Privacy Policy
Last updated: 9 October 2026
1. Who is responsible
The controller for Kaho (the desktop app for macOS, Windows and Linux, and the Kaho Pocket app for iPhone) and for wovero.com is Wovero GmbH, Badestube 6, 36251 Bad Hersfeld, Germany (full details in the Imprint). Contact: privacy@wovero.com.
2. Our principle: processed on our own infrastructure in Germany
Your voice, your text and everything Kaho makes from them are processed on our own servers and our own GPU, rented from Hetzner Online GmbH in Germany. Speech recognition, cleanup, translation, meeting notes and speaker labels all run there. Kaho does not send your audio or your text to any external AI service, in Germany or anywhere else, and has no fallback to one.
Sign-in runs on our own server in Germany too. No part of Kaho depends on a service outside the EU.
3. What we process
Dictation
- Audio — recorded while you hold the dictation shortcut (or tap record in Kaho Pocket) and sent over TLS to our server for transcription. Our server deletes it as soon as the text is ready, unless you share recordings (below).
- Screen context — the name and window title of the app you dictate into (for example "Slack — #general") and the text in the field at your cursor. Used to adapt tone and vocabulary and for translation. No screenshots, no pixels, nothing outside the focused field.
- Your dictation history — the text Kaho produced, the text before cleanup, the language, the translation pair, the app name, the length and the time. Stored in your account so your history is the same on all your devices. Deleting an entry deletes its text on our server too.
- Shared recordings (test phase) — while Kaho is in testing, the app also sends each dictation's audio to us after it finished, with the recognised and the pasted text, the languages, its length, the reason a take failed, the app version and your platform, linked to your account. Why: to find and fix recognition errors by listening to what was actually said. Only the Kaho team can access them. On by default; turn it off in Settings → General → Share recordings to improve Kaho. From then on nothing is sent, and recordings not yet sent stay on your device. Kaho tells you once, in the app, before the first recording is sent.
- Glossary, profile and settings — your own words and how they are heard, role, writing style, rewrite rules and the terms you add to your team's glossary. Used to personalise recognition and cleanup.
- Usage counter — how many words you dictated this month, for the free plan's limit and cost planning. Reset every month; no text.
- First-run counts — that a sign-in completed and how long the first dictation took after installing, in coarse buckets, stored only as daily totals: no user id, no device, no text, no audio. Turn it off in Settings → General → Share usage counts.
Meetings
- Meeting audio — when you record a meeting, Kaho sends it in short pieces: your microphone ("Me") and, on desktop, the meeting app's sound ("Them"). Our server deletes each piece as soon as its text is stored; a piece that keeps failing is deleted after 24 hours at the latest.
- Meeting transcripts and notes — the text, who spoke when, the summary and notes made from it on our GPU, the meeting app's name, the title and the languages.
- Speaker labels and your voice bank (where enabled) — to tell speakers apart, our server computes a numeric voice signature (an embedding) for each speaker of a meeting. When you name a speaker, Kaho saves that signature under the name in your personal voice bank, so it can suggest the name in later meetings. A signature is saved only when you name or confirm a speaker. On macOS, if you turn on "Suggest from my calendar", Kaho also sends the display names of the other attendees of the calendar event. You can rename, merge or forget each person, or delete the whole voice bank, in the app. The voice bank is never shared with other users.
Feedback and error reports
- Feedback — when you send a bug report or an idea from inside Kaho: your text, an optional screenshot and an optional app log, your platform and app version, and our replies. Stored on our server so you can follow it and answer in the app.
- Error reports (only when you turn on Settings → Send error reports, or for test accounts where we enabled them) — what went wrong, where in the code, the app version, your platform and a short log tail, with personal data removed in the app and again on our server. The reports are stored under a one-way hash of your user id, not the id itself.
- Internal tickets — for each new feedback report and each new kind of error, our server files a task in our internal ticket system. The task holds only the report id, the kind of error, where it happened, the app version, the OS and counts: no text of yours and nothing that identifies you. The report itself, with any screenshot and log, stays on our server.
Account
- Account data — your email address, your name and your user id, and with Google or Apple sign-in the identifier they give us. Stored on our own sign-in server in Germany and used to sign you in on all your devices.
Website
- Server logs — our web server processes the technically necessary request data (IP address, time, page, browser) to deliver and protect the site.
- Plausible Analytics — the Kaho pages count visits with Plausible: no cookies, no cross-site tracking, no personal profiles. Your IP address is only used to compute an anonymous daily visitor id and is not stored.
4. What we don't do
- We do not send your audio or text to any external AI provider.
- We do not take screenshots or read your screen beyond the focused text field (a feedback screenshot is only taken when you attach one).
- We do not access your files, documents or browsing history.
- We do not sell your data or share it with advertisers.
- We do not use your audio or text to train AI models.
