Skip to content
How it worksThe appProject memoryAI toolsYour data
Request beta access ↗

Legal

Privacy Policy

How the Loci beta handles the recordings, results and details you trust it with.

Effective date · August 12, 2026

Operator and controller

Loci is operated by David Lewenko, Alt-Karow 57, 13125 Berlin, Germany. David Lewenko is the data controller for the beta and public website. Contact: [email protected].

What Loci does

Loci records meetings and working sessions that you choose to capture, then creates transcripts, summaries, structured notes, source links for supported outputs, tasks, Project Memory, and chat answers. The current beta is single-user, device-token based, and does not provide team workspaces or cross-device sync.

Data we collect and use

Loci may process audio you choose to record, transcripts, generated results, notes, tasks, chat messages, project context, a per-install device credential, app and diagnostic metadata, optional calendar metadata, and beta-application details such as your email, work type, Mac compatibility, and optional project description. This data is used to provide the beta, keep your history available, answer your requests, provision approved beta access, prevent abuse, process deletion or export requests, and troubleshoot reliability.

If you opt in, Loci also collects anonymous product-usage events — a feature name and a coarse option only — to understand which product features are used. See Device identity, diagnostics and analytics below.

Your content

You retain the rights you hold in recordings and other content you submit. Loci does not claim ownership of that content. You give Loci only the limited permission needed to process it to operate, secure, and support the beta.

Storage, retention and deletion

This depends on when your copy of Loci was installed. Settings › Data and Privacy tells you which applies to your Mac.

Installs from 18 August 2026 onward. Your meeting history — recordings, transcripts, generated results, tasks, Project Memory, and related metadata — is stored in a Loci vault on your Mac and protected by the storage controls your Mac applies, including FileVault when you have it enabled. Loci keeps no durable copy on its servers: to create transcripts and generated results, selected data passes through Loci’s servers, and the working copy is deleted once your Mac confirms it has the result. If a Mac never collects a result, Loci deletes the server copy after 90 days. Because your Mac holds the only durable copy, keep a backup — Loci cannot restore your meeting history for you.

Earlier installs. Your history is still stored on Loci’s servers in Germany until it moves to your Mac. It remains there until then, or until you delete it or ask David to delete it, subject to legal and operational needs. Object-storage cleanup can complete separately after a deletion request, and temporary processing objects may follow separate cleanup schedules.

Processors and international transfers

Loci’s production API and object storage run on Hetzner infrastructure in Germany. Deepgram processes selected audio for speech-to-text, OpenAI processes selected data for generated results, and Cloudflare delivers the public website. Resend processes beta applications to send an operational alert to David. Resend’s primary processing is in the United States under its Data Processing Addendum and Standard Contractual Clauses. See the Resend DPA. PostHog processes anonymous product-usage events for Loci on PostHog Cloud EU, hosted in the European Union. These providers may process selected data outside Germany under their applicable processor and transfer terms.

Legal basis and your rights

Where applicable, Loci processes data to provide the service you request, pursue legitimate interests in operating and securing the beta, comply with legal obligations, and act on consent where consent is required. You can ask for access, correction, deletion, export, restriction, or objection by emailing [email protected]. You may also have the right to complain to a data protection authority.

Device identity, diagnostics and analytics

Loci uses a server-issued per-install device credential instead of account login. On macOS, the credential is stored in the macOS Keychain. A separate non-secret device-id marker is stored in local preferences and is also mirrored to iCloud key-value storage, so that reinstalling Loci on the same Mac, or setting up a replacement Mac from the same Apple Account, can recognise the same device id. The credential itself is never mirrored to iCloud. If you use Send Feedback, Loci may receive app version, build number, environment, a recording identifier, recent process logs, and diagnostic references needed to investigate the issue.

Product analytics in the app is opt-in and off by default. Only when you turn on the "Share anonymous usage statistics" toggle does the app send anonymous product-usage events to PostHog — a feature name and a coarse option only, never audio, transcripts, titles, or search text — tied to a random install-scoped identifier that is not linked to your device credential. The opt-in covers these product-analytics events; the content-free reliability signals described in this policy are separate and unaffected. The public website uses cookieless, anonymous analytics that store no persistent identifier in your browser.

Connecting Loci to another app

Loci can give an editor or AI client running on the same Mac read-only access to your sessions, project context, and tasks, through a connection you create and can revoke in Settings. Audio is never exposed this way.

Once you authorize a client, that client can send the text it receives to whichever model provider it is configured to use, and can keep it in its own chats, logs, and history. Loci cannot determine or control which provider a client selects. To remove that content, revoke the connection in Loci and delete the related history in that client or provider.

The configuration Loci generates contains a reusable connection secret in plain text. Anyone who can read that file, including software running as you, can use the granted access until you revoke it. Semantic search sends your search query to Loci’s configured embedding provider; if that is unavailable, Loci falls back to local keyword search.

Recording consent

You are responsible for using Loci only where recording is lawful and appropriate, including telling participants and obtaining consent when required.

Contact

For privacy, deletion, export, or support requests, email [email protected].

Operator and controllerWhat Loci doesData we collect and useYour contentStorage, retention and deletionProcessors and international transfersLegal basis and your rightsDevice identity and diagnosticsConnecting Loci to another appRecording consentContact

Know where the work stands.
Know what moved it.

Request beta access
ProductHow it worksThe appProject memorySource evidenceAI tools
LociYour dataPrivacyTermsLegal notice (Impressum)
Contact[email protected]David LewenkoBerlin, Germany
Free during the beta© 2026 Loci