TopoTopic Legal
How TopoTopic protects and uses your data.
Last updated 2026-08-25.
This Privacy Policy explains how TopoTopic ("TopoTopic", "we", "us") processes personal data when you use our website and services at topotopic.com(the "Service"). It is written to meet the transparency requirements of Articles 12 to 14 of the EU General Data Protection Regulation (GDPR).
The controller of this processing is the TopoTopic operator identified in our Legal Notice / Imprint. TopoTopic is operated from Austria and is in the process of incorporating there; the Legal Notice is updated as registration details are finalized. We are not currently required to appoint a data protection officer and have not appointed one.
TopoTopic is operated independently. Unless a written agreement or the Legal Notice says otherwise, people or organizations outside the TopoTopic operator that may be connected with developing, supporting, facilitating, hosting, funding, reviewing, advising on, or providing services to TopoTopic do not operate the Service and are not controllers of this processing.
This policy applies to the Service, including workspaces, capture and import flows, Newsstand, Messages calls, live translation, and AI-assisted features. For contractual terms, see our Terms of Service.
Contact for all privacy matters: support@topotopic.com.
We process personal data in these categories:
You are not legally required to provide personal data, but core data (such as an email address) is needed to create and secure an account; without it the Service cannot be provided.
We process personal data for the following purposes, each with its legal basis under Article 6 GDPR:
| Purpose | Main data used | Legal basis |
|---|---|---|
| Providing the Service you request: accounts, storage, sync, search and retrieval, transcription, analysis, collaboration, sharing you enable, and support | Account, content, voice and audio, derived, connected-service data | Contract, Art. 6(1)(b) |
| AI-assisted features you invoke (summaries, answers, keyword extraction, translation, Newsstand articles, learning content) | Content, derived data | Contract, Art. 6(1)(b) |
| Optional voice recognition (cross-session speaker matching) | Voice reference clip (special category, see Section 7) | Explicit consent, Art. 6(1)(a) with Art. 9(2)(a); revocable at any time |
| Keeping the Service and accounts secure: abuse and fraud prevention, sign-in monitoring, session integrity, rate limiting, audit logging | Security and log data | Legitimate interests, Art. 6(1)(f): protecting the Service, our users, and their content |
| Service emails: verification, security notices, account lifecycle | Account data | Contract, Art. 6(1)(b) |
| Optional product analytics (first-party and third-party) | Usage data, analytics identifiers | Consent, Art. 6(1)(a); device storage and access only with consent under the Austrian TKG |
| Error monitoring and reliability diagnostics | Error events with scrubbed identifiers | Legitimate interests, Art. 6(1)(f): keeping the Service working |
| Keeping proof of legal acceptance and consent decisions | Consent and acceptance records | Legal obligation, Art. 6(1)(c), and legitimate interests, Art. 6(1)(f) |
| Preserving provenance and audit records to investigate incidents and resolve disputes | Provenance records, audit events | Legitimate interests, Art. 6(1)(f): establishing and defending legal claims |
| Compliance with legal obligations and lawful requests | The data covered by the obligation | Legal obligation, Art. 6(1)(c) |
| Billing and entitlements (when paid plans are enabled) | Billing data | Contract, Art. 6(1)(b), and legal obligation, Art. 6(1)(c) |
Where we rely on legitimate interests, you can object as described in Section 15. We do not sell personal information and we do not share personal information for cross-context behavioral advertising.
The Service processes workspace content using third-party AI providers to generate the outputs you request. Depending on the feature path, this may involve sending portions of your content, audio, URLs, transcripts, public-safe topic or query text, or related metadata to:
We do not use Customer Content to train or fine-tune general artificial intelligence or machine learning models. When we send content to these providers, we contract with them, where available, to process Customer Content only for the outputs or imports you request and not for general model training. Provider names, purposes, regions, and transfer safeguards are listed at Subprocessors.
Conversational and voice surfaces in the Service are automated AI assistants. When the assistant helps you search, summarize, or draft actions, it may retrieve workspace context and call integrated providers only to complete the workflow you requested. Generated material can contain errors, and search, retrieval, and ranking involve machine-generated representations of your content (such as embeddings). Review AI output before relying on it; it is not professional advice.
For Newsstand, topic selection may use an AI provider to rank broad interest topics over redacted signals derived from your recent activity, such as concept labels and short excerpts with internal identifiers removed. The public-web research request itself is built from the selected broad interest topic and public-safe keyword refinements rather than private workspace content, private session notes, or internal workspace identifiers.
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR). Ranking, recommendations, and learning-schedule features personalize what you see inside the product; they do not determine your legal position or access to essential services.
