Privacy Policy Summarize.One

Summarize.One is a WhatsApp assistant developed in Germany that summarizes and transcribes voice and text messages. We are financed by our customers – we do not sell, rent, loan or lease any of your personal data. This Privacy Policy explains what data we process, why, for how long, and how you can exercise your rights.

In this Privacy Policy, “we”, “us” and “our” refer to Tasler IT Inh. Thomas Tasler. “Summarize.One” or “service” refers to the Summarize.One WhatsApp assistant and this website. “You” refers to you as a user of the service or visitor of the website.

1. Controller and contact

Tasler IT Inh. Thomas Tasler, Schießstattweg 12, 87772 Pfaffenhausen, Germany. For any privacy question or request please contact privacy@summarize.one. Our data protection officer is Tobias Knobl (privacy@summarize.one).

2. How Summarize.One works

You write to the Summarize.One number on WhatsApp and send or forward voice messages, audio files or texts. Summarize.One creates a summary (and on request a transcript) and sends it back to you in the same chat. You do not need an account, a password or an app. Your WhatsApp number identifies you.

3. Data we process when you use the WhatsApp assistant

3.1 Account data

  • your WhatsApp phone number and your WhatsApp profile name
  • the country derived from your phone number's country code
  • your settings (summary style, language, transcript on/off, watermark on/off)
  • your credit balance, your plan and the time you accepted our terms
  • if you came via a link on our website: the referral code of that link and the website visit it came from (see 8.2)

Purpose: providing the service and billing. Legal basis: Art. 6(1)(b) GDPR (contract).

3.2 Message content

The voice messages, audio files and texts you send or forward to Summarize.One are processed only to create your summary or transcript. We download the audio from WhatsApp, send it (or the text) to Google’s Gemini API, and send the result back to you via WhatsApp. Large audio files are uploaded to Google temporarily and deleted right after processing.

We do not store the content of your messages, transcripts or summaries. Nobody at Summarize.One reads or listens to your messages. Legal basis: Art. 6(1)(b) GDPR.

Messages you forward may contain personal data of other people. Please only forward messages you are allowed to share (see our Terms and Conditions).

3.3 Message metadata

For each message we store technical data without its content: type, length or duration, detected language, processing times, status, error codes, credits charged and AI usage (tokens, cost). We use it for billing, to fix errors and to improve the service. After 13 months this data is de-linked from your account (anonymized); only aggregated statistics remain. Legal basis: Art. 6(1)(b) and (f) GDPR (our legitimate interest in a reliable and economical service).

3.4 Usage events

We record which menu actions you use (e.g. “language changed”, “checkout link opened”) – without message content and without your phone number. They help us understand where the service can be improved. They are deleted together with your account and after 13 months at the latest. Legal basis: Art. 6(1)(f) GDPR.

3.5 Payments

Payments are processed by Stripe. When you buy credits or a subscription, Stripe collects your payment details on its own payment page; card or bank details never reach our systems. We store your Stripe customer ID, your subscription status, purchases and invoices. Legal basis: Art. 6(1)(b) GDPR and, for invoices, Art. 6(1)(c) GDPR (statutory retention duties). Stripe’s privacy policy: https://stripe.com/privacy

4. Recipients and processors

We use the following service providers. We have data processing agreements with them where required.

Some of these providers may process data outside the EU, especially in the USA. Such transfers are based on the EU-US Data Privacy Framework and/or the EU Standard Contractual Clauses.

5. Retention

  • Account data: until you ask us to delete your data.
  • Message content: not stored (see 3.2).
  • Message metadata: de-linked from you after 13 months.
  • Website statistics: events 90 days, visits 13 months (see 8.2).
  • Invoices and payment records: as long as required by German tax and commercial law (up to 10 years).

6. Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21).

To delete your data, choose “Delete my data” in the menu of the Summarize.One chat, or send an email to privacy@summarize.one. Please cancel an active subscription first. For all other requests, contact privacy@summarize.one.

You also have the right to lodge a complaint with a supervisory authority, for example the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, www.lda.bayern.de).

7. AI and automated decisions

Summaries are generated automatically by AI and may be incomplete or wrong. We do not make automated decisions with legal or similarly significant effect on you (Art. 22 GDPR).

8. Website

8.1 Hosting and server logs

This website is hosted by Cloudflare. When you visit it, technical data such as IP address, time, requested page and browser type is processed to deliver and secure the website. Legal basis: Art. 6(1)(f) GDPR.

8.2 Website statistics

We measure how our website is used with our own statistics. No third-party analytics tool is involved, nothing is used for advertising, and the data is stored only in our database at Supabase (EU). We record which pages are viewed, how long and how far they are read, which buttons are clicked, the website or campaign you came from (referrer host, UTM parameters), your country (derived from the IP address by Cloudflare), language, device type, browser and operating system family, page loading times (Web Vitals) and technical JavaScript errors.

Without your consent no cookies are used and nothing is stored on your device. To tell visits apart we compute a pseudonymous key from your IP address and browser identifier together with a random value that changes every day and is then deleted. Neither your IP address nor your full browser identifier is stored, and the key cannot be traced back to you after the day ends. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in understanding and improving our website). You can object at any time, e.g. by opening any page with ?notrack=1 (stores an opt-out flag in your browser); the “Global Privacy Control” signal is respected.

With your consent (cookie banner, category “Statistics”) we additionally set the cookie “so_vid” with a random visitor ID (13 months) so that returning visits can be recognised across days. Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG. You can withdraw your consent at any time via “Cookie settings” in the footer; the cookie is then deleted.

Link to the WhatsApp assistant: when you start Summarize.One from a button on our website, the code at the end of the prefilled WhatsApp message also contains a random session code (e.g. “k3j9x2ab” in “#ref-how-home--k3j9x2ab”). If you send this message, we link the website visit to your new Summarize.One account, so we can see which pages and campaigns lead to sign-ups and purchases. You can remove the code before sending. Legal basis: Art. 6(1)(f) GDPR.

Search engine and AI crawlers (e.g. Googlebot, GPTBot) are only counted per page and day, without IP address.

Retention: detailed events 90 days, visits 13 months, then deleted; afterwards only aggregated page statistics remain. When you delete your account, the link to your website visit is removed.

8.3 Cookies

Besides the optional statistics cookie (8.2) we only set the technically necessary cookie that stores your cookie settings (“cc_cookie”, 6 months). Legal basis: § 25(2) TDDDG and Art. 6(1)(f) GDPR.

8.4 Fonts – Bunny Fonts

Our fonts are delivered by Bunny Fonts, a service of BunnyWay d.o.o., Cesta komandanta Staneta 4A, 1215 Medvode, Slovenia (EU). Bunny Fonts does not log or share personal data. https://bunny.net/privacy

9. Security

We use encrypted connections (HTTPS/TLS) for all transfers, restrict access to personal data to the people who need it, and keep message content out of our storage altogether. No system is completely secure, but we work to keep the risk as low as possible.

10. Vulnerability disclosure

If you found a security vulnerability, please email privacy@summarize.one with a short description of the issue and where it occurs. Please do not include exploit details in the first email if the vulnerability is still exploitable. We will confirm your report and keep you informed.

11. Changes

We update this Privacy Policy when the service or the law changes. The current version is always available on this page.

Last updated: 6th October, 2026