Privacy Policy

Last Updated: April 19, 2026

1. Introduction

Lecsy (“the App”) is built for international students who attend English-language lectures. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.

2. How Your Data Flows

The short version

When you record a lecture, audio is streamed in real time to Deepgram (our speech-to-text provider) over an encrypted connection. Deepgram returns transcript text immediately and automatically deletes the processed audio within 30 days. Lecsy itself never stores your audio on its servers. Transcript text is saved on your device and, when you are signed in, synced to our database for cross-device access. When you tap AI Summary or Bilingual Translation, the transcript text (not audio) is sent to OpenAI to generate the result.

DataYour DeviceLecsy ServerDeepgramOpenAICondition
Audio (live stream)YesNeverYes (auto-deleted < 30d)NeverStreamed only while you are recording
Audio (.m4a file)YesNeverNeverNeverLocal backup file, stays on your device
Transcript textYesYesNoSynced when signed in
AI Summary / Translation inputYesYesYesText only, never audio; only on demand
Account info (email, name, ID)YesNoApple / Google / Magic Link sign-in
Ads / Trackers / IDFANoneNoneNoneNo ad SDKs installed; IDFA not collected

3. Real-Time Transcription via Deepgram

Lecsy uses Deepgram Nova-3 to perform real-time speech-to-text on lecture audio. While you are recording, audio is streamed to Deepgram's servers over an encrypted (TLS) WebSocket connection. Transcript text is returned within milliseconds and stored on your device.

Deepgram's data handling:

  • Audio is processed only to produce the transcript and is not used to train Deepgram's models (per Deepgram's API terms).
  • Processed audio is automatically deleted within 30 days.
  • Lecsy uses short-lived API tokens (15-minute TTL) to authorize each session, so no permanent credentials live on your phone.
  • For organization customers we will negotiate a Zero Data Retention agreement with Deepgram on request.

If you are offline, real-time transcription is unavailable. The local audio file is still saved and you can re-attempt transcription when you reconnect.

4. AI Summaries, Translation & Study Guides

When you tap AI Summary, Bilingual Translation, or Study Guide, the transcript text (never audio) is sent from our server to OpenAI's API (GPT-4o-mini and gpt-5-nano) to generate the result. OpenAI does not use API content to train its models. Lecsy does not use your data to train AI models either.

5. Information We Collect

Account Information (optional but required for cloud features)

  • Email address (from Apple ID or Google account)
  • Display name
  • User ID

Audio Recordings

  • Lecture audio recorded through the app
  • Local file (.m4a) stored on your device only — never uploaded to Lecsy servers
  • Streamed to Deepgram in real time for transcription, then deleted by Deepgram within 30 days (see Section 3)

Transcription Text

  • Text returned by Deepgram during recording
  • Stored locally on your device
  • If you are signed in, text is synced to our server (Supabase) for cross-device access and backup

Usage Data

  • Recording minutes per day / per month (for usage caps and billing)
  • Device type and operating system version

6. How We Use Your Information

  • Real-Time Transcription: Audio is streamed to Deepgram while recording; transcript text is returned and stored.
  • AI Features: Transcript text is sent to OpenAI when you use AI Summary, Translation, or Study Guide.
  • Authentication: To verify your identity and manage your account.
  • Data Synchronization: To sync transcript text across devices.
  • Service Operation: Anonymized usage data to enforce quotas and improve reliability.

7. Data Storage

On Your Device

  • Audio recording files (.m4a)
  • Transcript text and segments
  • App settings and preferences

On Lecsy Servers (Supabase, when signed in)

  • Account information (email, display name)
  • Transcript text (for cross-device sync and backup)
  • Usage logs (rate-limit and billing tracking)
  • Audio recordings are never stored by Lecsy

Security Measures

  • All data is transferred over encrypted connections (HTTPS/TLS 1.3)
  • Data at rest is encrypted
  • Row-level security ensures you can only access your own data
  • Short-lived (15-minute TTL) API tokens for Deepgram, never long-lived secrets in the app

8. Sub-Processors

We use the following third-party services (sub-processors) to operate Lecsy. Each is bound by their own privacy and security commitments:

ServicePurposeData SharedPrivacy Policy
DeepgramReal-time speech-to-text (Nova-3)Live audio stream (auto-deleted < 30 days)deepgram.com/privacy
OpenAIAI summaries, translation, study guidesTranscript text only (no audio); on demandopenai.com/privacy
SupabaseDatabase, authentication, cloud syncAccount info, transcript text (no audio)supabase.com/privacy
StripeSubscription billingEmail, payment method (held by Stripe)stripe.com/privacy
Apple Sign InUser authenticationApple ID credentialsapple.com/privacy
Google Sign InUser authenticationGoogle account credentialspolicies.google.com/privacy

9. Data Sharing

We do not sell, rent, or share your personal information with third parties, except in the following circumstances:

  • With Your Consent: When you explicitly authorize sharing
  • Sub-Processors: Listed in Section 8, solely to operate the Service
  • Legal Requirements: To comply with applicable laws or legal processes

We never share or sell your transcript text or audio data for advertising or model training.

