Privacy Policy

Last updated 19 September 2026

Last updated: 19 September 2026

GodaDev LLC (“GodaDev”, “we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and disclose your personal information when you visit godadev.com, use our applications, or otherwise interact with us (collectively, our “Service”).

By accessing or using our Service, you confirm that you have read and understood this Privacy Policy. Where we rely on your consent, we will ask for it separately and clearly.

Who we are

GodaDev LLC is the data controller responsible for your personal information under this Privacy Policy.

Definitions and key terms

Cookie: a small amount of data generated by a website and saved by your web browser. See our Cookies Policy.

Company: when this policy mentions “Company”, “we”, “us”, or “our”, it refers to GodaDev LLC.

Customer: the company, organisation, or person that signs up to use the Service.

Device: any internet-connected device such as a phone, tablet, or computer used to access the Service.

End User: an individual whose personal data is processed by a Customer through our Service — for example, a participant in a recorded call that a Customer uploads.

IP address: a number assigned to every device connected to the internet, which can be used to approximate the location a device is connecting from.

Personal Data: any information that directly or indirectly, alone or combined with other information, allows a natural person to be identified.

Personnel: individuals employed by or contracted to GodaDev LLC to perform services on our behalf.

Service: the services provided by GodaDev LLC through this Website and our applications.

Third-party service: analytics providers, hosting providers, and other partners that support our Service.

Website: GodaDev LLC’s site, accessible at https://www.godadev.com.

You: a person or entity that visits our Website or is registered to use the Service.

What information we collect

Information you provide to us

  • Account information: your name, email address, and password (hashed with BCrypt — we never store your password in readable form, and cannot retrieve it).
  • Profile information: phone number, address, city, and a profile picture, where you choose to add them.
  • Signing in with Google or another provider: if you sign in this way instead of creating a password, we receive the identifier, name, and email address that provider shares with us, and record which provider you used.
  • Call audio and recordings that you or your organisation upload to the Service for transcription and analysis.
  • Correspondence: messages you send us by email, contact form, or support channels.

Information generated by your use of the Service

  • Transcriptions produced from uploaded audio, including the detected language.
  • AI analysis results: the values and justifications our system produces for each transcription against the parameters your organisation has configured.
  • Usage data: actions taken in the application, such as jobs created and reports generated.
  • Preferences: your chosen display language and similar in-app settings.
  • Biometric sign-in token: if you enable fingerprint or face sign-in on a device, we store a token used to recognise that device on future sign-ins. We do not receive or store your fingerprint or facial data itself — that stays on your device and is managed by its operating system.

Information collected automatically

When you visit our Website we automatically collect technical information including your IP address, browser type and version, device characteristics, operating system, language preferences, referring URLs, approximate location derived from IP address, pages viewed, and the dates and times of your visits.

Where this information is collected through non-essential cookies, we collect it only with your consent. See our Cookies Policy.

Information collected by our mobile applications

Where our mobile applications request the following permissions, they are optional, requested only at the point they are needed, and can be declined or revoked at any time in your device settings:

  • Location (GPS) — used to provide location-dependent features.
  • Contacts — used only to let you select contacts when that is required by a feature.
  • Camera — used to let you capture and upload an image directly.
  • Photo gallery — used to let you upload an existing image.

Declining any of these permissions will disable only the specific feature that needs it; the rest of the application will continue to work.

Information we do not collect

We do not collect or store payment card numbers. We do not knowingly collect information from children (see “Children’s privacy” below).

Call audio, transcriptions, and AI analysis

Because this is the most sensitive category of data we handle, we describe it separately.

What happens: when a Customer uploads call audio, we transcribe it and then analyse the transcription against the parameters that Customer has configured. For each parameter, our system returns a value and a justification. These results are stored and made available to that Customer.

Our role: for this data, GodaDev acts as a data processor on behalf of the Customer, who is the data controller. We process this data only on the Customer’s documented instructions.

Responsibility for consent: the Customer is responsible for having a lawful basis to record and upload calls, and for informing call participants and obtaining any consent required by the laws that apply to them. Many jurisdictions require all parties to a call to be notified that it is being recorded. Customers must not upload recordings they are not legally entitled to process.

End User rights: if you are an End User whose call was uploaded by an organisation and you wish to exercise your rights, please contact that organisation directly, as they control that data. If you contact us, we will refer your request to them and support them in responding.

Retention: call audio, transcriptions, and analysis results are retained for as long as the Customer’s account is active, or until the Customer deletes them. On account termination, see “How long we keep your information” below.

If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data only where we have a legal basis to do so:

PurposeLegal basis
Providing the Service and administering your accountPerformance of a contract (Art. 6(1)(b))
Processing call audio and producing transcriptions/analysisPerformance of a contract with our Customer; we act as processor on their instructions
Responding to your enquiries and support requestsPerformance of a contract or our legitimate interests (Art. 6(1)(f))
Security, fraud prevention, and maintaining service integrityLegitimate interests (Art. 6(1)(f))
Analytics and session-recording cookiesYour consent (Art. 6(1)(a))
Marketing and social media cookiesYour consent (Art. 6(1)(a))
Sending marketing emailsYour consent (Art. 6(1)(a)) — withdrawable at any time
Meeting legal and regulatory obligationsLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object to such processing at any time (see “Your rights” below).

