Privacy Policy
Last updated 29 July 2026
What Demist does
Demist transcribes your lectures, reads them back, and explains and translates unfamiliar terminology in real time, building a personal glossary for you to review. Built for students who find lectures harder to follow, this policy explains what data we collect, why, and how it is handled.
Using Demist without an account
In the Windows desktop app you can choose Start without an account. We then create an anonymous account that has no email address and no name attached to it. Your glossary, flashcards and session history are stored against that anonymous account so the app works normally. Because there is no email address on it, there is no way for us, or for you, to recover it if this device's storage is cleared or the app is reinstalled. You can add an email later in Settings to make it recoverable; doing so upgrades the same account rather than creating a new one.
Data we collect
- Email address: used for authentication via a one-time code, and to contact you if you join the Pro waitlist. We do not send marketing emails. On the desktop app an email is optional, as described above.
- Audio recordings: in the web app, microphone audio is captured in short chunks, sent to Groq or OpenAI for transcription, and immediately discarded. In the desktop app audio never leaves your device at all, as set out in the desktop section below. We do not store audio files in either case.
- Transcripts: for live microphone sessions we save a transcript only if you've declared a support need in your profile, or your lecturer has consented for your module. For recordings you upload or capture from an officially provided source, transcripts are saved to your account.
- Term definitions: in the web app, to define a term we send the flagged term and a short excerpt of surrounding context to OpenAI: a single sentence per term, never full transcripts. Nothing sent for definitions is stored by us. In the desktop app definitions are generated on your device and nothing is sent. If you've set a translation language and your browser supports on-device translation (Chrome), the definition is translated on your device automatically; otherwise the same OpenAI request that generates the definition also translates it.
- Detected terms: the terms and definitions picked up from your sessions are stored in your account so you can review them later.
- Profile information: course, year of study, and date of birth. Used to tailor term explanations to your level and to keep the service age-appropriate. Date of birth is never shared.
- Support need: an optional, self-declared category (hearing, reading/dyslexia, focus/attention, language, none of these, or unspecified) used only to unlock full transcript saving without requiring lecturer consent each time. Choosing "none of these" means microphone transcripts are saved only where your lecturer has consented for the module, which is the stricter setting. You choose whether to set this, can change it any time in your profile, and it is never shared or used for any other purpose.
- Session data: timestamps and duration of recording sessions. Used to calculate your streak and weekly stats.
- Flashcard history: your grading responses (Again / Hard / Good / Easy) used to schedule spaced repetition reviews.
- Usage analytics: product events (e.g. "recording started", "flashcard graded") collected via PostHog to help us improve Demist. Once you sign in these events are linked to your account's user ID, so they are pseudonymous rather than anonymous: we can tell one person's activity apart from another's, but the events themselves carry no email, name, transcript text or term content. PostHog also automatically records unhandled errors, which may include technical details of what the app was doing when something went wrong.
- Pro waitlist: if you join the waitlist we store your email, which part of the product prompted you, and whether you have confirmed the address. Joining sends you a confirmation link, and we only treat you as being on the list once you click it. We store a one-way hash of that link's token, never the token itself. This is used only to contact you about Pro, once, when it is ready. You can join without an account.
Third-party services
- Supabase: database and authentication.
- Groq & OpenAI: used by the web app only. Audio is transcribed using Groq's and/or OpenAI's APIs, and term detection uses OpenAI. Unless your browser supports on-device translation (Chrome), definition translation also uses OpenAI. Audio is processed in real time and not stored by us. These providers are based in the United States; data is transferred under their data processing agreements and standard contractual clauses, and is not used to train their models.
- PostHog: product analytics, as described above.
- Hugging Face: the desktop app's transcription models are bundled in the app and are never fetched. Its term-detection and translation models are downloaded from Hugging Face the first time they are needed and cached on your computer. These are ordinary file downloads. No lecture audio, transcript or personal data is sent, and nothing is uploaded.
Desktop app (on-device processing)
If you use the Demist desktop app (Windows), transcription, translation, and term detection all run locally on your device using open-source models. Your lecture audio and the text derived from it are never sent to Groq, OpenAI, or any other third party for processing while using the desktop app. This covers every route text can take through the app, not only live recording: files you import, slides and transcripts you upload, and looking up a phrase you have selected are all processed by the same local models.
The transcription models ship inside the app itself, so transcription works on first launch with no download and no internet connection. The term-detection and translation models are larger and are downloaded from Hugging Face the first time they are needed, then cached on your computer; until that finishes you get transcription without term cards, rather than nothing. The app uses Whisper (MIT licensed), OPUS-MT translation models (Apache 2.0), Qwen (Apache 2.0) and Meta's Llama models (Llama Community License); license and attribution details ship with the app.
This changes how data is processed, not whether it's stored: the same consent rules above still apply to saving a microphone-mode transcript, and detected terms, session timestamps, and flashcard history are still synced to our Supabase database exactly as in the web app, so your glossary and progress stay available across devices. The desktop app also loads its interface from demist.app, so it needs a connection to start.
Data sharing
We do not sell, rent, or share your personal data with any third party outside of the services listed above.
Data retention and deletion
Your data is kept for as long as your account is active. You can delete your account and everything stored against it (profile, transcripts, detected terms, sessions and flashcard history) at any time and without asking us, from Settings → Delete account. This takes effect immediately and cannot be undone. If you would rather we did it, or you can no longer sign in, email the address below and we'll process the request within 30 days.
Cookies
We use a session cookie to keep you signed in, and PostHog sets its own cookie so that your product events can be recognised as coming from the same browser between visits. We do not use advertising cookies, and we do not sell or share any of this with advertisers.
Contact
Questions about this policy or your data: privacy@demist.app
Complaints
If you have a concern about how we handle your data, email privacy@demist.app. We'll acknowledge your complaint within 30 days. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk).