Legal

Privacy

What InteliLang holds, where it goes, and how long it stays. Every sentence here describes what the code does.

Last updated 28 September 2026.

Who is responsible for what

InteliLang is made and run by Dodera Software SRL, a Romanian limited liability company with its registered office at Str. Banat nr. 1, Satu Mare, Romania, registered with the Trade Register under J30/958/2023, tax identification number (CUI) 49004234, e-mail office@doderasoft.com. Where this page says "we", that is who it means.

For your account — your name, your e-mail address, your sessions and which companies you belong to — and for billing and product analytics, we are the controller. Those records exist because without them there is no sign-in, no payment and no way to see what needs fixing.

For everything a company puts into a project — meeting transcripts, Slack messages, repository activity, uploaded documents, notes — that company is the controller and we are its processor. We hold it and process it on that company's instructions, which are the settings its owners and admins choose in the app, under our Data Processing Agreement. If you were invited into someone else's project as a client, the company that invited you is the controller of what is in it.

InteliLang is a service for businesses and other organisations, not for consumers, and it is not meant for anyone under 16. We do not knowingly hold data about children; if you think we do, write to us and we will delete it.

What we hold about you

One account per person, which can belong to several companies.

  • Your name and e-mail address — given when you sign up or accept an invitation. If you sign in with Google, also the link to your Google profile picture and the tokens Google returns at sign-in. There is no profile beyond that.
  • Your sessions — signing in stores a token, when it expires, and the IP address and browser the sign-in came from. Signing out deletes the session.
  • How you sign in — your password, stored only as a hash; if you turn on two-step sign-in, its secret and your backup codes; and the personal keys and assistant connections you created, the keys stored only as hashes.
  • Where you belong — which companies, your role in each, your role on each project, what you do there, and whether you see leadership notes.
  • Who you are elsewhere — your Slack account, GitHub login, Atlassian account and the names you go by in transcripts, so the app can tell that a message is yours. A guess waits for you to confirm it. Once confirmed, your GitHub login and your names in transcripts are visible to the people in your company, so they can see who said what. If you connect your own GitHub account, its access token is stored encrypted.
  • What you chose — which e-mails and Slack messages you want, per company, whether you share usage and screen recordings with us, and which version of the Terms you accepted and when.

What your company puts in

All of it is stored in full. The app never throws away an original to save space.

  • Messages, threads, pull requests, issues, commits, comments, transcripts, documents, notes and webhook deliveries — each with its title, the author's name, the date, and a link back to where it came from. The complete text is kept, not a summary.
  • Uploaded files — kept twice: the original bytes on the server's disk, and the text pulled out of them in the database.
  • Recordings — a recording becomes a transcript. The audio itself is not kept; see "Recordings" below.
  • Notes — what people type into the chat, and what an assistant shares into a project on someone's behalf.
  • What a company writes for the AI — who is who, client and product names, internal terms and spellings. It is a settings field of at most 2,000 characters, and it is not a place for secrets.

Each piece of content carries an audience — client, team or leadership — chosen when it arrives.

What the app makes from it

None of this is something you typed. It is what the app computes so it can search and answer.

  • Passages and vectors — each item is split into passages, and each passage gets a list of 384 numbers produced on our own server, so that searching by meaning works.
  • Memory entries — decisions, who thinks what, action items, open questions and risks. Each carries up to three short quotes copied word for word from the item it was taken from, and the date it was said.
  • Project briefs — a short compiled summary of each project, rewritten nightly, one for each audience.
  • Cached answers — the answer to the first question of a conversation, so the same question from someone with exactly the same access costs nothing. Kept seven days.
  • Board cards — what is on a project's board, and which action item each card came from.
  • Notifications — the bell stores ids only: who, which project, what kind, and which entry. The words are read back from the entry itself when you open it, through your own access.
  • Spend records — one row per model call: the task, the model, token counts and the cost, so a company can see what it is spending.
  • The audit log — who changed keys, people, roles, projects, sources, retention, sharing and billing, and when. It records what changed, not what was in it, and never a secret. Where the change is a person — an invitation sent, a role given — the name or e-mail address is recorded, because that is the change.

