Privacy Policy
For Ponora hardware, app, web, cloud and AI services
Controller | Ponora International GmbH |
Address | Hammfelddamm 4 A, 41460 Neuss, Germany |
support@ponora.ai | |
Website | https://ponora.ai |
Commercial Register | Local Court of Neuss (Amtsgericht Neuss), HRB 25047 |
VAT No. | DE460769264 |
Version | 5.0 | As of: 31 August 2026 |
This privacy policy explains transparently which personal data Ponora processes, for what purposes this is done and what rights data subjects have.
Privacy contact: support@ponora.ai
Table of Contents
1. Controller and Data Protection Contact | 16. Third-country transfers and remote access |
2. Scope and data protection roles | 17. Storage duration and deletion criteria |
3. Purposes and legal bases of the processing | 18. Account deletion and data export |
4. Categories of personal data | 19. Security and data breaches |
5. Registration, account and consents | 20. Orders, payments and subscriptions |
6. Devices, device binding and usage quotas | 21. Website, cookies and local storage |
7. Audio recordings, local storage and upload | 22. Communication, support and marketing |
8. Transcription and language processing | 23. Automated decision-making and AI transparency |
9. Long Recordings, Segmentation and Speaker Diarisation | 24. Data Subject Rights and Right to Lodge a Complaint |
10. AI Summaries, Highlights and Sharing | 25. Minors and Lawful Audio Recordings |
11. No use for general AI training | 26. Changes to this privacy policy |
12. Special categories of personal data | Annex A. Data flow |
13. Information for Recorded Persons Without a Ponora Account | Annex B. Storage and deletion criteria |
14. Infrastructure and processing regions | Annex C. Essential recipients and service providers |
15. Recipients and service providers |
1. Controller and Data Protection Contact
The controller within the meaning of the General Data Protection Regulation (GDPR) is Ponora International GmbH, Hammfelddamm 4 A, 41460 Neuss, Germany.
Data protection-related inquiries can be sent to support@ponora.ai. Further contact options can be found in the imprint at https://ponora.ai.
No data protection officer has currently been appointed. If one is appointed in the future, their contact details will be published in this Privacy Policy.
2. Scope and data protection roles
This privacy policy applies to the Ponora websites, the mobile app, the web application, Ponora recording devices and recorder cards, the cloud, transcription and AI functions, and to orders and subscriptions.
Ponora generally acts as controller for managing user accounts, contractual relationships, orders, payments, customer communications and system security, and for operating its own website.
Where Ponora processes personal data exclusively on the documented instructions of a corporate customer, Ponora may act as processor for that processing. A data processing agreement under Art. 28 GDPR must be concluded before such processing begins. The specific role always depends on the actual processing activities and decision-making powers, not merely on how a contract is labelled.
Payment service providers, app stores, platform operators or other providers may act as independent controllers for particular processing activities. In that case, their privacy notices also apply.
3. Purposes and legal bases of the processing
Ponora processes personal data only for specific, unambiguous and legitimate purposes. The relevant legal basis depends on the specific processing.
Purpose / Processing | Data | Legal basis | Note |
|---|---|---|---|
Account, contract and requested services | Account, device, content and tariff data | Art. 6(1)(b) GDPR | Contract and pre-contractual measures |
Accounting, taxes and legal documents | Billing, payment and contract data | Art. 6(1)(c) GDPR | Legal obligations |
System security, abuse and fraud prevention | IP, device, security and log data | Art. 6(1)(f) GDPR | Legitimate interests in security and integrity |
Voluntary marketing and non-essential technologies | Contact data, consent and usage data | Art. 6(1)(a) GDPR | Consent; may be withdrawn at any time |
Processing on behalf of a corporate customer | Content and personal data provided by the customer | The legal basis is determined by the respective controller. | Ponora processes the data as a processor on the basis of a data processing agreement pursuant to Article 28 GDPR and in accordance with the customer's documented instructions. |
Special categories of personal data | For example, health data in audio and text | Article 9(2)(a) GDPR | Explicit consent of the data subject |
User-initiated AI functions: transcription, summarisation, title suggestion, mind map, tasks, keywords, AI suggestions and recurring context notes | Audio, transcript, note and context data, user prompts | Article 6(1)(b) GDPR | Only after active initiation |
Push notifications (Firebase Cloud Messaging) | Push token, platform, device identifier, device language, app version | Article 6(1)(b) and (f) GDPR | Google Ireland Ltd.; transfer to Google LLC (USA) based on the standard contractual clauses (Commission Implementing Decision (EU) 2021/914); copy via support@ponora.ai |
Provision and logging of public sharing links | Shared content, sharing code, access time, IP address, user agent | Article 6(1)(b) and (f) GDPR | Recipients can access without a Ponora account |
Where particular information is required to conclude or perform a contract, failure to provide it may mean that an Account or requested function cannot be provided, or that an order cannot be processed.
