Privacy Policy
Last updated: 2 October 2026
This Privacy Policy explains how Weeve B.V. (“Weeve”, “we”, “us”) collects, uses, and protects your personal data when you use the Weeve macOS app (the “App”), the Weeve for Chrome browser extension (the “Extension”), and the website at https://getweeve.io (the “Site”).
We’ve written this in plain language because we believe you should actually understand it. If anything is unclear, email us at support@getweeve.io.
TL;DR
Weeve runs on your own device: the App on your Mac, the Extension inside your Chrome profile. Your audio recordings and transcripts stay there by default.
The models that do the work are downloaded to your device before you first use them: the Extension gets them from our own CDN, the App from Hugging Face. Your recordings are never sent away to be processed.
We use a small backend (Supabase) for account login, subscription status, and usage limits — that’s it.
We use Stripe to handle payments (we never see your card details).
We use PostHog to understand which features people use. These events describe what you did, never what you said, and they are linked to a one-way hash of your account ID rather than to your name or email.
On our website, we use Google Ads (conversion tracking and remarketing), the LinkedIn Insight Tag, and the Meta Pixel to measure how well our ads work. These only run if you accept marketing cookies in the banner.
If you name a speaker, the App saves a voiceprint so it can recognise that person again. Voiceprints are biometric data. They are encrypted on your Mac, never synced, and never sent to us.
We do not sell your data and we do not train AI models on your recordings.
1. Who we are
The data controller is:
Weeve B.V.
MediArena 2, 1114 BC Amsterdam-Duivendrecht, Netherlands
KVK: 42068756
Email: stefan@getweeve.io
2. What data we collect
2.1 Data you give us when you create an account
Email address — used to sign in (we use a one-time code sent to your inbox; we do not store passwords).
2.2 Data we generate when you use the App or the Extension
Authentication tokens — a short-lived access token plus a longer-lived refresh token that together keep you signed in. The App stores them in the macOS Keychain, marked so they stay on that Mac and are not synced to iCloud. The Extension stores them, together with the email address you signed in with, in Chrome’s extension storage inside your browser profile.
Subscription and billing metadata — your plan, trial start/end dates, subscription status, and a Stripe customer ID. We do not store your card number, CVC, or full card details. Stripe handles all of that.
Usage counters — the number of qualifying recordings and imports counted toward your account’s allowance, shared between the App and the Extension. The free allowance is 10 recordings in total and does not reset. Only recordings and imports of 5 minutes or longer count.
2.3 Data that stays on your device (we never see it)
In the App:
Audio recordings (microphone and system audio) you create.
Transcripts and AI-generated summaries.
Speaker labels from the on-device diarization service.
Notes, moments, templates, projects, and people you create in the App.
Voiceprints and speaker embeddings, if you name a speaker. These are biometric data and are covered separately in section 2.4.
App preferences (theme, hotkey, model choice, etc.).
By default these are stored in ~/Library/Application Support/Weeve/Users/<your-user-id>/. You can move that library somewhere else under Settings → Data & Storage → Where your data lives, in which case your content follows the folder you picked. Downloaded AI models, application logs, your preferences, and the encrypted biometric data described in section 2.4 stay in their own locations on the device and do not move with it. None of it is uploaded to our servers, and none of it is backed up by us.
The App keeps the source audio of a recording by default so you can play it back. You can turn that off with Keep recording audio under Settings → Data & Storage, after which new recordings are transcribed without their audio being written to disk. Turning it off does not delete audio you have already recorded.
The Extension requires you to sign in. Before starting a recording, you choose whether to include your microphone. When you start with the microphone switched off, Weeve does not request microphone access or record it. To capture audio from a browser tab, first invoke Weeve on that tab from the toolbar icon or keyboard shortcut. If microphone access is unavailable, Weeve can record tab audio alone when tab capture is available. The Extension stores the following content inside your Chrome profile:
Audio. This is written to the Origin Private File System, a private storage area Chrome gives the Extension inside your browser profile. It is scoped to the Extension, so websites and other extensions cannot read it.
Transcripts, to do’s, speaker labels, people, and recording details. These are stored in the Extension’s own IndexedDB databases in the same profile.
