Home

Policy change history

Every material change to the Privacy Policy and Terms of Service is recorded here. You are entitled to know what the policy said at the time you agreed to it.

This log begins on 2026-07-08.

Scheduled

Voluntary contribution to the Mongolian speech model

Duudlaga Flow begins training its own Mongolian speech recognition model. This is a voluntary setting that ships switched off for every user. We ask each person once — at registration, during onboarding, or on their next sign-in if they have not answered yet. For a user who agrees, only recordings made FROM THAT POINT FORWARD are included. Nothing recorded before they agreed is ever used, and no path exists in our systems to backfill older data into training.

  • Terms of Service §7

    The unconditional "we never use your audio or transcribed text to train our own AI models" is narrowed: not used by default, used only where a user has agreed, and then only for recordings made afterwards. Adds the right to withdraw and to delete what was contributed. Also states plainly that the training copy is readable by our training team while the copy in the user’s own history stays closed to us.

  • Privacy Policy §2

    Closes a reading in which the general word "improve" could have been taken to permit training: the word explicitly does NOT include training AI models, and the only case in which that happens is the voluntary opt-in described in section 3.

  • Privacy Policy §6

    Rewrites the unconditional "never used to train" sentence as a default. The promises never to sell, share, or publicly expose content are unchanged, as are all of the encryption provisions.

Read the full explanation
In force

Revision naming every third-party processor in full

The text currently in force. This revision names each processor in section 3 — Google (speech-to-text), OpenAI (text processing), Speechmatics (speaker separation, optional), and ElevenLabs or Google (speech generation, optional) — along with what each receives and its retention terms. Section 6 sets out application-level encryption, the separate per-user key, and the absence of any internal tool that can display user content.

  • Privacy Policy §3

    Names each provider, what it receives, and how long it retains it. Notes that Speechmatics’ own terms permit it to use resulting transcripts to improve its service, and that the feature is therefore off by default and chosen per file.

  • Privacy Policy §6

    Describes AES-256-GCM application-level encryption, the per-user key, the unique per-file key, and keeping the master secret outside the database.

In force

Encryption became the default; raw audio no longer stored

The revision that made privacy the default rather than an option. Transcripts, notes, and uploaded files became encrypted automatically and the old privacy code was removed. Raw dictation audio stopped being retained on our servers after transcription. Two permanent-deletion actions were added: "Clear my data" and "Delete account".

  • Privacy Policy §1

    Records that dictation audio is not retained after processing — only the resulting transcript remains, encrypted. Uploaded files stay encrypted until the user deletes them.

  • Privacy Policy §7

    Guarantees that a transcript, note, or file deleted in the app is permanently removed from our database and storage.

Read the full explanation
© 2026 Duudlaga Flow LLC