Where processing is based on consent, that consent may be withdrawn at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the consent was withdrawn.
4. Categories of personal data
Depending on the use, Ponora processes the following data categories in particular:
• Master data and contact data, such as display name, e-mail address, language, time zone and, if applicable, company information.
• Account and authentication data, such as password hashes, login times, session information, OAuth connections, and verification and security data.
• Device and linking data, such as device ID, serial number, model, firmware version, linking status, and the most recently reported battery and storage status.
• Audio and content data, such as recordings, imported audio files, transcripts, summaries, tags, notes, tasks, mind maps, user prompts, and shared content.
• Speaker-related technical data, such as technical speaker labels, temporarily extracted audio segments and assignment results.
• Usage, quota and diagnostic data, such as used processing minutes, function calls, IP address, browser and app information as well as error and security logs.
• Order, payment and billing data, for example ordered products, tariff, billing data, payment status and transaction IDs.
• Communication and support data, such as requests, messages, attachments, and processing notes.
• Consent and evidence data, such as the purpose, text or version reference, language, time and source of consent, and records of its withdrawal.
• AI usage logs, e.g. process type (transcription, summary), model used, token count, costs and association with user and recording.
• Push and notification data, e.g. push token, platform, device identifier, device language and time of last registration.
• Sharing and access data, e.g. sharing code, permissions, expiry and access counter values, and IP address and user agent of persons who access a sharing link.
• Recurring context notes (“Memory”) derived from user content and used across recordings to improve output quality.
• Speaker-assignment data for long recordings, e.g. segment identifiers, technical speaker labels, time windows, confidence values and procedure version.
Ponora does not access the device's address book; the app does not request such permission. For a user-initiated one-off selection of an image and for saving the user's own evaluation graphics, a multimedia permission is requested by the system. A location permission is requested solely for Bluetooth and Wi-Fi detection of Ponora devices (on Android only up to API level 32); location coordinates are not collected and are not stored.
5. Registration, account and consents
When users register, Ponora processes, in particular, their email address, password hash, display name, language and time zone. For registration through Apple or Google, the Account data released by the respective provider may be processed.
Sign-in with Apple in the mobile app is technically routed via a forwarding service operated by Ponora on Google Cloud Run.
Acceptance of the GTC, acknowledgement of this Privacy Policy and voluntary consent are legally distinct processes. Voluntary consent, in particular for marketing, is not bundled with acceptance of the GTC.
The newsletter consent is not preselected, requires an active choice and is confirmed by double opt-in by email. Marketing consent that has been given may be withdrawn at any time via the unsubscribe link in each marketing email, in the account settings or via support@ponora.ai.
Ponora stores evidence of acceptance of contracts, privacy notices and consents insofar as necessary for statutory accountability requirements and the defence of legal claims. For registration, a confirmation flag and timestamp are stored. For the newsletter, the purpose, version of the consent text, version of the Privacy Policy, language, source, times of request, confirmation and unsubscribing, and a continuing event history are additionally stored. For the notice before recording, a versioned confirmation is stored; this confirmation covers recordings started via telephone or app, but not recordings started directly offline via the device button.
6. Devices, device binding and usage quotas
When connecting a Ponora device or a recorder card to an account, Ponora processes device IDs, serial number, model, firmware information, binding status, and timing of the last status message.
Battery and storage indicators are generally only snapshots transmitted to the backend when the device connects through the mobile app. They do not mean that the web application polls the device in real time.
