Privacy Policy for SpeechCatcher

September 1, 2026

·Français

1. Introduction #

1.1. Who We Are and What This Policy Covers

This Privacy Policy describes how Speech Metrics ("we," "us," or "our") handles information in connection with the SpeechCatcher iPad application and the associated cloud platform (collectively, the "Service" or "SpeechCatcher").

This policy applies to all users of our Service, which includes licensed Speech Language Pathologists and other qualified healthcare professionals ("Providers") who subscribe to the Service, as well as their Clients whose speech productions may be recorded using the Service ("Clients").

This document is designed to provide transparent information about our privacy practices in a format that is concise, intelligible, and easily accessible, using clear and plain language as required by global data protection standards. It outlines what information we process, why we process it, and the rights and choices available to you regarding your information.

1.2. Our Commitment to Your Privacy: The "Zero-Knowledge" Promise

The foundation of our Service is a steadfast commitment to the privacy and confidentiality of the sensitive information entrusted to it. We have engineered our Service on a "zero-knowledge" architecture using state-of-the-art end-to-end encryption (E2EE).

This means:

  • All data, including client information, audio recordings of therapy sessions and metadata (collectively "Session Data") are encrypted directly on the Provider's device before they are transmitted or stored.
  • The cryptographic keys required to decrypt this Session Data are held exclusively by the authorized users (the Provider and, if applicable, the Client) and are never shared with or accessible by Speech Metrics.
  • As a result, we cannot listen to, view, or otherwise access the content of any therapy session. We process your Session Data as an opaque, unreadable, and securely sealed container of information.

This architectural choice is a deliberate one, designed to ensure that the confidentiality of the Provider-Client relationship is technically and programmatically protected. By leading with this promise, we aim to provide immediate assurance that your most sensitive data remains private, accessible only to those you authorize. This approach moves beyond simple compliance to build a foundation of trust, proactively addressing the primary privacy concern associated with health-related communications.

2. Information We Process #

To provide our Service, we must process certain categories of information. We are committed to the principle of data minimization, meaning we only collect and process information that is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.

2.1. Information You (the Provider) Provide Directly

When a Provider registers for and uses the Service, we collect information necessary to establish and maintain a professional account. This includes:

  • Account Information: Your full name, email address, and your chosen data region. Authentication credentials are handled by our identity provider (Firebase Authentication, operated by Google LLC) and are never visible to Speech Metrics. You may sign in with an email and password, with Sign in with Apple, or with Sign in with Google; when you use a federated sign-in option the identity provider verifies you with Apple or Google and shares only the information you authorize (typically your name and email address). If you use Apple's "Hide My Email" feature, we receive a private relay address rather than your personal email.
  • Payment Information: Subscriptions purchased through the iPad application are billed by Apple Media Services via Your Apple ID account. Apple handles Your billing address and payment card details directly; Speech Metrics does not collect, see, or store this information. We use RevenueCat as our subscription-management platform; through RevenueCat we receive an Apple subscription identifier, the product purchased, the purchase and renewal dates, and Your current entitlement status, so that we can grant or revoke access to subscriber features. We do not receive payment card numbers, CVV codes, or billing addresses.
  • Communications: If you contact us for customer support or other inquiries, we will collect the content of those communications, including your name, email address, and any other information you choose to provide.

2.2. Information We Process on Your Behalf (Encrypted Session Data)

When a Provider uses the Service to record a therapy session, the primary data generated is the Encrypted Session Data. This category includes:

  • Encrypted Audio Recording: The audio file of the therapy session, which is immediately encrypted on the recording device.
  • Encrypted Metadata: Associated information such as the date, time, and duration of the session, which is also encrypted alongside the audio.

We process this Encrypted Session Data solely as a Data Processor (under GDPR) or Business Associate (under HIPAA) on behalf of the Provider. Our role is strictly limited to facilitating the secure storage and transmission of this encrypted "container" of information as directed by the Provider. We have no technical means to access the content within this container.

2.3. Information We Do Not Collect or Access

To reinforce our "Zero-Knowledge" promise, we explicitly state that we do not engage in the following activities:

  • We do not listen to, transcribe, or analyze the content of your audio recordings.
  • We do not access or process any Client health information contained within Session Data.
  • We do not share the content of your sessions with any third parties.
  • We do not use the content of your sessions for advertising, marketing, or any other purpose.

Disclosing what is not collected is a critical component of transparency and helps to build user trust by eliminating ambiguity about our data practices.

2.4. Information Collected Automatically (Usage and Device Data)

In the SpeechCatcher iPad application, we collect a limited amount of technical information when you explicitly opt in to analytics. Application analytics are disabled by default and activate only after you provide consent through the Analytics Consent screen in SpeechCatcher. You may withdraw your consent at any time through the application settings. This category includes:

  • Device Information: The type of device you are using, its operating system version, and unique device identifiers.
  • Usage Analytics: We use PostHog, a product analytics platform, to collect information about how you interact with the Service. This includes events related to test administration (starting, completing, and cancelling tests), test navigation (advancing between screens), target tracking (marking speech targets as produced), record validation, report generation, client management (creating and updating client records), content downloads, and user feedback submission. Each event includes the screen where it occurred and the application environment. No client names, session content, assessment data, or audio recordings are included in analytics events.
  • Error Tracking: PostHog automatically captures application errors, including uncaught exceptions, unhandled promise rejections, and console output at the error, warning, info, and log levels. Error reports may include diagnostic information from log messages that were written by the application. We do not intentionally log Client identifiers, audio content, or other Encrypted Session Data content.
  • Log Data: When you use our Service, our servers automatically record information, which may include your Internet Protocol (IP) address, the date and time of your requests, and data related to application crashes or errors.

Crucially, this automatically collected data is processed in a way that is never linked to the content of your Encrypted Session Data. It is used for operational purposes only. No user identification is performed through analytics; all analytics events are captured anonymously.

2.5. Tracking Technologies and Identifiers

The Service uses the following persistent identifiers and tracking technologies on Your device or within third-party services we engage:

  • Apple Identifier for Vendor (IDFV): Provided by iOS, this identifier is common across all Speech Metrics apps on Your device and is used solely for device-scoped diagnostics. It is not used for cross-app tracking.
  • RevenueCat App User ID: An anonymous identifier maintained by RevenueCat so We can synchronize Your subscription entitlement across devices. It is not used for advertising or cross-app tracking.
  • Firebase Installations ID: A pseudonymous identifier assigned by Firebase Authentication and used to associate Your device with Your account for secure server-to-device communication.
  • PostHog Distinct ID: Assigned in the iPad application only when You opt in to analytics; used to join analytics events from the same install into a single session for debugging and product-improvement purposes.
  • Web Cookies (marketing site only): The speechcatcher.ca marketing website uses only strictly necessary cookies required to operate the site. We do not place advertising or cross-site tracking cookies.

App Tracking Transparency (ATT): The iPad application does not engage in tracking as defined by Apple's App Tracking Transparency framework. We do not link user or device data collected within the Service to user or device data collected in third-party apps or websites for advertising or advertising-measurement purposes, and We do not share user or device data with data brokers. Accordingly, the application does not present an App Tracking Transparency prompt.

2.6. Information Processed Through the speechcatcher.ca Website

The speechcatcher.ca marketing website processes the limited information You submit through its forms, a browser-side language preference, and cookieless page-view analytics. Specifically:

  • Mailing-list signup: When You subscribe to product updates, We require and store Your email address, first name, and last name. Comments are optional. Cloud Firestore (a Firebase service operated by Google LLC) stores these fields, a server-generated subscription timestamp, and the status needed to synchronize the Signup with Mailtrap. Mailtrap receives the same contact fields so We can send the product updates You requested. You may ask us to remove this information at any time by emailing support@speechcatcher.ca.
  • Support requests: When You submit the support form, We process Your name, email address, selected issue category, message content, the page language at submission, and—if You choose to provide them—an alternate account email, Your iPad model, Your iPadOS version, and Your SpeechCatcher app version. A Speech Metrics Cloud Function records the request and its delivery status in Cloud Firestore before Mailtrap processes the staff request and acknowledgement emails. Support records are retained only as long as needed to resolve Your request and meet our record-keeping obligations.
  • Website analytics: When configured, the website sends page views, page exits, referral information, and campaign parameters to PostHog automatically. This website configuration is separate from the in-app Analytics Consent setting. It always uses PostHog's cookieless mode: it does not set cookies, use localStorage or sessionStorage, create person profiles, autocapture interactions, record sessions, or capture application exceptions. PostHog derives a privacy-preserving hash on its servers to group anonymous events for a limited session.
  • Language preference: If You use the in-page language switcher to choose between English and French, the website saves Your selection as preferred-locale in Your browser's localStorage so subsequent visits open in the same language. This value remains on Your device, is not transmitted to our servers, and can be cleared at any time through Your browser's site-data controls.

