Last updated: 2026-07-12
Verbamint ("the App") is a mobile application developed and published by Alessandro Nocentini, an individual developer based in Italy, trading as "Verbamint" (the "Developer", "we", "us"). This Privacy Policy explains, precisely and completely, what data the App processes, why, for how long, and what rights you have. It should be read together with our Terms of Use, which set out your responsibilities when using the App, including when recording other people.
Verbamint records meetings, transcribes the audio and generates the minutes entirely on your device, using on-device AI models (whisper.cpp for speech-to-text, llama.cpp / Gemma for the minutes). Your audio, transcripts and minutes are never uploaded to us or to any third party. We do not run analytics, advertising, or tracking SDKs of any kind, and we have no user accounts. A small backend, described in full in Section 4, is used strictly for two narrow purposes: verifying Verbamint Pro purchases, and preventing abuse of the free tier's daily limit. This section is not a substitute for the full policy below.
The following is created, processed and stored exclusively on your device, in the App's private storage, and is never transmitted to us:
None of this data is accessible to us. We have no technical means to view, retrieve or reconstruct it, because it never leaves your device unless you personally choose to export or share it (see 2.1).
Content leaves your device only when you explicitly export or share it, for example by sending a transcript, the minutes, or an MP3 through the Android share sheet, saving a file, or adding an event to your calendar. You choose the destination and the recipient each time; the App never uploads this content on its own initiative.
If you use the optional speaker diarization feature, the App analyzes the audio on your device to tell different speakers in a recording apart, and to let you label them. This process creates mathematical voice embeddings ("voiceprints") for each speaker it detects, including participants other than yourself. These voiceprints:
You can turn speaker diarization off at any time in the App's Settings, or disable it for a single meeting with the per-meeting speaker selector. When it is off, no voiceprints are created and new transcripts are produced as plain text. You can also copy, share, or save any transcript without speaker labels, even if it was originally diarized.
Because you are the one operating the App and deciding whose voice to record and diarize, you act as the party responsible (for example, as "controller" under GDPR, or as the collecting entity under biometric-privacy statutes) for any voiceprint created about a meeting participant other than yourself. See our Terms of Use for your responsibilities when recording and diarizing other people. We do not access, receive, or process these voiceprints in any way.
Outside of what you explicitly export, we collect only the following limited, purpose-specific data. We do not collect your name, email address, contacts, location, or any content of your recordings, transcripts or minutes.
| Purpose | Data sent | When |
|---|---|---|
| Verifying a Verbamint Pro purchase | The Google Play purchase token, the product ID, and a Play Integrity attestation token. | Only once, at the moment you complete a purchase (or restore one). |
| Preventing abuse of the free-tier daily limit | Your device's ANDROID_ID (a per-device, per-app identifier that is not tied to
your Google account, name, or email), a timestamp, and which free-tier feature was used
(recording, transcription, or minutes generation). |
Each time you use a free-tier feature that is subject to the daily limit. Not sent if you own Verbamint Pro, which is not subject to this limit. |
Both purposes are served by the same lightweight backend (a Cloudflare Worker that we operate). It has no database of user profiles, no analytics dashboard, and is not used for advertising, profiling, or any purpose other than the two described above.
Why we need this data: the free tier limits recording to about 30 minutes per
meeting, once per day, transcription to once per day, and minutes generation to once per day. Without a way to recognize a returning device,
this limit could be trivially reset by uninstalling and reinstalling the App, which would make the
limit meaningless and undermine the business model that funds the App's development. The
ANDROID_ID is the minimum data necessary to enforce this: it identifies the
installation, not you personally, and we deliberately avoided identifiers that would also tie to
your Google account, name, or advertising profile. If you would prefer this data not be sent at
all, purchasing Verbamint Pro removes the limit and stops this data from being collected,
permanently, going forward.
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with similar requirements, our legal bases are:
ANDROID_ID,
timestamp and feature flag for free-tier abuse prevention serves our legitimate interest in
preventing circumvention of usage limits, using the least intrusive means available and for the
shortest retention period practical (see Section 6). We have weighed
this interest against your rights and consider it proportionate because the identifier is
device-scoped, not linked to your identity, and is deleted within 24 hours.| Data | Retention |
|---|---|
| Purchase verification data (purchase token, product ID, Play Integrity token) | Processed in real time to verify your purchase with Google and to return a signed entitlement verdict to your device. Not persisted beyond what is technically required to complete that verification; the verdict itself is then stored only on your device. |
Free-tier abuse-prevention data (ANDROID_ID, timestamp, feature used) |
Automatically deleted no later than 24 hours after it is recorded. |
| Audio, transcripts, minutes, settings (on-device) | Retained on your device until you delete it. Uninstalling the App deletes all of it. |
We do not sell, rent, or share your data with third parties for their own marketing or advertising purposes. We use the following service providers, strictly as data processors acting on our instructions:
We do not use any other analytics, advertising, crash-reporting, or tracking service.
| Permission | Why we ask for it |
|---|---|
Microphone (RECORD_AUDIO) | To record your meetings. Never used for any other purpose, and never active unless you have started a recording. |
| Foreground service / notifications | To keep recording and on-device processing running reliably while the App is backgrounded or the screen is off, and to show you the status notification while this happens. |
Because the vast majority of your data never leaves your device, most of your rights are exercised directly within the App (deleting a meeting, deleting audio while keeping the text, or uninstalling to remove everything). For the limited data described in Section 4, you additionally have the right to:
To exercise any of these rights, contact us at the address in Section 11. We aim to respond within 30 days.
All network requests described in this policy are made over encrypted connections (HTTPS/TLS). On-device data benefits from the Android application sandbox; we do not implement any additional server-side storage of your content because none is ever transmitted to us.
Verbamint is not directed to children, and we do not knowingly collect data from anyone under the age of 13. If the digital consent age in your country is higher than 13 under applicable law (for example, 14 in Italy or 16 in Germany), that higher age applies to you instead. If you believe a child has provided us with data described in Section 4, see Section 11 to have it deleted.
We may update this policy as the App evolves. Material changes will be reflected by an updated "Last updated" date above; if a change is significant enough to affect your rights, we will make reasonable efforts to highlight it (for example, in the App's release notes). Continued use of the App after a change constitutes acceptance of the revised policy.
For any privacy question, request, or complaint, contact the Developer at: verbamint.app@gmail.com. We aim to respond to all legitimate requests within 30 days.