DM
Donald’s MicRecord clearly. Follow through.

Privacy and data

Current product information · Updated 23 August 2026

What stays on your device

Donald’s Mic saves recordings locally first. The web app uses IndexedDB; iPhone, iPad, Apple Watch, and Android use app-private files. Audio is written in independently recoverable chunks and validated before a chunk is treated as saved. Meeting titles, consent records, transcripts, summaries, categories, review state, and your edits also remain available locally.

AI processing

After you stop a recording, audio is sent through the Donald’s Mic server to ElevenLabs for transcription and speaker labelling. Transcript text, meeting title, date, and speaker timestamps are then sent to MiniMax to prepare the editable brief. Raw audio request bodies are not saved in the Donald’s Mic cloud database. To make retries safe across server instances, successful transcript and brief responses are encrypted by the application and may be cached in Neon for up to 24 hours.

Provider handling

ElevenLabs and MiniMax receive meeting content needed for their processing stage. Their retention, training, human review, regional processing, and account-level privacy controls depend on the configured provider accounts and current provider terms; this application does not enforce or independently verify those settings.

Account and private sync

After you choose to sign in, Donald’s Mic may receive and store your account email address and optional display name from Sign in with Apple or Google Sign-In. They are used for sign-in, private sync, account management, and support. Reviewed meeting records can synchronise through the private Donald’s Mic database. Native apps receive a revocable device token through a secure system-browser handoff; only a SHA-256 hash of that token is stored by Donald’s Mic. Passwords, passkeys, and browser session cookies are not returned to the native app. Raw recording files are not included in ordinary record sync. A private audio object is recorded as uploaded only after its ownership, byte size, and optional checksum have been verified.

Retention and deletion

Local meetings remain until you delete them, the browser storage is cleared, or a retention cleanup that you explicitly confirm removes eligible unpinned audio. The Apple app keeps transcripts and briefs when confirmed audio cleanup runs. Short-lived encrypted processing responses expire within 24 hours. Verified private cloud audio objects default to a 90-day retention date unless pinned. The Account page and the public account-deletion instructions provide a permanent deletion path: it removes private audio objects, synchronized meeting records, native device sessions, and the authentication account. Local copies on other devices must be deleted on those devices.

Security and transport

Production connections use HTTPS. Native session tokens are stored in Keychain on Apple platforms and Android Keystore-protected storage on Android. Application databases and object storage must be provisioned with private credentials on the server; provider API keys are not bundled in the apps.

Consent

Recording begins only after you deliberately press the recording control and grant microphone access. Donald’s Mic shows an active recording state while capturing audio. It does not notify other participants for you; you remain responsible for informing them and obtaining appropriate permission. Recording rules vary by location and context.