Legal
Terms, Conditions & Privacy Policy
The terms, privacy commitments, and core policies for using Taim.
Last updated / 27 July 2026
Terms and Conditions
Welcome to Taim ("we", "our", "us") a product by Kyrosphere Inc. These Terms and Conditions ("Terms") govern your access to and use of the Taim website, application, and related services (collectively, the "Services"). By accessing or using Taim, you agree to be bound by these Terms. If you do not agree, please do not use our Services.
1. About Taim
Taim is a digital product designed to help users manage their time, schedules, and productivity more effectively.
Taim is currently offered as a beta. Features may change, be interrupted, or be discontinued at any time while the Services are in beta.
2. Eligibility
You must be at least 18 years old (or the age of majority in your jurisdiction) to use Taim. By using the Services, you represent that you meet this requirement.
3. Account Registration
- You may need to create an account to use certain features of Taim.
- You are responsible for maintaining the confidentiality of your account credentials.
- You agree to provide accurate and up-to-date information.
4. Acceptable Use
You agree not to:
- Use Taim for any unlawful or fraudulent purpose.
- Interfere with or disrupt the security or functionality of the Services.
- Attempt to gain unauthorized access to our systems.
- Use the Services to capture, transcribe, or process the personal information of another person without the legal basis or consent required in your jurisdiction.
5. Intellectual Property
All content, trademarks, logos, and software associated with Taim are owned by or licensed to us and are protected by intellectual property laws. You may not copy, modify, distribute, or reverse engineer any part of the Services without our prior written consent.
6. User Content
If you submit content to Taim (such as schedules, notes, voice notes, transcripts, or preferences):
- You retain ownership of your content.
- You grant us a limited, non-exclusive, non-transferable license to host, process, and transmit it for the sole purpose of operating and supporting the Services for you.
- That license does not extend to training, fine-tuning, or evaluating artificial intelligence or machine learning models, whether ours or a third party's. See Section 10 of our Privacy Policy.
- The license terminates when you delete the content or your account, subject only to the limited retention described in Section 13 of our Privacy Policy.
7. Third-Party Services
Taim integrates with third-party services, including Google Calendar and Apple Calendar, to provide scheduling and time-management functionality.
By connecting these services, you authorize Taim to access, read, and write calendar data strictly as required to deliver core features such as scheduling, reminders, synchronization, and productivity insights. We request the narrowest permission scopes that allow those features to function.
We do not control and are not responsible for the content, policies, or practices of third-party services. Your use of Google Calendar or Apple Calendar remains subject to their respective terms and privacy policies.
8. Voice Notes, Recording, and Your Responsibilities
Taim allows you to capture voice notes. The microphone is accessed only when you explicitly start a capture in the app. Taim does not listen in the background and does not initiate a capture on its own.
Recording laws differ by jurisdiction. Many jurisdictions require the consent of one or all parties to a conversation before it may be recorded or transcribed. You are solely responsible for determining whether you may lawfully capture a given conversation and for obtaining any consent required. You agree to indemnify and hold us harmless from any claim arising out of your failure to do so.
9. AI Features and Outputs
Taim uses automated systems operated by third-party providers under contract to us to transcribe voice notes and generate summaries, tasks, reminders, and scheduling suggestions ("Outputs"). Transcription is performed by ElevenLabs; language model inference is performed by Anthropic and OpenAI. Sensitive identifiers are redacted before content is transmitted to these providers, as described in Section 9 of the Privacy Policy.
Outputs are generated probabilistically and may be incomplete, inaccurate, or unsuitable for a given purpose. You are responsible for reviewing Outputs before relying on them. Taim does not provide legal, medical, financial, or professional advice, and Outputs must not be treated as such.
We do not make decisions about you that produce legal effects, or similarly significant effects, solely by automated means.