How we use the information we collect

We use personal information to:

  • provide, operate, and maintain the Service;
  • create and administer your account and authenticate you;
  • transcribe and analyse audio that you or your organisation upload;
  • respond to your questions and provide customer support;
  • improve the Service, including diagnosing technical problems and understanding how it is used;
  • send you service-related communications (such as verification and security notices — these are not marketing and cannot be opted out of while you hold an account);
  • send you marketing communications, where you have consented;
  • protect the security and integrity of the Service and prevent abuse; and
  • comply with legal obligations.

We do not use your call audio, transcriptions, or analysis results to train machine-learning models for other customers or for our own general-purpose model development.

How we share information

We do not sell your personal information, and we do not share it with advertisers or data brokers.

We share personal information only in the following circumstances:

  • Service providers (sub-processors) who process data on our behalf, under contract and on our instructions, and may use it only to provide their service to us:

    ProviderWhat it does
    Google FirebaseSign-in verification and push notifications for our mobile app
    Gmail / Google Workspace (SMTP)Delivers account, verification, and notification emails
    Our hosting infrastructureStores application data, uploaded audio, and files

    We do not use Firebase Analytics or any Firebase product to track your behaviour for advertising purposes — Firebase is used here only for authentication and notification delivery.

  • Analytics and social media providers, where you have consented to the relevant cookies. See our Cookies Policy.

  • Legal and safety reasons, where we believe in good faith that disclosure is necessary to comply with a legal obligation, court order, or lawful request, or to protect the rights, property, or safety of GodaDev, our users, or the public.

  • Business transfers, if we are involved in a merger, acquisition, or sale of assets. We will notify you before your personal information is transferred and becomes subject to a different privacy policy.

International transfers

We are based in Egypt and some of our service providers operate outside the European Economic Area, including in the United States.

Where we transfer personal data of individuals in the EEA, the UK, or Switzerland outside those areas, we do so on the basis of appropriate safeguards — principally the European Commission’s Standard Contractual Clauses, supplemented where necessary by additional technical and organisational measures. You may request a copy of the safeguards we rely on by contacting us.

How long we keep your information

We keep personal information only for as long as necessary for the purposes described in this policy:

DataRetention period
Account informationFor as long as your account is active
Call audio, transcriptions, and analysis resultsFor as long as the account is active, or until deleted by the Customer
Data after account deletionDeleted or anonymised within 90 days, except where we must retain it by law
Support correspondenceUp to 3 years after the matter is closed
Website analytics dataAs stated in our Cookies Policy
BackupsBackup copies are overwritten on a rolling cycle and fully purged within 90 days

Where we are required to retain information to comply with a legal obligation, we retain it for the period required by that obligation and then delete it.

How we protect your information

We implement technical and organisational measures appropriate to the risk, including:

  • encryption of data in transit using TLS;
  • access controls, so that personal data is accessible only to personnel who need it;
  • hashed password storage;
  • network-level isolation and firewalling of our infrastructure;
  • logging and monitoring to detect unauthorised access; and
  • regular review of our security practices.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where the risk is high, notify you without undue delay.

Your rights

If you are in the EEA, UK, or Switzerland (GDPR)

You have the right to:

  • Access — obtain confirmation of whether we process your data, and a copy of it.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your data deleted where one of the grounds in Art. 17 applies.
  • Restriction — have processing restricted in the circumstances set out in Art. 18.
  • Data portability — receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
  • Object — object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent — at any time, without affecting the lawfulness of processing before withdrawal.
  • Not be subject to solely automated decision-making that produces legal or similarly significant effects on you.
  • Lodge a complaint with your local supervisory authority. You can find yours via the European Data Protection Board. If you are in the UK, contact the ICO.

To exercise any of these rights, email [email protected]. We will respond within one month, and may extend this by two further months for complex requests, telling you why. We may need to verify your identity before acting on a request. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.

If you are a California resident (CCPA/CPRA)

You have the right to know what personal information we collect and how we use it, to request deletion, to request correction, to opt out of the sale or sharing of personal information, and to non-discrimination for exercising your rights.

We do not sell or share your personal information as those terms are defined under the CCPA/CPRA. To exercise your rights, contact [email protected]. We will respond within 45 days, extendable once where reasonably necessary.

Marketing communications

We send marketing emails only to people who have asked to receive them. Every marketing email contains an unsubscribe link, and you can opt out at any time by using that link or by emailing us. We do not send unsolicited commercial email.

Opting out of marketing does not stop service messages necessary to operate your account, such as email verification, password resets, and security notices.

Children’s privacy

Our Service is not directed at anyone under the age of 16, and we do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us and we will delete it. If we learn that we have collected personal data from a child without the appropriate consent, we will take steps to remove it promptly.

Automated decision-making

Our Service uses AI to analyse transcriptions and produce values against parameters configured by our Customers. These outputs are provided to the Customer as information; GodaDev does not use them to make automated decisions that produce legal or similarly significant effects on individuals. If a Customer uses these outputs to make such decisions, that Customer is responsible for meeting the requirements of Art. 22 GDPR, including providing human review.

Our Service may contain links to websites we do not operate or control. This Privacy Policy does not apply to those sites, and we are not responsible for their content or privacy practices. We encourage you to read the privacy policy of every website you visit.

Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes to our Service or to legal requirements. Unless otherwise required by law, we will notify you before material changes take effect and give you an opportunity to review them. The “Last updated” date at the top of this page shows when it was last revised. If you do not agree to an updated policy, you may close your account.

Governing law

This Privacy Policy is governed by the laws of the Arab Republic of Egypt, without prejudice to any mandatory data protection rights you have under the laws of your country of residence, including the GDPR.

Contact us

For any question about this Privacy Policy or about how we handle your personal data: