Recapp

Privacy policy

Recapp is operated by Rising Devs. This policy explains Private Azure Cloud processing, user-owned files, accounts and this website. Contact: support@risingdevs.com.

Updated October 5, 2026

Optional Google and Outlook calendars

Pro users can connect multiple Google and Outlook accounts through separate, read-only provider consent in Connectors. Recapp sign-in does not grant calendar access. With your permission, the device reads calendar names and event details, including titles, times, meeting links, organizers and invited participants. Recapp uses this information to display your calendars, prepare meetings from notes in your selected vault, and associate a recording with a meeting. It does not modify events, invite participants or request mailbox access.

Calendar credentials, retention and disconnection

Calendar access tokens, protected refresh grants and account/calendar selection are kept in the device’s secure storage. The account service exchanges and refreshes provider credentials using encrypted, owner- and device-bound grants; it does not store a calendar event database. Encrypted tokens awaiting device exchange are cleared when exchanged; abandoned flows expire after ten minutes and are removed by the cleanup job. Calendar events stay in device memory. Disconnect removes local credentials and cached events and attempts to revoke the Google calendar grant. For Outlook, remove provider consent through Microsoft’s account permissions page if needed. Signing out clears this device’s connector storage; deleting a Recapp account invalidates its protected grants. Disconnecting does not delete meeting or preparation notes you chose to save.

Meeting participants and sharing

Preparation searches your selected local vault. Saved preparation and recording notes can contain event references and participant names and email addresses; these remain in your vault and travel with exports or backups. If you enable participant names for processing, up to fifty eligible invitee names are sent with selected meeting content to Private Azure Cloud to help transcription and summaries; you can turn this off. Invitee email addresses are not included in these processing hints. Cloud conversation refinement requires the existing processing consent. Invited names do not prove attendance or identify who spoke. A recording-notice email is an editable draft opened in your device’s mail app: you review recipients and choose whether to send. Recapp never sends it automatically, and the notice does not replace recording consent.

Google API Limited Use

Recapp’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data is used only for the calendar and meeting features described above. It is not sold, used for advertising or used to train generalized AI models. Selected context is transferred for the visible processing or sharing features only with your consent. Rising Devs does not routinely read calendar content; any exceptional human access requires your affirmative agreement for specific data, or is limited to security or legal obligations.

Private Azure Cloud

Recapp sends audio for transcription, text for summaries, chat and reports, and only screenshots you explicitly include as context. Transfers use TLS encryption; Azure decrypts content for processing. Recapp does not keep recordings, screenshots, notes or results in cloud storage. Originals and results belong to you and are saved on your device. Microsoft may temporarily retain flagged prompts or output under its standard abuse-monitoring process.

Required sign-in

Sign in with Google, Apple or Microsoft to use Recapp. The account service stores a profile and sessions in Azure, separately from meeting content. Signing in does not upload files: processing requires separate consent. Signing out locks the workspace and preserves your files.

Subscriptions and device activation

Recapp stores subscription status, payment-provider identifiers, single-use access-code redemption status and an opaque installation identifier in Azure to verify access and enforce one active Pro device. Stripe or Apple processes payment details in its own checkout. Recapp does not collect card numbers in the app. No meeting content is needed for billing. Activating Pro on another device changes the active installation without moving your local files.

Account storage and deletion

Account profiles are stored in Azure until you delete your account. Sessions last up to 90 days; incomplete sign-in flows expire after 10 minutes. Google and Apple refresh credentials are encrypted with protection managed through Azure Key Vault and are used for provider-grant revocation. Microsoft sign-in does not retain a provider refresh credential. The app stores its Recapp session using the device’s secure storage. Use Delete account in the app to delete the account profile and sessions; it also revokes the stored Google or Apple grant. Local notes remain on your device. A temporary pseudonymous account identifier and deletion timestamp prevent an unfinished sign-in from recreating the deleted account; this record expires after 20 minutes and is removed by the cleanup job, which normally runs every 15 minutes. Signing out ends your local sign-in but does not delete your account.