10. Prohibited and Sensitive Data
Taim is a general-purpose productivity product. It is not designed, certified, or offered as a system of record for regulated data. You agree not to submit to the Services:
- Protected health information subject to HIPAA. We are not a HIPAA business associate and we do not enter into Business Associate Agreements.
- Payment card data subject to PCI DSS, other than through our payment processor.
- Government-issued identification numbers, financial account credentials, authentication secrets, or API keys.
- Classified, export-controlled, or similarly restricted information, or information subject to GLBA, FERPA, or comparable sector-specific regimes.
The redaction controls described in Section 9 of our Privacy Policy and Section C of our Data Processing and Security Addendum are a defense-in-depth measure. They are not a substitute for your compliance with this Section, and we disclaim liability for consequences arising from prohibited data you choose to submit.
11. Disclaimer
Taim is provided on an "as is" and "as available" basis. We do not guarantee that the Services will be error-free, uninterrupted, or meet your specific needs.
12. Limitation of Liability
To the maximum extent permitted by law, Kyrosphere Inc. and its officers, employees, and agents shall not be liable for any indirect, incidental, special, or consequential damages arising from your use of the Services. Our total aggregate liability for any claim arising out of or relating to the Services shall not exceed one hundred US dollars (USD $100) or the amount you paid us for the Services in the twelve months preceding the claim, whichever is greater.
13. Termination
We may suspend or terminate your access to Taim at any time if you violate these Terms or if we discontinue the Services.
14. Changes to These Terms
We may update these Terms from time to time. Continued use of the Services after changes become effective constitutes acceptance of the revised Terms.
15. Governing Law
These Terms are governed by and construed in accordance with the laws of the State of Delaware, USA, without regard to its conflict of law principles. Any dispute arising from these Terms or the Services shall be brought exclusively in the state or federal courts located in Delaware, and you consent to their jurisdiction.
16. Contact Us
If you have any questions about these Terms, contact us at:
Email: sofia@trytaim.com
Last updated / 27 July 2026
Privacy Policy
Your privacy is important to us. This Privacy Policy explains how Taim collects, uses, discloses, retains, and protects your information. Taim is operated by Kyrosphere Inc., a Delaware corporation, which is the data controller (and, under U.S. state privacy laws, the "business") for the personal information described in this policy.
The technical detail behind the commitments in this policy, including our processing pipeline, sub-processors, retention schedule, and security controls, is set out in the Data Processing and Security Addendum below. That Addendum forms part of this Privacy Policy.
1. Our Core Commitments
The sections that follow state our obligations in full. In summary, and as legally binding commitments:
Taim uses AI to turn what you say into notes, tasks and calendar events. Voice recordings are sent to ElevenLabs for transcription. Transcripts and calendar details are sent to Anthropic and OpenAI to write summaries, tasks and scheduling suggestions. None of them train on your data. This is the same disclosure shown in the app before you create an account.
- Audio is not kept. Voice note audio is processed transiently for the sole purpose of producing a transcript and is deleted once the transcript is created. We do not retain, archive, or build a library of your recordings, and neither does our transcription provider.
- We tell you who receives your data. Voice note audio is sent to ElevenLabs for transcription. Transcript excerpts are sent to Anthropic and OpenAI to generate summaries, tasks, and scheduling suggestions. These are the only AI providers that receive your content. The remaining sub-processor categories are listed in Section B of the Addendum.
- Sensitive information is redacted before it is sent. Before any content is transmitted to Anthropic or OpenAI, we apply automated detection and redaction to payment card numbers, bank account numbers, government identification numbers, passwords, authentication secrets, and API keys, and we strip your account identity from the request. The controls, and their limits, are described in Section 9.
- No model training, by us or by anyone else. Your content is never used to train, fine-tune, evaluate, or otherwise develop AI or machine learning models. This is enforced contractually against every provider in our pipeline and is not an opt-out setting you must find.
- No human reads your content. We do not permit human review of your voice notes, transcripts, or calendar content, except in the narrow circumstances described in Section 12.