The website does not require an account, store visitor profiles, or place advertising or cross-site tracking cookies. Its cookieless analytics do not change Your saved language preference.

3. How and Why We Use Your Information (Purpose of Processing) #

Every piece of information we process is tied to a specific, explicit, and legitimate purpose. This mapping is a core requirement of data protection law and ensures we do not use your data beyond what is necessary and disclosed.

Purpose of ProcessingDescriptionData Categories Used
Service Provision and Account ManagementTo create and maintain your account, authenticate you as a user, process payments, and provide the core functionality of the Service.Account Information, Professional Verification Information, Payment Information.
Secure Storage and TransmissionTo securely store, manage, and transmit the Encrypted Session Data as directed by you, the Provider.Encrypted Session Data.
Customer SupportTo respond to your inquiries, provide technical assistance, and resolve issues.Account Information, Communications, Usage and Device Data.
Service Improvement and AnalyticsTo understand how our Service is used, identify areas for improvement, develop new features, and enhance usability.Usage and Device Data.
Security and Fraud PreventionTo protect the integrity of our Service, monitor for malicious activity, prevent security breaches, and enforce our terms of service.Account Information, Usage and Device Data, Log Data.
Legal and Contractual ObligationsTo comply with applicable laws, regulations, legal processes, and to fulfill our contractual obligations to you.Account Information, Payment Information, Communications.

For individuals in the European Economic Area (EEA), the United Kingdom (UK), and Switzerland, we process personal data based on the following lawful bases as defined under the General Data Protection Regulation (GDPR):

  • Performance of a Contract: We process Provider Account Information, Payment Information, and Encrypted Session Data because it is necessary to perform the service contract we have with our Providers. This includes creating their account and providing the core recording, storage, and transmission features they have subscribed to.
  • Legitimate Interests: We process Usage and Device Data and Log Data based on our legitimate interest in maintaining a secure, functional, and reliable Service. We also rely on legitimate interests to communicate with Providers about important service updates. We have balanced these interests against your data protection rights and have concluded that our processing is necessary and does not override your fundamental rights and freedoms.
  • Consent: For any processing activities that are not essential for service delivery, such as non-essential analytics cookies or marketing communications, we will rely on your explicit consent.
  • Processing on Behalf of a Controller: For the Encrypted Session Data, which contains "special categories of personal data" (i.e., data concerning health) under Article 9 of the GDPR, we act as a Data Processor. The Provider is the Data Controller. The Provider is responsible for establishing a lawful basis for processing this sensitive data, which will typically be the explicit consent of the Client. Our policy requires Providers to certify that they have obtained all necessary consents from their Clients before using our Service to record sessions. Section 5 describes how that consent is collected, recorded, and withdrawn.

This clear delineation of roles is a critical aspect of GDPR compliance. As a Processor, we are bound by our contractual agreement with the Provider to protect the data and only process it according to their instructions. The Provider, as the Controller, retains primary responsibility for the data and for ensuring that Client rights are upheld.

Before a Provider may record a Client with SpeechCatcher, the Provider must obtain Recording Consent. This section explains what a Recording Consent record contains, who holds it, how long it is kept, and how it can be withdrawn. In the SpeechCatcher Recording Consent form the Provider is called the Clinician, and the person who gives consent — the Client, or a parent, legal guardian, or other authorized representative acting for the Client — is called the Consenting Party.

The Service will not start an audio recording for a Client unless a Recording Consent is in force for that Client at that moment.

5.1. What a Recording Consent Record Contains

A Recording Consent record is a dated history of the consent decisions made for one Client. Each decision is stored as its own entry, so the record shows both the consent that is in force today and every consent that came before it. The record contains:

  • The grant. The consent decision itself: the date it was accepted and the date it takes effect, the Client it applies to, the name of the responsible Clinician, the name of the Consenting Party and their relationship to the Client (the Client themselves, a parent, a legal guardian, or another authorized representative), and whether Research Consent was also given.
  • The terms. Where the consent form built into SpeechCatcher was used, the record stores the version of that form, the language it was presented in, and the version of this Privacy Policy that the form referred to. Where a Provider's own paper or electronic form was used, the record stores the Provider's reference for that form and its version, together with the Provider's confirmation that the form covers recording, retention, processing, and analysis.
  • The evidence. One or more of the following, depending on how consent was collected: a signature drawn in the application by the Consenting Party; a photograph, scan, or PDF of a signed form completed outside the application, stored with a checksum so that later alteration can be detected; or a Clinician attestation — the Provider's dated confirmation that a signed written consent exists in the Client's clinical record, stored together with the exact wording that was attested to and, where the Provider supplies one, a reference to where that consent is filed.
  • Withdrawals. Where consent has been withdrawn, the record stores the date the withdrawal takes effect, the name of the person withdrawing consent and their relationship to the Client, and the version of the withdrawal acknowledgement they were shown.
  • Replacements. Where a new consent replaces an earlier one — because the form changed, because the earlier consent was withdrawn, or because the scope changed — the new entry records which earlier grant or withdrawal it replaces. Nothing is overwritten, so the sequence of decisions remains auditable.

Recording Consent records, including drawn signatures and uploaded copies of signed forms, are encrypted on the Provider's device in the same way as Encrypted Session Data. Speech Metrics stores them but cannot read them.

5.2. The Versioned Consent Form

The Recording Consent form built into SpeechCatcher carries a version identifier. Every grant records the exact form version and language that the Consenting Party was shown, and that version is retained with the grant. If We materially change the wording of the form, consents that were given under an earlier version can be marked as requiring renewal, and the Provider is prompted to collect consent again on the current wording. A consent collected on an earlier version is never silently treated as consent to new wording.

5.3. Who Holds the Consent Record

The Provider is the data controller (in Mexico, the responsable; in Brazil, the controlador) for Recording Consent records, as they are for the rest of the Client's clinical record. The Provider decides what consent is sought, collects it, and is responsible for its validity under the law that applies where the Client is located.

Speech Metrics acts only as a data processor (encargado, operador) for these records. We store and synchronize them on the Provider's instructions, in encrypted form. We cannot read the identity of a Consenting Party, the content of a signature, an uploaded consent form, or whether Research Consent was given. We therefore cannot verify consent on a Provider's behalf and cannot answer questions about a particular Client's consent; those questions must be directed to the Provider.

5.4. Research Consent

Recording Consent covers the clinical use of a recording: capturing it, keeping it with the Client's clinical record, processing it to support transcription and assessment, and analyzing it to produce clinical results and reports. It does not cover research.

Where a Provider conducts research, the SpeechCatcher consent form offers a separate, optional Research Consent. It is presented as a distinct choice, it is declined by default, and declining it has no effect on the Client's care, on the assessment, or on the Recording Consent itself. Where consent was collected outside the application, a Provider may instead attest separately that research consent was obtained; that attestation records the wording that was attested to.

Research carried out with these recordings is conducted by the Provider, under the Provider's own controllership and under whatever research ethics approval applies to that research in the Provider's jurisdiction and institution. Speech Metrics does not conduct research on Client recordings, does not receive them in readable form, and is not a party to any research use of them. Obtaining and documenting ethics approval, and confirming that a proposed research use falls within the scope of the consent that was given, are the Provider's responsibility.

