Held Privacy Policy
This policy explains how Held processes personal data when you use the Held macOS application, the Held Pro service, and related support.
1. Who is responsible
David SeyserKochgasse 3–5
1080 Vienna
Austria
david@seyser.org
David Seyser is the controller for personal data processed by Held.
2. Data Held processes
On your Mac. Held stores preferences, your local history and glossary, and credentials such as your own OpenRouter API key in macOS Keychain. Local content remains on your Mac unless a feature must transmit it to provide the service.
Bring your own key. When you use your own OpenRouter key, Held sends the content needed for the requested transcription or assistance directly to OpenRouter. Held does not receive or store that API key on its servers.
Held Pro. Held processes an installation identifier, subscription status and identifiers, an access token, provisioned-provider key information, creation and last-use timestamps, and rolling usage and cost records. Audio submitted for transcription, and text, images, or context submitted to Screen Assist, pass through Held's Cloudflare-hosted service to OpenRouter. Held does not intentionally persist that request content in its application database. Network and provider systems may process technical logs and request data under their own policies and your selected provider settings.
Support and website. If you contact Held, Held processes your email address, message, and attachments. Hosting and security systems may process IP address, user-agent, timestamps, and similar request metadata.
Accounts. When you sign in with Google, Held processes Google's stable account identifier, your verified email address and name, authentication records, installation metadata, and Held sessions needed to secure and operate the account. Held does not receive your Google password. Google Calendar access is optional and requires a separate permission.
3. Why Held processes data
Held processes data to perform its contract with you, including transcription, Screen Assist, subscriptions, usage limits, and support; to comply with legal obligations such as tax and accounting requirements; and for legitimate interests in securing, preventing abuse of, maintaining, and improving the service. Where the law requires consent, Held asks for it separately and you may withdraw it prospectively.
4. Service providers and transfers
Held uses Cloudflare for API hosting and security, OpenRouter and model providers selected through OpenRouter for AI processing, Lemon Squeezy as merchant of record for checkout, billing, tax, and subscription administration, and Apple platform services for the macOS application and Keychain. These providers may process data outside the EEA using the safeguards described in their terms and data-protection documentation.
5. Retention
Rolling usage events are kept only as needed to enforce the displayed windows and are removed after seven days. Active installation, access, and subscription records are kept while the service is active. Support correspondence is kept only as long as reasonably needed. Billing, tax, fraud-prevention, dispute, and legal records may be retained for the periods required or permitted by law. Provider and infrastructure logs follow the applicable provider retention settings and policies.
6. Deletion and your rights
You may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where applicable. Email david@seyser.org from the address associated with your purchase and include enough information to locate it. Held may verify your identity before acting.
When a deletion request is verified, Held will revoke service access and delete the provisioned provider key and personal service records without undue delay, except for narrowly limited information that must be retained for legal obligations or the establishment, exercise, or defence of legal claims. Deletion from encrypted backups may occur through the normal backup-rotation cycle; restored data remains subject to the deletion request.
Deleting Held or clearing a locally stored key removes local access but does not by itself cancel an external subscription. Cancel subscriptions through the billing portal or contact Held. You may complain to the Austrian Data Protection Authority at dsb.gv.at, or to another competent supervisory authority.
7. Security and changes
Held uses access controls, encrypted transport, macOS Keychain for local credentials, scoped service tokens, and server-side usage enforcement. No system is completely secure. Material policy changes will be communicated in the app or through another appropriate channel, and the date above will be updated.