← Back to Tacite
Privacy by design

Privacy Policy

We explain what data Tacite processes, why it is needed, and what happens to meeting audio and transcripts.

Last updated: September 15, 2026

1. Who we are

Tacite is operated by RUB Conseil SAS, the data controller for the processing described in this policy.

Registered office: 19 rue Ducourouble, 59000 Lille, France. SIREN: 792 792 053.

Contact: contact@tacite.app.

2. Scope of this Privacy Policy

This policy applies to the Tacite website, user accounts, meetings processed through supported integrations, Tacite Direct 1-to-1 conversations, and website visitors when technical data is collected.

The international web service currently supports Google Meet web, Microsoft Teams web, Zoom web and Tacite Direct. Telephone services are not part of the international offer.

3. Personal data we process

Account data

Name where collected, email address, authentication and account identifiers, and preferred language or market where applicable.

Meeting data

Information needed to identify and process a meeting, meeting metadata, participants' names or identifiers when available, temporarily processed audio and the generated summary.

Usage and subscription data

Usage duration, Free or paid plan information, subscription status and technical usage events needed for metering.

Technical data

IP address where technically required, browser and device data, logs and security information, and cookies or local storage used for authentication, routing or operation.

4. How meeting content is processed

Meeting and call content is processed to produce a transcription and a summary. Audio is processed temporarily and is not retained after processing. The transcript is not retained after processing.

The resulting summary may be stored in the user account and made available to the account holder. Technical meeting metadata and usage information may be retained independently of the audio and transcript.

This describes the current operation of the service; this policy does not promise a specific processing time where one is not documented.

5. Participants who do not have a Tacite account

A person taking part in a meeting may be affected by processing even if they do not have a Tacite account. Their speech may be temporarily processed to provide the service.

The Tacite user who starts the processing is responsible for using the service lawfully and informing participants where required. Depending on the meeting flow, Tacite may also provide an information or consent mechanism.

6. Purposes and legal bases

The legal basis can depend on the context in which Tacite is used. The main purposes are:

PurposeDataLegal basis
Create and manage an accountAccount dataPerformance of the contract
Provide meeting transcription and summarisationMeeting data and account dataPerformance of the contract and, where applicable, legitimate interests
Measure Free and subscription usageUsage duration, plan and subscription dataPerformance of the contract
Protect the service and prevent fraudTechnical data, logs and account identifiersLegitimate interests
Meet legal and accounting obligationsAccount, subscription and billing data where applicableLegal obligation

7. Data retention

  • Audio: not retained after processing.
  • Transcript: not retained after processing.
  • Summaries: retained until the user deletes them or the account is deleted, as documented for the service.
  • Account data: retained for the operation and authentication of the service; the French privacy policy documents deletion up to one month after account closure.
  • Usage and metering data: retained as necessary to operate the Free plan and subscriptions, account for usage and meet applicable obligations. No additional fixed period is documented here.
  • Billing and accounting data: retained for ten years where the applicable accounting retention obligation applies.
  • Security logs: retained only for as long as necessary for security and the stated purposes; no fixed period is documented here.

8. Service providers and recipients

Tacite uses the following providers, as confirmed by the current project:

  • OVH: hosting. The legal notice identifies OVH SAS, 2 rue Kellermann, 59100 Roubaix, France, as the host.
  • Supabase: authentication and database services.
  • Mistral AI: LLM processing used for summaries and generated titles.
  • Brevo: transactional email delivery.
  • Stripe: payment and subscription services where applicable.

These providers receive only the data needed for their respective functions and act within the arrangements applicable to the service.

9. International data transfers

Where a processing operation involves a transfer outside the European Economic Area, Tacite will apply the safeguards required by applicable data-protection law. The current repository does not contain enough verified information to state the location or specific transfer mechanism for every provider.

10. Your rights

Subject to the conditions provided by applicable law, you may request access to, rectification or erasure of your personal data, restriction of processing, objection to processing, and portability where applicable. You may withdraw consent at any time where processing is based on consent.

You also have the right to lodge a complaint with the French data-protection authority, the CNIL.

11. How to exercise your rights

To exercise your rights or ask a privacy question, contact contact@tacite.app. Please provide enough information for us to identify the relevant account or request.

12. Cookies and local storage

Tacite uses technical browser mechanisms needed for authentication, routing and operation. The persistent locale preference cookie is tacite_locale; it stores fr or en for one year, with path /, SameSite Lax, and Secure in production. During Google sign-in, the short-lived tacite_oauth_origin cookie carries the locale context for up to 600 seconds; it is HttpOnly, uses path /auth, SameSite Lax, and Secure in production. Tacite also uses Supabase session cookies and the tacite_device_id device identifier for one year (path /, SameSite Lax, Secure in production). The request header x-tacite-locale communicates the selected locale to the application; it is not itself a cookie.

This policy does not describe marketing or advertising cookies because the current project does not show such functionality.

13. Security

Tacite implements technical and organisational measures designed to protect personal data. No online service can guarantee absolute security.

14. Changes to this Privacy Policy

We may update this policy when the service or applicable legal obligations change. The date at the top of this page indicates the latest update.