Model files. The speech, speaker, and language models are cached in the browser’s own storage for the Extension, so each one only has to download once.
Sign-in state and preferences. These are kept in Chrome’s extension storage.
Transcription, speaker identification, and the drafting of to do’s all run on your own machine, inside the browser. None of it is uploaded to our servers.
The Extension shows recordings and people for the Weeve account that is signed in. Signing out hides that library but keeps its local files for when the same account signs in again. If you also have the Weeve Mac app installed, signed in to the same account, and its bridge switched on, the Extension can hand that account’s recordings over to it. The hand-off uses Chrome native messaging, a direct connection to a helper program on the same computer. It does not travel over the internet. A connection to a different Weeve account is refused.
Weeve’s use of information received through Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
2.4 Voiceprints and speaker embeddings (App)
When you put a name to a speaker in a recording, the App saves a voiceprint for that person: a mathematical summary of how their voice sounds. It also saves a speaker embedding sidecar alongside the recording. With Automatic speaker recognition switched on, which is the default, the App compares the voices in a new recording against the voiceprints you have already saved so it can label those people for you.
Voiceprints and speaker embeddings are biometric data under Art. 9 GDPR, so we treat them more strictly than anything else in the App:
They are encrypted at rest with AES-GCM. The key is generated on your Mac, kept in the macOS Keychain, and marked so it can never leave that device.
They are stored outside your relocatable content library, so moving your library to a synced folder such as Dropbox or iCloud Drive cannot drag your biometric data into the cloud with it.
They are never uploaded to us, never synced, never shared, never logged, and never used to train anything.
They are scoped to your account on that device. Signing in as someone else does not give access to them.
You can turn automatic recognition off under Settings → Preferences, remove an individual person’s voice samples from that person in the People section, or delete all of them at once with Delete all data under Settings → Data & Storage → Manage local data.
2.5 Product analytics (PostHog)
The App sends product analytics events to PostHog (hosted in the EU) so we can see which features people actually use. Each event is sent on its own, as it happens. Examples of events:
App opened
Recording started (with the type: meeting, quick paste, uploaded file, or re-transcribe, and which button or shortcut you used)
Transcription generated
Meeting notes created (which model produced them)
A model finished downloading
A permission was granted or denied
Onboarding completed
An error occurred (a category and an error code, never a message)
Every event also carries your app version, build number, platform, and whether the build is development or production.
Events are linked to a single identifier: a SHA-256 hash of your Weeve account ID while you are signed in, and a random ID generated on your Mac while you are not. The hash is one-way, so your raw account ID never leaves your device. When you sign in for the first time on a device, the activity recorded against that random ID is joined to the hashed one. This makes the data pseudonymous rather than anonymous, which is why we give it a legal basis in section 4 rather than claiming the GDPR does not apply to it.
Events do not contain the contents of your recordings, transcripts, summaries, notes, prompts, speaker or person names, file names, or your email address. Where an event needs to describe a file we send its extension and rounded duration, never its name or contents.
The Extension reports to a separate PostHog project, “Weeve for Chrome”, also hosted in the EU. Its events are linked to a hashed identifier: a SHA-256 hash of your Weeve account ID while you are signed in, and a random ID generated on your machine while you are not. Because the project is separate, your Extension activity and your App activity are not combined into one profile. The Extension never sends recording titles, transcript text, speaker or person names, to do text, your email address, or the address of the tab you recorded. Its analytics client drops those properties before an event leaves your machine.
Turning it off in the App. The App does not yet have a switch for this. We are building one, and until it ships you can object at any time by emailing support@getweeve.io; we will switch analytics off for your account and confirm when it is done. We will update this section when the switch is available.
Turning it off in the Extension. The Extension has a Product analytics row in its Settings screen, under About. It ships switched on. Switching it off stops new submissions immediately, discards waiting events, cancels requests in progress where possible, and clears the hashed account identifier and the random identifier kept on your machine. No event is sent to report that you switched it off. Cancelling a request cannot retract data already delivered. Your choice is saved on your machine and survives browser restarts. If you switch analytics back on while signed out, new events use a fresh random identifier. While signed in, new events use the same hashed account identifier again and can be linked to that account’s earlier events.
