Privacy Policy
Last updated: 14 July 2026
This Privacy Policy describes how Lee Robinson trading as Strandweave ("Strandweave", "we", "us" or "our"), with a contact address at 21A Benin Street, London, SE13 6UB, United Kingdom, handles personal information in connection with the Strandweave application and the website at strandweave.app.
Please read this policy carefully. If you have questions, contact us at privacy@strandweave.app.
1. What information we collect
Website visits
When you visit strandweave.app, our web host may record standard server log data, which can include your IP address, browser type and version, the page you requested, the referring page, and the date and time of your visit. This information is used to operate and maintain the website and is not used to identify you individually.
Purchase and checkout
Purchases of Strandweave are made through Lemon Squeezy (lemonsqueezy.com), who acts as the merchant of record. Lemon Squeezy collects and processes your payment details, email address and billing information. We receive order confirmation data — such as your email address and order reference number — from Lemon Squeezy for the purpose of licence delivery and purchase-related support.
Your payment card details are handled by Lemon Squeezy and are not received or stored by us. Please review Lemon Squeezy's privacy policy for full details of their data practices.
Licence activation
When you activate a licence key in the Strandweave app, a verification request may be made to confirm your licence status. This may involve transmitting your licence key, activation instance information and a device identifier to our licence management provider. Licence keys and activation instance identifiers may be stored locally in the macOS Keychain. No recording, transcript, imported audio or export content is collected for licence activation.
App updates and model downloads
The App may contact Strandweave download services to check for App updates, retrieve model catalogues or download local processing models. Those services and their hosting providers may receive standard request information such as your IP address, request date and time, App version and technical request headers. These requests do not include recordings, transcripts, imported media, voice profiles, session titles or export content.
Support communications
When you contact us by email, you voluntarily share the information contained in your message. This may include your name, email address, macOS version, app version, a description of an issue, screenshots and any other details you choose to provide. We use this information only to respond to and resolve your enquiry.
Beta programme applications
If you apply for the Strandweave beta, we collect the name, email address, role, optional organisation, Mac compatibility details, intended use and acknowledgements you submit. We use this information to review applications, administer the beta, send selected testers setup information, request feedback and understand the programme in aggregate.
A beta application does not subscribe you to launch or product marketing. The mailing list is a separate EmailOctopus form with its own optional signup. Do not include recordings, transcripts or sensitive session content in a beta application.
Mailing list sign-up
The mailing list signup form on this website is provided by EmailOctopus (emailoctopus.com). If you choose to sign up for launch and product updates, your email address and any other details you submit are processed by EmailOctopus for the purpose of sending product launch news, early access updates, release updates, pricing or offer updates, and occasional Strandweave product emails. Mailing list data is handled separately from app recordings, transcripts, imported audio files, session data and payment details.
EmailOctopus may record signup metadata needed to operate the list, such as consent timestamp, source/form information, IP address, user agent and technical/security metadata. We use this information to manage consent, prevent abuse, send requested emails and maintain the mailing list.
You can unsubscribe at any time using the unsubscribe link in any email we send. Please review EmailOctopus's privacy policy for full details of their data practices.
2. Lawful basis for processing
The table below summarises why we process personal information and the lawful basis we rely on.
| Purpose | Personal data | Lawful basis |
|---|---|---|
| Operating and securing the website | Server logs, IP address, browser/device data | Legitimate interests |
| Processing purchases and licence delivery | Email address, order reference, licence information | Contract |
| Licence activation and anti-abuse checks | Licence key, activation status, device identifier | Contract and legitimate interests |
| Providing App updates, model catalogues and model downloads | IP address, App version and technical request data | Contract and legitimate interests |
| Support | Name, email address, support message, screenshots or diagnostics you provide | Contract and legitimate interests |
| Reviewing and administering beta applications | Name, email address, role, compatibility details, intended use and acknowledgements | Legitimate interests and steps requested before a beta agreement |
| Analytics | Website usage data after consent | Consent |
| Optional app analytics | Anonymous app usage events after opt-in | Consent |
| Mailing list | Email address and any submitted signup details | Consent |
| Legal, tax and accounting | Purchase and transaction records | Legal obligation |
| Fraud prevention and dispute handling | Order, licence, support and usage records where relevant | Legitimate interests and legal obligation |
3. The Strandweave app — local data model
Strandweave is designed to process audio and generate transcripts locally on your Mac. Recordings, transcripts and exports created in the Strandweave app are intended to be stored locally on your device unless you choose to export, share, back up, upload or otherwise transfer them using your own systems or third-party services.
