SermonEcho Privacy Policy
Last Updated: August 28, 2026
1. Introduction
Welcome to SermonEcho ("the App", "we", "us", or "our"). We respect your privacy and are committed to protecting your personal data. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our application.
Please read this Privacy Policy carefully. By accessing or using the App, you acknowledge that you have read, understood, and agree to be bound by the terms herein. If you do not agree, please discontinue use immediately.
Please note that certain features of the App, specifically AI-powered transcription, summarisation, and note-generation features, require your explicit and separate consent before your audio recordings, generated transcripts, sermon notes, or related processing metadata are transmitted to AssemblyAI, our third-party AI service provider. This consent will be requested through an dedicated in-app consent notice before the first AI processing operation.
2. Information We Collect
We collect the following categories of information in connection with the provision of our services:
2.1 Account and Registration Information
When you register for an account, we may collect the following:
Phone number (for SMS verification and account authentication)
OAuth identifiers from third-party platforms (Apple, Google, Facebook) where you elect to sign in via such methods
Display name and profile information (if voluntarily provided)
We do not store your third-party OAuth credentials beyond what is strictly necessary for authentication purposes.
2.2 Audio Recordings
The App enables you to create audio recordings (including but not limited to prayers, devotional reflections, and spiritual notes). We collect:
Audio files recorded within the App
Associated metadata, including duration, creation date, tags, and user-defined categories
2.3 AI-Processed Content and AssemblyAI Processing
When you first choose to use AI-powered features, SermonEcho will ask for your explicit permission before sending any personal data or user content to AssemblyAI, a third-party AI speech processing service provider (https://www.assemblyai.com/). We will not send your audio or related content to AssemblyAI unless you give this consent.
The data that may be sent to AssemblyAI includes: audio files recorded or imported in the App; audio metadata needed to process the request, such as duration, file format, language settings, timestamps, request IDs, and technical diagnostics; transcripts or corrected transcript text generated from your audio; and sermon notes, titles, tags, or prompts only when needed to provide a feature you request.
AssemblyAI uses this data to provide speech recognition, transcription, and related AI processing for SermonEcho. The output may include transcripts, summaries, structured notes, topic labels, reference extraction, searchable text, and other content generated from your recordings or notes.
Your recordings may contain personal, sensitive, or confidential information spoken by you or others in the recording. Please obtain any permissions you need from speakers before recording or submitting audio for AI processing.
AssemblyAI processes data in accordance with its applicable Terms of Service, Privacy Policy, and Data Processing Addendum. AssemblyAI's official privacy policy is available at https://www.assemblyai.com/legal/privacy-policy, and its Data Processing Addendum is available at https://www.assemblyai.com/legal/data-processing-addendum.
Depending on the applicable AssemblyAI service plan and configuration, AssemblyAI may process Customer Data for service delivery, maintenance, testing, evaluation, benchmarking, model improvement, and legal or security purposes as described in its terms. Where the applicable AssemblyAI service plan supports the Model Improvement Program Opt-Out or similar controls, we will configure our AssemblyAI account consistent with this Privacy Policy and applicable law.
All transmissions between the App, our servers, and AssemblyAI are protected using industry-standard encryption protocols such as TLS/SSL.
Required for AssemblyAI processing. If you decline to consent to AssemblyAI processing, we will not send your recordings, transcripts, notes, or related processing metadata to AssemblyAI. As a result, the related in-app features will not be available.
In-App Consent Mechanism: Before transmission to AssemblyAI, the App will display a dedicated in-app consent screen.
2.4 Cloud Storage Service — Tencent Cloud
To store and manage your audio recordings and related data, the App uses Tencent Cloud as its cloud storage infrastructure. Your audio recordings and associated metadata are uploaded to and stored on Tencent Cloud servers.
Third-Party SDK Service Provider: Tencent Computer Systems Company Limited
Personal Information Involved: Network access, network status, Wi-Fi status, Wi-Fi configuration status, and device information (including device model and operating system); audio recordings and associated metadata uploaded for storage.
Purpose of Use: Cloud storage of audio recordings and associated data.
Use Scenario: Audio recording, storage, and retrieval.
Collection Method: SDK collection and API transmission.
Provider Website: https://cloud.tencent.com/document/product/1093/48982
Provider Privacy Policy: https://cloud.tencent.com/document/product/301/94121
Tencent Cloud processes data in accordance with its applicable service terms and privacy policy. We require Tencent Cloud to protect your data in a manner consistent with this Privacy Policy and applicable data protection requirements.
2.5 Usage Data
We automatically collect information regarding your interactions with the App, including:
Page views, module exposures, click events, and scroll behaviour
Session duration, frequency, and retention metrics
Feature usage patterns, including recording, playback, filtering, sharing, and other feature interactions
Error logs, crash reports, and performance diagnostics
We use third-party analytics and attribution services, including Firebase and Adjust, to understand how users interact with the App, measure application performance, analyse acquisition and attribution, evaluate marketing campaigns, and improve our services.