5.5. Withdrawing Consent

Recording Consent and Research Consent can be withdrawn independently of each other:

  • Withdrawing Recording Consent stops any further audio recording for that Client. It can be done in the application with the Provider, or by asking the Provider to record the withdrawal. The withdrawal is stored with the date it takes effect and remains part of the consent history.
  • Withdrawing Research Consent alone leaves clinical recording in place. It is stored as a replacement consent covering clinical use only, so the Client's care and assessment continue uninterrupted while research use stops.

Withdrawal governs what happens next. It does not by itself delete recordings that were made while consent was in force, because those recordings form part of a clinical record that the Provider may be legally obliged to keep. A request to delete existing recordings, or to stop using recordings that have already been collected for research, is a separate request and must be made to the Provider, who will act on it subject to their own record-keeping obligations. The rights available to you, and how to exercise them, are set out in Section 8.

5.6. Retention of Consent Records

A consent record is the Provider's evidence that recording was authorized, so it is kept for at least as long as the recordings it authorizes. The Provider retains a Recording Consent record — including its evidence, its withdrawals, and the form version that was signed — for as long as the Client's clinical record is retained under the health-record-retention law and professional guidelines that apply to the Provider, plus any limitation period during which a claim relating to that care could still be brought. As with Encrypted Session Data, the Provider determines the retention period and controls deletion, and Speech Metrics retains these records solely at the Provider's direction (see Section 7.2).

6. Data Sharing and Disclosure #

We do not sell your personal information. We limit the sharing of your information to the specific circumstances described below:

  • Third-Party Service Providers (Sub-processors): We engage a limited number of third-party companies to perform functions on our behalf. These include:
    • Cloud Hosting Provider (Google LLC, through the Firebase platform): All Service infrastructure runs on Google's Firebase platform, comprising Cloud Firestore (structured data), Cloud Storage for Firebase (Encrypted Session Data audio files), Cloud Functions (server-side logic), and Firebase Authentication. At account creation You choose a data residency region, which determines where Your data is stored and processed: North America (Firebase region us-east1), European Union (Firebase region europe-west1), or Australia (Firebase region australia-southeast1). The hosting provider stores Encrypted Session Data but is contractually and technically prevented from accessing the content of that data.
    • Identity and Authentication Provider (Firebase Authentication, operated by Google LLC): Manages account authentication, including email and password sign-in and the federated Sign in with Apple and Sign in with Google flows. The identity provider stores authentication identifiers and, for email/password accounts, a hashed credential. It does not receive any Encrypted Session Data or its decryption keys.
    • App Store Billing (Apple Media Services, operated by Apple Inc.): Subscriptions purchased through the iPad application are billed by Apple through Your Apple ID account. Apple handles all payment information directly under its own terms and privacy policy.
    • Subscription Management (RevenueCat, Inc.): We use RevenueCat to validate App Store receipts, synchronize subscription state across Your devices, and determine entitlement to subscriber features. RevenueCat receives an Apple subscription identifier, product identifier, purchase and renewal timestamps, and an anonymous user identifier. RevenueCat does not receive payment card information or Encrypted Session Data.
    • Email and Contact Processing (Mailtrap): Mailtrap stores mailing-list contact fields and processes Support Request and acknowledgement emails on our behalf. It does not receive Encrypted Session Data.
    • Analytics Services (PostHog): We use PostHog for in-app usage analytics and error tracking as described in Section 2.4, and for the limited cookieless website analytics described in Section 2.6. PostHog processes this data on our behalf under a data processing agreement that requires confidentiality and security. In-app analytics require your explicit consent. The website's cookieless page-view analytics run automatically when configured and do not use the in-app consent setting.
  • Legal Requirements: We may disclose your information if we are required to do so by law, or if we believe in good faith that such disclosure is necessary to comply with a legal obligation, such as a court order or subpoena. In such a scenario, it is important to note that for Encrypted Session Data, we can only provide the encrypted, unreadable data file, as we do not possess the keys to decrypt it.
  • Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.

7. Data Security and Retention #

7.1. Our Security Measures: End-to-End Encryption Explained

We take the security of your data extremely seriously and have implemented robust technical and organizational measures to protect it. Our primary security control is End-to-End Encryption (E2EE).

Think of E2EE like sending a letter in a locked box. You, the sender, lock the box with a key that only you have. You then create a copy of that key and securely give it to the intended recipient. The postal service can transport the box, but they cannot open it. Only the recipient, who has the duplicate key, can unlock the box and read the letter.

In our Service, this works as follows:

  1. Encryption: When a session is recorded, the audio data is immediately scrambled on the Provider's device into an unreadable format called ciphertext, using a strong encryption algorithm like AES-256.
  2. Transmission: This encrypted ciphertext is transmitted to our servers for storage. At no point during this transmission can anyone—including us, our hosting provider, or any third party—read the data.
  3. Decryption: The data remains encrypted while stored on our servers. It can only be decrypted and turned back into readable audio on a device that possesses the correct decryption key—namely, the Provider's authorized device(s).

In addition to E2EE, we employ other security measures, including access controls to limit internal access to data, regular security assessments, and employee training on data protection.

7.2. Data Retention Periods

We retain different categories of data for different periods, guided by the principle of storing data only for as long as is necessary.

  • Provider Account Data: We retain this information for as long as the Provider's account remains active. After an account is closed, we may retain some information for a limited period to comply with legal, financial, and tax obligations.
  • Encrypted Session Data: As the Data Controller and Covered Entity, the Provider is responsible for determining the retention period for this data. Healthcare record retention requirements vary by jurisdiction and professional guidelines (e.g., HIPAA requires records to be kept for a minimum of six years). Our Service provides Providers with the tools to manage and delete their Encrypted Session Data in accordance with their own legal and professional obligations. We retain this data solely at the direction of the Provider.
  • Recording Consent Records: As with the recordings they authorize, the Provider is responsible for determining the retention period for Recording Consent records, their evidence, and any withdrawals. A consent record is normally kept for as long as the Client's clinical record is kept under the law and professional guidelines that apply to the Provider, plus any limitation period during which a claim relating to that care could still be brought (see Section 5.6). We retain these records solely at the direction of the Provider.
  • Usage and Device Data: We retain this data for a limited period, typically 18–24 months, as needed for security, analytics, and service improvement purposes. After this period, the data is either deleted or anonymized.

This retention policy directly addresses the potential conflict between regulations like GDPR, which grants a right to erasure, and HIPAA, which mandates long-term record-keeping. By empowering the Provider—the party with the legal and ethical obligation to their Client—to control the data's lifecycle, we ensure that these complex requirements can be properly managed.

7.3. Account Deletion

You may delete Your Provider account at any time from within the iPad application by navigating to Account > Delete Account. Deleting Your account terminates Your subscription entitlement on our side (Apple-billed subscriptions must be cancelled separately through Your Apple ID account settings), removes Your Provider Account Data from active systems, and initiates deletion of Your Encrypted Session Data subject to the retention rules described above and to Your obligations under applicable health-record-retention law. If You are unable to access the in-app deletion control, You may contact privacy@speechmetrics.ca and We will process Your deletion request manually. We may retain a limited subset of account information for the period required to comply with legal, financial, and tax obligations.

7.4. Fulfilling a Client's Data Access Request

Because Encrypted Session Data is held under End-to-End Encryption, only the Provider can produce a human-readable copy of a Client's records. The iPad application provides a built-in tool for this purpose:

  1. Open the application and navigate to the Clients tab.
  2. Select the Client whose records you intend to disclose.
  3. In the header at the top of the Client screen, tap the More options menu (the three-dot icon), then choose Data access request.
  4. Read the on-screen confirmation, which describes what the export contains and the safety implications of producing an unencrypted copy of Client data.
  5. Optionally enter a password. When a password is supplied, the resulting archive is encrypted with AES-256 and the recipient will need the password to open it. The same password must be entered twice to guard against typing errors. Leaving the password fields blank produces an unencrypted archive.
  6. Tap Continue. The application gathers the Client's profile, assessments, sessions, transcribed records, generated reports (as PDF), and on-device session recordings (as audio files), and packages them as a single .zip file.
  7. When the system share sheet appears, choose how You wish to deliver the archive to the Client (for example, via secure email, an end-to-end encrypted messaging service, or a managed file-transfer system in keeping with Your organisation's policies).

