Privacy Policy
Last updated: September 22, 2026
The Change Mindset Co ("we") operates Anicca at web.anicca.app. This policy explains how we use information when you use the service, including information about other people in recordings and stakeholder maps.
Your data and your choices
You can delete individual sessions from your session history. To permanently delete your account, sign in and open Settings → Your data → Delete account. Save any available exports or request a copy of your data before deleting: deletion cannot be undone.
If you cannot sign in, want a copy or correction, or your information appears in another person's session or stakeholder map, submit a privacy request. For help deleting an account, use the account deletion request form. You receive a reference on screen. We verify your authority over the data before disclosing or deleting it; submitting an email address alone does not authorize deletion.
Information we collect and use
We collect account details such as your name and email, recordings and transcripts you submit or connect, and the analysis and feedback generated from them. Team features may include rosters, invitations, and stakeholder information. We also process support messages, subscription records, security logs, and information about how the product is used.
We use this information to provide transcription, analysis and coaching, operate your account and team, prevent abuse, improve the product, and respond to requests. Stripe processes payment details; we keep the subscription information needed to provide your plan. We do not sell your personal information.
Service providers and integrations
We share the information needed to operate Anicca with our service providers. These include AWS and Vercel for hosting and processing, AssemblyAI for transcription, Recall for connected meeting recordings, Stripe for payments, Resend for service email, and PostHog and Sentry for product analytics and diagnostics. Connected services such as Roam supply content when an integration is used. The information sent depends on the feature you use.
General business inquiries may also be recorded in our customer relationship system. Requests submitted under the privacy or account deletion categories are kept in our privacy review inbox and are not forwarded to that sales system.
Retention periods
- Raw audio and video: deleted 90 days after the session is analyzed, including copies processed by our transcription and meeting-recording providers. Transcripts and analysis remain available until their own deletion.
- Transcripts, analysis and scores: retained for the life of your account, unless you delete the session earlier. Sessions imported from Roam follow the same rules.
- Account deletion: access ends when deletion is accepted and removal from live systems begins immediately. Remaining copies in live systems, including queued provider cleanup, are removed within a maximum of 30 days. Rolling backup copies age out within a further 35 days. Manual recovery snapshots do not expire automatically and require separately tracked and verified disposal. This is a cleanup window, not a recovery period.
- Team data: team rosters, invitations, and stakeholder maps are kept for the life of the team; a team that is closed or archived is retained so its members and administrators can still review it. Members' personal sessions survive team closure and follow their individual accounts' retention rules. A team owner must arrange transfer or dissolution before deleting their account.
- Shared links: expire 30 days after creation unless the owner extends them, and can be revoked sooner. A person with a link can view the full conversation transcript, including other participants' words, alongside the shared analysis. Only share with people who should have that access.
- Operational records: verification and rate-limit records are kept for up to 7 days, service email records for 30 days, and backend activity for 90 days. Usage records follow the life of the account.
- Security and request records: administrator audit records are kept for 7 years, then expire. We retain hashed references without an expiry to prevent deleted data from being imported again. We keep identifying cleanup references while verifying removal and checking for late-arriving copies, for up to 30 days. If cleanup fails, those references remain only as needed to finish deletion, and the failure is escalated for review. Privacy request records are kept while we handle the request and for 30 days after it is closed, then deleted. A limited record of the administrator's actions remains in the security audit log. These exceptions do not keep your session content available for normal product use.
Deletion cannot remove copies someone has already downloaded or independently retained. Tell us if another user's content includes information about you so we can review the request and the rights of everyone involved.
Cookies and analytics
We use cookies and browser storage for sign-in and product functionality. When analytics is enabled, PostHog also uses cookies and local storage to understand product usage and may record interactions for troubleshooting. Form inputs and designated transcript and analysis panels are masked in those recordings. Sentry helps us diagnose errors. Browser privacy settings can affect cookies and storage.
Security and updates
We use safeguards such as access controls and encryption in transit and at rest. No system can guarantee absolute security. We review this policy as the service changes and show the latest revision date above.
For privacy questions or to exercise access, correction, or deletion rights, contact The Change Mindset Co. We will explain any verification needed and any limits that apply to your request.