Privacy Policy
We explain what data Tacite processes, why it is needed, and what happens to meeting audio and transcripts.
Last updated: September 15, 2026
1. Who we are
Tacite is operated by RUB Conseil SAS, the data controller for the processing described in this policy.
Registered office: 19 rue Ducourouble, 59000 Lille, France. SIREN: 792 792 053.
Contact: contact@tacite.app.
2. Scope of this Privacy Policy
This policy applies to the Tacite website, user accounts, meetings processed through supported integrations, Tacite Direct 1-to-1 conversations, and website visitors when technical data is collected.
The international web service currently supports Google Meet web, Microsoft Teams web, Zoom web and Tacite Direct. Telephone services are not part of the international offer.
3. Personal data we process
Account data
Name where collected, email address, authentication and account identifiers, and preferred language or market where applicable.
Meeting data
Information needed to identify and process a meeting, meeting metadata, participants' names or identifiers when available, temporarily processed audio and the generated summary.
Usage and subscription data
Usage duration, Free or paid plan information, subscription status and technical usage events needed for metering.
Technical data
IP address where technically required, browser and device data, logs and security information, and cookies or local storage used for authentication, routing or operation.
4. How meeting content is processed
Meeting and call content is processed to produce a transcription and a summary. Audio is processed temporarily and is not retained after processing. The transcript is not retained after processing.
The resulting summary may be stored in the user account and made available to the account holder. Technical meeting metadata and usage information may be retained independently of the audio and transcript.
This describes the current operation of the service; this policy does not promise a specific processing time where one is not documented.
5. Participants who do not have a Tacite account
A person taking part in a meeting may be affected by processing even if they do not have a Tacite account. Their speech may be temporarily processed to provide the service.
The Tacite user who starts the processing is responsible for using the service lawfully and informing participants where required. Depending on the meeting flow, Tacite may also provide an information or consent mechanism.
6. Purposes and legal bases
The legal basis can depend on the context in which Tacite is used. The main purposes are:
| Purpose | Data | Legal basis |
|---|---|---|
| Create and manage an account | Account data | Performance of the contract |
| Provide meeting transcription and summarisation | Meeting data and account data | Performance of the contract and, where applicable, legitimate interests |
| Measure Free and subscription usage | Usage duration, plan and subscription data | Performance of the contract |
| Protect the service and prevent fraud | Technical data, logs and account identifiers | Legitimate interests |
| Meet legal and accounting obligations | Account, subscription and billing data where applicable | Legal obligation |
7. Data retention
- Audio: not retained after processing.
- Transcript: not retained after processing.
- Summaries: retained until the user deletes them or the account is deleted, as documented for the service.
- Account data: retained for the operation and authentication of the service; the French privacy policy documents deletion up to one month after account closure.
- Usage and metering data: retained as necessary to operate the Free plan and subscriptions, account for usage and meet applicable obligations. No additional fixed period is documented here.
- Billing and accounting data: retained for ten years where the applicable accounting retention obligation applies.
- Security logs: retained only for as long as necessary for security and the stated purposes; no fixed period is documented here.
8. Service providers and recipients
Tacite uses the following providers, as confirmed by the current project:
- OVH: hosting. The legal notice identifies OVH SAS, 2 rue Kellermann, 59100 Roubaix, France, as the host.
- Supabase: authentication and database services.
- Mistral AI: LLM processing used for summaries and generated titles.
- Brevo: transactional email delivery.
- Stripe: payment and subscription services where applicable.
These providers receive only the data needed for their respective functions and act within the arrangements applicable to the service.
9. International data transfers
Where a processing operation involves a transfer outside the European Economic Area, Tacite will apply the safeguards required by applicable data-protection law. The current repository does not contain enough verified information to state the location or specific transfer mechanism for every provider.
10. Your rights
Subject to the conditions provided by applicable law, you may request access to, rectification or erasure of your personal data, restriction of processing, objection to processing, and portability where applicable. You may withdraw consent at any time where processing is based on consent.
You also have the right to lodge a complaint with the French data-protection authority, the CNIL.
11. How to exercise your rights
To exercise your rights or ask a privacy question, contact contact@tacite.app. Please provide enough information for us to identify the relevant account or request.
12. Cookies and local storage
Tacite uses technical browser mechanisms needed for authentication, routing and operation. The persistent locale preference cookie is tacite_locale; it stores fr or en for one year, with path /, SameSite Lax, and Secure in production. During Google sign-in, the short-lived tacite_oauth_origin cookie carries the locale context for up to 600 seconds; it is HttpOnly, uses path /auth, SameSite Lax, and Secure in production. Tacite also uses Supabase session cookies and the tacite_device_id device identifier for one year (path /, SameSite Lax, Secure in production). The request header x-tacite-locale communicates the selected locale to the application; it is not itself a cookie.
This policy does not describe marketing or advertising cookies because the current project does not show such functionality.
13. Security
Tacite implements technical and organisational measures designed to protect personal data. No online service can guarantee absolute security.
14. Changes to this Privacy Policy
We may update this policy when the service or applicable legal obligations change. The date at the top of this page indicates the latest update.