Who is responsible
This policy covers the PACKIT iPhone app, its supporting services and the website at packit.cc. A “memory” is a saved recording with its transcript, summary and related information.
Usto AI Corporation, trading as Usto AI, operates PACKIT and is the data controller responsible for the personal information described in this policy. You can contact us about privacy, your account or the service at shsobirov.dev@gmail.com.
Usto AI Corporation1007 North Orange Street
4th Floor 3928
Wilmington, DE 19801
United States
People you record also have privacy rights. Tell them that you are recording and using cloud transcription, and obtain any permission required for the recording and the way you intend to use it.
Information we process
- Account information. Your account identifier, email address and profile information supplied when you sign in, together with authentication and access records.
- Recordings and memories. Audio you record or upload; titles, dates and durations; transcripts and timestamps; speaker labels and names; summaries, decisions, tasks and your corrections.
- Ask and actions. Questions and answers about your memories, email and event drafts, recipient addresses, scheduling details, automation preferences and records of attempted or completed actions.
- Voice samples. Short clips associated with a memory and, when you choose to remember a person, that person’s confirmed name and samples used to suggest the speaker in later recordings.
- Technical and support information. App and device versions, processing status, error codes, usage counters and information you choose to send when asking for help. Hosting services also process connection information, such as an IP address, to deliver and protect the service.
Recordings may contain information about people other than the account holder, including sensitive information they discuss. PACKIT receives that information from the person who records or uploads it. Avoid recording or uploading information you are not entitled to process.
Recordings and AI
Audio is stored on your iPhone before upload to private cloud storage. PACKIT’s server sends audio to OpenAI for transcription and speaker separation, and sends transcript content to OpenAI to generate summaries, decisions, tasks and suggested names. When you use Ask, relevant memory content, your question and conversation context are processed to answer it or prepare an action.
The complete transcript and the summary are stored separately. If you ask for an email or meeting draft, recipient addresses and scheduling information you provide may be included in the AI request needed to prepare that draft.
These features process your content to provide the service you request. PACKIT does not sell recordings or use them to build advertising profiles. We use OpenAI’s API; its business data commitments explain its approach to model training and data protection.
AI output can be incomplete or wrong, including a person’s identity or a task assignment. You can review and correct the result. PACKIT’s suggestions are not decisions about a person’s legal rights or eligibility for services.
Names and remembered voices
PACKIT may suggest a name from the words in a recording or from a previously confirmed voice. A suggestion remains something for you to confirm or correct. A name mentioned in a conversation does not necessarily identify the person speaking.
Choosing to remember a person allows their confirmed voice samples to help identify them in future recordings in your account. Voice matching can involve biometric information. Obtain that person’s informed permission before enabling it for them. You can label a speaker for the current recording without choosing to remember their voice.
Samples stay associated with the recording they came from. Deleting that recording or its audio also deletes its samples. If other recordings retain confirmed samples of the same person, those samples may still be used. To stop remembering the person entirely, remove the retained source samples or contact us for help. PACKIT does not use these samples to clone or generate someone’s voice.
Google connections
Signing in with Google identifies your account. Connecting Gmail and Google Calendar is a separate, optional step in Settings. Google shows the permissions requested before you approve access.
What access is used for
- Account identity: Google’s account identifier and email address associate the connection with your PACKIT account.
- Gmail: the permission to send email lets PACKIT send a message from your connected account to the recipients in the action. PACKIT does not request inbox-reading permission.
- Calendar: the permission to manage events on calendars you own lets PACKIT create events in your primary calendar and send invitations. Although Google’s permission also allows reading, changing and deleting owned events, PACKIT currently uses it to create events and, when needed, check an event it has already attempted to create.
We store the connected account identifier, email address, granted permissions and an encrypted refresh token on the server. The token lets PACKIT obtain access without asking you to sign in for each action; it is not your Google password. Drafts and action status, including links returned by Google, are stored with the associated memory.
Your control over sending
You review and confirm an action unless you have enabled the relevant automatic action in Settings. Automatic email and calendar actions are off by default. After-meeting automation uses the recipients you saved in its settings. A sent message or invitation shares the action’s content with Google and those recipients.
Use and sharing of Google data
PACKIT’s handling of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Google data is used for the connected features you choose. It is not sold, used for advertising, used for credit decisions or used to train general-purpose AI models.
Any sharing is limited to providing the features you authorize, protecting security or meeting legal requirements. Human access to Google data is limited to your specific permission, necessary security investigations, legal requirements or aggregated internal operations allowed by Google’s policy.
Disconnecting
Disconnect Google in PACKIT Settings to remove the stored connection token and turn off its automatic actions. PACKIT also requests revocation from Google. You can independently remove access in your Google Account connections. Disconnecting does not delete existing PACKIT drafts, sent emails or calendar events. Delete memories in PACKIT and manage sent messages and events in Google separately.
Service providers and recipients
PACKIT uses the following services for the functions described here. A provider receives the information needed for the part of the service it performs.
- Supabase
- Account authentication, application database and private file storage.
- OpenAI
- Audio transcription, speaker processing, summaries, answers and action drafting.
- Hetzner
- Hosting the PACKIT API and processing services.
- Sign-in and the optional Gmail and Calendar actions you authorize.