- We do not sell or share your data. We do not sell personal information and do not share it for cross-context behavioral advertising or targeted advertising.
- Encryption throughout. Your data is encrypted in transit and at rest.
2. Categories of Information We Collect
- Account Information: name, email address, authentication identifiers, and account settings.
- Usage and Device Data: feature interactions, app version, device model, operating system, language, crash reports, and diagnostic logs. We derive approximate location from IP address for security, fraud prevention, and regional configuration.
- Location: if you grant location permission, we collect your precise device location and include it with the request you send to Ask Taim, so that answers about places near you are accurate. It is therefore part of the content sent to Anthropic and OpenAI as described above. Location is not collected when permission is denied, and you can revoke it at any time in your device settings.
- Calendar Data: information from Google Calendar and Apple Calendar that you explicitly authorize us to access, such as event titles, start and end times, descriptions, locations, attendee availability, and reminder settings.
- Voice Notes: audio you explicitly capture, and the transcript derived from it. See Section 4.
- User Content and Derived Outputs: notes, threads, tasks, reminders, and the summaries, extracted tasks, and scheduling suggestions Taim generates from them.
- Support Communications: messages you send us and the metadata attached to them.
- Payment Information: processed by our payment processor. We do not collect or store full payment card numbers.
3. Information We Do Not Collect
We do not collect biometric identifiers, voiceprints, or speaker-recognition templates. We do not perform voice identification, emotion inference, or any other biometric analysis of your audio. Audio is used only to produce text.
We do not access your contacts, photos, files, health data, or message history, and we do not use advertising identifiers or operate advertising SDKs in the app.
4. Voice Notes: Capture, Processing, Storage, and Deletion
Because voice input is the most sensitive category of information Taim handles, we describe its lifecycle specifically and in full.
Capture is always user-initiated. The microphone is engaged only after you affirmatively start a capture within the app. Taim contains no wake word, no always-on listening, and no background audio capture. Recording is visually indicated in the app for its entire duration, in addition to the indicator your operating system displays. You may stop or discard a capture at any point before it is processed.
Audio is processed transiently and is not stored. Audio is transmitted over an encrypted connection to our transcription provider, ElevenLabs, for the sole purpose of producing a text transcript. Once the transcript is produced, the audio is deleted. We do not write voice note audio to durable storage, do not back it up, and do not retain it after the transcript exists. ElevenLabs is contractually prohibited from retaining audio after returning the transcript and from using it to train or improve any model.
Only the transcript persists, and only for you. The transcript and anything you or Taim derive from it (summaries, tasks, reminders) are stored in your account, encrypted at rest, and accessible only to you and to those you choose to share them with. You may delete any transcript, individually or in bulk, at any time.
Redaction is applied before model processing. Before a transcript is sent to Anthropic or OpenAI to generate summaries, tasks, or scheduling suggestions, we apply the automated redaction and minimization controls described in Section 9. Sensitive identifiers are detected and removed or tokenized, only the narrowest excerpt needed for the feature is transmitted, and the request carries no account identity.
No training, no human review. Neither your audio nor your transcript is used to train or improve any model, ours or a third party's, and neither is reviewed by a human except in the narrow circumstances described in Section 12.
5. Calendar and Integration Data
Calendar data is used solely to provide the scheduling, conflict detection, reminder, and time-management features you have enabled. We request the narrowest OAuth scopes sufficient for those features.
Calendar data is never used for advertising, profiling for advertising purposes, resale, market research, or model training. It is not disclosed to any party other than the sub-processors listed in Section B of the Addendum, and only for the purpose of providing the Services to you.
You may disconnect any calendar integration at any time from within the app or from your Google or Apple account settings. On disconnection, we cease all further access and delete the calendar data we hold, subject only to the residual backup window in Section 13.
6. Device Permissions and Consent
Taim requests operating system permissions only for features you use, and each is optional. Where a permission is declined, Taim continues to function and the dependent feature is disabled rather than the app being blocked.
