Privacy Policy
The short version: your knowledge base never reaches our servers. Below is the full policy. Last updated: 17 July 2026.
1. Controller
Thalassa Consulting, Patrik Talasi, Helle-Wiesen-Str. 17, 72406 Bisingen-Thanheim, Germany · Phone: +49 7476 914717 · E-mail: mail@thalassa-consulting.com (also the contact for all privacy requests). A data protection officer is not appointed, as none is legally required. German law applies to our services.
2. Local-first by design: what we deliberately do NOT process
Your knowledge base — your own documents, case files, preparation material and session content — is stored exclusively on your device (desktop app: local files and a local search index; web app: your browser's IndexedDB). It is never uploaded to, stored on, or backed up by our servers. The live transcript of your meetings likewise exists only on your device; we keep no copy. We could not access, sell or lose this data even if we wanted to — we do not have it.
3. What we do process: account & usage metadata
To provide subscriptions and enforce fair-use limits we process: e-mail address, authentication token, plan, billing period, meeting counters, token counts and timestamps (Art. 6(1)(b) GDPR — performance of contract). We never store the content of your meetings, questions or answers; our database contains no tables for such content, which is enforced by automated tests. This metadata is deleted or anonymised when your account is deleted, unless statutory retention duties (e.g. tax law) require longer storage.
4. Transient AI processing (Deepgram & Anthropic)
Live transcription (Deepgram): during a meeting, the audio signal is streamed TLS-encrypted to Deepgram, Inc. (USA) and transcribed in real time (Art. 6(1)(b) GDPR). Neither the audio nor the resulting transcript is stored on our servers — the transcript is delivered straight back to your device. Transfers are safeguarded under the EU–US Data Privacy Framework and/or Standard Contractual Clauses; see Deepgram's privacy policy.
Answers (Anthropic): when you request an answer, the recent transcript excerpt and relevant knowledge-base snippets are transmitted TLS-encrypted through our API to Anthropic (Anthropic PBC, USA) solely to generate that answer (Art. 6(1)(b) GDPR). On our servers this payload exists only in memory for the duration of the request — it is not written to logs, databases, caches or analytics. Transfers to the USA are safeguarded under the EU–US Data Privacy Framework and/or Standard Contractual Clauses; see Anthropic's privacy policy.
5. Hosting & server logs
Our website is hosted by Vercel Inc. (USA; EU–US Data Privacy Framework / SCCs). When you visit it, technically necessary server logs (IP address, timestamp, requested page, user agent) are processed for delivery and security (Art. 6(1)(f) GDPR) and deleted on a short rotation.
6. E-mail
Transactional e-mails (welcome, usage alerts, billing, password reset) are sent from mail@thalassa-consulting.com via Proton AG, Switzerland — a country with an EU adequacy decision (Art. 45 GDPR).
7. Payments (Paddle)
Paid plans are processed by Paddle (Paddle.com Market Ltd., UK / Paddle Payments Ltd.) acting as Merchant of Record. Paddle processes your payment data under its own privacy policy; we receive only confirmation of payment and the data needed for entitlement and invoicing (Art. 6(1)(b) GDPR). VAT is calculated and added at checkout by Paddle. See Paddle's privacy policy.
8. Analytics & cookies
We use Plausible Analytics, a cookie-free, privacy-friendly statistics tool (EU-hosted) that counts visits without building personal profiles, and PostHog on EU servers for anonymous product-funnel events (Art. 6(1)(f) GDPR — legitimate interest in understanding aggregate website usage). Neither tool receives meeting content, transcripts, document contents or other sensitive data; we do not use advertising pixels (no GA4, no Meta Pixel). Because no tracking cookies are set, no cookie banner is required. The only browser storage we use is technically necessary localStorage for your language choice, attribution of your first visit, and your login session (§ 25(2) TDDDG — no consent required).
9. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21 GDPR), as well as the right to lodge a complaint with a supervisory authority — for us: Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg. For your knowledge base no request is needed: it is on your device, with one-click export and deletion in your own hands.
10. Your responsibilities as a user
You are responsible for obtaining any consent required to transcribe a conversation (in Germany, all participants must consent) and for disclosing AI assistance where required. Thalassa gives you the controls; you decide how to use them.
11. Changes
We will update this policy when our services change and indicate the date of the latest revision above.