- Apple
- iPhone platform services and optional push notifications.
- Cloudflare
- Website delivery, network services and security.
- DataFast
- Cookieless analytics on the public website, described below.
Information is also shared with people you choose as email recipients or event attendees, and through exports or sharing you initiate. We may disclose information when required by law or when necessary to investigate abuse or protect the service, subject to applicable restrictions, including Google’s Limited Use rules.
Usto AI Corporation is based in the United States. Our providers operate internationally, and information may be processed in the United States or other countries whose data protection laws differ from those where you live. Transfers that require protection under European data protection law are subject to the relevant provider’s contractual safeguards and applicable transfer mechanism, such as standard contractual clauses or an adequacy decision. Contact us to request information about the arrangements applicable to your data.
Website analytics
The public website uses DataFast’s cookieless script to understand visits, referral sources and use of links. It processes page URLs, including query parameters, referrers, browser and device information, and session information. DataFast receives the IP address associated with the request and uses network and browser signals to derive a pseudonymous visitor identifier that changes approximately daily.
This mode does not use a persistent visitor-identification cookie. It may use session storage for the current browser tab. Cookieless analytics still involves data processing; it is not a promise that no visitor information is collected. See DataFast’s description of cookieless tracking.
We do not connect website analytics to your PACKIT recordings or Google connection. The website does not have a recording upload form. Do not place personal or confidential information in website URLs. You can block the analytics script through your browser’s privacy controls without preventing access to these pages.
Retention and deletion
Audio and memories
You choose whether to keep the audio with a memory or delete cloud audio after processing. Deleting audio removes the original cloud recording, its processing parts and its voice samples. The saved transcript, summary and confirmed speaker names can remain until you delete the memory.
Deleting a memory removes it from your library and schedules removal of its private audio, related transcripts and analysis, voice samples, Ask conversations and action drafts. Deletion may take time to complete if a device is offline or a service is unavailable.
Your account and Google connection
You can request account deletion from Settings. The deletion process removes stored recording objects before deleting your account and its associated application records. Disconnecting Google removes the stored connection token. Neither operation recalls email or removes events already created in Google.
Other records
Account content is retained while you keep it in the service, unless you choose deletion or an applicable legal requirement calls for retention. Technical, security and support records are kept for the time needed to operate the service, resolve the issue, investigate abuse or satisfy a legal obligation. Content-free aggregate usage totals may remain after an account is deleted.
Deletion from active PACKIT storage does not necessarily erase a provider’s backup or security record immediately. Those records are subject to the provider’s retention and deletion arrangements. Copies you export or send to other people remain under their control.
Security and device permissions
PACKIT uses authenticated access, private cloud storage and account-based database access controls. Google refresh tokens are encrypted on the server. Service credentials are not distributed in the iPhone app. Our structured support events exclude audio, transcript text, summaries, credentials and signed download URLs.
These measures reduce risk but cannot guarantee that every device, network or service will always be secure. Protect your device and sign-in account, and contact us if you believe someone has accessed your PACKIT data without permission.
Microphone access is needed for recordings you start. Notifications are optional. Google Calendar access uses the Google connection you authorize; it does not require access to your iPhone’s local calendar database. If you select a recipient using the system contact picker, PACKIT uses the selected contact information rather than importing your address book.
Reasons for processing
Where European data protection law applies, our reasons for processing depend on the feature and the information involved:
- Providing the service: account administration and processing the recordings, questions and actions you request are necessary to deliver PACKIT under our agreement with you.
- Your permission: optional connections and permissions are controlled by your choices. Where processing requires consent, you may withdraw it; withdrawal does not affect processing that was lawful before it.
- Operating and protecting PACKIT: proportionate technical records, abuse prevention, support and limited website measurement serve our interest in maintaining a reliable service, subject to your rights and any consent required by law.
- Legal obligations: we process information when necessary to meet an applicable legal requirement.
A recording may contain sensitive information or another person’s voice. You must have a lawful basis for recording and sharing that information, and obtain any additional consent needed for sensitive data or remembered voice identification. Granting PACKIT microphone access does not provide consent on behalf of everyone recorded.
Your rights and requests
Depending on the law that applies to you, you may request access to your personal information, correction, deletion, a portable copy or restrictions on its use. You may also object to processing based on legitimate interests and withdraw consent where we rely on it. These rights can have legal exceptions.
Use the contact details at the beginning of this policy. You do not need a PACKIT account to raise a concern about your information in someone else’s recording. Explain the request and provide enough context for us to locate the relevant information; we may need to verify your identity before releasing or changing personal data.
You may complain to the data protection authority where you live, work or believe a violation occurred. People in the European Economic Area can find their authority in the European Data Protection Board’s directory.
Children and changes to this policy
PACKIT accounts are intended for adults aged 18 or older. We do not knowingly provide accounts to, or collect account information directly from, children under 18. If you believe a child has created an account or supplied information directly to PACKIT, contact us so we can investigate and take appropriate action. This age requirement does not remove the privacy rights of younger people who may appear in someone else’s recording.
We will update the effective date when this policy changes. If a change materially affects how we handle your information, we will provide an appropriate notice. We will seek additional consent before using Google data for a new purpose when Google’s rules require it.
Download