Privacy policy
Last updated: July 2026
1. Controller
Curioskar FlexCo
Leopold Steiner Gasse 26/A2, 1190 Vienna, Austria
Email: support@plexcoach.com
2. Processing on this website
2.1 Hosting and server logs
This website is served via Firebase Hosting (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). When you visit, technically necessary data (IP address, time, requested resource, user agent) is briefly processed in server logs. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation). Google may transfer data to third countries; EU Standard Contractual Clauses and the EU-US Data Privacy Framework apply.
2.2 No cookies, no tracking
This website sets no tracking cookies and uses no analytics or tracking services. If you manually switch the site language, a single functional cookie stores your choice.
2.3 Demo requests / contact
If you request a demo or contact us via the form, we process your name, email address and — where provided — your company and message, in order to handle and answer your request. Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps at your request) and Art. 6(1)(f) (legitimate interest in answering enquiries). The data is stored in the EU, not shared with third parties, and deleted once the purpose no longer applies or you request deletion.
3. Processing in the service (app.plexcoach.com and the mobile apps)
At your instruction, Plexcoach processes audio recordings, transcripts, notes and content derived from them ("knowledge cards"). The key points:
- End-to-end encryption with user-held keys: content (audio, transcripts, notes, goals) is unreadable to the operator; our servers store ciphertext. Your key is derived from a 12-word recovery phrase that only you hold.
- Storage and processing in the EU (Frankfurt region) with customer-managed encryption keys (CMEK).
3.1 Account data
To operate your account we process your name, email address, password (as a salted hash via Firebase Authentication), your company affiliation, and — where provided — your position. Legal basis: Art. 6(1)(b) GDPR (performance of the contract). Accounts are created by invitation from your organization; there is no public sign-up.
3.2 Recordings, transcripts and notes
Recording is always started by you — the app never records on its own, and shows a visible recording indicator while a recording is running. You are responsible for informing the people you record and, where required by applicable law, obtaining their consent. Recordings, transcripts, the notes derived from them and photos you attach are stored end-to-end encrypted; the operator cannot read them. Legal basis: Art. 6(1)(b) GDPR at your instruction.
3.3 Transcription and AI processing
For speech-to-text, audio is processed ephemerally by our transcription processor (EU endpoint, contractual zero data retention) and then discarded there. A short list of names and terms drawn from your own notes — people, organisations and recent meeting places — travels with the audio so that they are spelled correctly. It is a word list, not your notes. AI coaching features send only the excerpts needed for your request — with names and other personal identifiers replaced by placeholders where feasible — to AI model providers under data-processing agreements that exclude training on your data. No AI provider receives your stored knowledge base or your keys. Search by meaning runs offline: the small open-weights model that indexes your notes runs locally on your own device, so the text it reads — including anything from a connected calendar or mailbox — is processed there and is never sent to that model's provider, for training or for any other purpose.
3.4 Voice recognition (voiceprints)
Optionally, and only with your explicit consent (Art. 9(2)(a) GDPR), the app derives a mathematical voice profile ("voiceprint") so your own turns in transcripts can be labelled with your name. You can withdraw this consent at any time in the settings; the voiceprint is then deleted. No voiceprint is ever created for third parties without their enrolment.
3.5 Optional integrations
If you connect them, we process calendar events (meeting titles and times, to match recordings to meetings), e-mail from a mailbox you connect (see below), and — where enabled for your organization — messages from chat workspaces you link. An approximate-location option (off by default) can tag where a note was captured. Each integration can be disconnected in the settings at any time. Legal basis: Art. 6(1)(a)/(b) GDPR.
Google user data — Limited Use. With your permission, Plexcoach reads your Google calendar and, if you connect a Google mailbox, your recent Gmail messages. Both of those reads are read-only — nothing in your calendar or your mail is changed or deleted. Calendar events — title, time, attendees and any conferencing link — are read to help you prepare for a meeting and to match a recording to the meeting it belongs to. Messages are read so that what matters can become a note, and so that a reply can be prepared. Plexcoach additionally asks for permission to create drafts, and uses it for one thing: to place a draft reply in your own Drafts folder, for you to edit and decide about. That draft is the only thing Plexcoach ever writes to your account, and Plexcoach never sends e-mail on your behalf. Plexcoach’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data, do not use it for advertising, and do not use it to train generalised artificial intelligence or machine-learning models. You can revoke access at any time in the app settings or at myaccount.google.com/permissions.
3.6 Technical data
We process push-notification tokens, device model and app version, a once-per-day usage signal (how often you opened the app that day, plus feature-usage counters such as the number of AI requests — metadata only, never content), and technical crash diagnostics that contain no note or audio content. An aggregated usage overview (active days per member) is visible to your organization's administrator; the operator sees usage metadata for service administration and billing. Legal basis: Art. 6(1)(f) GDPR (reliable and secure operation).
4. Retention and deletion
Content remains stored for as long as your account exists. If you delete your account or individual content, it is deleted; backup copies rotate out within 30 days.
You can delete your account and all associated data yourself at any time — in the app under Settings → Delete account & data, or without the app at app.plexcoach.com/settings (sign in → Delete account & data). Deletion removes the account record, all recordings, transcripts, notes, goals and voiceprints, and is irreversible. Details: how to delete your account.
5. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR), and the right to withdraw any consent at any time. A full data export and account deletion are available directly in the product. Complaints can be addressed to the Austrian data protection authority (dsb.gv.at) or to us at the address above.
6. Changes
We update this policy as the service evolves. The current version is always available on this page.