This guide is practical background, not legal advice.

JesRecap is designed to support your compliance process — it is not certified, and no software can make you compliant on its own. What it can do is shrink the surface you have to document, because the meeting audio and the transcript never leave the machine that made them.

Why cloud transcription creates GDPR work

A meeting recording is dense personal data. It contains voices (biometric-adjacent in some readings), names, opinions, health remarks, salary numbers, client matters, and the occasional thing someone said before they realised recording had started. It routinely includes data about people who never agreed to anything: the customer on the other side of the call, the colleague who was mentioned, the patient being discussed.

The moment that recording is uploaded to a transcription vendor, you have created a controller-to-processor relationship, and a list of obligations follows:

  • A data processing agreement. Article 28 requires a written contract with specified subject matter, duration, purpose, security measures, and deletion terms. Someone has to read it, negotiate the parts that do not fit, and re-read it when the vendor updates it.
  • A sub-processor chain. Transcription vendors run on cloud infrastructure, use model providers, and buy support tooling. Each of those is a sub-processor you inherit, and each change is something you are supposed to be told about and can object to.
  • Transfer analysis. If any part of that chain processes data outside the EEA, Chapter V applies: an adequacy decision, standard contractual clauses, or another mechanism, plus a transfer impact assessment. "Our EU region" is not the end of the question if support staff or model inference sit elsewhere.
  • Security assurances you cannot verify. Article 32 makes security your obligation too. You are assessing a system you cannot inspect, usually from a certification summary and a trust page.
  • Retention you do not control directly. Deletion becomes a request to a vendor rather than an action on a disk. Backups extend the real retention window past the number in the policy.
  • Records and possibly a DPIA. The vendor goes into your Article 30 records of processing. Systematic recording of conversations, especially in a health, legal, or employment context, is the kind of processing that often pushes you toward an Article 35 assessment.
  • Secondary use questions. Whether recordings are used to improve models, for how long, and under which setting — a question you have to keep asking as terms change.

None of this means cloud transcription cannot be done lawfully. Plenty of organisations do it properly. It means the work is real, recurring, and paid for in the time of people who are usually busy.

What changes when the processing happens on the device

JesRecap captures the microphone and the system audio locally, transcribes with a speech model that runs on the same machine, and writes the results to that machine's disk. There is no upload step for meeting content, because there is nowhere for it to go.

The practical consequences:

  • There is no third-party processor for the meeting content. We never receive the audio, the transcript, or the meeting titles, so there is nothing for us to process on your behalf and no content DPA to negotiate. Your own processing as controller still applies in full.
  • No sub-processor chain to inherit for that content, and so nothing to re-review when an infrastructure vendor changes.
  • No international transfer of meeting content. The data stays on the endpoint, in whatever jurisdiction that endpoint is in.
  • Data minimisation gets easier. Two source tracks and a transcript exist in one place, and you can delete them with the tools you already use to manage that laptop.
  • Security measures are the ones you already run. Full-disk encryption, screen lock, device management, backup policy. You are not assessing someone else's data centre.

The honest counterpart: an endpoint is now holding sensitive recordings. That is a real risk profile, just a familiar one, and one your existing device controls were built for.

The only vendor traffic

Being precise matters more than being reassuring, so here is the entire list of network activity JesRecap involves:

  1. Model download, once. The speech model is fetched from models.jesrecap.com the first time you need it (public mirrors are used as a fallback), then reused from disk. Speaker labelling uses a separate one-time 54 MB download, and the optional on-device AI notes add a one-time download of about 1.3 GB from the same hosts if a user enables them. These are plain file downloads — no account, no meeting data attached, and they can be pre-seeded before rollout.
  2. Licence activation and validation. The app sends your licence key and a device fingerprint to our licence API so it can enforce the two-device limit. Purchase runs through Stripe checkout in a browser, which is where your email address comes from. That is the only personal data we hold, and it is about the buyer, not about the meeting.

Nothing else. No telemetry, no crash reporting to us, no analytics, no accounts. The privacy statement spells out each field, and the security page lists the endpoints.

Obligation-by-obligation comparison

ObligationCloud transcriptionJesRecap
Art. 28 processor contract for meeting content Required, per vendor Not applicable — we never receive the content
Sub-processor tracking Ongoing None for meeting content
Chapter V transfer mechanism Usually needed Content does not leave the device
Art. 32 security Yours plus the vendor's, partly unverifiable Yours, on hardware you control
Art. 30 records of processing Include the vendor and its chain Record the local processing and the licence data
Retention and erasure Vendor settings, vendor backups Delete the meeting; then your own backups
Consent or notice for recording Still yours Still yours
Lawful basis for recording at all Still yours Still yours

The bottom two rows are the point. Local processing removes the vendor questions. It does not remove the questions about you.