The resulting archive contains Protected Health Information in plaintext form. The Provider remains the Data Controller and Covered Entity for the exported file and is responsible for ensuring it is delivered through a channel appropriate to the sensitivity of the data and to applicable legal and professional obligations. When a password is used, We recommend communicating the password through a channel that is separate from the delivery of the archive itself.

If the Client requests records that are not stored on the device producing the export (for example, session recordings that exist only in cloud storage and have not been downloaded), the archive will include a recordings/MISSING.txt note identifying the affected sessions, so the Provider can repeat the export from another authorised device or download the missing recordings before retrying.

7.5. Encrypted Archive Export and Import

SpeechCatcher can package one or more clients' data — including encrypted assessments, sessions, records, generated reports, and any on-device audio recordings — into a single password-protected .spmarchive.zip file. You choose the password at export time. The file can be opened only by another SpeechCatcher install that has both the file AND the password.

The archive includes a one-time transport key embedded in the file. All document keys inside the archive are wrapped to that transport key (not to your account key), so transferring the file does not expose your account's private key. The transport key's private half is itself encrypted with the password you choose.

On import, SpeechCatcher uses the password to unlock the transport key, re-wraps each document key onto the importing user's account key, and writes the documents into the importing user's local storage. The importing user must already have any Tests referenced by the imported assessments — missing Tests are flagged in the import preview but not bundled.

The archive password cannot be recovered. A lost password means the archive cannot be opened.

To export an archive: Clients → select one or more clients → Export archive → set a password → Export.

To import an archive: Clients → open the add-client menu → Import archive → choose the file → enter the password → review the import summary → Import.

8. Your Privacy Rights and Choices #

We believe in empowering you with control over your personal information. Depending on your location, you have certain rights regarding your data. The two tables below give a clear, at-a-glance comparison of your key rights under the privacy laws that most often apply to users of the Service. The first table compares the GDPR and HIPAA and explains how to exercise each right with our Service; the second covers Canada, Australia, Brazil, and Mexico. These tables are a user-friendly summary; the detailed explanations are in Sections 9 through 17, and the rights that attach specifically to Recording Consent and Research Consent are described in Section 5.

RightGeneral Data Protection Regulation (GDPR)Health Insurance Portability and Accountability Act (HIPAA)How to Exercise with Our Service
AccessThe right to obtain a copy of your personal data that we process.The right to inspect and obtain a copy of your Protected Health Information (PHI).Contact your Provider to request a copy of your session data; the Provider can use the in-app Data access request tool described in Section 7.4 to produce a readable archive of Your records. You can access your account data directly in your profile settings.
Rectification / AmendmentThe right to have inaccurate personal data corrected.The right to request an amendment to your PHI if you believe it is incorrect or incomplete.You can correct your account data in your profile settings. To amend session records, you must contact your Provider.
ErasureThe right to have personal data deleted ("Right to be Forgotten") under certain conditions.No equivalent right. PHI is subject to mandatory legal and professional record retention laws.To request the deletion of session data, you must contact your Provider, whose decision will be subject to their legal obligations.
Restriction of ProcessingThe right to limit how your personal data is processed in certain situations.The right to request restrictions on certain uses and disclosures of your PHI.You must contact your Provider to request restrictions on the processing of your session data.
Data PortabilityThe right to receive your data in a structured, commonly used, and machine-readable format.No equivalent right, though the right of access provides for copies in a requested format if readily producible.Contact your Provider to request an export of your session data.
ObjectionThe right to object to processing based on legitimate interests or for direct marketing.The right to object to certain disclosures (e.g., to a health plan for payment, if you pay out-of-pocket).You can manage your marketing communication preferences in your account settings. Other objections should be directed to your Provider.
Withdrawal of ConsentArticle 7(3): where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing that was already carried out.45 CFR § 164.508(b)(5): an authorization may be revoked in writing, except to the extent your provider has already acted in reliance on it.Recording Consent and Research Consent are withdrawn with your Provider, in the application or by asking the Provider to record the withdrawal; see Section 5.5. Analytics consent can be withdrawn at any time in the application settings.
Accounting of DisclosuresThe right to be informed of third-party recipients of your data.The right to receive an accounting of certain disclosures of your PHI made by your provider.See the "Data Sharing" section of this policy. For an accounting of disclosures of PHI, you must contact your Provider.

The second table sets out the equivalent rights under Canada's PIPEDA, Australia's Privacy Act 1988 and the Australian Privacy Principles (APPs), Brazil's LGPD, and Mexico's LFPDPPP. The "How to Exercise with Our Service" column of the first table applies to these rights as well.

RightCanada — PIPEDA (and provincial law)Australia — Australian Privacy PrinciplesBrazil — LGPDMexico — LFPDPPP
AccessPrinciple 9: the right to be told that we hold information about you, what it is used for, and to be given access to it.APP 12: the right to request access to the personal information we hold about you.Article 18(I)–(II): confirmation that processing is taking place and access to the data.Acceso: the right to know what personal data we hold and the terms on which we process it.
Rectification / AmendmentPrinciple 4.9.5: the right to challenge the accuracy and completeness of your information and have it amended.APP 13: the right to have information corrected where it is inaccurate, out of date, incomplete, irrelevant, or misleading.Article 18(III): correction of incomplete, inaccurate, or out-of-date data.Rectificación: the right to have inaccurate or incomplete data corrected.
ErasureNo general right to erasure. You may withdraw consent (Principle 3.8), subject to legal and contractual restrictions. Quebec's Law 25 adds limited rights to have dissemination stopped and search results de-indexed.No general right to erasure. APP 11.2 requires personal information to be destroyed or de-identified once it is no longer needed for a permitted purpose.Article 18(IV) and (VI): anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data, and deletion of data processed on the basis of consent, subject to the retention duties in Article 16.Cancelación: the right to have data blocked and then deleted, subject to legal retention duties.
Restriction of ProcessingNo standalone right. Withdrawing consent for a stated purpose limits further processing for that purpose.No standalone right. APP 6 limits use and disclosure to the purpose of collection unless you consent or an exception applies.Article 18(IV): blocking of data that is unnecessary, excessive, or processed in breach of the LGPD.The right to limit the use or disclosure of your personal data.
Data PortabilityNo federal right. Quebec's Law 25 provides a right to receive computerized personal information in a structured, commonly used technological format.No general right under the Privacy Act.Article 18(V): portability to another provider, on the terms set by the ANPD.Portability of data processed by automated means, where it is technically feasible.
ObjectionYou may withdraw consent to a use or disclosure on reasonable notice, subject to legal or contractual restrictions. Consent to marketing messages may be withdrawn at any time (see Section 10.3).APP 7: the right to opt out of direct marketing. Sensitive information, including health information, may not be used for direct marketing without your consent.Article 18(§2): the right to object to processing carried out on a legal basis other than consent where the LGPD has not been complied with.Oposición: the right to object to the processing of your data for a legitimate reason.
Withdrawal of ConsentPrinciple 3.8: consent may be withdrawn at any time, subject to legal or contractual restrictions and reasonable notice.Consent given for the collection of sensitive information, including health information, may be withdrawn (APP 3.3).Articles 8 (§5) and 18(IX): consent may be revoked at any time by an express declaration, free of charge and by a simplified procedure.The right to revoke consent previously given, by a process no more onerous than the one used to give it.
Accounting of DisclosuresPrinciple 9: on request, you may be given an account of the third parties to whom your information has been disclosed.APP 1.4 and APP 8: our policy must state the kinds of entities to which we disclose personal information, including overseas recipients.Article 18(VII): information about the public and private entities with which the controller has shared the data.The privacy notice must identify the transfers we make; details may also be requested together with an acceso request.