- Microphone — required to capture voice notes. Used only during an active, user-initiated capture.
- Calendar — required to read and write events for scheduling, conflict detection, and reminders. Declining it disables calendar-linked features; the rest of Taim remains available.
- Notifications — required to deliver reminders and nudges you have configured.
- Speech recognition — where on-device speech recognition is used to convert your capture to text.
Where Taim explains why a permission is needed before the operating system prompt appears, that explanation is informational only. It does not substitute for, gate, or condition the operating system prompt, and it does not record a decision on your behalf. The operating system prompt remains the sole place where permission is granted or refused.
You may grant or revoke any permission at any time in your device settings. Revoking a permission takes effect immediately and does not require any action in Taim. Revoking calendar access additionally triggers the deletion described in Section 5.
7. How We Use Your Information, and Our Legal Bases
We process personal information only for the purposes below. For users in the EEA, UK, or Switzerland, the applicable Article 6 GDPR legal basis is stated for each.
- To provide, operate, and maintain the Services, including transcribing voice notes and generating summaries, tasks, and scheduling suggestions — performance of a contract.
- To sync, analyze, and manage schedules across connected calendars — performance of a contract.
- To personalize your experience within your own account — performance of a contract.
- To secure the Services, detect and prevent fraud and abuse, and maintain audit logs — legitimate interests.
- To diagnose faults and improve reliability using aggregated or de-identified telemetry that does not include your content — legitimate interests.
- To communicate with you about your account, security, and support — performance of a contract and legitimate interests.
- To send optional product marketing, where required by law — consent, withdrawable at any time.
- To comply with legal obligations and respond to lawful requests — legal obligation.
We do not process your content for any purpose that is incompatible with providing the Services to you. In particular, we do not process it for advertising, profiling for advertising purposes, resale, benchmarking against other users, or model development.
8. Automated and AI Processing; Sub-Processors
Delivering Taim requires third-party infrastructure and model providers. Each such provider acts as our processor (or sub-processor) under a written data processing agreement that, at minimum:
- limits processing to the documented purpose of providing the service to us, and prohibits any independent or secondary use;
- expressly prohibits use of your data for training, fine-tuning, evaluating, or otherwise developing AI or machine learning models;
- prohibits human review of your content except as strictly necessary and permitted under Section 12;
- imposes confidentiality obligations, security requirements, breach notification duties, and deletion obligations on termination;
- where the provider offers it, applies a zero-data-retention configuration so that inputs and outputs are not retained by the provider after the response is returned;
- incorporates the European Commission Standard Contractual Clauses and the UK International Data Transfer Addendum where personal data is transferred out of the EEA or UK.
The AI providers that receive your content are named. Voice note audio is sent to ElevenLabs for speech-to-text transcription. Redacted transcript excerpts and calendar context are sent to Anthropic and OpenAI for language model inference, to generate summaries, tasks, and scheduling suggestions. No other AI provider receives your content. Which of the two model providers handles a given request depends on the feature and on availability; both are engaged under the terms above.
We use enterprise or commercial tiers of our AI providers, which are governed by the terms above, rather than consumer offerings whose default terms may permit training or extended retention. The remaining sub-processor categories, which support hosting, authentication, messaging, monitoring, and billing rather than AI processing, are listed in Section B of the Addendum. A current, fully named sub-processor list is available on request to sofia@trytaim.com. We will give notice of material sub-processor changes as described in Section 23.
9. Data Minimization and Redaction of Personal Identifiers
We apply automated controls designed to reduce the personal information that leaves our environment. Before content is transmitted to ElevenLabs, Anthropic, or OpenAI:
- We transmit only the content necessary for the requested operation. We do not transmit your account identity, email address, billing details, or authentication credentials to these providers, and requests are not associated with your real-world identity at the provider.
- We apply automated detection and redaction or tokenization to categories of sensitive identifiers, which include payment card numbers, bank account numbers, government-issued identification numbers, passwords, authentication secrets, and API keys.