To manage the free and chargeable scope of services, Ponora processes the device binding, the tariff status and the used processing minutes. The free quota is assigned to a user account after device binding; several devices linked to the same account share the quota of this account.
7. Audio recordings, local storage and upload
Ponora follows a local-first principle. New recordings are first stored locally on the recording device or in the mobile app. Automatic cloud synchronization is not enabled by default.
An upload to the Ponora cloud is triggered when the user actively selects a cloud-based function, in particular transcription or summary, or turns on an available synchronization function.
The user is responsible for ensuring that recording, uploading, processing and sharing are lawful. In Germany, the unauthorised recording of the non-publicly spoken word may, in particular, be punishable under section 201 StGB. Any necessary information must be provided, and any required consent or other legal basis must be obtained, before recording begins.
Audio data transferred to the cloud is stored encrypted. For transcription, it is temporarily decrypted on the processing server in a temporary file and deleted after processing is completed or fails. For transfer to the speech-recognition service, time-limited signed access URLs are generated.
8. Transcription and language processing
Ponora uses Microsoft Azure Speech as the sole service for automatic speech-to-text processing. Processing takes place in the Azure Germany West Central region (Germany). The Azure procedures “Fast Transcription” (REST) and the Azure Speech streaming interface are used; for very long recordings, the recording is divided into segments.
For the transcription requested by the user, the selected audio data is transmitted to Microsoft Azure. The processing is used for speech recognition and the associated technical speaker separation.
There is no fallback route to another provider for speech recognition. Requests naming a provider other than Azure are rejected server-side. Switching between the Azure procedures (Fast Transcription and Streaming) remains with the same provider and in the same region.
Accuracy depends, among other things, on speech, pronunciation, noise level, microphone quality and overlapping speech. Transcripts should be reviewed before further use.
For automatic speech recognition, languages including German, English, Chinese and French are supported. Processing takes place in the stated Azure region irrespective of the detected language. For recordings exceeding a specified maximum duration, speaker separation is automatically disabled.
9. Long Recordings, Segmentation and Speaker Diarisation
Longer recordings can be divided into several sections. Within the sections, the speaker separation assigns technical speaker identifications to conversation contributions.
To ensure consistent assignment across several segments, Ponora may select several short, high-quality voice samples of the same candidate from adjacent segments, separate them with short intervals of silence and analyse them again using Azure Speech. At least three speech segments of at least two seconds each are used; unsuitable or overlapping segments are excluded.
For this additional test, the complete long recording is not transmitted again. The analysis serves only as a technical auxiliary signal and is combined with other criteria.
The temporary audio files generated for this additional check are deleted immediately after processing is successfully completed or fails; there is no additional retention period. By contrast, the speaker-assignment results are stored as metadata for the recording, in particular segment identifiers, technical speaker labels, time windows, confidence values, procedure version and check status. This metadata contains no audio data; it is deleted with the recording or the account and is not subject to its own expiry period.
Technical speaker labels are not automatically linked to real names; users may assign a name to a speaker label themselves, and that name then originates from the user. In cases of doubt, speaker assignment may be subject to an internal review; the review status and reviewing body are logged for this purpose.
10. AI Summaries, Highlights and Sharing
To generate summaries, Ponora processes transcripts, highlights and, where applicable, other contextual information provided by the user.
For AI-supported text analyses, Anthropic Claude is used via Google Vertex AI in the europe-west1 region (European Union). Google Gemini via Google Vertex AI in the same region is used as the fallback model. The fallback chain remains entirely within the European Union.
The available AI functions include audio transcription, summarisation, title suggestions, highlighting important content, mind maps, task extraction, keywords, AI suggestions, cross-recording context notes, and sharing and exporting results.
Photos attached to a recording or note are not passed to the language model as image content; only references are passed.
When the user creates a share, the selected content is made accessible via a link. A share includes transcript sections, summaries, structured results, key statements, tasks, participant details, recording time and the display name of the person creating the share; the audio file itself is not provided through the public sharing route. It can be accessed without a Ponora account. An expiry period and access and download limits can be set; without corresponding details, a sharing link does not automatically expire under the current method. Accesses to sharing links are logged, including the IP address and user agent of the person accessing them. Ponora recommends setting an expiry period for shares.
