Privacy.
This notice describes how Quendian ("we," "us," or "our") collects, uses, and handles
information when you use the Quendian macOS application or visit quendian.app.
We have written this in plain language because we believe you deserve to understand it.
Who we are
Quendian is an independent software product operated by Kapital Labs LLC. References to "Quendian," "we," or "us" in this notice refer to that entity.
Data the app transmits to third parties
Microphone and system audio
Quendian records audio only when you start a recording. It can capture your microphone and the audio playing through your Mac so it can create the transcript and summary you requested. macOS places access to system audio under its Screen Recording permission, even for an audio-only app. Quendian does not capture or upload screen images, video frames, window contents, the names of visible applications, keyboard input, or pointer activity.
Depending on the transcription option you select, recorded audio is uploaded either directly to the transcription provider configured with your own API key or through Quendian Cloud to its transcription provider. A resulting transcript may be sent to the summarization provider you select. When you use Ask Quendian, archive retrieval remains local, then your question and a bounded set of locally selected meeting passages are sent to the provider displayed in the app. These transfers happen only when you request the corresponding feature. Quendian does not use this data for advertising.
Bring your own key
In bring-your-own-key mode, audio is sent directly from your device to the transcription provider you configure using the API key you provide. The resulting transcript is sent directly to whichever summarization provider you configure in Preferences, such as a supported remote provider, a local Ollama instance, or another compatible endpoint. Ask questions and the selected supporting passages follow that same configured summarization route. Genuine local endpoints keep this processing on your Mac.
Quendian does not proxy bring-your-own-key requests. Your API keys and your data travel directly between your Mac and the provider you select. Each provider processes your data under its own privacy policy and terms of service, which we encourage you to review.
Quendian Cloud
Quendian Cloud is an optional paid subscription tier that provides hosted transcription, summarization, and evidence-backed answers without requiring your own API keys. If you use Quendian Cloud, additional data handling applies.
What we collect. When you create a Quendian account, we store your email address and a unique account identifier. We record usage counters, including transcription minutes, summarization usage, Ask request counts, token totals, provider route, and cost, to enforce quotas, calculate billing, and detect abuse. These counters do not contain your questions, meeting passages, transcripts, or generated answers. We receive payment metadata (subscription status, transaction identifiers, billing period) from our payment processor; we do not store full payment card details.
How your audio is handled. When you finish recording, the audio is uploaded from your Mac through our infrastructure to our transcription provider, who transcribes it and returns the transcript with speaker labels. Our transcription provider is contractually prohibited from using your audio or transcripts to train their machine-learning models. Audio is automatically deleted from their servers within 48 hours of upload; the transcript text is deleted within one hour. Quendian itself does not store the audio or the transcript on our servers. Both pass through in transit, and the finished transcript lands on your Mac.
How Ask Quendian is handled. Quendian builds and searches its lexical and semantic indexes on your Mac. It does not upload your archive to build those indexes. For each question, the app sends the question and no more than the bounded passages selected as possible evidence through Quendian Cloud to an inference provider. The gateway is configured to retain request metadata without storing prompt or response payloads. Quendian's application servers do not retain the question, passages, or generated answer. The inference provider may retain inputs and outputs for up to 30 days under its commercial API terms for abuse monitoring. The content is not used to train provider models. Ask history is stored locally on your Mac and can be cleared from the Ask window.
Sub-processors. To deliver Quendian Cloud, we engage third-party service providers in the following categories: authentication and identity services, AI inference providers, payment and subscription processors, cloud infrastructure, and crash diagnostics provider (Sentry). Each operates under a data processing agreement with us and is prohibited from using your data for purposes other than delivering the service.
Account deletion. You may delete your Quendian account at any time from Preferences → Account → "Delete account." Deletion removes your account record, usage history, and subscription from our systems. Local session data on your Mac is not affected. It belongs to you and remains until you choose to delete it.
Retention. Account and usage data is retained for a reasonable period to support billing, dispute resolution, and aggregate service analytics, after which it is deleted or anonymized.
Data the website collects
quendian.app uses Plausible Analytics, a privacy-first analytics service
that is cookieless, stores no personal identifiers, and collects only anonymized
aggregate statistics: page views, referral sources, and country-level geography. We do
not operate advertising pixels, run retargeting campaigns, collect email addresses, or
sell data. The site serves no ads.
Data we store
Quendian does not operate application servers that store your recordings, transcripts, summaries, Ask questions, selected evidence passages, or generated answers. Its internal session database is stored locally on your Mac in the application's sandboxed container. Before the first recording, Quendian requires you to choose an export location using the standard macOS folder picker. Each completed session is also written as a Markdown document in that user-selected folder. Quendian remembers the permission granted by that folder choice; if the folder is no longer accessible, it asks you to choose again before recording.
While a recording is active, Quendian writes a private local recovery copy of the captured audio inside its sandboxed application container. After transcription succeeds, that copy is deleted. If recording or transcription is interrupted, the local copy remains available so you can retry. It is deleted when processing succeeds or when you delete the session.
Ask questions and validated answers are retained in a separate local history file, bounded to the most recent 100 turns. The file stores opaque citation pointers rather than copies of the retrieved transcript passages. You can permanently clear this history without deleting your meetings. Local search and semantic indexes are derived caches and are not uploaded for indexing.
Crash diagnostics
Quendian can send anonymized crash reports to help us identify and fix bugs quickly. This is off by default and begins only if you opt in. You can turn it off at any time in Preferences > Privacy inside the app.
What we collect. When the app or our servers encounter an unexpected error: the crash itself (stack trace, function names, line numbers in our source code), the app version, the macOS version, and locale. We also collect a short timeline of the operations leading up to the error, for example, "started recording," "transcription failed," or "tier changed," using a fixed list of categories. On the server side, errors are tagged with a one-way hash of your account ID so we can identify recurring patterns and respond to support requests without storing your raw account identifier.
What we never collect. Transcripts, audio, recording titles, filenames, questions, selected passages, generated answers, file paths, API keys, email addresses, and IP addresses are never included in crash reports. We enforce this with both a typed allowlist at the source code level and a scrubbing pass before any event leaves your device or our server.
Sub-processor. Crash diagnostics are processed by Sentry (sentry.io/security), under a data processing agreement. Reports are retained for up to 90 days, after which Sentry deletes them.
Turning it off. Open Quendian → Preferences → Privacy → toggle "Send crash reports" off. New reports stop immediately. Reports already queued from before disabling may still be sent on the next launch.
Cookies and tracking
We do not set cookies on this website. Plausible Analytics operates without cookies or browser fingerprinting. No tracking of any kind persists between your visits.
Children's privacy
Quendian is not directed at children under the age of 13, and we do not knowingly collect personal information from children. If you believe a child has provided information in connection with our services, please contact us so we may address it.
Your rights
BYOK users who have not created a Quendian Cloud account: we do not store your personal data on our servers. Your data lives on your device and is subject to the policies of the third-party providers you elect to use.
Quendian Cloud account holders: you may request access to, correction of, or deletion of your account data by contacting us at [email protected]. You may also delete your account directly from Preferences → Account at any time.
If you have questions about exercising rights under applicable law (including GDPR or CCPA), we are happy to assist where we are able.
Changes to this notice
We may update this notice from time to time. The effective date below reflects the most recent revision. Continued use of Quendian after a change constitutes acceptance of the updated notice.
Contact
For privacy questions or concerns, contact us at [email protected].
Effective: 09-2026