To exercise any of these rights, please follow the instructions in the first table. For rights related to your account data, you may contact us directly at privacy@speechmetrics.ca. For rights related to your session data, you must contact your Provider, who is the controller of that information. We will provide our Providers with the necessary tools and support to help them respond to your requests.

9. Information for Users in Australia #

The privacy of individuals in Australia is protected by the federal Privacy Act 1988 and the Australian Privacy Principles (APPs) contained within it.

  • Applicability: The Privacy Act applies to Australian Government agencies, private sector organizations with an annual turnover of more than AUD 3 million, and all health service providers.
  • Personal and Sensitive Information: The Act defines "personal information" as information or an opinion about an identifiable individual. It provides special protection for "sensitive information," which includes health information, genetic data, and racial or ethnic origin.

9.1. The Australian Privacy Principles (APPs)

The 13 APPs set out the standards for the handling of personal information. Our practices are aligned with these principles.

  • APP 1 — Open and Transparent Management: We are committed to managing your personal information transparently. This Privacy Policy is designed to be clear and up-to-date, explaining the kinds of information we collect, how we handle it, and for what purposes. It also details how you can access your data, make corrections, or file a complaint.
  • APP 2 — Anonymity and Pseudonymity: You have the right to deal with us anonymously or by using a pseudonym where it is lawful and practicable to do so.
  • APP 3 — Collection of Solicited Personal Information: We only collect personal information that is reasonably necessary for our functions. We will not collect sensitive information (including health information) about you without your consent, unless an exception applies.
  • APP 5 — Notification of Collection: At or before the time we collect your personal information, we will notify you of the purposes of collection, who we might disclose it to, and other relevant details as outlined in this policy.
  • APP 6 — Use or Disclosure: We will only use or disclose your personal information for the primary purpose for which it was collected, unless you have consented to a secondary use or disclosure, or another exception applies.
  • APP 7 — Direct Marketing: We will not use your sensitive information for direct marketing without your explicit consent. For all direct marketing, we will provide a simple way for you to opt out.
  • APP 12 & 13 — Access and Correction: You have the right to request access to the personal information we hold about you and to request that we correct any information that is inaccurate, out-of-date, or incomplete.

9.2. Your Rights in Australia

Under the Privacy Act, you have the right to:

  • Know why your personal information is being collected and how it will be used.
  • Access and correct your personal information.
  • Remain anonymous or use a pseudonym in certain situations.
  • Opt out of receiving direct marketing communications.

Complaints regarding a breach of the APPs can be directed to the Office of the Australian Information Commissioner (OAIC), which is the independent national regulator for privacy and freedom of information.

10. Information for Users in Canada #

Personal information, including personal health information, is protected by a combination of federal and provincial laws in Canada. Our data handling practices are designed to comply with these regulations.

10.1. Federal Privacy Law: PIPEDA

Canada's federal privacy law for the private sector is the Personal Information Protection and Electronic Documents Act (PIPEDA). PIPEDA governs how organizations engaged in commercial activities collect, use, and disclose personal information.

  • Applicability: PIPEDA applies to our service when we handle the personal information of Canadian users across provincial or national borders. For activities that occur entirely within a province with a "substantially similar" privacy law, the provincial law will apply.
  • Personal Information: Under PIPEDA, "personal information" is broadly defined as any "information about an identifiable individual." This includes your name, age, ID numbers, and sensitive data such as medical and health records.
  • Your Rights Under PIPEDA: You have the right to:
    • Know why an organization is collecting, using, or disclosing your personal information.
    • Expect that your information will be collected, used, and disclosed for reasonable and appropriate purposes.
    • Access the personal information held about you and challenge its accuracy and completeness. Organizations must respond to access requests within 30 days.
  • Our Obligations Under PIPEDA: We are obligated to:
    • Obtain meaningful and informed consent for the collection, use, and disclosure of your personal information.
    • Implement appropriate security safeguards to protect your personal information against loss, theft, or unauthorized access.
    • Notify the Office of the Privacy Commissioner (OPC) and affected individuals of any data breach that poses a "real risk of significant harm."

10.2. Provincial Privacy Laws

Several Canadian provinces have their own private-sector privacy laws that have been deemed "substantially similar" to PIPEDA. For activities conducted wholly within these provinces, the provincial law applies.

  • Quebec: An Act to modernize legislative provisions as regards the protection of personal information (Law 25, formerly Bill 64). Law 25 significantly modernizes Quebec's privacy framework, introducing stricter requirements. Key provisions include:
    • Enhanced Consent: Consent must be clear, granular, and requested separately for each specific purpose. Express consent is required for sensitive personal information, and parental consent is needed for minors under 14.
    • Privacy Impact Assessments (PIAs): We are required to conduct PIAs for certain activities, including before transferring personal information outside of Quebec, to ensure the data receives adequate protection.
    • Expanded User Rights: Law 25 grants you rights similar to the GDPR, including the right to data portability (effective September 2024) and the right to request the de-indexation of your information (a "right to be forgotten").
    • Privacy by Default: Technological products and services must be configured to provide the highest level of privacy by default.
    • Breach Reporting: We must report any confidentiality incident that presents a "risk of serious injury" to the Commission d'accès à l'information (CAI) and affected individuals.
  • Alberta: Personal Information Protection Act (PIPA). Alberta's PIPA governs how private sector organizations in the province handle personal information.
    • Applicability: PIPA applies to provincially regulated organizations in Alberta. Personal health information is primarily protected under a separate law, the Health Information Act.
    • Your Rights: You have the right to know why your data is being collected, expect it to be handled reasonably, and to access and request corrections to your personal information.
    • Consent: Organizations must obtain your explicit consent before collecting, using, or disclosing your personal information.
  • British Columbia: Personal Information Protection Act (PIPA). BC's PIPA sets the rules for how private sector and non-profit organizations in the province manage personal data.
    • Applicability: PIPA applies to most private organizations in BC. Health-specific records are also covered by the E-Health (Personal Health Information Access and Protection of Privacy) Act.
    • Personal Information: The law defines personal information broadly to include name, address, medical information, and employment history.
    • Your Rights: You have the right to know why your information is being collected, expect it to be used reasonably, access it, and request corrections.
  • Ontario: Personal Health Information Protection Act (PHIPA). For users in Ontario, the collection, use, and disclosure of personal health information is specifically governed by PHIPA. This law applies to "health information custodians," such as healthcare providers, and is considered substantially similar to PIPEDA for health data.
  • Other provinces: Provincial health information statutes also apply in Newfoundland and Labrador (PHIA), Manitoba (PHIA), New Brunswick (PHIPAA), Nova Scotia (PHIA), and Saskatchewan (HIPA). The Provider is responsible for determining the applicable framework and meeting the obligations of a health information custodian thereunder.

10.3. Canada's Anti-Spam Legislation (CASL)

We comply with Canada's Anti-Spam Legislation (CASL). We will not send You a commercial electronic message without Your express or implied consent, and every commercial electronic message We send will identify Speech Metrics, provide our contact information, and include a working unsubscribe mechanism. You may withdraw consent at any time by following the unsubscribe link in any commercial email or by contacting privacy@speechmetrics.ca.

11. Information for Users in the European Economic Area (EEA), UK, and Switzerland #

If you are located in the EEA, UK, or Switzerland, you have certain rights and protections under the GDPR. This section provides the detailed disclosures required by that regulation.

11.1. Your Rights Under GDPR

You have the following rights with respect to your personal data:

  • The Right of Access: You have the right to request a copy of the personal data we hold about you.
  • The Right to Rectification: You have the right to request that we correct any inaccurate or incomplete personal data.
  • The Right to Erasure ('Right to be Forgotten'): You have the right to request the deletion of your personal data where there is no compelling reason for its continued processing.
  • The Right to Restrict Processing: You have the right to request that we suspend the processing of your personal data in certain circumstances.
  • The Right to Data Portability: You have the right to receive your personal data in a structured, machine-readable format and to have it transmitted to another controller.
  • The Right to Object: You have the right to object to our processing of your personal data where we are relying on a legitimate interest as our legal basis.
  • Rights in Relation to Automated Decision-Making and Profiling: You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you. We do not engage in such processing.