Why we are allowed to hold it

Under the GDPR, four grounds cover what we do as controller:

  • Performing a contract — your account, your sessions, your memberships and your company's billing exist so that we can give you, or your employer, the service that was signed up for.
  • Legitimate interests — keeping the service working and secure: the audit log, rate limiting, error reports and the record of what was spent; and counting which pages and features signed-in people use, so we can improve it, which you can turn off for yourself and your company can turn off for everyone.
  • Consent — product analytics for visitors who are not signed in, and screen recordings for anyone. You can withdraw it at any time, as easily as you gave it.
  • Legal obligation — where Romanian or EU law requires us to keep something, such as invoices.

Who inside your company can see it

Every piece of content carries an audience: client means everyone on the project including the client, team means everyone except the client, and leadership means only people who have been given leadership access.

This is not a filter the app has to remember to apply. It is a row-level security policy inside Postgres, so a query that forgets its condition returns nothing rather than too much. The Security page explains how it works.

Your chats are yours. A conversation and its messages can only be read by the person who wrote them. Nobody else in your company, including an owner, can open them in the app.

What our own staff can see

The few people at Dodera Software who run InteliLang have an administration area, which only works with two-step sign-in. It shows each company's name, plan, number of people, memory size and last activity, and each person's name, e-mail address, sign-in methods, sessions and companies. It never shows project content, chats, keys or tokens.

From there they can suspend a company, change its plan, delete it at its request, resend an invitation, sign someone out everywhere, turn an account off or send a password reset. Every one of those actions is recorded in a log of its own.

The services we use

These receive personal data because we chose them to run InteliLang. This is the whole list.

  • Hetzner Online GmbH, Germany — the server the application runs on, in Nuremberg, and the database and disk everything is stored on.
  • Hostinger International Ltd., Cyprus — sends our e-mail, which leaves as no-reply@intelilang.com, and holds our support mailbox, office@intelilang.com, from its data centres in the EU. Hostinger receives the recipient's address and whatever the message says: a sign-in link, a password reset, an address change, an invitation, a download being ready, the morning brief, a decision alert or a note that a project's memory is full. The brief and the alerts carry real content — project names, decisions, open questions, risks and the people attached to them. What you write to our support address is kept there too.
  • PostHog Inc., stored in the EU — product analytics, stored in PostHog's EU region in Frankfurt: which pages are opened and which features are used, only within the limits under "Product analytics" below, and screen recordings with every word hidden only if you allowed them. Never content.
  • Stripe Payments Europe, Ltd., Ireland — takes payment when a company chooses a paid plan. Stripe receives the e-mail address of the owner or admin who subscribes, the company's name, billing address and VAT number, and the card or other payment details, which we never see. It never receives project content. Stripe is also a controller of this data for its own legal duties, such as preventing fraud, under its own privacy policy.
  • Google, if you choose "Continue with Google" — confirms who you are. We ask only for your name, e-mail address and profile picture. Google learns that you signed in to InteliLang, under Google's own privacy policy.
  • Slack, for our own alerts — our team's own Slack workspace receives error reports from the server, with no content in them, and the "Missing a tool?" requests people send, with their name, e-mail address, company and what they wrote.

Where a company is not in the EU, or belongs to a group outside it, the transfer is covered as described under "Leaving the EU" below.

The services your company chooses

These work on your company's own accounts and keys, under your company's own agreements with them. We send them what they need only because your company turned them on.