You are responsible for the recordings and transcripts stored on your Mac, including ensuring you have any necessary consents or rights required by law before recording a conversation. See also the End User Licence Agreement.
Optional AI features (bring your own key)
Strandweave may offer optional AI features, such as AI-assisted summaries. These are turned off by default. To use cloud AI providers such as Claude or OpenAI, you must opt in and provide your own third-party API key. API keys are stored in the macOS Keychain on your device and are never sent to us. Strandweave may also support local OpenAI-compatible providers such as Ollama, where transcript processing can happen on your Mac or local network.
When you enable and use a cloud AI feature, the App may send transcript text from the sessions you choose, plus populated meeting metadata and meeting notes, to your selected provider using your own key. Audio recordings, voice samples, voice profiles, local files and API keys are not sent for this purpose. The App includes consent and exclusion checks before cloud summarisation; sessions marked as excluded from AI exports or where consent was declined are blocked from cloud summarisation. We do not receive or store the content you send to your AI provider, which processes it under its own terms.
Optional local integrations and model downloads
Strandweave may offer optional integrations for calendar linking, Obsidian or Markdown vault exports, watched folders, Mail.app draft sharing, semantic search, speaker recognition and local agent access. Calendar linking is read-only. Apple Calendar uses macOS calendar permissions. Google Calendar and Microsoft Outlook use OAuth with read-only calendar scopes, and tokens are stored in the macOS Keychain. Calendar event details you choose to link may be copied into local session metadata and can be refreshed or unlinked by you in the App.
Obsidian, Markdown, watched-folder, clipboard and email-share features write or draft files locally or into destinations you choose. If you then sync, email, upload or share those files using another app or service, that destination handles the data under its own terms. Strandweave does not send email itself.
Semantic search and speaker recognition run locally. The App may download local model files, such as embedding, transcription, diarization or speaker models, from model or update hosting locations and cache them under your Strandweave folder. Transcript, recording and voice-profile content is not uploaded to download those models.
Optional podcast and web-audio imports
If you enable podcast and web-audio importing and provide an RSS feed or direct media URL, the App contacts that address to retrieve the feed or media file you requested. The feed provider, media host or content-delivery network may receive your IP address and standard technical request information under its own privacy terms. The downloaded media is imported into your local Strandweave library. Strandweave does not receive the URL you enter or a copy of the downloaded media.
Optional meeting-window detection and global shortcuts
Strandweave can optionally use macOS Accessibility permission for global keyboard shortcuts and to detect whether a supported Zoom or Webex meeting window is open. Meeting detection is off by default. When enabled, the App periodically checks supported applications' window titles locally so it can offer a notification to start recording. It does not read meeting audio, video, chat, participant lists or call content, does not start recording automatically, and does not send meeting-window information to Strandweave. macOS Accessibility permission is broader than these uses, but Strandweave uses it only for the enabled shortcut and meeting-detection functions.
Speaker recognition generates voice profiles — numerical representations of voice characteristics used to distinguish speakers. In some jurisdictions, this may be treated as biometric or special category data. Voice profiles are generated and stored locally on your Mac, are not uploaded or shared with us or any third party, and are only created if you enable speaker recognition. You can delete voice profiles at any time in the App.
Optional local agent access
Strandweave may include a local MCP server or agent pack for power users. This is off by default and must be enabled by you. When enabled, local agent clients you configure may read governed Strandweave context according to the permission profile you choose. Strandweave does not operate those agent clients and is not responsible for what a third-party or local agent does with data after you connect it.
If you use the App's setup wizard for a supported local agent client, the App may add or update the Strandweave connection entry in that client's local configuration file. Configuration changes remain on your Mac and are not sent to Strandweave. You should review the proposed client, permission profile and configuration before applying it.
4. Analytics
This website uses Google Analytics 4 (GA4) to understand aggregate website usage. GA4 is optional. Google Tag Manager is the sole analytics loader, and neither it nor GA4 is loaded until you explicitly accept analytics via the consent banner shown on first visit. If you decline, no Google analytics script or iframe is loaded, no analytics request is sent to Google, and no Google Analytics cookies are set.