AI-generated results may be incomplete or incorrect. They serve as support and do not replace medical, legal, tax, financial or other professional advice.
11. No use for general AI training
Ponora does not use audio recordings, transcripts or summaries to train generally available or cross-provider AI models.
The current product version does not include a voluntary opt-in option for model training or a general improvement programme. Such a programme is therefore not presented as an available user option.
Technical quality controls, security checks and abuse detection may be carried out to the extent necessary, provided there is a legal basis and the processing is limited to the relevant purpose.
Ponora does not export user content for training, dataset or feedback purposes. Whether and to what extent the providers used may process content for their own purposes or for abuse controls is governed by the contracts concluded with those providers and the account settings there; provider-side exclusions are controlled contractually and through provider configuration, not in the application.
12. Special categories of personal data
Audio recordings and transcripts may include special categories of personal data within the meaning of Art. 9 GDPR, in particular health data, political opinions, religious or ideological beliefs, trade union membership, ethnic origin as well as data on sexual life or sexual orientation.
Such content may be processed only if there is both a legal basis under Art. 6 GDPR and an applicable condition under Art. 9(2) GDPR. Depending on the use, this may be express consent or another statutory exception.
Corporate customers remain responsible, in principle, for assessing the lawfulness of their recording and processing purposes, informing data subjects and documenting compliance with the necessary conditions under Articles 6 and 9 GDPR. A data processing agreement does not replace the customer’s own legal basis.
This Privacy Policy does not constitute authorisation under medical law or professional rules to process special categories of personal data.
13. Information for Recorded Persons Without a Ponora Account
This section is also intended for individuals whose voice or statements are contained in a recording made or uploaded by a Ponora user even though they do not themselves have a Ponora account.
In these cases, the data is generally obtained from the user who makes or uploads the recording. The data processed may include, in particular, voices, spoken content, technical speaker labels and contextual information. Processing is carried out for the functions selected by the user, particularly storage, transcription, speaker diarisation, summarisation and sharing.
The user making the recording must inform the data subjects in good time and obtain any necessary consent or other legal basis. This obligation does not exclude Ponora’s own information and support obligations.
Recorded persons may exercise their data protection rights without a Ponora account by contacting support@ponora.ai. To identify a recording and protect other participants, Ponora may request appropriate information to identify the recording concerned and verify the requester’s identity.
14. Infrastructure and processing regions
Ponora's primary infrastructure is operated on the Google Cloud Platform in the europe-west3 region in Frankfurt am Main. Google Cloud Storage, the database (Cloud SQL), compute clusters (GKE), the container registry and Cloud Run services are located there.
Google Cloud Pub/Sub is used for message processing. Deletion and processing events with user identifiers are transported via this service; content of recordings, transcripts or summaries is not transmitted. Storage of these messages outside the European Union cannot currently be ruled out. In this case, the transfer relies on the European Commission's standard contractual clauses (Commission Implementing Decision (EU) 2021/914) together with the provider's supplementary safeguards. A copy of the safeguards can be requested from support@ponora.ai.
Microsoft Azure Speech processes audio data in the Germany West Central region (Germany). Anthropic Claude and Google Gemini are used via Google Vertex AI in the europe-west1 region (European Union). Google Cloud Storage (europe-west3) and a storage environment at IONOS (Frankfurt am Main) are used for object data.
The processing routes for primary storage, speech recognition and AI analysis are located in Germany or the European Union, respectively. Message storage at Google Cloud Pub/Sub is not limited exclusively to the European Union; the information in this section and in section 16 applies to it.
15. Recipients and service providers
Ponora transmits personal data only to the extent necessary for the provision of the requested services, payment processing, communication, legal obligations or the protection of legitimate interests.