When you use voice recording features:
Speaker attribution in this context is per-session labeling (for example "Speaker 1" and "Speaker 2"). By default, TopoTopic does not store voice reference data and does not identify speakers across sessions.
Voice assistant and call workflows may also search your workspace, translate active call audio using live translation, persist call transcript artifacts, or draft next actions. If an assistant flow prepares a Google Calendar event or a message draft, the action remains pending until you approve it in Messages.
Recording and transcription depend on feature requirements, including in-session speaker labeling and audio retention, which are core to how these features work. If your recordings include other people, you are responsible for obtaining their consent where required by law.
When you import URLs or external content:
You must have the right to import and process any content you submit. Our use of the YouTube API is subject to the YouTube Terms of Service and Google Privacy Policy. External source services, websites, and connected accounts process your request under their own terms. Do not import private, paid, confidential, or restricted content unless you have permission to process it in TopoTopic.
If you opt in to Voice Recognition (Settings, Privacy), a short audio reference clip (2 to 10 seconds) is stored to help automatically label you as a speaker in future sessions within your workspace. Because this data can uniquely identify you from characteristics of your voice, it is a special category of personal data under Article 9 GDPR, and we process it only with your explicit consent (Article 9(2)(a) GDPR).
The clip is used only for the speaker matching workflow you requested. During matching it is sent to OpenAI as part of the transcription request, together with the display names used to label matched speakers. It is not used to identify you anywhere outside your own workspace, and it is not used for advertising or training general models.
You can revoke consent at any time in Settings, Privacy. Revocation deactivates the profile immediately and starts deletion of the stored reference clip, subject to the backup and legal-retention limits described in Section 12. Revoking consent does not affect the lawfulness of processing before the revocation.
First-party analytics. With your consent, we record product events (page views, feature usage, experiment assignment) keyed to a random analytics session identifier and, when you are signed in, an account reference. Event records can include the address and title of the page you were viewing. The first-party analytics store keeps coarse location (country and region) rather than raw IP addresses. Event records in the current analytics pipeline are deleted after 90 days. Some measurement records are retained longer for aggregate product measurement: session-level records, signup and funnel milestone records with their acquisition attribution, and a small suppression registry that enforces analytics exclusions. Retained measurement records are deleted or stripped of your account reference when your account is deleted.
Google Analytics 4. Loaded only after you enable analytics, with IP shortening, without Google advertising signals, and without ad personalization.
PostHog. Loaded only after you enable analytics. PostHog is hosted in the United States, and requests are routed through our own domain. If you are signed in and analytics is enabled, the analytics profile may include your account email, display name, handle, and avatar reference, along with first-visit attribution (for example the campaign or referrer that brought you here). On a small set of pages, session replay may capture interaction recordings with all inputs masked and sensitive elements excluded.
Error monitoring (Sentry). To detect and fix failures, error events with stack traces and runtime metadata are sent to Sentry with EU-region ingestion. Error reports are sent without your IP address attached, and emails, tokens, cookie values, and internal identifiers are redacted from report contents before sending. This runs on our legitimate interest in keeping the Service working.
Reliability signals. The app reports web performance metrics and client error reports to our own endpoints for reliability purposes.
Withdrawing analytics consent stops future collection from that browser; it does not retroactively delete analytics records collected while consent was enabled, which expire on the schedules above.
Our primary infrastructure (AWS) is located in the EU (Ireland, eu-west-1), and error monitoring uses EU-region ingestion. Some service providers process personal data in the United States or other countries outside the European Economic Area when you use the related features.
For those transfers we rely on the safeguards of Chapter V GDPR:
The per-provider schedule is maintained at Subprocessors. You can request a copy of the relevant safeguards via support@topotopic.com.
We keep personal data only as long as needed for the purposes above. Current retention practice:
| Data | Retention |
|---|---|
| Workspace content, sessions, recorded audio, transcripts | Until deleted by you or a workspace administrator |
| Account data | While your account is active, plus the 30-day deactivation grace period after a deletion request, plus the time for backups to cycle out |
| Derived data (embeddings, keywords, graph and index artifacts) | Deleted or de-linked with the source deletion; storage cleanup completes asynchronously afterwards. Some derived learning artifacts and de-linked operational records persist until account deletion, subject to shared-workspace retention and backup cycles |
| Server and application logs | Up to 30 days |
| First-party analytics events | Event records in the current pipeline are deleted after 90 days; session-level and funnel milestone records are retained longer for aggregate measurement and are deleted or stripped of your account reference on account deletion |
| Security records (session histories, sign-in attempts) | Kept while relevant to account security, abuse prevention, and incident investigation; security audit records are retained as an audit trail with your user reference removed on account deletion |
| Encrypted database backups | Rolling short-term window (at least a 7-day point-in-time recovery window), plus a small number of operational snapshots taken before major infrastructure changes. Deleted data leaves the rolling window as it cycles out and leaves operational snapshots when those snapshots are deleted |
| Data export files | Download access expires 7 days after generation |
| Legal acceptance and consent records | Kept as proof of compliance while your account exists; after account deletion, erasure receipts with your user reference removed are retained as proof of deletion |
| Deletion audit records | Kept as proof of erasure with your user reference removed or set to null |
We may retain limited information beyond these periods where a legal obligation requires it, or where it is necessary to establish, exercise, or defend legal claims.
