Who we are
Security and compliance
People record lectures, meetings and private notes in Recallify, so how we look after that data matters more than most things we build. This page sets out what we hold, where it lives, who processes it and what we can show for it.
TinieAI Ltd, registered in England and Wales, is the data controller. Our Data Protection Lead is Dr M. Berkan Sesen; write to info@recallify.ai for his attention.
How data is handled
Six things that are true of every account, on iPhone, Android and the web.
-
Encrypted in transit and at rest
Data is encrypted between the device and our servers, and in our cloud storage. Access to production systems is restricted to the people who need it to run the service.
-
Stored in the UK and the EU
Account data and content are stored in the United Kingdom and the European Union. Where a processing task runs elsewhere, it is covered by the safeguards UK GDPR requires and a transfer impact assessment.
-
Recordings are not kept
The original audio or video file is deleted as soon as it has been transcribed. The transcript stays alongside the summary, tasks and quizzes made from it, so a person can check and correct them.
-
AI providers do not train on your content
Transcription and summarisation run at specialist providers acting as our processors, under enterprise terms. They keep content only for as long as the task takes and never use it to train their models.
-
Deleted when you say so
Anyone can delete a note, a recording or their whole account inside the app. What is deleted is gone from our systems within 30 days.
-
Notes belong to the person
Each person has their own account. An institution or employer that funds a licence does not see the recordings, notes or tasks in it; usage data we collect describes events in the app, not what was said.
Who processes the data
Recallify uses AI for four bounded jobs: transcription, summarisation, extracting tasks and reminders, and active-recall quizzes. It is not a chatbot, it does not browse the internet or act on a person's behalf, and it makes no automated decisions about anyone. The processors, by category, are:
- Cloud infrastructure: hosts and stores account data and content.
- Automated speech recognition: transcribes recordings.
- Large language model provider: generates summaries, tasks and quizzes.
- Analytics: aggregated usage events only; never the content of a recording or note.
- Email and support: support correspondence.
- Apple and Google: payment and sign-in, under their own policies. We never hold card details.
No processor may use the data for its own purposes, for marketing or for model training. We do not sell personal data or share it with advertising networks.
How long we keep it
| Information | Kept for |
|---|---|
| Original recordings | Deleted once transcribed |
| Account details and content | While the account is active, then deleted within 30 days |
| Support correspondence | Up to two years after the case closes |
| Subscription records | Up to seven years, as HMRC requires |
| Anonymised analytics | Ongoing; no longer personal data |
Under UK GDPR anyone can ask for access, correction, erasure, restriction, portability or objection, and we answer within one calendar month. Most of it can be done directly in the app.
What we can show for it
- UK GDPR. TinieAI Ltd is the controller; lawful bases, special category handling and international transfers are set out in the privacy policy.
- ICO registration. Registered with the Information Commissioner's Office as a data controller, entry ZB860514.
- Cyber Essentials. Certified; the certificate is on the IASME register. Automated security scanning runs on every change to our code, and a breach likely to put people's rights at risk is reported to the ICO within 72 hours and to the people affected.
- Accessibility. The app and this site are tested against WCAG; the accessibility statement says how, and how to report a problem.
- Not a medical device. Recallify does not diagnose, treat or recommend treatment, and does not replace clinical care. It has not been through the NHS Digital Technology Assessment Criteria; that preparatory work sits within the NIHR feasibility study.
Recallify accounts are for people aged 18 and over. Research studies involving younger participants run separately from the product, with ethics approval and their own consent and data protection arrangements.
Questions we are asked
Does any content leave the UK?
Storage is in the UK and the EU. The AI transcription and summarisation steps run at specialist providers that may process content in the United States, under UK adequacy regulations, the UK extension to the EU-US Data Privacy Framework, or the International Data Transfer Agreement or Standard Contractual Clauses with the UK addendum, depending on the provider. Content sent for a task is deleted once the task is done, and we hold a transfer impact assessment for each transfer.
Is what people record treated as health data?
Often, yes. Many people who use Recallify have a cognitive or health condition, and what they record can include information UK GDPR treats as special category data. We do not solicit it; where content contains it, the lawful basis is the person's explicit consent, given when they add the content and withdrawn by deleting it. Where there is a risk of serious harm we can rely on vital interests, under our safeguarding and adverse event policy.
Who do we contact about a data protection matter?
Email info@recallify.ai, marked for the attention of the Data Protection Lead, M. Berkan Sesen, or write to TinieAI Ltd, 82a James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE. Anyone also has the right to complain to the ICO at ico.org.uk or on 0303 123 1113.
A question about your data?
Write to us and mark it for the Data Protection Lead. We reply to data requests within one calendar month, and usually much sooner.