Provider / Recipient | Purpose | Data types | Region / Classification |
|---|---|---|---|
Google Cloud Platform | Primary cloud infrastructure: storage, databases, computing power and message processing | Account, audio, transcript, usage and technical data | europe-west3, Frankfurt am Main, Germany; for message processing (Pub/Sub), see section 14 |
Microsoft Azure Speech | Speech recognition and technical speaker separation | Selected audio data, audio segments, and speaker labels | Configured Azure region, default Germany West Central (Germany) |
Anthropic Claude on Google Vertex AI | AI summaries | Transcripts, tags, and context data | Europe-west1, EU |
Google Gemini via Google Vertex AI | Fallback for AI summaries | Transcripts, tags, and context data | Google Vertex AI, configured EU region, default europe-west1 |
Mailgun | Transactional emails and support communications | Email address, message and delivery metadata | EU endpoint api.eu.mailgun.net, sender domain send.ponora.de |
Stripe / SEPA | Payment processing and billing; SEPA direct debit only insofar as offered in Stripe Checkout | Customer, invoice, payment and transaction data | Stripe Payments Europe Ltd., Ireland (EU) |
PayPal | Payment processing only for one-off purchases in the shop; not for subscriptions | Customer, payment and transaction data | Only for one-off purchases in the shop; not for subscriptions |
Apple App Store / Google Play | Platform purchases, subscriptions and platform management | Account, purchase, subscription and transaction data | Independent platform conditions |
Transport and logistics service providers | Delivery of hardware and processing of transport damage | Name, delivery address, contact and shipping data | Depending on the delivery route |
Google Firebase Cloud Messaging | Delivery of push notifications | Push token, platform, device identifier, notification content | Google Ireland Ltd.; transfer to Google LLC (USA) based on the standard contractual clauses (Commission Implementing Decision (EU) 2021/914); copy via support@ponora.ai |
IONOS (object storage) | Object storage | Recordings, export files, profile pictures | eu-central-1, Frankfurt am Main, Germany |
Where necessary, Ponora concludes data processing agreements with processors under Art. 28 GDPR. Providers acting for their own purposes or as independent contracting parties provide information about their processing in their own privacy notices.
The current service provider overview can be updated in case of significant changes. Changes with data protection relevance will be handled in accordance with the legal requirements.
16. Third-country transfers and remote access
Primary technical processing takes place in the European Union. Authorised technical and administrative support access may take place from Germany and China. Such access takes place exclusively by authorised persons via secure access and is logged.
Access from China is treated as a transfer to a third country. Such access may take place only to the extent that the requirements of Articles 44 et seq. GDPR are met, the necessary safeguards are documented and appropriate technical and organisational measures are implemented. Ponora bases such transfers on the European Commission's standard contractual clauses (Commission Implementing Decision (EU) 2021/914) together with a documented risk assessment and supplementary technical and organisational safeguards.
Data subjects may contact support@ponora.ai for information about the safeguards used for a specific transfer to a third country and to request a copy of the relevant safeguards, provided this does not prejudice third-party rights or security interests.
17. Storage duration and deletion criteria
Ponora does not retain personal data longer than necessary for the relevant purpose. The decisive factors include, in particular, the duration of the Account and contract, user decisions, statutory retention obligations, the need to establish, exercise or defend legal claims, and technical erasure and overwriting cycles.
Active user content such as audio recordings, transcripts, summaries, highlights, notes and mind maps is stored without an automatic expiry time until the user deletes it, the account is deleted or the processing purpose ceases.
Temporary audio files for cross-segment speaker assignment are deleted immediately after successful completion or failure. Other technically time-limited data: temporary objects in object storage are removed after seven days, export files after 90 days, signed download URLs expire after no more than seven days, and backup copies in object storage are retained for 365 days.
Billing data and data required under tax and commercial law are retained for the periods required by statute.
Data in backups is removed as part of the applicable rotation and overwriting cycles. Until overwrite, they are not used for regular product operation and are kept only for recovery and security purposes.
Logs concerning use of AI functions (process type, model, token count and costs) are retained for billing, abuse prevention and evidentiary purposes on the basis of Article 6(1)(c) and (f) GDPR for no more than 30 days. The personal reference of these logs is removed no later than 30 days after an account is deleted. You may object under Article 21 GDPR to processing based on Article 6(1)(f) GDPR.
18. Account deletion and data export
When closing their account through the regular, user-initiated process, the user may expressly choose a recovery period of 30 days. This period is voluntary. During the chosen period, the user may cancel the closure and use the export functions that remain available.