  • Anthropic, United States — answers chat questions, reads new content into memory, writes the nightly briefs and describes uploaded images. For an answer it receives the question, the conversation so far, the background notes your company wrote, the project brief, the board, their own to-dos, the people on the project and the passages retrieved for that question; when new content arrives, the new item in full. When someone turns on web search for a question, Claude also searches the web through Anthropic, so the search words leave too; it is told never to put names or confidential details in them. It runs on your company's own Anthropic key, entered in Settings. There is no InteliLang key and no fallback: with no key the assistant refuses rather than billing anyone else.
  • Soniox, United States — transcribes meetings, when a company chooses that engine. The audio goes straight from the browser to Soniox and never passes through our server. It runs on your company's own Soniox key, which stays on our server: what the browser gets is a single-use key that expires in five minutes.
  • Your browser's own speech service — the recording engine every new company starts with. On Chrome and Edge that means the audio is sent to the browser vendor's speech service, under their terms, with no key or contract of ours involved. Choosing Soniox avoids it.
  • TypeSafe, United States — answers small sorting and matching questions more cheaply than Claude, and only if a company turns on "Quick decisions". It is off for every new company and needs your company's own TypeSafe key. With it on, TypeSafe receives what those questions are about: the passages a search found, the wording of a chat question, card titles and descriptions, the people on a project with their roles and open cards, and memory entries being compared.
  • Slack, GitHub and Atlassian — only when your company connects them, through your company's own install of our app, or when you connect your own GitHub account. The app reads the channels, repositories and Jira projects that were picked. In Slack it also writes: it joins the public channels you picked, answers in a thread when someone mentions it, reacting while it works, and sends people their notifications as direct messages if they want them. An answer in Slack contains project content that everyone in that channel may see. For Atlassian, the app also tells Atlassian each night which Atlassian accounts it holds, as Atlassian requires, so it can learn which ones were closed and forget them.

If someone connects their own assistant to InteliLang at https://intelilang.com/mcp, that assistant reads only what that one person is allowed to read, and what it reads goes to whoever runs it — Anthropic, in Claude's case.

Product analytics

To see how many people use InteliLang and which parts help them, the browser can send usage to PostHog, in PostHog's EU region in Frankfurt. It only happens within these limits:

  • Before you sign in — nothing is measured until you answer the bar at the bottom of the page. If you choose Allow, page views and clicks are counted, never anything you type; PostHog keeps an id in a cookie and in local storage on this site, so the visit can be joined to the account you may create; and the campaign that brought you — the utm tags in the link and the name of the site you came from — is kept in a cookie for up to 90 days and sent once, when you sign up. Visits before sign-in are never recorded. If you choose No thanks, or do not answer, nothing is sent.
  • When you are signed in — page views and feature counts are sent, on our legitimate interest, while your company shares usage and you have not turned it off in Settings → Your account → Help improve InteliLang. An owner or admin can turn off "Share anonymous usage with InteliLang" for the whole company; from then on nothing is sent for anyone in it.
  • Screen recordings — only if you allowed them. You are asked once, and can change your answer in the same place in Settings at any time; the answer is kept with your account, so it applies on every device. A recording shows how a session moves through the app with every word and every field hidden, so it shows layout and clicks, never words.
  • What is counted — which pages are opened and for how long, as addresses with every id and all search text removed; clicks, with the words on what was clicked hidden; and that a question was asked (and whether web search was on), a recording saved with its length as a range, a file of a given type and size range uploaded, a source connected, a card moved, an update written, a data download requested, a setup step finished.
  • Who — once you are signed in, your account's id, your role in the company, and your company's id and plan; always your browser, operating system and screen size. Never your name or e-mail address.

Never sent: what anyone writes, uploads, records or asks, answers, file names, project names or people's names. Without your consent nothing is stored in your browser for analytics. PostHog is set not to keep IP addresses; recordings are deleted after 30 days and events after a year.

What never leaves

Search stays on the server. Finding the passages that answer a question is Postgres work, a vector index and a full-text index, and the vectors themselves are made by a small model running inside our own process on the CPU. No text is sent anywhere to be searched or embedded.

For a chat answer, a model never gets the whole project. It gets what is listed under Anthropic above, with the retrieved passages cut to a budget of 6,000 tokens. Everything else stays in the database.

Recordings

Audio is never stored. Not on disk, not in the database, not as a temporary file of ours. What is saved is the transcript, the speaker names someone typed in the review screen, and how long the recording was, which engine made it and which languages it heard.

Where the audio becomes text depends on the engine the company chose: your browser's own speech service, which is the default, or Soniox, streamed from the browser.