Deleting content.You can delete sessions and content inside the product. Session deletion runs through a verified erasure process that removes the session's content, transcripts, audio files (including stored file versions), embeddings, and graph entries, and records a verification receipt. Learning and practice artifacts generated from a session and de-linked operational records can persist until account deletion.
Deleting your account. Requesting account deletion in Settings, Privacy first deactivates the account and starts a 30-day grace period during which signing in cancels the deletion. After the grace period, a scheduled purge permanently deletes the account and its stored data, including stored file versions, subject to the limits in Section 12. If you are the last owner of a shared workspace, you may need to transfer ownership before deletion can complete. Content you contributed to shared workspaces may remain available to other members, and messages you sent to other users remain in those conversations, in each case with references to your user removed or set to null.
What deletion cannot reach. Deletion inside the Service does not delete copies or excerpts previously exported, downloaded, copied, or retained by other workspace members or share recipients, and records held by independent services (for example the payment processor) are governed by their own retention obligations.
Exporting your data. Settings, Privacy lets you request a machine-readable export. Exports currently include user-owned collection and session metadata across workspaces where you are a member, plus user-owned upload metadata, stored transcript text, parsed upload text, user-facing session analysis items, and report records where available. Exports do not currently include original file binaries, bearer-style share tokens, shared-workspace records retained by others, internal embeddings, hidden system analysis records, backups, or legal-retention copies. Session reports can additionally be exported from the product in document formats.
We apply technical and organizational measures designed to protect personal data (Article 32 GDPR), including encryption in transit (TLS) and at rest, row-level access controls in the database, scoped credentials, malware scanning of uploads, audit logging, and verified deletion flows. Our Security and Responsible Disclosure page describes how to report vulnerabilities.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected users in line with Articles 33 and 34 GDPR.
No system is completely secure. You are responsible for maintaining the security of your own account credentials and devices.
Under the GDPR you have the right to:
The fastest paths are the built-in controls (Settings, Privacy) for export, deletion, consent, and voice recognition. For anything else, contact support@topotopic.com. We will verify your identity and respond within one month; for complex requests this can be extended by up to two further months, and we will tell you if that happens.
Some requests may be limited by law, by security requirements, or by the need to preserve shared-workspace records, audit and provenance evidence, fraud-prevention records, or the rights of other users. Where a request is limited, we will explain why.
Complaints. You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement. The authority for Austria is: Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, Austria, telephone +43 1 52 152-0, email dsb@dsb.gv.at, www.dsb.gv.at.
The Service is not directed at children under 16, and our Terms of Service require users to be at least 16 years old. We do not knowingly process personal data of children under 16; if you believe a child has created an account, contact support@topotopic.com and we will delete it.
United Kingdom and Switzerland. If you are in the UK or Switzerland, the rights and safeguards described in this policy apply equivalently under UK GDPR and the Swiss Federal Act on Data Protection.
California and other regions. We extend the core controls in this policy (access, export, deletion, no sale of personal information, no sharing for cross-context behavioral advertising) to all users regardless of location. If your local law grants you additional rights, contact support@topotopic.com and we will handle the request under that law where it applies to us.
Browser privacy signals.We do not currently respond to browser "Do Not Track" or Global Privacy Control signals. Optional analytics stays off unless you enable it through the consent controls, regardless of those signals.
We update this policy when the product or our providers change. Each version carries a version identifier and a "Last updated" date, and material changes are presented for review and renewed acceptance in the product before you continue using the Service.
Privacy questions and requests: support@topotopic.com. Controller and operator details are published in the Legal Notice / Imprint.
Last updated 2026-08-25.
We use cookies to keep you signed in. Optional analytics are off unless you allow them. We do not sell personal information or share it for cross-context behavioral advertising. Privacy policy • Cookie policy