privacy
Privacy, in plain words
What Whozit keeps, who else touches your audio, and how to remove any of it.
Last updated
Each factual line on this page has an automated check. Most run Whozit's real code on a throwaway copy and measure what it does; a few (where data is hosted, how long snapshots are kept) check the deployment settings instead.
1. What Whozit keeps, and where
- Your recordings. The audio files you upload.
- Transcripts. The words, who said them, and the names you confirmed. Whozit also keeps the original transcript ElevenLabs sent back, next to the recording.
- A small log of each transcription. When it ran, how long the audio was, and the id ElevenLabs gave it. Whozit uses it to count your free hours and to ask ElevenLabs to delete its copy. It holds no text.
- Voiceprints. A voiceprint is a list of 192 numbers worked out from a few seconds of someone's voice. It is not audio. Whozit makes them in two places:
- In each recording. When a recording is processed, right after you upload it, Whozit makes voiceprints for every voice in it, including people you haven't named: up to 80 per voice, each from a stretch of speech at least 2.5 seconds long. They stay with that recording and are deleted with it. This is how Whozit can put names on old recordings later.
- In your voice library. Only for people you name and then press Save & learn for: up to 20 per voice per recording. In Name people, choosing a name for a voice does both at once. Whozit uses these to recognise that person in later recordings.
- Whozit never changes your audio files.
- Server logs. They hold user ids and recording ids only: never emails, names, titles, transcript text, passwords, tokens or IP addresses.
All of this sits in a folder that belongs to your account, with its own database. The only things kept outside it are your sign-in details, your consent record and your MCP token (see Your account).
Other accounts can't open your recordings, transcripts, voice library or exports, and you can't open theirs.
2. Who else touches your audio
ElevenLabs transcribes your audio with its Scribe service.
- Whozit sends ElevenLabs the audio file and the transcription settings.
- Whozit doesn't send your email, your name, the recording's title or any other account detail with it.
- As soon as the transcript comes back, Whozit asks ElevenLabs to delete its copy.
- If ElevenLabs doesn't confirm, Whozit asks again every hour until it does.
While ElevenLabs holds your audio, its own terms and privacy policy apply to what it does with it. Whozit can't see inside ElevenLabs' systems.
Fly.io hosts Whozit. Your folder sits on one volume attached to a single Fly.io machine, and Fly.io runs that machine.
Your data is stored in the United States: the volume is in Fly.io's Ashburn, Virginia region.
Whozit has no analytics and no ads, and loads nothing that reports back to a third party.
The site and the app load no third-party scripts, fonts, styles, images or embeds. The fonts are served by Whozit itself.
3. What Whozit never does
- It never sells or shares your recordings, transcripts or voiceprints. The only outside service that receives your audio is ElevenLabs.
- It never uses them to train AI models. The model that makes voiceprints is a fixed file that your data never changes.
- It has no admin screen that lists or opens people's recordings or transcripts.
Like any hosted service, Whozit runs on a server that the person who runs it can reach. The list above is about what the software does.
4. Consent and voiceprints
In some places a voiceprint counts as biometric data. Illinois (under BIPA) and the EU and UK (under the GDPR) are examples. Those laws can require you to get a person's consent before you collect their voiceprint. This is general information, not legal advice.
- Whozit refuses an upload until you have agreed to its consent statement.
- It also refuses to learn a voice from your own recordings until you have.
- When you agree, Whozit keeps a dated record: your account, the version and exact wording you agreed to, the time, and the IP address you were using.
- That record exists before any voiceprint is made from your own recordings.
- A consent record can't be edited once it is written.
- If you delete your account, your consent records are deleted too. Whozit then keeps no proof that you agreed.
- If the wording changes, Whozit asks you to agree to the new version before it accepts another upload or learns another voice.
- The sample team uses public audio (the AMI Meeting Corpus), so trying it doesn't ask for consent.
That record is your agreement. It isn't the agreement of the people in your recordings. Tell the people you record, ask whether they're fine with it, and forget anyone who isn't.