2.6 Advertising measurement on the Site
When you visit our website, and only if you accept marketing cookies in the cookie banner, we use:
Google Tag Manager — a container that loads our other marketing tags.
Google Ads conversion tracking and remarketing — measures whether a click on one of our Google ads led to a sign-up, and lets us show ads to people who have already visited the Site.
LinkedIn Insight Tag — measures whether a click on one of our LinkedIn ads led to a sign-up, and lets us build audiences for LinkedIn campaigns.
Meta Pixel — measures whether an ad on Facebook or Instagram led to a sign-up or other action and lets us create audiences of people who previously visited the Site.
These tools may use your IP address, device and browser information, the pages you visited, the referring page, advertising or cookie identifiers, and events such as a page view or sign-up. They are operated by Google LLC, LinkedIn Ireland Unlimited Company, and Meta Platforms Ireland Limited. Google and LinkedIn process certain data as independent controllers. For certain Meta Pixel data collected and sent to Meta, Weeve and Meta act as joint controllers.
The Weeve App itself does not contain Google Ads, LinkedIn, Meta, or any other advertising trackers.
3. What we do NOT collect
We do not record, store, or transmit your audio or transcripts to our servers.
We do not use your audio, transcripts, or notes to train AI models — ours or anyone else’s.
We do not sell your personal data.
We share visit data with ad networks only for the purpose of measuring our own ads and reaching potential customers — and only when you consent on the website.
4. Why we process your data (legal bases under the GDPR)
Purpose | Data | Legal basis |
|---|---|---|
Provide the App and your account | Email, auth tokens | Contract (Art. 6(1)(b) GDPR) |
Bill you and manage your subscription | Subscription metadata, Stripe IDs | Contract (Art. 6(1)(b)) |
Enforce plan limits | Usage counters | Contract (Art. 6(1)(b)) |
Improve the App and the Extension | Pseudonymous product analytics | Legitimate interests (Art. 6(1)(f)), with an opt-out in the Extension’s Settings and on request for the App |
Measure ad performance and remarketing on the Site | Google Ads, LinkedIn Insight Tag, and Meta Pixel data | Consent (Art. 6(1)(a)) |
Detect abuse and protect the service | Logs, rate-limit counters | Legitimate interests (Art. 6(1)(f)) |
Comply with legal obligations | Billing records | Legal obligation (Art. 6(1)(c)) |
We rely on legitimate interests for product analytics rather than consent, because the events are coarse, carry no content from your recordings, and are linked only to a hashed or random identifier. To keep that balance fair you can object at any time under Art. 21 GDPR: in the Extension, switch Product analytics off in Settings; in the App, email support@getweeve.io until the in-app switch ships. See section 2.5.
5. Who we share your data with
We share the minimum amount of data needed to run the service. Our processors and ad partners are:
Recipient | Role | What for | Where |
|---|---|---|---|
Supabase | Processor | Authentication, subscription metadata, usage counters, and hosting the App’s update files | EU |
Stripe | Processor | Payment processing and subscription management | US/EU (DPF-certified) |
Hugging Face | Independent controller | Hosts the open-weight AI models the App downloads. Your Mac fetches the files directly, so Hugging Face sees your IP address as its own controller. We send them nothing about you. | US |
Cloudflare | Processor | Serving our own model files ( | EU/US |
PostHog | Processor | Pseudonymous product analytics | EU |
Framer | Processor | Hosting our website | EU/US |
Notion | Processor | Hosting the feedback form the App links to, if you choose to send us feedback | US |
Google (Ads + Tag Manager) | Independent controller | Ad conversion tracking and remarketing on the Site | US/EU (DPF-certified) |
LinkedIn (Microsoft) | Independent controller | LinkedIn ad conversion tracking | EU/US (DPF-certified) |
Meta Platforms Ireland | Joint/independent controller | Meta ad conversion tracking and website retargeting | EU/US |
We have data-processing agreements with each processor where the GDPR requires one. We never share your audio or transcripts with any of them.