A request for the permanent erasure of personal data under Article 17 GDPR is not subject to a mandatory recovery period. Where the statutory conditions are met, Ponora erases the relevant data without undue delay, unless an exception under Article 17(3) GDPR applies. Such requests may also be sent to support@ponora.ai during a chosen recovery period; the remaining period will not be awaited. Ponora provides information on the measures taken without undue delay and at the latest within one month of receipt of the request. Any extension permitted under Article 12(3) GDPR will be communicated within the first month, together with the reasons. Access for cancelling a regular account closure remains available only during an expressly chosen recovery period; cancellation is also possible via Support.
Export of individual content differs by application: in the web application, PDF, DOCX, TXT and Markdown formats are available for transcripts and notes, and PNG, SVG and Markdown for mind maps. In the mobile app, PDF, DOCX, TXT and Markdown are available, with no PDF for transcripts; DOCX export requires a recording synchronised to the cloud; mind maps may be output as PNG or Markdown. Tasks are output together with their associated notes only when exporting via the mobile app; the server-generated export contains the title, transcript and summary and no tasks.
The export is available in the app via the share function of the audio detail page and in the web application in the upper right area of the recording detail page.
This export of individual content is distinct from your right of access (Article 15 GDPR) and right to data portability (Article 20 GDPR). You may exercise these rights at any time via support@ponora.ai; Ponora will provide you with the relevant data in a common machine-readable format.
For a regular account closure with an expressly chosen recovery period, the technical deletion process is initiated after that period expires. If no recovery period has been chosen, or in the case of a valid erasure request under Article 17 GDPR, the deletion process is initiated promptly and carried out without undue delay. Once the deletion process begins, the export functions are no longer available. Statutory retention obligations and the exceptions under Article 17(3) GDPR remain unaffected. Data temporarily remaining in backups, security logs or with service providers are subject to the deletion criteria described in Section 17; technical or contractual procedures do not justify undue delay in erasure required by law.
Ponora does not promise that deletion from all active systems, backups and service-provider systems will occur simultaneously by any particular, technically unverified time. Deletion is carried out in accordance with the processes of the respective systems and service providers.
Upon completion of deletion, account, session, settings, recording, transcript, note, sharing, notification and AI-processing data is deleted; object files are deleted through a subsequent deletion job. The only data remaining are a record of the deletion operation with a pseudonymised user identifier and data subject to statutory retention obligations.
19. Security and data breaches
Ponora implements appropriate technical and organisational measures under Art. 32 GDPR. These include, in particular, encryption in transit, role-based access rights, separation of development and production environments, logging of security-relevant processes, security updates, and backup and recovery procedures.
Access to user accounts and the user management system is protected by tiered authentication and authorisation procedures.
No technical system offers absolute security. Ponora reviews its safeguards on a risk-based basis and adjusts them where necessary.
If a personal data breach occurs, Ponora documents the incident and complies with the statutory reporting and notification obligations. Where the breach is likely to result in a risk to the rights and freedoms of natural persons, it will, in principle and where required by law, be notified to the competent supervisory authority within 72 hours after Ponora becomes aware of it. Where the breach is likely to result in a high risk, the data subjects will be informed without undue delay unless a statutory exception applies.
20. Orders, payments and subscriptions
For orders and subscriptions, Ponora processes in particular names, contact details, invoice data, ordered products, tariff, payment status, transaction IDs and, if applicable, tax-required information.
Payments under direct Ponora contracts are processed via Stripe; the payment methods appearing at checkout may include, in particular, card payment and SEPA direct debit. PayPal is available only for one-off purchases in the shop, not for subscriptions. Purchases and subscriptions via the Apple App Store and Google Play are processed via the respective platform.
Complete payment data may be processed directly by the relevant payment service provider or platform operator. Those providers may act as independent controllers in this respect. Ponora generally receives only the information needed for contract management, payment status, accounting and support.
The processing serves the execution of the contract, the fulfillment of statutory accounting and tax obligations, the prevention of fraud and the processing of payment and support cases.
21. Website, cookies and local storage
When the Ponora website is visited, server-log data such as the IP address, time, page accessed, referrer, browser and operating system may be processed. This processing is carried out for technical operation, security and error analysis.
