Privacy policy
Tymbr turns your recordings into transcripts. Recordings are personal information, and sometimes special personal information. This policy explains what we do with them, in plain terms, as the Protection of Personal Information Act (POPIA) requires.
1. Who is responsible
Tymbr is operated by Gareth Saul trading as 20 East, a sole proprietor in South Africa. For your account information, we are the responsible party. Our Information Officer is Gareth Saul, reachable at hello@tymbr.dev or 18 Lyndhurst Road, Kenilworth, Cape Town, 7708. We do not have a telephone line. Email is the way to reach us with questions and complaints.
2. Your recordings: two roles
Your recordings contain other people's voices and words. For that content, you are the responsible party under POPIA and we are your operator. We do not decide what is recorded or why. Our terms of service are the written operator agreement that section 21(2) of POPIA requires. In practice this means:
- You decide what to record and must have a lawful basis to do so. Section 4 of the Regulation of Interception of Communications Act lets a party to a conversation record it. Telling participants where the law or your professional rules require it is your responsibility.
- People in your recordings who want to see, correct or delete their information must direct that request to you, not to us. If such a request reaches us, we will forward it to you within five business days and leave the decision with you. Tymbr gives you the tools to act on it.
- We process the content only on your instructions. Uploading a recording is an instruction to transcribe it, and deleting one is an instruction we carry out without question.
- We keep the content confidential, secure it as section 8 describes, and tell you as soon as we reasonably can if we believe it has been accessed without authority.
- You must obtain a person's explicit consent before you enrol their voiceprint, keep evidence of it, and delete the voiceprint if they withdraw it. See section 3.
We never look inside your recordings or transcripts except when you ask us to help with a specific problem, or when the law compels us. We do not check whether you had the right to make a recording. We do not use recordings to train models, ours or anyone else's.
3. What we collect and why
| Information | Why we process it | Lawful basis |
|---|---|---|
| Your email address and sign-in identity | To create your account, keep your data separate from everyone else's, and contact you about the service | Performing our contract with you |
| Recordings you upload, record or dictate | To produce transcripts and let you play back audio | Performing our contract with you; for other people in the recording, you are the responsible party |
| Transcripts and your edits | To show, search and export your transcripts | Performing our contract with you |
| Speaker rosters (names you assign to speakers) | To label who said what | Performing our contract with you |
| Voiceprints, if you enrol them | To recognise the same speaker across recordings | Consent, under section 27(1)(a) of POPIA. Voiceprints are biometric information and are special personal information under section 26. You can withdraw consent by deleting the voiceprint. |
| Device credentials for the desktop recorder | To let the recorder upload to your account and let you revoke it | Performing our contract with you |
| Purchases and credit usage | To sell credit, deduct it per minute, show your balance and meet tax and accounting duties | Performing our contract with you; legal obligation |
| Technical logs (IP address, request times, errors) | To keep the service secure and working | Our legitimate interest in security and reliability |
We collect nothing else. There is no tracking for advertising, and we do not buy or combine information about you from other sources.
4. Children
Tymbr is for adults and businesses. We do not knowingly open accounts for anyone under 18. If a child's voice appears in your recording, you are responsible for having the consent of a parent or guardian where POPIA requires it.
5. Who we share it with
We do not sell or rent your information. We share it only with operators that we need to run the service, under written terms that bind them to confidentiality and security:
| Operator | What they do | What they receive |
|---|---|---|
| Cloudflare | Hosts the web app, database, file storage and job queue | All account data, recordings and transcripts, encrypted at rest |
| Mistral | Transcribes and diarises audio (Voxtral models) | The audio of each recording while it is being transcribed |
| Google Cloud | Provides Google sign-in; runs voiceprint inference on infrastructure we control | Audio segments and voiceprints for enrolled speakers; your email for sign-in |
| Yoco (Yoco Technologies (Pty) Ltd, South Africa) | Takes card and other payments | Your payment details and purchase amount. We never see your full card number. |
We will also disclose information if a court or a competent authority lawfully requires it. Where we are allowed to, we will tell you first.
6. Where your information goes
Some of our operators store or process information outside South Africa. Section 72 of POPIA lets us do this where the recipient is bound by law or contract to protect your information to a standard like POPIA's.
- Mistral processes audio on servers in the European Union, where data protection law is recognised as adequate.
- Cloudflare and Google Cloud may process information in several regions. Both are bound by data processing terms that meet POPIA's requirements. The voiceprint inference region is a European Union region or the Johannesburg region, never a region without adequate data protection law.
7. How long we keep it
- Recordings, transcripts, rosters and voiceprints: until you delete them or close your account. Deleted items leave the live service immediately and are purged from backups within 30 days.
- Device credentials: until you revoke them or close your account.
- Purchase and usage records: five years after the transaction, to meet tax and accounting law.
- Technical logs: 30 days, unless we need a specific entry to investigate a security incident.
8. How we protect it
Every recording, transcript, roster and voiceprint is tied to one account, and every read and write in our systems checks that account first. Data is encrypted in transit and at rest. Voiceprints are additionally encrypted before storage. Access to production systems is limited to the Information Officer and protected by multi-factor authentication. If we become aware that your information has been accessed without authority, we will notify you and the Information Regulator as section 22 of POPIA requires.
9. Your rights
Under POPIA you may, free of charge unless the law allows a fee:
- ask whether we hold personal information about you and get a copy of it;
- ask us to correct or delete information that is inaccurate, out of date or no longer needed;
- object to processing based on our legitimate interests;
- withdraw consent to voiceprint processing at any time, without affecting anything done before;
- complain to the Information Regulator if you are not satisfied with our response.
Most of these you can do yourself in the web app: download, edit and delete recordings, transcripts, rosters and voiceprints, and close your account. For anything else, email hello@tymbr.dev. We will reply within 30 days. If you appear in someone else's recording, the account holder is the responsible party for it. Contact them first. If you cannot reach them, contact us and we will forward your request to them within five business days, and act ourselves only where the law requires us to.
10. Cookies
We set only the cookies needed to keep you signed in. There are no analytics or advertising cookies. Clearing cookies signs you out and nothing more.
11. Changes
We will update this policy as the service changes, for example when we add a payment processor. Material changes will be emailed to you at least 14 days before they take effect, and the date at the top will always show the current version.
12. Contact and complaints
Information Officer: Gareth Saul, trading as 20 East
Email: hello@tymbr.dev
Address: 18 Lyndhurst Road, Kenilworth, Cape Town, 7708
Telephone: no telephone line; email hello@tymbr.dev for questions and complaints
If we do not resolve your concern, you may complain to the Information Regulator of South Africa:
The Information Regulator
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Email: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za