Skip to content

Privacy Policy

How Kalima collects, uses, and protects your personal data, and the controls you have over it.

Version 1.0 · Effective February 18, 2026

1. Introduction

Kalima ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our multilingual transcription and translation platform ("Service"). It complies with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Data Controller

The data controller responsible for your personal data is:

  • Kalima Labs UG (haftungsbeschränkt)
  • [Registered address: to be completed], Germany
  • Represented by its managing director (Geschäftsführer): [Managing director (Geschäftsführer): to be completed]
  • Company register: [Register court and HRB number: to be completed]
  • [VAT ID (USt-IdNr.): to be completed]

For questions or requests regarding your personal data, you can reach our data protection contact at [email protected]. We have not appointed a separate Data Protection Officer; this address reaches the team responsible for data protection.

3. Data We Collect

3.1 Account Data

When you register, we collect your name, email address, and authentication credentials. If you sign in via Google, we receive your Google profile information (name, email, profile picture).

3.2 Usage Data

We automatically collect information about how you use the Service, including session durations, features used, and performance metrics.

3.3 Audio Data

Audio streamed for transcription is processed in real time and is not stored permanently unless you explicitly choose to record and save a session. All audio processing occurs on EU-based servers for GDPR compliance.

3.4 Cookies and Similar Technologies

We use essential cookies for authentication and session management. Optional analytics and marketing cookies are only set with your explicit consent. See our cookie consent banner for details and controls.

We process your personal data on the following legal bases:

  • Contractual necessity - to provide the Service you have signed up for.
  • Consent - for optional cookies, marketing communications, and analytics.
  • Legitimate interest - for security, fraud prevention, and service improvement.
  • Legal obligation - to comply with applicable laws and regulations.

5. How We Use Your Data

  • To provide, maintain, and improve the Service.
  • To authenticate your identity and manage your account.
  • To process payments and manage subscriptions.
  • To send service-related communications (e.g., billing, security alerts).
  • To monitor and analyze usage patterns for performance and reliability (with consent).
  • To detect, prevent, and address technical issues and security threats.

6. Data Sharing and Third Parties

We share personal data only with service providers (processors) acting on our instructions, in the following categories:

  • Transcription processing provider - audio data for real-time speech-to-text, processed on EU servers.
  • AI processing provider - text data for summarization, chat, and translation features.
  • Cloud infrastructure provider - hosting and data storage in the EU.
  • Product analytics and session replay (PostHog) - product usage analytics, session replay, surveys, and feature flags, hosted in the EU and reached through our own reverse proxy. Loads only with your consent and stops when you withdraw it. Session replay is heavily masked (all text and form inputs are hidden) and is fully disabled on the Studio, transcript, and sharing pages, so no transcript or session content is ever recorded. PostHog may derive a coarse, country-level location from your IP address; it does not use your IP to identify you.
  • Error and performance monitoring (Sentry) - error reports, performance traces, and application logs, hosted in the EU (Germany). Sentry does not use session replay. We do not send your IP address or cookies to Sentry, and we identify you only by an internal account ID, never your name or email. It runs in production only, loads only with your consent, and stops when you withdraw it. A filter strips secrets and known content fields from every report before it leaves your device.
  • Authentication provider (Google) - only if you use Google sign-in.
  • Payment processor (Stripe) - for subscription and credit billing.

Some operational events, such as billing and subscription changes processed through Stripe, account signup, and the start or completion of a recording, are recorded on our servers using PostHog regardless of your cookie choice, because they originate from payment webhooks and background jobs that never see your browser. These events never contain transcript or AI content, are tied only to your internal account ID, and are processed as part of operating the Service and fulfilling our contract with you, not as consent-based analytics. We also use feature flags to decide which product features are enabled for your account; this is a functional decision about the product you receive, not tracking, and it may run even if you have declined analytics.

We do not sell your personal data to third parties, and we do not use your conversations to train AI models.

7. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. Deleted sessions and associated data are permanently purged within 30 days. You may request account deletion at any time.

8. Your Rights (GDPR)

As a data subject under the GDPR, you have the right to:

  • Access - request a copy of your personal data.
  • Rectification - correct inaccurate or incomplete data.
  • Erasure- request deletion of your personal data ("right to be forgotten").
  • Restriction - restrict processing of your data.
  • Data portability - receive your data in a structured, machine-readable format.
  • Objection - object to processing based on legitimate interest.
  • Withdraw consent - withdraw previously given consent at any time.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with a data protection supervisory authority.

9. International Data Transfers

All primary data processing occurs within the European Union. Where data transfers outside the EU are necessary (e.g., AI processing), we ensure adequate safeguards are in place, including Standard Contractual Clauses (SCCs) or equivalent mechanisms.

10. Data Security

We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS) and AES-256 encryption at rest, access controls, and regular security assessments.

11. Children's Privacy

The Service is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notification. The "Effective" date at the top indicates the latest revision.

13. Contact

For privacy-related questions, concerns, or requests, contact our data protection contact at [email protected].

Still have questions?

We're happy to walk you through any of this. Email [email protected] or reach the team directly.

Contact us