API privacy policy
Updated 23 September 2026
This policy covers the Kalemio transcription API, customer portal and website operated by P4LM inc. Contact Support email about your data.
What we process
We process the audio in each file you submit to produce a transcript, word timestamps and speaker labels. We also store your account email, password hash, recovery-code hash, API-key hashes, sessions, payment references, credit balance and usage records, including when a finished result is downloaded. Your email is a sign-in identifier and is not verified.
We review account, job, usage and payment records, including the server records of Kalemio app installs, per account or install in a private, owner-only dashboard to see where people get stuck and to fix failures. It shows pseudonymous IDs, not email addresses, and uses no third-party trackers.
Audio and result retention
Uploaded media is not used to train models. Working audio and upstream job files are deleted after processing. Downloadable results expire 24 hours after submission. Cleanup retries during service outages, so physical deletion can be delayed by an outage. Download any results you need before they expire.
Service providers
Cloudflare hosts the website, API gateway, account database and temporary storage. Our transcription infrastructure and compute providers process uploaded media to return results. Stripe processes payments and card details; card details are not stored by Kalemio. Data may be processed outside your country.
Account and payment records
Account, payment and usage records are retained for service operation, accounting and abuse prevention. Support correspondence is retained while needed to resolve your request. Previous waitlist records remain until they are no longer needed or you ask us to remove them.
Your choices
Revoke unused keys in your account. To request access, correction or deletion of personal information, email Support email. We verify requests before changing or deleting account data. Some payment, tax, security or legal records may need to be retained; we will explain any exception. See account deletion.
Website and security
We do not sell personal information or share recordings with advertising networks. The website uses privacy-limited, cookieless Google Analytics with storage denied to measure page paths and general product actions. It does not receive audio, transcripts, filenames, account details, payment details or API keys, and we do not send a persistent user identifier. You can turn it off with “Analytics settings” in the footer. We do not use personalized advertising trackers. Sign-in uses a session cookie. Requests use HTTPS, and the service uses authentication and rate limits to restrict access.