- Where redaction would break the feature you requested, we minimize instead: transmitting the narrowest excerpt required rather than an entire transcript or calendar history.
- Requests are transmitted over encrypted connections and are not retained by us beyond what is needed to return the result to you.
Important limitation. Automated redaction is a defense-in-depth measure operating on unstructured natural language. It reduces risk; it cannot eliminate it, and we do not warrant that every sensitive identifier will be detected and removed in every case. It is not a substitute for your obligations under Section 10 of the Terms. Please do not dictate or enter payment card numbers, government identification numbers, credentials, API keys, or protected health information into Taim.
10. No AI or Machine Learning Model Training
We do not use your personal information, voice note audio, transcripts, calendar data, User Content, or derived Outputs to train, fine-tune, benchmark, evaluate, or otherwise develop or improve any artificial intelligence or machine learning model, whether operated by us or by any third party.
We do not permit any third party, including ElevenLabs, Anthropic, and OpenAI, to use your data for those purposes. This prohibition is imposed contractually on every provider in our processing pipeline and is enforced by agreement rather than left to a provider's default settings.
This commitment is not an opt-out preference and is not contingent on a setting you must locate and change. It applies to every user, on every plan, by default. We do not construct de-identified or aggregated derivatives of your content for model training either.
Nothing in this Section prevents us from using aggregated operational telemetry that contains no User Content and no personal information, such as counts of feature invocations, error rates, and latency measurements, to operate and improve the reliability of the Services.
11. No Sale of Personal Information; No Targeted Advertising
We do not sell, rent, or trade your personal information, voice notes, transcripts, or calendar data, and we do not disclose them to third parties for monetary or other valuable consideration, as those terms are defined under applicable law, including the California Consumer Privacy Act as amended by the CPRA. We have not done so in the preceding twelve months.
We do not share personal information for cross-context behavioral advertising or targeted advertising, and we do not engage in profiling in furtherance of decisions that produce legal or similarly significant effects. We do not operate advertising SDKs, and we do not use your content to build advertising or marketing profiles.
12. When Information May Be Disclosed
We do not disclose your content except in the following circumstances, each limited to what is necessary:
- To sub-processors that operate the Services on our behalf, under the contractual terms in Section 8, and only to provide the Services to you. The sub-processors that receive your content for AI processing are ElevenLabs (transcription), Anthropic, and OpenAI (language model inference); the remainder are listed in Section B of the Addendum.
- At your direction, including to services you connect and to people you choose to share content with. Content you share may persist with the recipient under their own policies.
- Where you ask for support and expressly authorize a named member of our team to access a specific item in order to diagnose the issue. Such access is time-limited, scoped to what you identify, and logged.
- For security investigation, where access is strictly necessary to investigate a suspected security incident, abuse, or violation of the Terms. Such access is authorized by our security lead, minimized, and logged.
- To comply with law, where we are legally compelled. We assess each request for validity, disclose no more than the request requires, and, where we are legally permitted, notify you before disclosure so that you may object.
- In a corporate transaction, such as a merger, acquisition, or sale of assets. Any successor remains bound by commitments no less protective than this policy, including Sections 10 and 11, and we will notify you before your data becomes subject to a materially different policy.
Outside these circumstances, no human at Kyrosphere Inc. or at any of our providers is permitted to read your voice notes, transcripts, or calendar content. Access to production systems containing user content is restricted, requires multi-factor authentication, and is logged and reviewed.
13. Data Retention and Deletion
We retain personal information only as long as necessary to provide the Services or as required by law. Specific periods are set out in Section D of the Addendum. In summary:
- Voice note audio is deleted once the transcript is produced and is not retained thereafter.
- Transcripts, notes, and calendar data are retained while your account is active or until you delete them.
- On deletion of an item, it is removed from active systems promptly and purged from encrypted backups within 30 days.