11.2. Data Controller, Privacy Officer, and Data Protection Officer

As explained in Section 4, the Provider is the Data Controller for Encrypted Session Data. Speech Metrics is the Data Controller for Provider Account Data and Usage/Device Data. Our Privacy Officer is Gregory Hedlund and can be reached at privacy@speechmetrics.ca or via mail at our registered address. The Privacy Officer is responsible for overseeing this Privacy Policy, responding to data-subject requests, and serving as the point of contact for supervisory authorities.

Data Protection Officer (GDPR Article 37). Having reviewed the criteria in Article 37, We have concluded that We are not required to formally appoint a Data Protection Officer at this time. Our processing of Encrypted Session Data — which contains special-category health data — is conducted exclusively as a Data Processor on behalf of Providers, using end-to-end encryption that prevents Us from accessing the plaintext content of that data. We do not engage in regular and systematic monitoring of data subjects on a large scale, and We do not process special-category data on a large scale in a form that is decipherable to Us. We will reassess this conclusion if the scale, nature, or context of our processing changes, and We will appoint a DPO promptly if Article 37 thresholds are met.

EU and UK Representative (GDPR Article 27 / UK GDPR). Speech Metrics is established in Canada and is not currently established in the European Economic Area or the United Kingdom. We have not yet designated an Article 27 representative because the Service is not actively targeted at data subjects in those territories at a scale that triggers the obligation, and our processing of personal data of EEA/UK residents is occasional and low-risk relative to the encrypted nature of Session Data. We will appoint a written EU representative and a separate UK representative before commencing active marketing or large-scale processing directed at the EEA or the United Kingdom.

11.3. International Data Transfers

Your personal information may be transferred to, stored, and processed in a country that is not regarded as ensuring an adequate level of protection for personal data under European Union law, such as the United States. To provide adequate protection for these transfers, we have put in place appropriate safeguards, such as the Standard Contractual Clauses (SCCs) approved by the European Commission and the UK International Data Transfer Agreement (IDTA) or UK Addendum where applicable, to ensure that your personal data is treated in a manner that is consistent with and respects the EU and UK laws on data protection. Where You select a European Union data residency region at account creation, Your Encrypted Session Data and Provider Account Data are stored on Firebase infrastructure in the europe-west1 region and are not transferred outside the EEA in the ordinary course of providing the Service.

11.4. Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, We will notify the competent supervisory authority without undue delay and, where feasible, not later than seventy-two (72) hours after becoming aware of the breach, in accordance with GDPR Article 33 and UK GDPR. Where the breach is likely to result in a high risk to the rights and freedoms of natural persons, We will also notify affected data subjects without undue delay, in accordance with Article 34. For Providers acting as Data Controllers, We will notify You of any breach affecting Encrypted Session Data so that You may meet Your own notification obligations to Your Clients and to regulators.

12. Information for Users in the United States #

This section serves as our Notice of Privacy Practices ("Notice") as required by the Health Insurance Portability and Accountability Act of 1996 (HIPAA). It applies to the Protected Health Information (PHI) that is created or received by Providers using our Service.

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

12.1. Our Responsibilities

Speech Metrics functions as a "Business Associate" to your Provider, who is a "Covered Entity" under HIPAA. We are required by law to maintain the privacy and security of your PHI. We will notify you and your Provider if a breach of unsecured PHI occurs. We must follow the duties and privacy practices described in this Notice and provide you with a copy of it.

Due to our end-to-end encryption architecture, our primary responsibility is to implement robust security safeguards to protect the integrity and confidentiality of the Encrypted Session Data. We cannot access, use, or disclose the PHI contained within that data.

12.2. How We May Use and Disclose Your PHI

HIPAA permits Covered Entities (your Provider) to use and disclose PHI for purposes of treatment, payment, and healthcare operations without your specific authorization. Your Provider may use the PHI from your recorded sessions for these purposes.

Our role as a Business Associate is strictly limited. We do not use or disclose your PHI for treatment, payment, or operations because we cannot access it. Our only "use" of the PHI is to facilitate the secure storage and transmission of the encrypted data at the direction of your Provider.

12.3. Uses and Disclosures Requiring Your Authorization

Any other use or disclosure of your PHI by your Provider not described in their Notice of Privacy Practices will be made only with your written authorization. You may revoke this authorization at any time, in writing, except to the extent that your Provider has already acted in reliance on your authorization.

12.4. Your Rights Regarding Your PHI

You have the following rights concerning your PHI. To exercise these rights, you must contact your Provider directly.

  • Right to Inspect and Copy: You have the right to inspect and obtain a copy of your PHI.
  • Right to Amend: If you believe that PHI your Provider has about you is incorrect or incomplete, you may ask them to amend the information.
  • Right to an Accounting of Disclosures: You have the right to request a list of the disclosures your Provider has made of your PHI for purposes other than treatment, payment, and healthcare operations.
  • Right to Request Restrictions: You have the right to request a restriction or limitation on the PHI your Provider uses or discloses about you.
  • Right to Request Confidential Communications: You have the right to request that your Provider communicate with you about medical matters in a certain way or at a certain location.

12.5. How to File a Complaint

If you believe your privacy rights have been violated, you may file a complaint with your Provider or with the Secretary of the U.S. Department of Health and Human Services. You may also contact our Privacy Officer at privacy@speechmetrics.ca. You will not be penalized for filing a complaint.

13. Information for Users in California #

This section supplements the rest of this Privacy Policy with disclosures required by the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the "CCPA"). It applies to consumers who are California residents. Terms defined in the CCPA have the same meaning when used in this section.

13.1. Categories of Personal Information We Collect

In the preceding twelve (12) months, We have collected or processed the following categories of personal information about California residents who use the Service. The list maps to the categories enumerated in Cal. Civ. Code §1798.140.

  • Identifiers (e.g., name, email address, federated sign-in identifier, Firebase Installations ID, RevenueCat App User ID, IDFV).
  • Customer records information (account profile information You provide).
  • Commercial information (subscription status, product purchased, purchase and renewal timestamps; payment card information is handled by Apple and is not collected by Us).
  • Internet or other electronic network activity information (PostHog in-app product analytics events and error reports with Your consent; limited cookieless website page-view, referral, and campaign events automatically when configured; and server log data including IP address and request metadata).
  • Inferences drawn from the foregoing to support, secure, and improve the Service.
  • Sensitive personal information in the form of Encrypted Session Data, which contains health-related audio recordings and associated metadata. We process this data only as a service provider acting at the direction of the Provider; the data is encrypted end-to-end and We do not have the ability to decrypt it.

13.2. Sources of Personal Information

We collect personal information directly from You (when You create an account, contact support, or use the Service), automatically from Your device when You opt in to in-app analytics, automatically from website requests when cookieless analytics are configured, and from third parties that authenticate You at Your direction (Apple, Google) or process Your subscription (Apple Media Services, RevenueCat).

13.3. Business or Commercial Purposes for Collection

We use the categories above to provide and secure the Service, manage Your account and subscription, process Your requests, respond to support inquiries, detect and prevent fraud or abuse, comply with legal obligations, improve the application through analytics and error tracking with Your consent, and understand limited website traffic through cookieless analytics when configured.

13.4. Categories of Third Parties with Whom We Share Personal Information

We share personal information only with the service providers and sub-processors identified in Section 6 of this Policy, in each case under contracts that limit their use of the data to providing services to Us. We do not share personal information with data brokers.

13.5. No Sale or Sharing of Personal Information

We do not sell personal information. We do not share personal information for cross-context behavioural advertising. We have not done so in the preceding twelve (12) months. We do not have actual knowledge of selling or sharing the personal information of consumers under sixteen (16) years of age.

13.6. Use of Sensitive Personal Information

Our use of sensitive personal information (Encrypted Session Data) is limited to that which is necessary to perform the Service at the direction of the Provider. We do not use or disclose sensitive personal information to infer characteristics about a consumer, and We do not use it for any purpose for which a California resident would have the right to limit use under the CCPA.

