Consent to the Cross-Border Transfer of Personal Data
Effective 19 September 2026 · Version 1.6
The Company's servers and processors are located in the United States. Under Article 28-8 of the Personal Information Protection Act, we request your consent to transfer personal data abroad as set out below.
1. Recipients, country, timing and method, items, purposes and retention
| Recipient | Country | Timing and method | Items transferred | Purpose | Retention | Type of transfer and basis | Recipient’s privacy contact |
|---|---|---|---|---|---|---|---|
| Supabase Pte. Ltd. | United States (where the data is stored). The recipient is established in Singapore | At the time you use the Service, over an encrypted connection (TLS) | Account data (email, account identifier), content encrypted on your device, service usage records, consent history | Authentication, database, encrypted file storage and sync | Until you delete the data or your account | Processing and storage on the Company’s behalf, necessary to perform the contract with you | privacy@supabase.io |
| Vercel Inc. | United States | At the time you use the Service, over an encrypted connection (TLS) | Access records created when you use the web service (IP address, request time, request path, browser information) | Hosting and delivery of the web service (recnovo.com, app.recnovo.com) | Kept in the provider’s runtime logs for one day and then deleted (on the plan the Company uses). | Processing on the Company’s behalf, necessary to perform the contract with you | privacy@vercel.com |
| Amazon Web Services, Inc. | United States | At the time you use the Service, over an encrypted connection (TLS) | A sealed value used to protect the encryption key (contents not readable), the account identifier sent with it so the value can be bound to your account, and a one-way proof derived from your passcode (the passcode itself cannot be recovered from it) | Secure custody of the value that protects encryption keys | Until you delete the data or your account | Storage, necessary to perform the contract with you | https://aws.amazon.com/privacy/ |
| Anthropic, PBC | United States | At the time you use the Service, over an encrypted connection (TLS) | Text data sent at the time of processing, such as transcripts | AI text processing (summaries, organized notes, translation, answers, study material) | Kept up to about 30 days for abuse monitoring, then deleted; never used for model training. For a request the provider judges to breach its own usage policy, the provider's policy may keep it longer than that. | Processing on the Company’s behalf, necessary to perform the contract with you | privacy@anthropic.com |
| Google LLC | United States | At the time you use the Service, over an encrypted connection (TLS) | Text data sent at the time of processing, such as transcripts | AI text processing (summaries, organized notes, translation, answers, study material) and generating chat and search answers | Kept for 55 days for the provider's abuse monitoring (detecting violations of its prohibited-use policy), then deleted. The period is set by the provider and the Company cannot shorten it. Under the provider’s terms, data sent to its paid service is not used to improve its products, and data kept for abuse monitoring is not used to train or fine-tune AI models other than those used for policy enforcement. Content flagged by safety filters may be reviewed by authorised provider staff. To speed up processing the provider caches input temporarily, in memory only, and that cache is cleared within 24 hours. The Company sends requests only to the provider’s paid service, and sends nothing if paid processing is not confirmed. The Company does not use your content to train the Company's AI models. | Processing on the Company’s behalf, necessary to perform the contract with you | https://support.google.com/cloud/contact/dpo |
| Eleven Labs Inc. | United States (where the recipient is established). The provider states that it may process in the United States, the European Union or Singapore for latency and performance | At the time you use the Service, over an encrypted connection (TLS) | the original recording audio and the transcript and speaker-separation data derived from it | speech recognition (transcription) and speaker separation | held in the provider's request history; deleted when we request deletion, after which it may remain in the provider's backups for up to about 30 days before expiring. Even without a deletion request, the provider does not keep voice data beyond three years from your last interaction with it (except where the law requires otherwise). The Company has turned off the setting that lets this provider use data to improve its models, so data sent after that change is not used to train the provider's models. That rests on the account setting rather than on a separate contract. The Company does not use your content to train the Company's AI models. | Processing on the Company’s behalf, necessary to perform the contract with you | legal@elevenlabs.io |
| OpenAI, L.L.C. | United States | At the time you use the Service, over an encrypted connection (TLS) | Audio and text sent at the time of processing | Speech recognition, search indexing, AI chat responses, and AI text processing (summaries, organized notes, translation, answers, study material) | Kept up to about 30 days for abuse monitoring, then deleted; never used for model training | Processing on the Company’s behalf, necessary to perform the contract with you | privacy@openai.com |
| Functional Software, Inc. (Sentry) | United States | At the time you use the Service, over an encrypted connection (TLS) | Anonymous error and crash diagnostics, app version, device type (never joined to anything that identifies you, and sent only from release builds after you have accepted the legal notice) | Fault and error diagnosis, service stability | Error records are kept for 30 days and then deleted (on the plan the Company uses). The provider’s backups are deleted 90 days after they are created. | Processing on the Company’s behalf, necessary to perform the contract with you | compliance@sentry.io |
| RevenueCat, Inc. | United States | At the time you use the Service, over an encrypted connection (TLS) | Purchase receipts, subscription status, account identifier | Verifying and managing subscriptions and purchases | Until you delete your account. If the Company ends its contract with the provider, the provider may delete the data from its live systems once 30 days have passed. | Processing on the Company’s behalf, necessary to perform the contract with you | compliance@revenuecat.com |
| Plus Five Five, Inc. (Resend) | United States | At the time you use the Service, over an encrypted connection (TLS) | Email address and the content of the message sent (e.g. sign-in codes) | Transactional email for sign-in and authentication | The send record is kept by the provider for 30 days and then deleted; after that not even the Company can look it up. | Processing on the Company’s behalf, necessary to perform the contract with you | support@resend.com |
Stored content is encrypted on your device before transfer, so the recipients — meaning the processors listed above, not anyone you choose to send a share link to — cannot read it. Transcription and AI processing inherently need plaintext at the moment of processing, so the data is sent only then. Turning off “AI features” in the app's settings stops transcription, AI summaries, organized notes and chat, transcript sync and audio backup. It does not stop sign-in and account management, subscription and credit checks, error diagnostics, or credit-funded cloud search — so it is not a switch that ends every transfer. Which of the AI processors above handles any given request can vary with availability and processing quality. The Company transfers User Content to no recipient other than those listed above; adding one means updating this consent and asking for it again.
2. Recipients' privacy contacts
Each recipient's privacy contact is the one published on its official website.
Contact the Company at hello@recnovo.com and we will provide it, or pass your enquiry on for you.
3. Level of protection in the destination country
The United States may not provide the same statutory protections as Korea. The Company compensates with encryption in transit (TLS), on-device encryption of stored content, least-privilege access controls, and data processing agreements with each processor.
The country shown in the table is where each recipient is established and mainly processes data. Each recipient entrusts part of its work, such as cloud infrastructure, to other companies (sub-processors), whose facilities may be in other countries. Their names and locations are in the sub-processor list each recipient publishes; the Company keeps an internal register of those that your information can reach and reviews it every quarter. Ask us and we will point you to the relevant list.
4. Your right to refuse, and what refusing means
You have the right to refuse consent to this cross-border transfer.
Because the Company's servers are in the United States, refusing means you cannot sign up or use cloud features (transcription, AI processing, sync). On-device local recording in the mobile app remains available without consent.
After signing up you can also turn off “AI features” in Settings, which stops audio and text being sent for transcription and AI processing. Communication needed to run the service — sign-in, account management, subscription and credit checks, error diagnostics — continues.
5. Contact
Privacy Officer: Junmee You (Representative Director) · hello@recnovo.com
You may request that the cross-border transfer be suspended; the related features will then be unavailable.