- On deletion of your account, we delete your personal information, transcripts, User Content, and calendar data from active systems within 30 days, and from encrypted backups within a further 30 days.
- Limited exceptions apply where retention is required by law, or is necessary to resolve a dispute, enforce our Terms, or preserve records subject to a litigation hold. Data retained under an exception is isolated from active processing.
You can delete individual items or your entire account at any time from within the app, or by emailing sofia@trytaim.com. Deletion is a purge, not a flag: deleted content is not recoverable by you or by us once the periods above have elapsed.
14. Data Security
We implement technical and organizational measures appropriate to the sensitivity of the information we process. These are described in Section F of the Addendum and include encryption of data in transit and at rest, least-privilege and role-based access control, multi-factor authentication for administrative access, secrets management, network isolation, and logging and monitoring designed to detect and respond to security events.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do commit to the incident notification obligations in Section 22.
15. Google API Limited Use Disclosure
Taim's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide or improve user-facing features that are prominent in the Taim interface; we do not transfer or sell it for advertising, credit assessment, lending, market research, or any other purpose unrelated to those features; we do not use it to develop, train, or improve generalized AI or machine learning models; and we do not allow humans to read it except with your affirmative consent for a specific item, as necessary for security purposes, to comply with applicable law, or where the data is aggregated and de-identified.
16. Apple Platform Data
Where you grant access to Apple Calendar or use Apple speech recognition, that data is used solely to provide the feature you invoked. We do not use data obtained through Apple frameworks for advertising, marketing, or model training, do not combine it with data from third-party data brokers, and do not disclose it other than as described in Section 12. Our use of Apple platform data complies with applicable Apple Developer Program requirements.
17. Your Privacy Rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you, and know how it is used.
- Correct inaccurate personal information.
- Delete your personal information.
- Receive a copy of your data in a portable, machine-readable format.
- Object to or request restriction of processing.
- Withdraw consent at any time, where processing is based on consent.
- Opt out of sale, sharing, targeted advertising, or profiling. We do not engage in these activities, so there is nothing to opt out of.
- Not be discriminated against for exercising any of these rights.
- Appeal a refusal of a rights request, where your jurisdiction provides for an appeal.
- Lodge a complaint with your local data protection supervisory authority, for users in the EEA, UK, or Switzerland.
To exercise any of these rights, contact sofia@trytaim.com. We will verify your request against your account and respond within the period required by applicable law, ordinarily within 45 days for U.S. state privacy law requests and within one month for GDPR requests, extendable where permitted with notice to you. An authorized agent may submit a request on your behalf with written proof of authorization.
18. International Data Transfers
We are based in the United States, and your information may be processed in the United States and other countries where our sub-processors operate. Where personal data is transferred from the EEA, UK, or Switzerland, we rely on the European Commission Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, and we carry out transfer impact assessments and apply supplementary measures including encryption in transit and at rest. A copy of the relevant transfer mechanism is available on request.
19. Sensitive Information and Prohibited Data
We do not intentionally collect sensitive personal information as defined by the CPRA or special category data as defined by Article 9 GDPR, and we do not use any such information to infer characteristics about you.
Because voice notes are unstructured, you may incidentally include sensitive details. Where you do, you direct us to process that content solely to provide the Services, subject to the redaction controls in Section 9. Taim must not be used for the categories of data prohibited by Section 10 of the Terms.
20. Cookies and Tracking
Our website uses strictly necessary cookies to maintain sessions and security, and privacy-respecting analytics to understand aggregate usage. We do not use advertising cookies, do not operate cross-site tracking, and do not sell information collected through cookies. Where required by law, we obtain consent before setting non-essential cookies. These technologies provide no access to your calendar or voice note content.
21. Children's Privacy
Taim is intended for users aged 18 and over and is not directed to children. We do not knowingly collect personal information from children under 13, or under the applicable minimum age in your jurisdiction. If you believe a child has provided us personal information, contact us and we will delete it promptly.