13.7. Retention

We retain each category of personal information for the periods described in Section 7.2 of this Policy. We retain personal information for no longer than is reasonably necessary for the purposes for which it was collected, except where a longer period is required or permitted by law.

13.8. Your California Privacy Rights

If You are a California resident, You have the following rights, subject to certain exceptions:

  • Right to Know: Request that We disclose the categories and specific pieces of personal information We have collected, the sources, the purposes for collection, and the categories of third parties with whom We have shared personal information.
  • Right to Delete: Request that We delete personal information We have collected from You, subject to legal retention requirements (note that Encrypted Session Data containing PHI is generally controlled by Your Provider; delete requests for that data must be directed to the Provider).
  • Right to Correct: Request that We correct inaccurate personal information We maintain about You.
  • Right to Opt Out of Sale or Sharing: We do not sell or share personal information; nonetheless, You may exercise this right and We will confirm our practices in writing.
  • Right to Limit Use of Sensitive Personal Information: As explained in Section 13.6, our use of sensitive personal information is already limited to purposes permitted under the CCPA without a separate opt-out.
  • Right to Non-Discrimination: We will not deny You service, charge You a different price, or provide You a different level of quality because You exercise any of these rights.

13.9. How to Exercise Your Rights

To exercise any of these rights, contact our Privacy Officer at privacy@speechmetrics.ca. We will verify Your identity using information already associated with Your account before responding. You may designate an authorized agent to make a request on Your behalf; the agent must provide written authorization signed by You, and We may require You to verify Your identity directly with Us before processing the request. We will respond within forty-five (45) days, with one extension of up to forty-five (45) additional days where reasonably necessary.

14. Information for Users in Other U.S. States #

Residents of Virginia, Colorado, Connecticut, Utah, Texas, and Oregon, and of other U.S. states that have enacted comprehensive consumer privacy laws, have rights substantially similar to those described in Section 13 for California residents, including the rights to access, correct, delete, and obtain a copy of personal information We hold about them, and to opt out of the sale of personal information or targeted advertising. We do not engage in the sale of personal information or targeted advertising as those terms are defined in these laws.

To exercise any right under Your state's privacy law, contact our Privacy Officer at privacy@speechmetrics.ca. We will verify Your identity, respond within the timeframes required by Your state's law, and provide an appeal process if We deny Your request.

15. Information for Users in Mexico #

If you are located in Mexico, this section, together with the rest of this Privacy Policy, serves as our privacy notice (aviso de privacidad) under the Federal Law on the Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares, "LFPDPPP"), as reformed in 2025.

15.1. Identity and Domicile of the Data Controller (Responsable)

As explained in Section 4, Speech Metrics, with its registered domicile in Canada and reachable through the contact details in Section 20, is the data controller (responsable) for Provider Account Data and Usage/Device Data. The Provider is the data controller for Encrypted Session Data; Speech Metrics processes that data solely as a data processor (encargado) on the Provider's documented instructions and cannot read its content.

15.2. Sensitive Personal Data

We inform you expressly that Encrypted Session Data contains health-related audio recordings and associated clinical information, which constitute sensitive personal data under the LFPDPPP. Sensitive personal data is processed only with the express written consent of the data subject or their legal representative, which the Provider collects before recording — either through the in-app Recording Consent form (signed electronically within SpeechCatcher) or through a signed written consent form retained in the Client's clinical record (see Section 5). All such data is end-to-end encrypted on the Provider's device, and Speech Metrics cannot access its content.

15.3. Purposes of Processing

The purposes for which personal data is processed are described in Section 3. The purposes necessary to provide the Service (account management, secure storage and transmission of Encrypted Session Data, billing, and support) are primary purposes. Optional in-app analytics, which are disabled by default and activated only with your consent, are a secondary purpose; you may decline or withdraw analytics consent at any time without affecting the Service.

15.4. ARCO Rights and Revocation of Consent

You have the rights of access (acceso), rectification (rectificación), cancellation (cancelación), and opposition (oposición) — the "ARCO rights" — as well as the right to revoke consent you have previously given and the right to limit the use or disclosure of your personal data. To exercise these rights with respect to data held by Speech Metrics, contact our Privacy Officer at privacy@speechmetrics.ca, stating your name, the right you wish to exercise, and information that allows us to locate your data; we will verify your identity and respond within the timeframes established by the LFPDPPP. Because We cannot access the content of Encrypted Session Data, ARCO requests and consent revocations concerning Client recordings must be directed to the Provider responsible for the Client's clinical record; the Provider can withdraw Recording Consent, export, or delete recordings using tools provided in the Service (see Section 5.5).

15.5. Transfers of Personal Data

Personal data is stored and processed outside Mexico, in the data residency region selected at account creation (see Section 6). Data is remitted (remisión) to the sub-processors listed in Section 6 under contracts that impose the same protection obligations that apply to us; these remissions to processors acting on our behalf do not require your consent under the LFPDPPP. We do not transfer personal data to third parties for their own purposes without your consent, except where the LFPDPPP permits a transfer without consent (for example, where required by law).

15.6. Complaints and Changes to This Notice

If you consider that your data protection rights have been infringed, you may file a complaint with the competent Mexican data protection authority (following the 2025 reform, the functions previously exercised by INAI are exercised by the anticorruption and good governance authority of the Federal Executive — Secretaría Anticorrupción y Buen Gobierno). Changes to this privacy notice are communicated as described in Section 19.

16. Information for Users in Brazil #

If you are located in Brazil, this section, together with the rest of this Privacy Policy, explains how we handle personal data under the General Personal Data Protection Law (Lei Geral de Proteção de Dados Pessoais, Law No. 13.709/2018, "LGPD").

16.1. Controller and Operator Roles

The Provider is the controller (controlador) of Encrypted Session Data and of the Recording Consent records described in Section 5: the Provider decides that a Client will be recorded, for what purpose, and for how long the record is kept. Speech Metrics is the operator (operador) for that data. We store and transmit it on the Provider's documented instructions and cannot read its content.

Speech Metrics is the controller of Provider Account Data, Usage and Device Data, and information submitted through the speechcatcher.ca website, as described in Section 2.

16.2. Legal Bases for Processing

For personal data that is not sensitive, we rely on the bases in Article 7 of the LGPD: performance of a contract (Article 7, V) for Provider Account Data and Payment Information; our legitimate interests (Article 7, IX) for security, fraud prevention, and keeping the Service reliable; and your consent (Article 7, I) for optional in-app analytics, which are disabled by default.

Session audio and the clinical information associated with it are sensitive personal data under Article 11, because they concern health. The Provider establishes the basis for processing them, which will normally be the specific and highlighted consent of the data subject or their legal representative (Article 11, I), recorded as the Recording Consent described in Section 5, or the protection of health in a procedure carried out by a health professional (Article 11, II, f). Speech Metrics does not select the basis and cannot read the data.

We do not communicate or share health data for the purpose of obtaining an economic advantage, which Article 11, §4 prohibits.

16.3. Your Rights Under Article 18

You have the right to obtain confirmation that processing is taking place and access to your data; to have incomplete, inaccurate, or out-of-date data corrected; to have unnecessary or excessive data, or data processed in breach of the LGPD, anonymized, blocked, or deleted; to data portability; to have data processed on the basis of consent deleted, subject to the retention duties in Article 16; to be told with which public and private entities the controller has shared your data; to be told that you may refuse consent and what the consequences are; and to revoke consent at any time.

To exercise these rights in relation to data Speech Metrics controls, contact our Privacy Officer at privacy@speechmetrics.ca. We will confirm your identity and respond within the periods set by Article 19 of the LGPD. Because we cannot read Encrypted Session Data or Recording Consent records, requests concerning a Client's recordings — including revocation of consent — must be made to the Provider responsible for that Client's clinical record. The contact details for our Privacy Officer, who acts as our point of contact for data protection matters, are in Sections 11.2 and 20; a Provider acting as controller is responsible for appointing its own data protection officer (encarregado) where the LGPD requires one.

