tautau.
tautau.xyz

Privacy Policy

Last updated: August 2026

The short version: your voice is used to write your text. We collect the minimum needed to transcribe, meter your plan, store recordings you start, and save assets you explicitly select.

What tautau does

tautau is a speech-to-text tool: a Chrome extension and web app that turn your voice into text in any input field. When you dictate, your microphone audio is sent over HTTPS to our transcription API (api.tautau.xyz) and processed by a speech-to-text provider (xAI, with failover to Groq or OpenAI) so it can be transcribed.

Audio and transcripts

  • Audio is used only to produce a transcript. It is not used to train models, not sold, and not shared with anyone other than the transcription provider processing that request.
  • In the web playground, recorded audio never leaves your browser tab — only the transcript is kept in the session log.
  • If you sign in, your dictations are saved to your private history — transcript and audio — stored in encrypted object storage (Google Cloud Storage) so you can replay them. Only you can read them, and you can delete any item or your whole history from the history page at any time.
  • If you use the extension or playground without an account, transcripts are returned to the page and nothing is retained by us beyond the request.

Screen recordings

  • Screen recording starts only when you explicitly start it from the extension. The video and audio of the tab you chose are uploaded to encrypted object storage (Google Cloud Storage) and combined into a recording you can play, rename, download, and delete from your dashboard.
  • If the camera bubble is enabled (on by default, switchable in the extension), your camera video is composited into the recording as a small circular overlay. It is never captured or stored separately, and disabling the bubble records the screen only.
  • If session capture is enabled (on by default, switchable in the extension), the recording also stores a technical debug bundle for the recorded tab: a page-structure outline, a cleaned copy of the page's HTML and visible text, an inventory of loaded assets (names, sizes, timing), storage key names (never values), page performance vitals, console messages, and network request URLs with status and timing. Successful responses are never read; for failed requests the error response body (text, size-capped) is included so failures can be diagnosed. Click and field-change events record which element, never the typed text, and page elements you explicitly pin are included. Secret-looking URL parameters (tokens, keys, signatures, session ids, passwords) are redacted before the bundle is stored. The bundle lives with the recording and is deleted with it.
  • While a tab recording or page scan is active, you can explicitly select an image, video, audio file, or document to collect. A cloud collection is copied into your private asset library and can have its own share link. A local download stays on your device and does not upload its bytes. Nothing is collected from a page just because it was inspected.
  • During a recording you can also speak page commands (for example, "click the search button"). The spoken command and the page's interactive-element outline (labels and attributes, never field contents) are sent to our AI providers solely to decide which element to act on, and the action taken is noted in the debug bundle. Commands only run while a recording is active.
  • Every recording gets a share link. Anyone with that link can watch the recording and read its transcript and debug bundle — treat it like a secret URL. Deleting the recording revokes the link.

Accounts

Sign-in is handled by Firebase Authentication (Google). If you create an account we store your email address and basic profile identifiers to manage your quota and subscription. We never see or store your Google password.

Usage quotas

To enforce fair-use limits, anonymous usage is counted against a browser cookie identifier and your IP address; signed-in usage is counted against your account email. These counters (plan, usage totals, subscription status) are stored in our transcription service database.

Payments

Paid plans are processed by Stripe. Card details go directly to Stripe — we never see or store them. We receive only your subscription status and a customer reference.

What the Chrome extension can access

  • Microphone — only while you actively start a dictation; recording stops when you stop it or the field changes.
  • Tab capture — only while you actively start a screen recording; the captured tab’s video and audio are uploaded as your recording.
  • Camera — optional, only while screen recording with the camera bubble enabled; composited into the recording, never stored separately.
  • Page content — the content script runs on pages you visit so it can place the mic button and insert transcripts into the focused field. During an explicitly started recording or scan, session capture records bounded page diagnostics. Asset bytes are collected only after you select an asset.
  • Storage — your settings and sign-in token are kept in Chrome’s local/sync storage on your device.

Third-party processors

  • xAI / Groq / OpenAI — speech-to-text transcription of dictation audio
  • Google Firebase — authentication
  • Stripe — payment processing
  • Google Cloud Storage — encrypted storage of signed-in users' history, screen recordings, session bundles, and cloud-collected assets
  • Vercel — web hosting

Data retention and deletion

Dictation history (transcripts and, for signed-in users, audio), recordings, session bundles, and cloud-collected assets are kept until you delete them. Deleting a recording also deletes its session bundle and revokes its share link. Local downloads remain on your device until you remove them. Quota counters reset on their own schedule (daily for free accounts, per billing period for paid plans). To delete your account and associated data, contact us at the address below.

Changes and contact

If this policy changes we will update this page. Questions or deletion requests: support@tautau.xyz.