22. Security Incident Notification
We maintain a documented incident response process. In the event of a personal data breach, we will notify affected users and, where applicable, the relevant supervisory authorities without undue delay and within the timeframes required by applicable law, including within 72 hours of becoming aware where GDPR Article 33 applies. Our notification will describe the nature of the incident, the categories of data involved, the measures taken, and the steps you can take.
23. Changes to This Policy
We may update this Privacy Policy periodically. The "Last updated" date above reflects the most recent revision. Where a change materially reduces the protections described here, or materially expands how we use your information, we will notify you in the app or by email before the change takes effect, and where the law requires consent for the new use, we will obtain it. Continued use after a non-material change constitutes acceptance of the revised policy.
24. Contact Us
For any privacy question, rights request, or request for our named sub-processor list or transfer documentation, contact:
Kyrosphere Inc.
Email: sofia@trytaim.com
Last updated / 27 July 2026
Data Processing & Security Addendum
This Addendum forms part of the Privacy Policy above and describes, in technical terms, how Taim processes, transmits, retains, and protects your data. It is intended for users, security reviewers, and platform reviewers who need detail beyond the summary commitments in the Privacy Policy.
A. Processing Pipeline for a Voice Note
A voice note moves through the following stages. No other stage exists, and no stage writes audio to durable storage.
- 1. Capture. You explicitly start a capture in the app. The microphone is engaged only for the duration of that capture, with an in-app recording indicator visible throughout. Audio is held in a temporary buffer on your device.
- 2. Transmission. Audio is transmitted to ElevenLabs over TLS. It is not written to our own durable storage at any point.
- 3. Transcription. ElevenLabs converts audio to text and returns the transcript. Under our agreement, ElevenLabs may not retain the audio after returning the transcript, and may not use it for model training.
- 4. Audio deletion. Audio is deleted from temporary buffers on completion of transcription, or on failure. Nothing about the audio survives this stage.
- 5. Redaction and minimization. The transcript passes through the redaction controls in Section C before any onward model processing.
- 6. Understanding. The redacted, minimized excerpt is sent to Anthropic or OpenAI to extract tasks, summaries, and scheduling suggestions. Under our agreements neither provider may train on it, and, where the provider supports it, retains neither the input nor the output.
- 7. Storage. The transcript and derived outputs are stored in your account, encrypted at rest, scoped to your user identity, and deletable by you at any time.
B. Sub-Processors
Each sub-processor below is engaged under the contractual terms in Section 8 of the Privacy Policy. The AI providers that receive your content are named. A current, fully named list, including the vendors behind the remaining categories, is available on request to sofia@trytaim.com.
- ElevenLabs — speech-to-text transcription. Converts voice note audio to text. Contractually prohibited from retaining audio after transcription and from training on it.
- Anthropic and OpenAI — large language model inference. Generate summaries, tasks, and scheduling suggestions from redacted transcript excerpts and calendar context. Engaged on enterprise or commercial terms that prohibit training and, where offered, apply zero data retention. No other AI provider receives your content.
- Cloud infrastructure and database hosting — storage and compute for your account, transcripts, and User Content.
- Authentication and identity — account sign-in and session management.
- Transactional email and push notification delivery — account, security, and reminder messages.
- Error monitoring and product analytics — configured to exclude User Content, transcripts, and calendar content from captured payloads.
- Payment processing — billing. We do not receive or store full payment card numbers.
C. Redaction and Minimization Controls
Before content is transmitted to ElevenLabs, Anthropic, or OpenAI, we apply the following controls:
- Identity separation. Requests to these providers carry no account identifier, name, email address, billing information, or authentication credential. Your content is not linked to your real-world identity at the provider.
- Pattern-based detection and redaction. Automated detection targets payment card numbers, bank account and routing numbers, government-issued identification numbers, passwords and authentication secrets, API keys and access tokens. Matches are removed or replaced with non-reversible placeholders before transmission.
- Scope minimization. We transmit the narrowest excerpt sufficient for the requested operation, rather than entire transcript histories or full calendars.
- Purpose binding. Each request is bound to the single user-initiated operation that triggered it. We do not perform background or speculative model processing of your content.
- Transport security. All model provider requests use TLS.
Stated limitation. These controls operate on unstructured natural language and are probabilistic in nature. They materially reduce the personal information leaving our environment but cannot be guaranteed to detect every sensitive identifier in every case. They are a defense-in-depth measure, not a warranty, and not a substitute for the user obligations in Section 10 of the Terms.
D. Retention Schedule
- Voice note audio — deleted on completion or failure of transcription. Not persisted, not backed up.
- Transcripts, notes, tasks, derived outputs — retained until you delete them or delete your account.
- Calendar data — retained while the integration is connected; deleted on disconnection.
- Model provider inputs and outputs — not retained by us beyond returning the result; not retained by the provider where zero data retention is available.
- Account and billing records — retained for the life of the account, and afterwards only as required by tax and accounting law.
- Security and audit logs — retained up to 12 months, then deleted. These record access events, not content.
- Encrypted backups — rolling window; deleted content is purged within 30 days of deletion from active systems.
- Support correspondence — retained up to 24 months from resolution.
E. AI Provider Terms
We contract with our transcription and language model providers on enterprise or commercial terms, not consumer terms. Those agreements require, at minimum:
- no use of our or your data to train, fine-tune, evaluate, or otherwise develop any model;
- processing limited to returning the requested output, with no independent or secondary use of the input;
- zero data retention of inputs and outputs where the provider offers that configuration, and otherwise the shortest retention the provider makes available, limited to abuse monitoring;
- no human review of content except as required by law;
- confidentiality, security, breach notification, audit, and deletion-on-termination obligations;
- Standard Contractual Clauses and the UK International Data Transfer Addendum for transfers out of the EEA and UK;
- flow-down of equivalent obligations to any onward sub-processor the provider engages.
We do not send your content to any model endpoint not governed by an agreement meeting these requirements, and we do not use consumer AI products in our processing pipeline.
F. Security Controls
- Encryption in transit — TLS for all connections between the app, our services, and our sub-processors.
- Encryption at rest — user content, transcripts, and calendar data are encrypted at rest in our managed database and object storage, using industry-standard algorithms.
- Tenant isolation — content is scoped to your user identity and enforced at the data access layer. Cross-account access is not possible through the application.
- Access control — least-privilege, role-based access to production. Administrative access requires multi-factor authentication, is granted only where necessary, is reviewed periodically, and is revoked on role change or departure.
- Secrets management — credentials and API keys are held in a managed secrets store, never in source control, and rotated on personnel change or suspected exposure.
- Network isolation — production databases are not publicly reachable, and administrative interfaces are not exposed to the public internet.
- Logging and monitoring — access to production systems is logged and monitored for anomalies. Logs record access events, not content.
- Change management — code changes are reviewed before deployment, and dependencies are monitored for known vulnerabilities.
- Incident response — documented process covering detection, containment, eradication, recovery, notification, and post-incident review. See Section 22 of the Privacy Policy.
- Personnel — everyone with production access is bound by confidentiality obligations and is prohibited from accessing user content outside the circumstances in Section 12 of the Privacy Policy.
G. Data Residency
Data is processed in the United States. We do not currently offer regional data residency. Transfers from the EEA, UK, and Switzerland are governed by the mechanisms in Section 18 of the Privacy Policy.
H. Compliance Posture
Taim is in beta and operated by an early-stage company. We hold no third-party security certification at this time and do not represent that we are SOC 2, ISO 27001, or HIPAA certified. We describe the controls we actually operate, above, rather than implying certifications we do not hold. Should our posture change, we will update this Addendum.
I. Questions and Documentation Requests
For our named sub-processor list, data processing agreement, transfer documentation, or a security questionnaire, contact sofia@trytaim.com.
