Duskeep is a voice journal. You record a short spoken note about your day, and Duskeep turns it into a written summary. This policy explains what we collect, how it's used, who processes it, and the choices you have.

What we collect

How your data is used

Your recording is encrypted on your device, uploaded, decrypted briefly on our server so it can be transcribed and summarized, and the finished page is encrypted back to your device before being stored. See How your recordings are protected below. It is the most important section of this policy.

Third-party processors

To provide the core feature, your content is processed by:

Your audio and text are transmitted securely (HTTPS/TLS), encrypted in transit and at rest, decrypted only transiently during processing, and are not used to train AI models. (This reflects the paid API terms of our providers.) Deepgram and Google are the only third parties that ever see your content in a readable form, and only during the few seconds a page is being written.

How your recordings are protected

Your recording is encrypted on your device before it is uploaded, with a key that is itself encrypted to a public key built into the app. The matching private key is held inside a hardware security module (Google Cloud KMS) and cannot be exported by us or by anyone else.

To turn your voice into a written page, that recording has to be readable for a short time. Here is exactly what happens in that window, and what happens after:

  1. The Cloud Function asks the hardware module to unwrap the key for this one recording. Every such request is recorded in an audit log we cannot alter.
  2. The recording is transcribed and written up. Deepgram and Google (Gemini) receive the audio and the transcript in the clear during this step. This is unavoidable if a machine is to write your day for you. Both are paid services, contractually barred from retaining your content or training on it.
  3. The finished page is encrypted to your device's public key, signed, and stored. The audio is deleted according to the retention schedule below.
  4. The key that let us read the recording is deleted from the entry. From that moment we cannot open that entry again: not from the database, not from a backup, not with any credential we hold.

Your device holds the only key that can open your stored pages. It is generated on your phone, kept in the iOS Keychain or Android Keystore, and never transmitted. We do not have a copy.

Consequences you should know about

On-device encryption

Separately from the above, everything stored on your phone (transcripts, summaries, moods, topics and chapters) is encrypted with AES-256-GCM before it is written to the journal database, under a second key held in the iOS Keychain or Android Keystore. If the database file were extracted from your phone or from a device backup, its content columns would be unreadable.

Erasing your journal also destroys that key, so any residue left in freed database pages becomes permanently unreadable.

Data retention

Your choices

Children

Duskeep is not directed to children under 13 (or the minimum age in your region) and we do not knowingly collect their data.

Contact

Questions or requests: chandankadarla2722002@gmail.com