These services may collect information such as device information, operating system information, application version, app events, session information, advertising or attribution identifiers where permitted, IP address or approximate location information, and other technical or usage information necessary for analytics, attribution, security, and diagnostics.
The information collected through these services is used for analytics, attribution, performance monitoring, crash diagnostics, fraud prevention, campaign measurement, and service improvement. We do not use these services to access the content of your private audio recordings, transcripts, summaries, or notes unless such access is necessary to provide a feature you have explicitly requested.
2.6 Device Information
We may collect the following device and technical information:
Device type, model, and manufacturer
Operating system name and version
Application version and build information
App-specific identifiers and device-related identifiers, such as identifiers generated by the App or used by third-party analytics and attribution services, including Firebase and Adjust
IP address and related technical information
Network, device, and application diagnostic information
These identifiers may be used for analytics, attribution, security, fraud prevention, application performance measurement, and service improvement. We do not use device identifiers to create a persistent profile of users across unrelated third-party apps or websites for targeted advertising without obtaining the permissions required by applicable law.
2.7 Notification Data
If you opt in to receive push notifications, we store your device push token for the purpose of delivering content updates and reminders. You may manage your notification preferences at any time via your device settings or the App's internal settings.
2.8 Profile and Avatar Information
If you choose to upload or select a profile avatar, we collect and store the image file you provide. Your avatar is used solely for the display of your profile within the App and is stored securely on our servers.
3. Device Permissions
The App may request the following permissions on your device. Each permission is requested only when necessary for the corresponding feature, and you may revoke any permission at any time through your device settings. Revoking a permission may affect the availability of certain features.
Microphone access: Required for audio recording functionality. The App will request microphone permission only first when you initiate a feature that needs recording. Before the iOS system permission request appears, the App may show a short explanation and a neutral button such as "Continue" . The App will not record audio unless microphone permission is granted.
File access (photo library / file system): Required for selecting a profile avatar image from your device. The App will request access when you choose to upload or select an avatar.
Photo library / download storage: May be requested when you choose to save images (e.g., share cards, exported notes) to your device. The specific behaviour may vary depending on your device's operating system and capabilities.
Clipboard access: May be requested when you choose to copy a sharing link. The App accesses the clipboard solely to paste the copied link and does not read other clipboard contents.
4. Data Privacy Principles
The following principles govern the privacy and visibility of your content within the App:
Default private: Your audio recordings, AI-generated transcripts, summaries, and structured notes are, by default, visible only to you. They are not accessible to other users or publicly displayed. They are shared with third-party service providers only as described in this Privacy Policy, such as with AssemblyAI after your explicit AI processing consent, or when you explicitly choose to share them.
User-initiated sharing only: Any sharing of your content — including but not limited to saving images, sharing via social media, or copying links — can only be triggered by your voluntary and explicit action. The App does not automatically share, publish, or distribute any of your content.
Consistency guarantee: The privacy protections described herein — including avatar storage, recording and note storage, sharing permissions, and data visibility — shall remain consistent with the App's actual technical implementation. Any material discrepancy between this policy and the App's real-world behaviour shall be promptly corrected.
5. How We Use Your Information
We use the information collected for the following purposes:
Service delivery: To provide core functionalities including account authentication, audio recording, AI transcription and summary generation where you have consented to AssemblyAI processing, and note management
Personalisation: To tailor content recommendations, filter suggestions, and notification delivery based on your usage patterns
Notifications: To deliver push notifications for content updates, devotional reminders, and service announcements (subject to your consent)
Service improvement: To analyse usage patterns, identify and resolve technical issues, and develop new features
Sharing functionality: To generate shareable images and links — solely upon your explicit and voluntary action
Security and compliance: To protect against unauthorised access, fraud, and other security threats, and to comply with applicable legal obligations
Analytics and diagnostics: To monitor application stability, troubleshoot technical issues, measure feature performance, and improve the overall user experience
Third-party AI processing: With your explicit permission, to transmit the data described in Section 2.3 to AssemblyAI for speech recognition, transcription, summarisation, and related AI-powered features
6. Data Storage and Security
6.1 Storage Location
Your data is stored on our secure cloud servers. Audio recordings, AI-generated content (transcripts, summaries, and notes), and profile avatars are retained for the duration of your account's active status.
6.2 Security Measures
We implement appropriate technical and organisational measures to protect your personal data, including but not limited to:
Encryption in transit (TLS/SSL) for all data transmissions
Encryption at rest for sensitive data
Access controls and authentication requirements for internal systems
Regular security assessments and vulnerability reviews
Please note that no method of transmission over the Internet or electronic storage is entirely secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.
6.3 Data Retention
We retain personal information only for as long as necessary to provide our services, comply with legal obligations, resolve disputes, enforce our agreements, and protect our legitimate business interests. Retention periods may vary depending on the type of data and applicable legal requirements.