Nothing recognises voices from one recording to the next. Naming who spoke is something a person does before saving, and that choice lasts only for that review.

Everyone in a meeting must be told before it is recorded. The app will not start until the person recording confirms that everyone knows, and gives them a sentence to say or paste into the meeting chat. Telling them is the recording company's duty, as the controller.

Cookies and browser storage

All set by InteliLang itself, on its own address. None is used to follow you across other sites, and there is no third-party cookie. Only the analytics ones depend on your consent.

  • __Secure-better-auth.session_token — keeps you signed in for seven days. Http-only, so no script can read it.
  • __Secure-better-auth.two_factor, __Secure-better-auth.trust_device — the first lives only while you type a two-step code; the second is set if you tick "Trust this device", so you are not asked again for 30 days. Both http-only.
  • __Secure-better-auth.state — set only while you sign in with Google, to tie the return trip to the browser that started it. Http-only, and it expires in five minutes.
  • slack-app-oauth-state — set only while an admin is connecting Slack, for the same reason. Http-only, and it expires in ten minutes.
  • analytics-consent — your answer to the analytics bar, so we do not ask again. Kept for a year.
  • ph_[project key]_posthog — PostHog's id for your browser, as a cookie and in local storage, so visits can be counted as one person's. Only after you chose Allow.
  • first-touch — the campaign tags and the referring site that brought you, sent once when you sign up. Only after you chose Allow, and kept for up to 90 days.
  • project, lang, time-zone, record-engine, record-language, signin-method, setup-list-hidden, hidden-announcement — the project you had open, your language, your time zone (so the server writes dates the way your browser will), the speech engine and spoken language you used last, whether you last signed in with a link or a password, the setup checklists and the announcement you dismissed. Kept for a year.
  • Local and session storage — how you like the files list shown, whether you have seen the product tour and two tips, and, for one tab, that you confirmed everyone knows a meeting is being recorded.

Everything except analytics is strictly needed for the service you asked for, or a preference you set, so it needs no consent. The analytics cookies are set only after you choose Allow, and choosing No thanks, or turning analytics off later, stops them.

How long it is kept

Each company sets its own retention in Settings. These are the defaults:

  • Content, 365 days — anything dated older than that is deleted, together with its passages, its vectors and its uploaded file. A company can choose anything from 7 days to 10 years, or keep it forever, within what its plan allows.
  • Chats, 180 days — counted from the last message in a conversation, not from when it started. Between 1 day and 10 years, or forever.
  • Spend records, 730 days — between 30 days and 10 years. This one cannot be set to forever.
  • Notifications, 90 days — or the content setting if that is shorter. Not configurable.
  • Cached answers, 7 days — and a project's cached answers are thrown away as soon as something in it is deleted, so an answer never outlives its source. Not configurable.
  • The audit log, indefinitely — it is the record of who changed what, so it is never swept.

A job runs at 02:00 UTC every night and deletes whatever is past its date. It is a real delete, not a flag. One thing outlives its source: a quote copied into a memory entry stays as long as that entry does, which is why the app says "the original was deleted" beside it.

Deleting things

Deleting a source, a file, a folder, a note, a project or a chat deletes the rows, and for files the bytes on disk as well. Deleting a project takes its sources, items, passages, vectors, memory, briefs, board, notifications and uploaded files with it, and it asks you to type the project's name first.

Removing someone from a company ends their access at once: their company membership and every project membership go. Their account stays, because it is theirs and may belong to other companies, and what they wrote stays with the project, because it is the project's record of what was said.

You can delete your own account from Settings, and it happens the moment you confirm it. It takes your sign-in and your password, every session, the personal keys you made for Claude and Cursor, the apps you let in, your chats, your e-mail preferences, your notifications, and the accounts you were matched to on Slack, GitHub and Jira; a GitHub account you connected yourself is disconnected and its token revoked at GitHub shortly after. What you put into a project stays there with your name on it, because it is the project's record of what was said. One thing stops it: if you are the only owner of a company, hand it to someone else or delete that company first, so it is not left with nobody who can run it.