5. Who processes data for us
| Processor | Purpose | Location | Data |
|---|---|---|---|
| Hetzner Online GmbH | Data centre for our own servers: sign-in, the website, the Kaho API and database, and our own GPU for speech recognition, cleanup, translation, meeting notes and speaker labels | Germany | Everything described in section 3. The servers are run by us; Hetzner provides the hardware and the data centre. |
| Plausible Insights OÜ | Cookieless website statistics for the Kaho pages | EU (Estonia; servers in Germany) | Page, referrer, browser, OS and country, aggregated. No cookies, no personal identifiers. |
Sign in with Google or Apple is your choice. If you use it, Google or Apple confirms your identity to our own sign-in server, under their own privacy policy, and gives us your email address, name and an account identifier. You can always sign in with an email code instead, sent from our own mail server.
App distribution. Kaho Pocket is distributed through Apple's App Store and TestFlight, and the Windows app will also be offered through the Microsoft Store. Apple and Microsoft process your download, purchase and (if you agreed with them) crash data under their own privacy policies; Kaho itself contains no Apple, Google or Microsoft analytics or advertising SDK. Desktop downloads and updates come from our own servers (wovero.com, api.wovero.com).
6. Transfers outside the EU
We do not transfer personal data outside the EU. If you choose Sign in with Google or Apple, that sign-in happens between you and Google or Apple, under their own terms.
7. Legal bases
- Providing Kaho (dictation, history sync, meetings, account, feedback): performance of our contract with you, Art. 6(1)(b) GDPR.
- Shared recordings, error reports, first-run counts, website statistics and server logs: our legitimate interest in a working, secure and improving product, Art. 6(1)(f) GDPR; you can object or turn each of them off.
- Voice bank and speaker recognition: your explicit consent, Art. 9(2)(a) GDPR, which you can withdraw at any time by deleting the voice bank.
8. Data on your device
The Kaho apps keep the following on your device, in Kaho's app data folder (macOS ~/Library/Application Support/com.wovero.kaho/, Windows %APPDATA%\com.wovero.kaho\, Linux ~/.local/share/com.wovero.kaho/; Kaho Pocket inside its iOS app container):
- Your dictation history and personal dictionary (an SQLite database)
- Your most recent recordings (up to 500)
- Meeting recordings, for 30 days after the meeting by default, and the notes and transcripts the app fetched
- A copy of your glossary and profile
- Application logs
Your sign-in is kept on the device. Signing out or deleting your account removes your history, recordings, meetings and sign-in from that device. We cannot see this data unless you send it to us (for example a log attached to feedback).
9. Permissions
- Microphone — to record while you dictate or record a meeting.
- Accessibility (macOS) — for the dictation shortcut, to read the focused text field for context and to paste the text where your cursor is.
- System Audio Recording (macOS, only for meetings) — to record the meeting app's sound. Kaho does not ask for Screen Recording and records no picture.
- Calendar (macOS, optional) — to suggest a meeting's title and attendee names.
On macOS you can revoke these in System Settings → Privacy & Security, on Windows in Settings → Privacy & security, on iPhone in Settings → Kaho. On Linux Kaho uses your desktop's microphone access and your session's input and clipboard access, controlled in your distribution's settings.
10. How long we keep data
- Dictation audio on our server: deleted as soon as the text is ready.
- Shared recordings (test phase): 90 days from upload, then deleted automatically. Deleting the dictation in Kaho deletes its recording too.
- Meeting audio on our server: deleted as soon as its text is stored, at the latest after 24 hours. For test accounts where we turned on keeping meeting audio for diagnosis, it is kept for 30 days and then deleted automatically.
- Meetings (transcript, notes, speaker labels): 1 year from creation, or until you delete the meeting.
- Dictation history, glossary, profile, settings, voice bank: until you delete them or your account.
- Feedback: until you delete your account.
- Error reports: 30 days.
- Usage counter: the current month only.
- First-run counts: daily totals, 400 days.
- Server logs: no audio and no text from your dictations or meetings; kept for operation and security only.
- Account data: until you delete your account.
11. Your rights (Art. 15–22 GDPR)
You have the right to:
- Access the data we hold about you (Art. 15)
- Have it corrected (Art. 16)
- Have it deleted (Art. 17)
- Restrict or object to processing (Art. 18, 21)
- Receive a portable copy of your data (Art. 20)
- Withdraw a consent at any time, with effect for the future (Art. 7(3))
- Complain to a supervisory authority; for us that is Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (company seat: Bad Hersfeld, Hessen)
Deleting your account. In Kaho (desktop or Pocket), open Settings → Account → Delete account. This deletes your account and everything we store for it, immediately: your dictation history, shared recordings, meetings with their transcripts, notes, audio and speaker labels, your voice bank, feedback, error reports, your settings and usage counter, and the terms you added to your team's glossary. Your sign-in is deleted at the same moment. The app also removes your data from that device. For anything else write to privacy@wovero.com; we answer within one month.
12. Security
All connections to our servers are TLS-encrypted. Our servers, database and GPU are operated by us in Germany and reachable only through our API. The macOS app is signed and notarized by Apple; updates are signed with our own key and checked by the app before they are installed.
13. Changes to this policy
We update this policy when Kaho or the services we use change. The date at the top shows the latest change. For material changes we tell active users in the app or by email.
14. Contact
Questions, requests or concerns: privacy@wovero.com.