Technically necessary cookies or comparable local storage can be used to provide the website, manage sessions, enable security features and store data protection settings.
Specifically used are: session and renewal tokens as server-only cookies, a language cookie with a term of one year set for the Ponora domains, and the local-storage entry containing the consent selection. When payment and login functions are used, scripts from Stripe, PayPal, Apple and Google are additionally loaded; these are required for the respective expressly requested function and are not loaded on ordinary information pages. Display names and email addresses are not stored in cookies readable by JavaScript. The account data required to display the logged-in user are retrieved after authentication via a protected interface.
At present, no analytics or marketing technologies requiring consent are integrated on the Ponora websites. Only technically necessary cookies and local-storage entries within the meaning of section 25(2) TDDDG are used. The consent banner shows non-essential categories as disabled by default. You can change or withdraw your selection at any time via the “Cookie settings” link in the footer of each page.
If Ponora uses non-essential analytics or marketing technologies in the future, they will be activated only after the necessary consent has been obtained and will be identified in the then-current Cookie Policy and consent tool.
22. Communication, support and marketing
When contacting us, Ponora processes the transmitted data in order to answer the request, to document the process and, if necessary, to fulfill contractual or legal obligations.
Mailgun via the EU endpoint (api.eu.mailgun.net) and sender domain send.ponora.de is used for transactional emails and support communication. Open and click tracking is disabled. To limit abusive newsletter registrations, a key-bound hash value is generated from the requester's IP address and passed to the backend; the IP address itself is not stored for this purpose.
Marketing communications are sent only on the basis of voluntary consent or a legally permitted exception. The marketing option is disabled by default. Each marketing message should contain an appropriate unsubscribe option.
Necessary service, security, contract or payment communications are not marketing communications and can be sent independently of a marketing consent.
23. Automated decision-making and AI transparency
Within the framework of the standard services described, Ponora does not make exclusively automated decisions that have legal effect on users or similarly significantly affect them.
Transcripts, summaries and other automatically generated content may contain errors and must be reviewed before important use. Details on labelling automatically generated content are set out in the AI Transparency Notice.
The labelling of automatically generated content will be further standardised across products. This transparency information does not replace the user’s own responsible review.
24. Data Subject Rights and Right to Lodge a Complaint
Subject to the statutory requirements, data subjects have, in particular, the rights of access, rectification, erasure, restriction of processing, data portability and objection. Consent already given may be withdrawn at any time with effect for the future.
Where processing is based on legitimate interests, the data subject may object on grounds relating to their particular situation. The data subject may object to direct marketing at any time without giving specific reasons.
Right to object under Article 21 GDPR: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Article 6(1)(f) GDPR. You may object at any time, without giving reasons, to processing for the purposes of direct marketing.
Requests may be sent to support@ponora.ai. This also applies to recorded persons who do not have a Ponora account. To protect everyone involved, Ponora may request appropriate proof of identity and information needed to match the request to the relevant recording.
Ponora generally responds to requests within one month. For complex or numerous requests, that period may be extended in accordance with the GDPR; the data subject will be informed of the extension and the reasons for it within the first month.
Data subjects also have the right to lodge a complaint with a data protection supervisory authority, in particular with the authority at their place of residence, workplace or the suspected infringement. The authority responsible for Ponora is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf.
25. Minors and Lawful Audio Recordings
Ponora services are generally intended for persons aged 16 or over. Persons under 16 may use the services only where valid consent from a person with parental responsibility or another legal basis is in place.
Certain purchase or contract offers may only be reserved for adults. Corresponding requirements are displayed in the respective offer.
Ponora does not knowingly collect personal data from children under the age of 16 without the necessary legal basis. If unauthorized processing becomes known, Ponora may block content, request proof or arrange for deletion.
The age threshold does not mean that audio recordings of minors are generally prohibited by law. Irrespective of age, users must comply with the applicable criminal-law, personal-rights, data-protection, employment-law and professional requirements for each recording.
26. Changes to this privacy policy
Ponora may adjust this Privacy Policy if products, data flows, service providers, legal bases or legal requirements change.
