Labs LLC at [email protected]. We may need to verify your identity before acting on a privacy or account request.