10. AI Training

We do not use your audio, transcripts, or any other personal data to train artificial intelligence models. Our sub-processors (Deepgram, OpenAI) also commit, in their API terms, to not using your data for model training.

11. Your Rights

Right to Access

You can request access to the personal data we hold about you.

Right to Rectification

You can request correction of inaccurate data.

Right to Deletion

You can delete your account and all associated data directly from the app: Settings → Delete Account. All data is permanently deleted immediately.

Right to Data Portability

You can request a copy of your data in a portable format.

How to Exercise Your Rights: Contact us at support@lecsy.app

12. Data Retention

  • On-device data (audio, transcripts) remains until you delete it
  • Cloud transcript data is retained while your account is active
  • Upon account deletion, all cloud data is deleted within 30 days
  • Audio sent to Deepgram for live transcription is auto-deleted within 30 days by Deepgram
  • Some data may be retained longer if required by law

13. Children's Privacy

Lecsy is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.

14. International Data Transfers

Lecsy is operated from the United States. Audio (briefly) and transcript text may be processed in the United States by Deepgram, OpenAI, and Supabase. By using the Service, you consent to such transfers. Where required by law, we rely on Standard Contractual Clauses (SCCs) for cross-border transfers.

15. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the CCPA:

  • Right to know what personal information is collected
  • Right to know whether personal information is sold or disclosed
  • Right to opt out of the sale of personal information
  • Right to non-discrimination for exercising your rights

We do not sell personal information.

16. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), you have rights under the GDPR including access, rectification, erasure, restriction of processing, data portability, and the right to object.

Legal Basis for Processing: Consent, performance of a contract, and legitimate interests.

17. For Schools & Organizations

When Lecsy is provided to a school, university, language program, or other educational institution under a written pilot or license agreement, the following commitments apply in addition to the rest of this policy:

  • FERPA “school official”: Lecsy operates as a school official with a legitimate educational interest, processing student data only as directed by the institution. We do not disclose personally identifiable information from education records to third parties except as permitted by FERPA or with consent.
  • Lecsy never stores audio: Audio is streamed only during recording for real-time transcription. The local .m4a file remains on the student's device.
  • Deepgram retention & Zero Data Retention (ZDR): By default, Deepgram automatically deletes processed audio within 30 days. For institutional deployments we will negotiate a Zero Data Retention agreement with Deepgram on request, so audio is discarded after transcription with no retention window.
  • Transcript storage: Transcript text is stored in encrypted Supabase Postgres with row-level security scoped so that only members of the institution's organization can access its data. Audio is never persisted on Lecsy infrastructure.
  • Student consent: Before a student records under an organization, the iOS client surfaces a FERPA-aligned consent prompt. The acknowledgement timestamp is written to the student's organization membership record so administrators can produce evidence of consent. Consent can be withdrawn by emailing the school's Lecsy administrator or privacy@lecsy.app.
  • No model training on student data: Neither Lecsy nor our sub-processors (Deepgram, OpenAI) use institutional audio or transcripts to train AI models, per their API terms.
  • Compliance documentation on request: We provide a Data Processing Addendum (DPA) with Standard Contractual Clauses for cross-border transfers, and HECVAT-Lite responses for institutional security reviews.

Institutional inquiries: support@lecsy.app.

18. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes through:

  • In-app notifications
  • Email (if you have provided one)
  • Updating the “Last Updated” date above

19. Contact Us

If you have any questions about this Privacy Policy, please contact us:

Email: support@lecsy.app

Summary

DataHow It's UsedWhere It's StoredShared With
Audio (live)Real-time transcriptionStreamed to Deepgram, deleted < 30 daysDeepgram only
Audio (.m4a)Local backup of recordingYour device onlyNo one
Transcript textDisplay, search, cross-device backupDevice + cloud (if signed in)Supabase (our cloud provider)
AI summary / translation inputGenerate summaries, translations, study guidesProcessed, not stored by OpenAIOpenAI (text only, on demand)
Account infoAuthenticationCloud (Supabase)Supabase, Apple/Google (auth)

Key Points:

  • ✓ Audio is never stored on Lecsy servers
  • ✓ Live audio sent to Deepgram is auto-deleted within 30 days
  • ✓ AI features send transcript text only (not audio), only on demand
  • ✓ No data is sold to third parties
  • ✓ No data is used to train AI models
  • ✓ You can delete your data anytime

This Privacy Policy is effective as of April 19, 2026.

Back to Home