We may also disclose data if required by law (e.g., a valid court order) or to protect our rights and users.
6. International transfers
Some of our recipients are based outside the EU/EEA (notably Stripe, Hugging Face, Cloudflare, Notion, Google, LinkedIn, and Meta). When data is transferred outside the EEA, we rely on Standard Contractual Clauses, the EU-US Data Privacy Framework, or other safeguards required by the GDPR.
7. How long we keep your data
Account data (email, auth): for as long as your account exists, plus a short retention period after deletion to handle disputes.
Subscription/billing records: retained as long as legally required (typically 7 years under Dutch tax law).
Product analytics events: up to 24 months in PostHog, then deleted or anonymized.
Advertising cookies on the Site: between 15 minutes and 13 months depending on the cookie — see the Cookie Policy for the exact list.
Local content on your Mac: stays on your Mac until you delete it, including voiceprints and speaker embeddings. We have no way to access or delete it for you. You can wipe it yourself with Delete all data under Settings → Data & Storage → Manage local data.
Local content in your browser profile: recordings, transcripts, to do’s, and model files remain in the browser profile until removed. Signing out or deleting your online account does not erase local content. You can delete individual recordings, delete the current account’s recordings in settings, and remove shared downloaded models. Recordings from older versions without an account owner stay outside account libraries and Mac hand-offs. If those earlier recordings belong to you, the recovery control lets you review them and copy selected recordings and linked people into your signed-in account; the originals remain unchanged. You can download audio and saved text. Downloaded copies and copies already transferred to the Mac are not erased when you delete a recording from the Extension. Removing the Extension deletes its local storage, including originals and content retained for other accounts. We cannot access or erase that local content for you.
When you ask us to delete your account, we delete or anonymize the account-side data within 30 days, except for records we’re legally required to keep. Deleting your account does not touch the content on your Mac or in your browser profile, because we cannot reach it; delete that yourself before or after, as described above.
8. Your rights
Under the GDPR, you have the right to:
Access the personal data we hold about you
Correct inaccurate data
Delete your account and associated data (“right to be forgotten”)
Restrict or object to certain processing. To object to product analytics in the Extension, switch off Product analytics in its Settings, under About. To object in the App, email us and we will switch it off for your account.
Port your data to another service
Withdraw consent at any time (where processing is based on consent) — for advertising cookies, use the “Cookie settings” link in the website footer
Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority
To exercise any of these rights, including deleting your account, email support@getweeve.io. We reply to every request and complete account deletions within 30 days. Deleting your account is not yet something you can do from inside the App; we are building it.
Separately from your account, you can erase everything Weeve holds on your Mac at any time without asking us: Settings → Data & Storage → Manage local data → Delete all data. That removes your recordings, their audio, your people, and your voiceprints and speaker embeddings from the device. Delete all models next to it removes the downloaded AI models.
9. Security
All connections between the App and our backend use HTTPS/TLS.
Authentication uses one-time codes (no passwords to leak) and short-lived JWT tokens.
Supabase encrypts data at rest.
Stripe is PCI-DSS Level 1 certified.
Your session tokens are held in the macOS Keychain and marked so they never sync off the device.
Voiceprints and speaker embeddings are encrypted with AES-GCM using a key that is generated on your Mac, kept in the Keychain, and cannot leave it. The files are readable only by your macOS user account.
Other local data on your Mac is protected by macOS user-level permissions and (if you enable it) FileVault disk encryption.
No system is perfectly secure. If a breach affects you, we’ll notify you and the Dutch DPA within 72 hours, as required by the GDPR.
10. Children
Weeve is not intended for users under 16. We do not knowingly collect personal data from children. If you believe we have, contact us and we’ll delete it.
11. Changes to this policy
If we materially change this policy, we’ll notify you by email and/or in the App at least 14 days before the change takes effect. The “Last updated” date at the top will always reflect the current version.
12. Contact
Questions, requests, or complaints:
Weeve B.V.
MediArena 2, 1114 BC Amsterdam-Duivendrecht, Netherlands
KVK: 42068756
Privacy & legal: stefan@getweeve.io
Support, privacy requests, and account deletion: support@getweeve.io