Cleftβs complete Data Processing Agreement and transparency guide for all data handling
Formal DPA: This page serves as Cleftβs official Data Processing Agreement for all customers and compliance teams, while also providing transparent information for all users.
Last Updated: September 10, 2025 Effective: September 10, 2025
This document serves as both our user-friendly data transparency guide and our formal Data Processing Agreement (DPA) for customers requiring compliance documentation.
You (Data Controller): You control the personal data in your notes, recordings, and accountCleft (Data Processor): We process your data solely to provide voice-to-text services as instructed by youLegal Basis: Processing based on legitimate interests (service provision) and consent where applicable
Key Principle: We only collect and process data thatβs essential for delivering our service. Your content is never used for training AI models or shared with advertisers.Complete Vendor List: This DPA covers our key data processors. For our complete list of all 37 vendors (including business operations vendors that handle no personal data), see our Vendor Transparency page.
Apple App Store: Handles all iOS subscription billing
Stripe: Processes web payments (we donβt see card details)
RevenueCat: Manages subscription status and analytics
Important: We never see or store your actual payment details (card numbers, etc.). This is handled entirely by secure payment processors.Who Has Access:
Step 1: You record audio β Your Device (local storage)Step 2: Audio transcribed β Your Device (using OpenAIβs Whisper model)Step 3: Audio backed up β AWS (secure cloud storage)Step 4: Transcript enhanced β OpenAI/Groq/Anthropic (text processing only)Step 5: Final note saved β AWS (encrypted storage)Step 6: Synced to your devices β Your Apps (encrypted transfer)
Data at Rest
Your Device:
Audio files (during recording)
Transcripts and notes (local cache)
App preferences
AWS Cloud Storage:
Audio files (encrypted)
Transcripts and notes (encrypted)
Account information (encrypted)
Sync data (encrypted)
AI Providers (OpenAI, Groq, Anthropic):
No data stored - processing only
Receive text, never audio
No training on your data
Data in Transit
Device β AWS: End-to-end encryption using TLS 1.3AWS β AI Providers: Encrypted API calls (HTTPS/TLS)Device β Payment Processors: Direct secure connection (bypasses our servers)App β Analytics: Anonymous, aggregated data only
Audit Rights: Customers have the right to audit our data processing activities upon reasonable noticeCompliance Support: We assist with your GDPR, CCPA, and other regulatory compliance requirementsDocumentation: This page serves as your DPA - bookmark, download, or print for your compliance recordsUpdates: Weβll notify customers of material changes to our data processing practices
Notification Timeline: We notify affected customers within 72 hours of discovering a security incidentResponse Process: Immediate containment, investigation, remediation, and detailed incident reportsCustomer Support: Dedicated incident response team
Technical & Organizational Measures
Encryption: All data encrypted in transit (TLS 1.3) and at rest (AES-256)Access Controls: Role-based access, multi-factor authentication, regular access reviewsInfrastructure: SOC 2 compliant cloud infrastructure with redundancy and monitoringStaff Training: Regular security awareness training for all Cleft personnel