Speech-to-Text API & Playground — Privacy Note
Version: 1.2
Effective: 8 August 2026
Provider: Omi Health B.V., Eindhoven, Netherlands
Contact: [email protected]
This plain-language note explains what we collect when you use the Omi Speech-to-Text API or the public STT Playground on this website. It sits alongside our Website Privacy Policy, and the API is governed by the Data Processing Agreement where applicable. If anything here conflicts with a signed agreement you have with us, that agreement wins.
The short version
- Playground audio is deleted immediately after transcription. It is never written to durable storage.
- For API requests, audio is deleted when transcription completes. Result artifacts are retained only until the configured expiry: 24 hours by default, configurable from 1 to 72 hours. Owner-scoped job metadata and expiry tombstones may remain for up to 72 hours so expired jobs return a stable response. Content is not written to application logs.
- We keep request metadata (things like model, audio duration, and timestamps) to run, secure, and rate-limit the service.
- We never train, fine-tune, or evaluate models on customer content, including free-tier content.
What we collect
Playground (this website)
- Audio you record or upload — sent over an encrypted connection, transcribed, and then deleted immediately. It is held only in memory for the moments needed to produce the transcript, and is not persisted to disk or backups.
- The transcript — generated and returned to your browser. We do not store transcript content.
- A Cloudflare Turnstile token — a bot-protection check. Turnstile is provided by Cloudflare and does not require solving a puzzle in most cases.
- Request metadata — such as timestamp, approximate audio duration, model version, coarse status (success/error), and a truncated/hashed IP address used only for rate-limiting and abuse prevention. Any custom vocabulary terms you enter are used for that request and are not retained as content.
Speech-to-Text API accounts and keys (for developers)
- Account email — collected via Keycloak when you sign in to the developer console, so we can issue and manage your key. This is used for authentication and account communication.
- Usage metadata per request — model, published model build, audio duration, timestamps, request counts, and status codes. This drives allowances, billing, support, security, and abuse detection.
- API audio and result artifacts are retained only temporarily — audio is deleted when transcription completes; result artifacts remain until the configured 1–72 hour expiry, with a 24-hour default. Owner-scoped job metadata and expiry tombstones may remain for up to 72 hours. We log operational metadata, not the content you send or receive.
- Custom vocabulary you configure for your API key is stored separately as account configuration while the key/account remains active. You can ask us to correct or delete it by contacting [email protected].
What we do not do
- We do not sell your data.
- We do not use customer audio, transcripts, vocabulary terms, or other content to train, fine-tune, or evaluate models.
- We do not retain Playground audio after the transcription completes.
Where it runs and who processes it
API transcription is processed on Omi-operated infrastructure in AWS eu-central-1 (Frankfurt, European Union). We rely on a small set of sub-processors to deliver the service, including:
- Cloudflare — bot protection (Turnstile), CDN, and edge security.
- Amazon Web Services (AWS) — cloud hosting for the transcription service.
- Microsoft Azure — hosting for Omi-operated Keycloak, which provides developer-console sign-in. This system processes account and identity data (such as name, business email, and authentication events) only; no audio or transcript content is ever sent to it.
Our full production sub-processor list is at Sub-processors.
How long we keep things
- Playground audio: deleted immediately after transcription; it is held in memory only and never written to durable storage.
- Playground transcripts: returned to your browser and not stored.
- API audio: deleted when transcription completes.
- API result artifacts: retained until the configured expiry, from 1 to 72 hours, with a 24-hour default. AWS processes deletion asynchronously, so removal may complete after the nominal expiry time.
- Owner-scoped job metadata and expiry tombstones: may remain for up to 72 hours so expired jobs return a stable response.
- Operational request metadata / logs: typically kept up to 90 days for security, rate-limiting, and troubleshooting, then deleted or aggregated. Separate content-free security, compliance, contract, and billing records may be retained longer where needed for their stated purpose or required by law.
- Custom vocabulary: kept as account configuration while the relevant key/account is active, unless you ask us to correct or delete it sooner. Residual recovery copies age out under the applicable backup schedule.
- Console account (email): kept while your API account is active; deleted on request or when the account is closed.
Your rights
You can ask us to access, correct, or delete personal data we hold about your API account (for example, your console email or stored vocabulary). Because Playground audio and transcripts are not stored, there is usually nothing to retrieve or erase for a given Playground transcription. Contact [email protected].
You have the right to lodge a complaint with your data protection authority. In the Netherlands this is the Autoriteit Persoonsgegevens.
Changes and contact
We may update this note as the Service evolves. Material changes will be reflected here with a new version and effective date, and we will provide any notice required by law or our Terms of Use.
Privacy questions: [email protected] · Security reports: [email protected]