You can have Whozit forget anyone at any time (see Removing things).
5. How long it's kept
- Until you delete it. Whozit doesn't delete your recordings, transcripts or voiceprints on its own, and has no timer on them.
- When you delete something, its database rows are overwritten in the database file, not just hidden, and the database's write-ahead log is emptied straight after. Deleted files are removed from the volume.
- One exception: if ElevenLabs hasn't yet confirmed deleting its copy of a transcript, Whozit keeps one small log line (an id and a length, no text) until it does. If you delete your whole account first, only those bare ElevenLabs ids are kept, on a list with nothing that links them to you.
- Fly.io takes automatic daily snapshots (backups) of the volume and keeps each for 5 days. Something you delete can stay in a snapshot for up to 5 days.
6. Removing things
- One recording. Delete on the recording removes its audio, its transcript, ElevenLabs' original response, and every voiceprint made from it, both in the recording and in your voice library.
- One person. On People, Forget next to a name removes that person's voiceprints from your voice library and from every recording where their name is on a voice. Their name stays on lines you already confirmed until you change it.
- Everything. On People, Delete everything removes all your recordings, transcripts and voiceprints at once. Your account stays.
- Your account. On your Account page, Delete my account (it asks for your password) removes your whole folder (recordings, transcripts, voiceprints and voice library), your sessions, your MCP token, your consent records and the account itself.
- Before it removes your folder, Whozit overwrites every file in it up to 32 MB with zeros. A longer recording is removed without being overwritten.
7. Taking it with you
- Download all gives you every transcript as a Markdown file (one per recording, each line under its speaker) plus a list of the people Whozit knows.
- Download everything adds your original recordings.
- An export only ever holds your own data.
- Whozit builds the file when you ask and deletes its own copy once it has been sent.
8. Your account and signing in
- Whozit keeps your email address and a hash of your password. The password is stored only as an argon2id hash, never in plain text.
- When you sign in, Whozit starts a session. It stores only a SHA-256 hash of the session; the real value lives in the cookie in your browser.
- A session lasts 30 days.
- The cookie is HttpOnly (scripts on the page can't read it), SameSite=Lax, and Secure on https.
- Signing out ends that session on the server, not only in your browser.
- Nothing in your account can be read without signing in or presenting your MCP token.
- If the operator turns on email confirmation, Whozit emails only sign-up and password-reset messages (a confirmation link, a note that the address already has an account, or a link to choose a new password) through the email provider they set up, and sends that provider nothing else.
- Your IP address is stored in one place: your consent record. Fly.io, which hosts Whozit, handles IP addresses as part of running the network.
- The first 5 hours of audio on each account are free. When they are used up, uploads stop. Deleting recordings doesn't give hours back, because the count is kept on your account, not in your recordings.
- Paid plans aren't open yet. Whozit takes no payments and keeps no payment details.
9. Agents and MCP tokens
An MCP token lets an AI tool that you connect, such as Claude Code or Claude Desktop, read your meetings. (Claude.ai and ChatGPT connectors aren't supported yet.)
- Whozit shows you the token once and stores only a SHA-256 hash of it.
- You have one token at a time, and you can revoke it whenever you like. A revoked token stops working at once.
- A token reads only the data of the account that made it.
- With your token an agent can list and read your meetings and people, search lines, and put a name on a voice. Naming a voice changes a name, so that tool is marked destructive. An agent can't upload, delete or export anything.
What an agent reads goes to the company that runs it, under that company's terms. Revoking the token stops new reads. It can't take back what was already read.
10. Cookies and browser storage
- Whozit sets one cookie: your sign-in session. It is set when you sign up or sign in, not before.
- Three display choices are saved in your browser's localStorage, on your device only: light or dark (
whozit.theme), whether Name people plays each voice by itself (whozit.autoplay), and whether the Markdown preview shows timestamps (whozit.timestamps). Nothing else is stored there.
11. Contact
Questions, or something you want removed that the buttons above don't reach: hello@whozit.io
When this page changes, the date at the top changes too.