A practical checklist

1. Decide your lawful basis, then say it out loud

Write down why you are recording and under which basis — consent, legitimate interests with a balancing test, or something narrower. Keep it specific to a purpose ("accurate notes for project decisions") rather than "for our records". A vague purpose makes retention impossible to justify later.

2. Tell people before you press record

Announce it at the start, put it in the invite, and give people a way to say no. Recording law varies by country and by context — some jurisdictions require all parties to agree, and employment settings often bring works-council or consultation requirements on top of GDPR. If a participant objects, do not record; take notes.

3. Write a retention policy for your own disk

This is the step people skip, because on-device storage feels like it does not count. It does. Decide how long a recording is useful, and be strict: a fortnight for routine internal calls, longer only where you can explain why. JesRecap keeps both source tracks so you can re-transcribe, which is genuinely useful and also a reason files linger. Consider deleting the WAV files once the transcript is approved and keeping only the text.

4. Protect the endpoint

Full-disk encryption on (FileVault on macOS, BitLocker on Windows), a short screen-lock timeout, no shared user accounts, and a clear rule about whether recordings may be copied to personal drives. If the laptop is managed, meeting storage belongs in your backup and wipe policy.

5. Have a route for access and erasure requests

If someone asks for a copy of what you hold, you need to be able to find it. JesRecap has a searchable library and exports to Markdown, plain text, JSON, SRT/VTT captions, and WAV, so producing a copy is straightforward — but only if you know which machines hold recordings. Keep a simple register of who records meetings. Note that transcripts about one participant usually contain other participants too, so redaction judgement is part of the process.

6. Decide where your summaries are written

JesRecap has no cloud AI, and this is the step where that matters most. Its meeting actions work two ways, with very different consequences for your records.

Turn on AI notes on this device and the summary is generated by a model running on the same machine as the recording. No third party receives the personal data, so no processor is added to your Article 30 records for the summarising step — not even the AI you use elsewhere. For most controllers that is the shortest path through this section.

Leave it off, the default, and the buttons copy a prompt with the transcript included for you to paste into an assistant you already use. That paste is an upload, and everything you removed from the analysis comes back for that vendor: they are a processor and need the usual treatment — an Article 28 agreement, transfer mechanism, and retention terms. Alternatively, write the summary yourself.

7. Update your records and, if needed, run a DPIA

Add the local recording activity to your Article 30 records, including the licence data we hold as a processor for activation. If you are recording in a high-risk context — health, legal, employee monitoring, large scale — do the Article 35 assessment. Local processing usually makes that assessment shorter and easier to pass, not unnecessary.

What JesRecap will not do for you

It will not obtain consent, judge your lawful basis, delete files on a schedule, encrypt your disk, or stop someone emailing a transcript to the wrong person. It removes a vendor from the middle of your meeting data. The rest is process, and process is yours.

Frequently asked

Is JesRecap GDPR compliant?

No product is, on its own — compliance describes how an organisation processes data, not a piece of software. JesRecap is designed to support your compliance process: because meeting audio and transcripts stay on the device, there is no third-party processor and no international transfer for that content. Your own obligations as controller remain.

Do we need a DPA with you?

Not for meeting content — we never receive it. If you want a written agreement covering the licence data we do process (email, licence key, device fingerprint), write to support@jesrecap.com and we will talk it through with you.

Does the app work offline?

Recording and transcription run locally, so they do not need a connection once the model is on disk. Licence activation and the one-time model download do need network access. See the deployment guide for pre-seeding models.

Are voice recordings biometric data under Article 9?

It depends on what you do with them. A recording used to identify a person by their voice is treated far more strictly than a recording kept to write notes. JesRecap's speaker labelling distinguishes "You" from other speakers in a single meeting using a local model; it does not build a voiceprint identity database. If your use case edges toward identification, take advice.

Where exactly do the files live?

On macOS, ~/Library/Application Support/jesrecap/meetings/, with metadata in meetings.sqlite3. On Windows, the equivalent folder under %APPDATA%\jesrecap\. Each completed recording can hold microphone.wav, system-audio.wav, and a mixed meeting.wav.

Can a participant ask us to delete a recording?

Yes, and you can act on it directly — delete the meeting in the library, then make sure your own backup copies age out. There is no vendor to ask and no retention setting outside your control.

Fewer vendors in the analysis

JesRecap records and transcribes on the device. from €34.95 once, no subscription. macOS 14.2+ and Windows 10/11.