When analytics are accepted, GA4 collects aggregate data about page visits and navigation patterns. Google may process technical request information under its terms and privacy policy. GA4 does not have access to app recordings, transcripts, imported audio files, session data, support email contents, or payment details. Those are separate from website analytics.
You can change or reset your analytics preference at any time using the Cookie settings link in the site footer. See the Cookie Policy for full details of analytics cookies and how to clear them.
Optional app analytics
The Strandweave app may offer optional anonymous usage analytics through TelemetryDeck. This is off by default and requires your explicit opt-in in the app's privacy settings. If enabled, Strandweave sends privacy-safe usage events such as recording started or export triggered to TelemetryDeck over HTTPS. These events do not include recordings, transcripts, filenames, speaker names, participant names, session titles or session content. You can disable app analytics at any time in the app.
5. How we use information
- To operate and maintain the Strandweave website.
- To process licence purchases and deliver licence keys.
- To respond to support and general enquiries.
- To review beta applications, contact selected testers and administer the beta programme.
- To understand aggregate website usage (GA4, only if accepted).
- To understand anonymous app usage signals (TelemetryDeck, only if enabled in the app).
- To send launch and product updates to mailing list subscribers (EmailOctopus, only if signed up).
- To comply with applicable legal obligations.
6. Sharing information
We do not sell personal information. We may share information with:
- Lemon Squeezy — as the merchant of record for purchases, they process payment and order data under their own privacy policy.
- Google (GA4) — aggregate website usage data, only if you have accepted analytics. See Google's Privacy Policy .
- EmailOctopus — if you sign up for the mailing list, your email address is processed by EmailOctopus for sending launch and product updates. We do not share app recordings, transcripts, imported files or payment details with EmailOctopus. See EmailOctopus's privacy policy .
- TelemetryDeck — anonymous app usage events, only if you opt in from the App. These events do not include recording, transcript, participant, speaker, filename, title or session content.
- Your chosen AI, calendar, export, mail, vault or agent providers — only when you enable the relevant feature, connect the provider, export or share data, or configure an agent client.
- Feed, media and download hosts — standard network request information when you request an App update or model download, or when you choose to import media from a podcast feed or direct URL.
- Hosting and infrastructure providers — who process data on our behalf to operate the website, subject to appropriate agreements.
- Legal or regulatory authorities — where we are required to do so by applicable law or a valid legal process.
7. International transfers
Some of our service providers may process personal information outside the United Kingdom. Where this happens, we rely on appropriate safeguards, such as adequacy regulations or approved contractual protections, where required by data protection law.
8. Data retention
We retain personal data for as long as necessary to fulfil the purposes described in this policy, or as required by law.
Support correspondence is retained for up to 24 months after the last interaction, unless we need to retain it for longer to resolve a dispute, comply with legal obligations, prevent fraud or abuse, maintain security, or establish, exercise or defend legal claims.
Purchase, licence and transaction records may be retained for up to 6 years where necessary for tax, accounting, audit, fraud prevention or legal purposes.
Mailing list records are retained until you unsubscribe, request deletion, or we remove inactive or invalid subscribers during routine list cleanup.
9. Data security
We take reasonable technical and organisational measures to protect personal information against loss, misuse and unauthorised access. However, no method of transmission or storage is completely secure.
10. Your rights
Depending on your location and applicable laws, you may have rights regarding your personal information, including the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your data, subject to legal obligations.
- Obtain a portable copy of your data.
- Object to or restrict certain processing.
To exercise any of these rights, contact us at privacy@strandweave.app. We will respond within the timeframe required by applicable law.
You also have the right to complain to the UK Information Commissioner's Office if you are unhappy with how we handle your personal information. We would appreciate the chance to resolve your concern first, so please contact us before making a complaint.
11. US visitors and the CCPA
The California Consumer Privacy Act (CCPA) applies only to businesses that meet certain revenue or data-volume thresholds. We have assessed our processing and do not meet any of these thresholds, so the CCPA does not currently apply to us. We do not sell or share personal information for monetary or other valuable consideration. If our processing grows to meet the CCPA's thresholds in future, we will update this policy accordingly.
12. Cookies
See the Cookie Policy for details of how cookies are used on this website.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the date at the top of this page. We encourage you to review this policy periodically.
14. Contact
For privacy questions, data requests or complaints, contact us at privacy@strandweave.app.
Data protection contact: Lee Robinson
Email: privacy@strandweave.app
Related documents