Privacy Policy

Ripsa was built so that you can trust where your lectures end up. This page describes what we store, why, where it is processed and for how long.

Last updated 15 August 2026 På svenska →
The essentials at a glance
  • All processing of your recordings takes place within the EU.
  • No ads, no tracking, and your data is never sold.
  • You can delete a recording at any time, directly in the app.
  • Your account comes from your institution. Ripsa has no self-service sign-up.
  • When the account expires, all your data is deleted automatically after a 30-day grace period.

This is a translation of the Swedish policy; in case of discrepancy, the Swedish version prevails.

Who is responsible for your data?

Enjoy Solutions AB (Swedish company reg. no. 559213-5007), Sweden, is the data processor and processes the data on behalf of your institution. You can reach us at hello@ripsa.io.

Your account is created and managed by your educational institution. There is no self-service sign-up in the app, and Ripsa does not charge you as a student.

What data do we process?

  • Account data: your email address, used for signing in via one-time links.
  • Audio recordings: the lectures you record with the app.
  • Transcripts and summaries: the text produced from your recordings.
  • Uploaded material: photos (e.g. of the whiteboard) and documents you add yourself.
  • Course assistant questions: questions you ask and the answers you receive.
  • Technical information: IP address and device type for active sign-in sessions, for security purposes.
  • Error reports: when something goes wrong in the app, a report is sent with your IP address, device type and operating system, so that we can find the cause.

What is the data used for?

Solely to provide the service: transcribing your recordings, making them searchable, generating summaries and answering your questions about course material. Your email address is used for sign-in links and operational notices, such as a reminder before your account expires.

We show no ads, build no advertising profiles and never sell your data. There are no analytics tools at all in the app or the web service. On the ripsa.io website we count anonymous visits, which is described under Website statistics below.

Where is the data processed?

All processing happens with EU-based providers, in EU data centers:

  • Hetzner (Finland): servers, database and storage of recordings. Encrypted backups are kept in Germany.
  • Verda (Finland): GPU transcription with KB-Whisper, a Swedish speech-recognition model from the National Library of Sweden.
  • Scaleway (France): summaries, search index and course-assistant answers. Content is not retained after processing.
  • Brevo (France/Belgium): delivery of sign-in links by email.
  • Zoho (EU): the support mailbox hello@ripsa.io, that is, whatever you write to us yourself.

Recordings, transcripts, summaries and your own notes never leave the EU/EEA.

How long is the data kept?

  • For as long as the account is active. You can delete individual recordings, materials and questions at any time in the app. They are then removed permanently.
  • The audio is deleted as soon as the transcript and summary are ready, normally within an hour. It is the text that is kept, not the recording. A recording that is never transcribed is deleted after 30 days at the latest.
  • If your institution has ordered saved recordings, the audio stays until you or the institution deletes it.
  • When the account expires it is suspended for 30 days, so that your institution can renew it without anything being lost.
  • After the grace period the account and all associated data (recordings, transcripts, materials and questions) are deleted automatically and permanently.
  • Technical information about your sign-in is kept for as long as the session is valid, that is 30 days after you last used the app. For administrator accounts it is 12 hours. Signing out deletes it immediately.
  • Error reports are kept for 90 days.

Your rights

Under the General Data Protection Regulation (GDPR) you have the right to access your data, have inaccurate data corrected, have data erased, request that processing be restricted and object to processing. Get in touch with your institution or with us at hello@ripsa.io.

If you believe we are processing your data incorrectly, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

Security

  • All traffic between the app and our servers is encrypted (TLS/HTTPS).
  • Sign-in uses one-time links. There are no passwords that can leak.
  • Sign-in links and tokens are never written to logs.
  • Access to production data is kept to a minimum.

App permissions

The app requests only the permissions it needs, and uses them solely for the feature you start yourself:

  • Microphone: to record lectures. Used only when you start a recording yourself.
  • Camera: to photograph e.g. the whiteboard as course material. Used only when you open the camera feature; the photos go into your recording, not the phone's photo library.
  • Notifications: to show an ongoing recording and important service notices.
  • Background recording (Android): an ongoing recording continues with the screen off or when you switch apps. Recording never starts by itself.

Cookies

The app and web service use a single strictly necessary session cookie to keep you signed in. There are no tracking or marketing cookies.

Website statistics

The ripsa.io website uses GoatCounter for anonymous, aggregated visitor statistics (e.g. number of visitors and which pages are viewed). The tool sets no cookies and stores no personal data. Unique visitors are estimated from a temporary, salted hash of IP address and browser type that cannot be linked to you.

Changes

If this policy changes, we will update this page and the date above. We will notify you of material changes via the app or email.