16.4. International Transfers of Personal Data

The Service has no data residency region inside Brazil. Personal data is stored and processed in the region the Provider selects at account creation — North America, the European Union, or Australia (see Section 6) — so data relating to people in Brazil leaves the country. We make these transfers on the bases permitted by Article 33 of the LGPD: contractual guarantees, including standard contractual clauses of the kind adopted by the ANPD, imposed on every sub-processor listed in Section 6; and, where the Provider has obtained it, the specific and highlighted consent of the data subject to the transfer. Providers should tell their Clients which region they have selected.

16.5. Children and Adolescents

Under Article 14 of the LGPD, personal data of children and adolescents must be processed in their best interest, and data of a child must be processed with the specific and highlighted consent of at least one parent or legal guardian. Where a Provider records a child or adolescent Client, obtaining that consent is the Provider's responsibility; the Recording Consent form records who gave consent and their relationship to the Client.

16.6. Complaints

If you believe your data protection rights have been infringed, you may complain to the Autoridade Nacional de Proteção de Dados (ANPD), Brazil's national data protection authority. You may also raise the matter with us first at privacy@speechmetrics.ca.

17. Information for Users in South America #

This section applies to Providers and Clients located in South America outside Brazil, which is covered by Section 16.

17.1. Commitments That Apply Across the Region

Data protection law differs from one South American country to the next, and some countries have no general statute at all. Rather than offer a different standard in each country, we apply the same commitments everywhere in the region:

  • Roles. The Provider is the controller (responsable, controlador) of Encrypted Session Data and Recording Consent records. Speech Metrics is the processor (encargado, operador) and cannot read their content. Speech Metrics is the controller of Provider Account Data and Usage and Device Data.
  • Health data is sensitive data. Every country listed below treats health information as sensitive personal data that may be processed only with the express consent of the data subject or their legal representative, or under a narrow statutory exception. The Provider obtains and records that consent as described in Section 5.
  • Cross-border storage. The Service has no data residency region in South America. Data is stored in the region the Provider selects at account creation — North America, the European Union, or Australia (see Section 6) — so every record is an international transfer. We impose contractual protections equivalent to the standard contractual clauses described in Section 11.3 on every sub-processor. Where local law requires the data subject's specific consent for a transfer abroad, obtaining that consent is the Provider's responsibility as controller. Providers should tell their Clients which region they have selected.
  • Baseline protections. The security, retention, consent, and rights commitments in Sections 5 through 8 and Section 11 apply to everyone in the region, including in countries whose law would require less.

17.2. Argentina

Personal data in Argentina is protected by the Personal Data Protection Act (Ley 25.326) and by the constitutional habeas data remedy. Health data is sensitive data, and health professionals may process data about their patients subject to professional secrecy. You have the right to be told how your data is used, to access it free of charge at intervals of not less than six months, and to have it rectified, updated, or suppressed. Transfers to countries that do not provide an adequate level of protection require your consent or contractual guarantees; we rely on the contractual protections described in Section 17.1. Complaints may be made to the Agencia de Acceso a la Información Pública (AAIP).

17.3. Chile

Chile's data protection framework is changing. The Personal Data Protection Act (Ley 21.719) takes effect on 1 December 2026, replacing the regime under Ley 19.628. It requires express consent for the processing of health data and other sensitive data, grants rights of access, rectification, deletion, objection, and portability, and creates a dedicated supervisory authority, the Agencia de Protección de Datos Personales. Our practices are designed to meet that standard from the date it applies; until then, the earlier regime continues to apply.

17.4. Colombia

Personal data in Colombia is protected by Ley 1581 de 2012 and its implementing decrees, and by the constitutional right of habeas data. Health data is sensitive data and may be processed only with your explicit authorization; you cannot be compelled to authorize the processing of sensitive data. You have the right to know what data is held, to have it updated and rectified, to ask for proof of the authorization given, to be told how it is used, to revoke your authorization and request deletion where processing breaches the law, and to access your data free of charge. Transfers to countries that do not offer an adequate level of protection require your express and unequivocal authorization or another statutory exception. Complaints may be made to the Superintendencia de Industria y Comercio (SIC).

17.5. Uruguay

Personal data in Uruguay is protected by the Personal Data Protection Act (Ley 18.331) and its amendments. Health data is sensitive data and requires your express written consent, which may be given by electronic means. You have the right of access, and the rights to rectification, updating, inclusion, and suppression of your data, enforceable through a habeas data action. Transfers abroad are permitted to countries offering an adequate level of protection, with your consent, or under contractual guarantees. Complaints may be made to the Unidad Reguladora y de Control de Datos Personales (URCDP).

17.6. Ecuador

Personal data in Ecuador is protected by the Organic Law on the Protection of Personal Data (Ley Orgánica de Protección de Datos Personales, "LOPDP"). Health data is sensitive data requiring your express consent. You have the rights of information, access, rectification and updating, erasure, objection, portability, suspension of processing, and the right not to be subject to decisions based solely on automated processing. Complaints may be made to the Superintendencia de Protección de Datos Personales (SPDP).

17.7. Paraguay

Paraguay's general personal data protection law (Ley N.° 7593) sets out principles of lawfulness, purpose limitation, and data minimization, requires express consent for the processing of sensitive data including health data, grants rights of access, rectification, erasure, objection, and portability, and establishes a national supervisory authority to which complaints may be made.

17.8. Countries Without a General Data Protection Statute

Bolivia, Venezuela, Guyana, and Suriname do not have a comprehensive general data protection statute, although constitutional privacy remedies exist in Bolivia (acción de protección de privacidad) and Venezuela (habeas data). Where you are located in one of these countries, the commitments described in Section 17.1 apply to you as our baseline: we handle your data to the standard this policy describes for the European Economic Area, and you may exercise the corresponding rights by contacting our Privacy Officer at privacy@speechmetrics.ca or, for Client recordings, your Provider.

18. Children's Privacy #

Our Service is intended for use by licensed Providers and other qualified professionals. We do not market the Service to children and we do not knowingly collect personal information directly from a child for the child's own use of the Service. Where a Provider uses the Service to record sessions with a minor Client, it is the sole responsibility of the Provider to obtain legally valid consent from the child's parent or legal guardian in accordance with the law applicable to the Client's residence, including but not limited to:

  • United States — COPPA: For Clients under the age of thirteen (13), the Children's Online Privacy Protection Act requires verifiable parental consent before any collection of personal information from the child.
  • Quebec, Canada — Law 25: For Clients under the age of fourteen (14), consent must be given by the holder of parental authority.
  • European Economic Area, United Kingdom, Switzerland — GDPR and UK GDPR: For Clients under the age of sixteen (16), parental or guardian consent is required (member states may lower this floor to no less than thirteen (13); the Provider is responsible for applying the threshold applicable in the Client's jurisdiction).
  • Mexico — LFPDPPP: For Clients who are minors, consent must be given by the person exercising parental authority (patria potestad) or legal guardianship (tutela).
  • Brazil — LGPD: Personal data of children and adolescents must be processed in their best interest, and data of a child must be processed with the specific and highlighted consent of at least one parent or legal guardian (Article 14).
  • South America: Consent for a minor Client must be given by the person holding parental authority or legal guardianship under the law of the Client's country.
  • Other jurisdictions: The Provider is responsible for applying the minor-consent threshold required by local law.

If We become aware that We have collected personal information directly from a child in a manner inconsistent with the foregoing thresholds, We will take steps to delete that information promptly.

19. Changes to This Privacy Policy #

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. If we make material changes, we will notify you by email (sent to the email address specified in your account) or by means of a prominent notice within the Service prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices.

20. How to Contact Us #

If you have any questions, comments, or concerns about this Privacy Policy or our data practices, please contact us using the information below:

Speech Metrics

Attn: Privacy Officer

Email: privacy@speechmetrics.ca

Stay in the loop

Get updates on SpeechCatcher development progress, new features, and release milestones.