A company owner deletes the whole company from the same place, and it takes everything in it: every project with its sources, items, passages, vectors, memory, briefs, board, chats and notifications, every uploaded file on the disk, everyone's access and every invitation still waiting, the tools it connected and the tokens they were installed with, its activity log, and its own API keys. A paid plan is cancelled at Stripe at the same moment; Stripe keeps its own record of past payments and invoices, as tax law requires. It asks for the company's name to be typed out first and runs the moment you confirm, working through the content in batches; a run cut short by a restart is picked up the same night and finished, rather than left half-done. If you would rather write to us instead of pressing the button, we answer within one month, as the GDPR requires.

Taking it with you

Everyone can download what InteliLang holds about them, whatever their role, from Settings → Data and deletion → Download your data. It is a ZIP with your profile and sign-ins, the companies and projects you are in and your role in each, every chat you had, your notifications and preferences, who you are on Slack, GitHub and Jira, the names of your personal keys (never the keys) and the changes you made. It holds nobody else's chats or notifications.

A company's owners and admins can download everything the company has from the same place: every project with the complete text of its messages, transcripts and documents and the original uploaded files, its memory, briefs, board and updates, the people and their roles, the connected tools (never their tokens), the AI usage and the activity log. People's private chats stay out of it. A project lead can also download one project from its page, limited to what they may see.

A download is prepared in the background and whoever asked for it gets an e-mail when it is ready. It stays available for 7 days and is then deleted. Asking for one is recorded in the company's activity log.

Your rights

If you are in the EU, the GDPR gives you the rights below. Write to office@doderasoft.com and tell us which company you belong to.

  • Access — a copy of what we hold about you. Download it yourself in Settings → Data and deletion, or write to us.
  • Correction — your name or e-mail address, if it is wrong.
  • Erasure — deletion of your account and the records tied to it.
  • Restriction — asking us to stop processing while something is being sorted out.
  • Portability — your data in a form you can take elsewhere. The downloads above are plain JSON and Markdown files.
  • Objection and withdrawing consent — to the processing we do on legitimate interests, and taking back a consent you gave, such as to analytics or screen recordings, at any time. Taking it back does not make what happened before unlawful.

For the content inside a project, the controller is the company that runs the project, not us. If you want something taken out of a project's memory, ask that company; when they ask us, we do it. If you are not sure who to ask, write to us and we will tell you.

You can also complain to a supervisory authority. In Romania that is the National Supervisory Authority for Personal Data Processing (ANSPDCP).

We answer a request within one month, as Article 12(3) of the GDPR requires. If a request is complicated we may need up to two months more, and we will tell you inside that first month that we are taking longer, and why.

Leaving the EU

What InteliLang stores sits in the EU: the server, the database and the uploaded files in Nuremberg with Hetzner, a German company; our e-mail with Hostinger, in the EU; product analytics with PostHog in Frankfurt.

Some of the services we use belong to groups outside the EU, or may reach data from outside it: Stripe, Google, Slack and PostHog. Where that happens, the transfer relies on the EU-US Data Privacy Framework for companies certified under it, and otherwise on the European Commission's Standard Contractual Clauses in that provider's data processing terms.

Content leaves the EU through the services your company chooses: Anthropic, which answers; Soniox, if you record with it; TypeSafe, if you turn it on; all in the United States. In each case the account is your company's own, the contract is between your company and that vendor, and what they may keep, whether they may train on it and how the transfer is safeguarded is set by that agreement, not by ours.

A company that adds no Anthropic key, records with no Soniox and leaves TypeSafe off sends no content outside the EU through us — except, when someone records with the default browser engine, the audio their own browser sends to its vendor.

Changes to this page

When something here changes, the date at the top changes with it. If a change means your content starts going somewhere new, we will e-mail the owners and admins of every company at least 30 days before it takes effect.

Questions about your data

Write to us and a person will read it. If you are exercising a right under the GDPR, say which right and which company you belong to, so we can find the right records.

office@doderasoft.com

May we count visits to improve InteliLang? We would keep a small cookie for it. Nothing you type is ever sent. Privacy