Significant changes will be announced in an appropriate manner. A new consent will only be obtained if it is actually necessary for a modified processing; the mere continued use of the Services does not replace the necessary consent.
As of: 31 August 2026.
Annex A. Data flow of audio and AI processing
1. A recording is initially saved locally on the device or in the mobile app.
2. The user actively starts a cloud function, especially transcription or summary.
3. The data is transferred to the primary Google cloud infrastructure in europe-west3.
4. Microsoft Azure Speech processes selected audio data in Germany West Central.
5. For long recordings, segments and short-term speaker samples can be processed.
6. Temporary voice samples are deleted immediately after completion or failure.
7. Summaries, title suggestions, mind maps, tasks and keywords are generated via Anthropic Claude and, where necessary, Google Gemini through Google Vertex AI in the europe-west1 region (European Union) (default: europe-west1).
8. Results are made available to the authorised user and may be exported or shared by that user.
9. User content is generally stored until the user deletes it or the account deletion is carried out.
10. If the user creates a share, the selected text content can be accessed via a link without an account; accesses are logged with IP address and user agent.
Annex B. Storage and deletion criteria
Data type | Storage / deletion criterion |
|---|---|
Account and contract data | While the account is active; for a regular account closure, a recovery period of 30 days applies only if expressly chosen by the user. Without this choice, or in the case of a valid erasure request under Article 17 GDPR, erasure takes place without undue delay and without a mandatory recovery period; statutory retention obligations and Article 17(3) GDPR remain unaffected. |
Audio recordings, transcripts, summaries, notes and mind maps | No automatic expiry; until deletion by the user, Account deletion or cessation of the purpose |
Temporary voice samples | Temporary audio files immediately after completion or failure; assignment metadata (segment, speaker label, time window, confidence) with the recording or account |
Exported or shared content | Outside of Ponora under the control of the recipient; within Ponora according to user and product configuration |
Security, access and diagnostic data | As necessary for security, error analysis, accountability and legal claims; then erasure or anonymisation |
Billing and tax data | According to the statutory commercial and tax retention periods |
Evidence of consent and withdrawal | As long as this is necessary for the obligations of proof and the defense of legal claims |
Annex C. Essential recipients and service providers
Provider / Recipient | Purpose | Data types | Region / Classification |
|---|---|---|---|
Google Cloud Platform | Primary cloud infrastructure: storage, databases, computing power and message processing | Account, audio, transcript, usage and technical data | europe-west3, Frankfurt am Main, Germany; for message processing (Pub/Sub), see section 14 |
Microsoft Azure Speech | Speech recognition and technical speaker separation | Selected audio data, audio segments, and speaker labels | Configured Azure region, default Germany West Central (Germany) |
Anthropic Claude on Google Vertex AI | AI summaries | Transcripts, tags, and context data | Europe-west1, EU |
Google Gemini via Google Vertex AI | Fallback for AI summaries | Transcripts, tags, and context data | Google Vertex AI, configured EU region, default europe-west1 |
Mailgun | Transactional emails and support communications | Email address, message and delivery metadata | EU endpoint api.eu.mailgun.net, sender domain send.ponora.de |
Stripe / SEPA | Payment processing and billing; SEPA direct debit only insofar as offered in Stripe Checkout | Customer, invoice, payment and transaction data | Stripe Payments Europe Ltd., Ireland (EU) |
PayPal | Payment processing only for one-off purchases in the shop; not for subscriptions | Customer, payment and transaction data | Only for one-off purchases in the shop; not for subscriptions |
Apple App Store / Google Play | Platform purchases, subscriptions and platform management | Account, purchase, subscription and transaction data | Independent platform conditions |
Transport and logistics service providers | Delivery of hardware and processing of transport damage | Name, delivery address, contact and shipping data | Depending on the delivery route |
Google Firebase Cloud Messaging | Delivery of push notifications | Push token, platform, device identifier, notification content | Google Ireland Ltd.; transfer to Google LLC (USA) based on the standard contractual clauses (Commission Implementing Decision (EU) 2021/914); copy via support@ponora.ai |
IONOS (object storage) | Object storage | Recordings, export files, profile pictures | eu-central-1, Frankfurt am Main, Germany |