Legal

Privacy policy.

Last updated: 28.09.2026

1. Introduction

Munrel, based in Yverdon-les-Bains, Switzerland, is committed to protecting your privacy in accordance with Swiss data protection laws (nFADP) and the EU GDPR. This policy explains how we collect, use, store, and protect your personal information when you use our voice transcription application.

Controller:
VapeShop Sarl
Rue d'Orbe 1, 1400 Yverdon-les-Bains, Switzerland

2. Information we collect

2.1 Audio data

  • Temporary voice recordings for transcription
  • Recordings are processed in real time and deleted immediately after transcription
  • No audio recordings are permanently stored on our servers

2.2 Account data

  • Email address (for OAuth authentication)
  • Username and profile picture (from Google/GitHub)
  • App preferences and user settings

2.3 Usage data

  • Transcription history (text only)
  • Usage statistics and performance metrics
  • Error logs and technical diagnostics

3. How we use your information

  • Voice transcription: convert your audio recordings into text
  • Service improvement: optimize accuracy and performance
  • Technical support: troubleshooting and user assistance
  • Authentication: secure management of your account
  • Communications: important service notifications

4. Data storage and security

4.1 Storage

  • Data is stored on secure servers in Europe
  • Encryption in transit (HTTPS/TLS) and at rest (AES-256)
  • Automated, encrypted backups

4.2 Data access

  • Limited to authorized personnel only
  • Multi-factor authentication for admin access
  • Logging of all data access

5. Sharing of information

We do not sell, rent, or share your personal information with third parties, except in the following cases:

  • Transcription services: with our API partners (Deepgram, JigsawStack) solely for transcription processing
  • Legal obligations: if required by law or court order
  • Protection of rights: to protect our rights, property, or safety

6. Your rights (nFADP / GDPR)

In accordance with the Swiss Federal Act on Data Protection (nFADP) and the GDPR, you have the following rights:

  • Right of access: obtain a copy of your personal data
  • Right to rectification: correct inaccurate data
  • Right to erasure: delete your personal data
  • Right to portability: receive your data in a structured format
  • Right to object: object to the processing of your data
  • Right to restriction: restrict the processing of your data
  • Right to lodge a complaint: with the Swiss Federal Data Protection and Information Commissioner (FDPIC)

To exercise these rights, contact us via the postal address above. We will respond within 30 days.

7. Data retention

  • Audio recordings: deleted immediately after transcription
  • Transcriptions: kept until manually deleted by the user
  • Account data: kept as long as the account is active
  • Technical logs: retained for up to 12 months

8. Cookies and product analytics

We use essential cookies to:

  • Maintain your login session
  • Save your app preferences
  • Improve performance and security

Product analytics (PostHog): We use PostHog (EU-hosted, eu.i.posthog.com) to understand how Munrel is used and to improve the product. We collect anonymous usage events such as:

  • Feature usage (e.g., recording started, workflow executed, chat message sent)
  • Performance metrics (latency, duration) — never the content of your recordings, transcriptions, or AI prompts
  • Model names and providers selected
  • Error types when something goes wrong

We never collect: audio recordings, transcription text, AI prompts/responses, or any content you create with Munrel.

Session replay and heatmaps: On the website, we use PostHog session replay and heatmaps to understand how visitors navigate our pages. All text inputs are masked, so we never capture what you type into forms.

Your user ID is hashed before being sent to PostHog. You can disable analytics at any time from Settings → Privacy → Send usage analytics in the Munrel desktop apps. On the website, we respect your browser's Do Not Track setting.

9. Changes to this policy

We may update this privacy policy from time to time. Material changes will be notified in the app. Continued use after changes constitutes your acceptance of the updated policy.

10. International data transfers

Some data may be processed by third-party services located outside Switzerland and the EU/EEA:

  • Transcription services: United States (with appropriate contractual safeguards)
  • Cloud storage: Europe only (GDPR compliant)
  • Analytics: data anonymized before processing

All transfers are secured by standard contractual clauses of the European Commission and safeguards equivalent under Swiss law.

11. Data security

We implement appropriate technical and organizational security measures:

  • Encryption: AES-256 at rest, TLS 1.3 in transit
  • Access: multi-factor authentication and least-privilege principle
  • Monitoring: 24/7 monitoring and intrusion detection
  • Backups: encrypted backups tested regularly
  • Training: ongoing staff security awareness

12. Contact and data protection officer

For any questions regarding this privacy policy or your personal data:

Controller:
VapeShop Sarl
Rue d'Orbe 1, 1400 Yverdon-les-Bains, Switzerland

Supervisory authority:
Swiss Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1, 3003 Bern
www.edoeb.admin.ch


This privacy policy complies with the Swiss Federal Act on Data Protection (nFADP), the EU GDPR, and applicable Swiss laws.
Last legal review: 28.09.2026