Last updated: 8 August 2026

Privacy Policy

1. Controller and contact

The controller is Ted Marcin. Privacy enquiries and requests can be sent to tedmarcin@atomicmail.io.

2. Local app data

Positions, totals, timestamps, session names, layouts, settings, text notes and local audio notes are stored in the app's protected local storage. We cannot access this local content. It remains on the device until you delete it, reset the app data or uninstall the app. Exported files are controlled by you and may remain with the destination you select.

3. Website access

This website uses no analytics, advertising, tracking pixels, external fonts or marketing cookies. To deliver and protect the website, the web servers may process the IP address, request time, requested address, browser information and response status in technical logs. Processing is based on our legitimate interest in secure and reliable operation (Article 6(1)(f) GDPR). Logs are retained only as long as needed for operation, error analysis and security, and are then rotated or deleted.

4. Device registration for online features

When you use an optional online feature, the app registers a pseudonymous device access. It sends a random installation ID, platform, app edition and version and, where available, Android ID or Apple's Identifier for Vendor over an encrypted connection. The raw platform identifier is not stored on the server. It is immediately converted with a secret server-side HMAC into a pseudonymous device group. Internal device IDs, token hashes, registration times, limits and revocation status are stored to secure the service, prevent abuse and provide the requested feature (Article 6(1)(b) and (f) GDPR). They remain until no longer required or a justified deletion request is fulfilled.

5. Optional live session sharing

Sharing starts only after a user deliberately creates or joins a connection. A shared session may contain positions, totals, timestamps and the current input. Master notes and private viewer notes are not part of the shared session. Sharing data is encrypted in transit, deleted immediately when the master ends sharing and otherwise expires no later than 24 hours after the last relevant update. A viewer keeps its received copy and private notes locally on its own device.

6. Optional server transcription

Local audio recording and playback do not require an upload. In KatKalk Pro, an audio note is sent only when you request server transcription or deliberately enable automatic transcription. The selected audio, language setting, pseudonymous device access and random job ID are processed on KatKalk-operated infrastructure with self-hosted faster-whisper; no external AI transcription API is used. Audio is removed after completion, cancellation or final failure. Job status and result remain available for up to one hour after completion; the app then stores the transcript locally. Processing provides the feature requested by you (Article 6(1)(b) GDPR). Do not record other people without an appropriate legal basis.

7. Permissions

8. Recipients and transfers

We do not sell personal data and currently use no advertising or analytics SDK. Technical hosting providers may process infrastructure data only as needed to operate the service and under applicable data-protection obligations. Google Play and the Apple App Store process downloads, updates and purchases under their own privacy terms. KatKalk does not intentionally transfer app content to an external AI provider.

9. Your rights

Subject to the legal requirements, you may request access, correction, deletion, restriction, portability or object to processing. Where processing is based on consent, you may withdraw it for the future. Contact us at the address above. You also have the right to lodge a complaint with the Polish President of the Personal Data Protection Office (UODO), uodo.gov.pl. KatKalk does not use automated decisions that produce legal or similarly significant effects.

10. Security and changes

Online connections use TLS, access credentials are random and server-side credentials are stored only as cryptographic checks where possible. No system can provide absolute security. We update this policy when the released app or its data handling changes and publish the new date here. KatKalk is not directed at children.