Website, downloads and service requests

Azure hosts the website, app packages, account service and diagnostics. Recapp sends sanitized crash/error reports, coarse hardware statistics, and signed-in foreground activity counters to Azure Application Insights by default; you can turn these off in Recapp Settings. Hardware statistics include RAM and free-space ranges, processor-count range, architecture, OS/app version, Windows CPU capabilities, and whether observable compatibility and estimated ideal targets are met. They do not include an exact device model, serial number, device name, MAC address or advertising identifier. Each report has a random installation identifier and, when signed in, a pseudonymous Recapp account identifier. Names and email addresses are not included. These diagnostic reports never include recordings, transcripts, Markdown notes, questions or generated answers, and are retained for 30 days. Loading Azure-hosted resources also sends ordinary network information such as your IP address, request time and requested resource to the hosting service. Recapp has no advertising SDK. Meeting content is excluded from operational telemetry. Azure, Google, Apple, and Microsoft process service and security requests under their own privacy policies.

Optional website analytics

The public website does not load analytics until you choose Allow analytics. If allowed, a separate Azure Application Insights resource receives the page path, page language, selected button and download events, demo navigation, engaged time while visible and recently used, coarse referrer categories, browser and operating-system category, approximate location and performance data. Full URLs, query strings, form values, account identifiers, recordings, transcripts, notes, questions and generated answers are not sent. Cookies, persistent analytics identifiers, browser storage, automatic request capture, error capture, advertising and session replay are disabled. Azure temporarily uses the network address to derive approximate location, discards it and stores 0.0.0.0 in the IP field. Website analytics are retained in the Recapp Log Analytics workspace for 30 days. Your allow or decline choice is stored only in this browser, and Analytics choices in the footer lets you change it.

Local preferences and the demo

The website follows your browser language and device appearance. The interactive demo uses fictional content and stores demo changes in your browser’s local storage; clear this site’s browser data to remove them. App preferences and vault access information are stored locally. Any authentication cookies or credentials used during sign-in support that sign-in, not advertising.

Your files, copies and backups

Vaults contain plain-text Markdown, transcripts and audio attachments. Recapp does not encrypt these files itself. Your device security, backups, Files provider or other folder-sync service may protect or copy them according to its own settings. Exporting or sharing files can send copies to a destination you choose. Those copies are controlled by you and the receiving service.

Deleting notes and recordings

Deleting a note removes that Markdown note but deliberately keeps its source audio and transcript for recovery. Recording work files, imported originals, temporary normalized audio and exported archives may also remain. To remove a meeting completely, close Recapp and remove the relevant files from the vault’s _attachments and _transcripts folders and any recovery, export or backup copies. Check for references from other notes before deleting shared files. Deleting the app does not guarantee deletion of external folders or backups. Contact support if you need help locating retained files.

Support and your choices

If you email support, we receive your email address and the information you choose to include so we can respond. Send your device model, OS, app version and a description of the problem; private recordings and transcripts are not needed for an initial report. Contact support@risingdevs.com to ask about access, correction or deletion of account or support information. We may need to verify that the request belongs to you.

Private Azure Cloud Preview in 0.4

Signed-in users consent before processing. Selected recording audio is sent to Azure Speech; transcripts and selected meeting context are sent to Azure for summaries and chat. In 0.5.4 and later, a cloud Report sends a bounded selection of saved note summaries to Azure; it does not read source audio or transcripts. Recapp does not persist cloud recordings, transcripts, prompts, summaries or answers. Processing uses transient requests and memory; results are saved in your local vault. Microsoft may temporarily retain flagged prompts or output under its standard Azure abuse-monitoring process. TLS encrypts transfers from the app to the authenticated Recapp service and from that service to private Azure inference endpoints. Azure decrypts content to process it; this is not cryptographic end-to-end encryption. Preview inference may process outside Canada. Account records and content-free operational metadata are retained as described above; no meeting content belongs in logs. Cloud processing does not synchronize or back up your vault.

Content-free quotas

The service stores content-free meeting counts per account and calendar month, recording allowances and chat counts linked to opaque meeting identifiers. These counters enforce Free and Pro limits across requests and restarts. They contain no notes, audio, screenshots, questions, answers or transcripts.

Enterprise

Only an agreed enterprise implementation can configure a different storage policy in customer infrastructure. It is not a personal-account upgrade switch.

Provider policies

← Back to RecappPrivacy questions ↗