6.4 Account Deletion
You may delete individual recordings, transcripts, notes, or your entire account at any time through the App's Settings. Upon account deletion, we will delete or anonymize your personal information within a reasonable period unless we are legally required or permitted to retain certain information.
7. Third-Party Services
The App integrates the following categories of third-party services:
Authentication providers: including Apple Sign In, Google Sign-In, and Facebook Login.
AI processing service provider: AssemblyAI (https://www.assemblyai.com/), which performs speech recognition, transcription, summarisation, and related AI-powered processing on our behalf only after the user has provided the consent described in Section 2.3.
Cloud storage service provider: Tencent Cloud (https://cloud.tencent.com/), which provides cloud storage infrastructure for audio recordings and associated data.
Analytics and diagnostics providers that help us understand application performance, usage trends, crashes, and feature improvements.
Push notification providers, including Apple Push Notification Service (APNs) and Firebase Cloud Messaging (FCM).
Each third-party service provider operates under its own privacy policy. We also require service providers that process user data on our behalf to protect such data in a manner consistent with this Privacy Policy and applicable data protection requirements. We encourage you to review their respective policies.
8. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties for advertising or marketing purposes. We may disclose your information only in the following circumstances:
User-directed sharing: When you voluntarily choose to share content via social media or other channels
Service providers: With trusted third parties who assist us in operating the App, including AssemblyAI for AI speech processing where you have consented, subject to contractual confidentiality, security, and data protection obligations that require the same or equal protection for user data as described in this Privacy Policy and required by applicable law
AssemblyAI disclosure: Before any audio recording, generated transcript, sermon note, or related processing metadata is shared with AssemblyAI, the App will identify AssemblyAI as the recipient, describe the data to be sent, and ask for your permission. If you do not grant permission, the data will not be sent to AssemblyAI.
Legal obligations: When required by applicable law, regulation, legal process, or government request
Business transfers: In connection with a merger, acquisition, reorganisation, or sale of assets; we will notify you of any such change and any choices regarding your data
9. Your Rights and Choices
Depending on your applicable jurisdiction, you may exercise the following rights regarding your personal data:
Right of access: Request a copy of the personal data we hold about you
Right to rectification: Request correction of inaccurate or incomplete personal data
Right to erasure: Request deletion of your personal data or specific recordings and notes
Right to opt out: Disable push notifications and revoke device permissions through your device or App settings at any time
Right to data portability: Request a portable copy of your data in a commonly used, machine-readable format
Right to restrict processing: Request that we limit the processing of your personal data under certain circumstances
To exercise any of the above rights, please contact us using the details provided in Section 14.
10. Children's Privacy
The App is not directed at children under the age of 13 (or the applicable minimum age under your local jurisdiction). We do not knowingly collect personal information from children below such age. If we become aware that we have inadvertently collected data from a child below the applicable age, we will take prompt steps to delete such information.
11. Legal Basis for Processing (EEA/UK Users)
If you are located in the European Economic Area (EEA), the United Kingdom, or another jurisdiction with similar data protection laws, we process your personal data based on one or more of the following legal bases:
Your consent;
Performance of a contract;
Compliance with the General Data Protection Regulation(GDPR) and other legal obligations;
Special Category Data (Article 9 GDPR): Where we process voice recordings through AI speech recognition and transcription services, such processing may involve biometric data as defined under Article 9(1) of the GDPR. We process such special category data exclusively on the basis of your explicit consent under Article 9(2)(a) of the GDPR. This consent is obtained separately from any other consent or acceptance of terms, through the dedicated in-app AI consent screen described in Section 4.1. You have the right to withdraw this consent at any time, and withdrawal will not affect the lawfulness of processing conducted prior to withdrawal.
Our legitimate interests, provided such interests are not overridden by your rights and freedoms.
12. California Privacy Rights
California residents may have additional rights under applicable California privacy laws, including the right to know, delete, or correct certain personal information. Where required by law, we will honor such requests in accordance with applicable regulations.
13. International Data Transfers
Your data may be transferred to, and processed in, countries other than your country of residence. Such countries may have data protection laws that differ from those of your jurisdiction. Where we transfer data internationally, we implement appropriate safeguards — including standard contractual clauses approved by relevant authorities — to ensure your data remains protected in accordance with this Privacy Policy and applicable data protection legislation.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
Email: igniteddy@icloud.com
We will make reasonable efforts to respond to your request within the timeframe required by applicable law.
15. Changes to This Policy
We reserve the right to update or modify this Privacy Policy at any time. When we make material changes, we will: (a) update the "Last Updated" date at the top of this page; and (b) where reasonably practicable, provide prominent notice within the App. Your continued use of the App following the effective date of any changes constitutes your acknowledgement of the revised policy. Where material changes affect the collection, use, processing, storage, or sharing of your personal data, including changes to AI processing practices or third-party providers handling your audio recordings, we will obtain your explicit consent through an in-app notification where required by law. You may choose to discontinue use of the affected features if you do not agree to the revised terms.
© 2026 IGNITEDDY TECH SDN.BHD. All rights reserved.