How we handle data.
What Acorn collects, how it is used, how long it is retained, and how deletion requests are handled during beta. Drafted for the beta period and pending lawyer review.
1. Information we collect
Account details, API keys and partner configuration, submitted audio references, generated transcripts, billing records, support correspondence, and diagnostic events such as worker heartbeats, abuse detections, manager sign-in activity, Acorn macOS app crash and launch diagnostics, and coarse product analytics events. The macOS app does not collect session replay.
2. How we use data
To operate the coordinator, dispatch jobs, validate worker quality, prevent abuse, bill for usage, pay workers, support users, spot field crashes, understand privacy-preserving feature usage, and improve the product. The macOS app's Settings > Privacy telemetry toggle opts out of both first-party diagnostics and product analytics. We do not sell personal data.
3. Worker processing model
Audio is split into short fragments and dispatched to workers. Workers receive shard-scoped audio plus task metadata for the fragment they claim; they do not receive the full merged transcript or other workers' rows. The current pilot is not designed for HIPAA-regulated audio.
4. Retention
Acorn automatically cleans up normalized audio seven days after completion for eligible non-recoverable terminal jobs. Transcript-bearing job data has an intended operational retention target of 180 days, but no automatic age-based transcript sweeper currently enforces that target. Approved authenticated deletion requests are operator-run as job-scoped scrubs of live transcript-bearing data and normalized audio for an eligible non-recoverable terminal job, under a provisional, non-guaranteed 30-day live-system target until the process has been exercised and verified. Active legal holds block that request workflow, not the routine seven-day normalized-audio sweep. Backup copies expire on their separate schedules, downstream deliveries already in flight or delivered to third parties require separate handling, and non-content billing, security, and audit records may be retained longer when needed.
5. Your rights
Subject to applicable law, you may request access to, correction of, or deletion of personal data that Acorn controls. Requests are reviewed during beta; the provisional 30-day target is not a guarantee and does not include records Acorn must retain, active legal holds, webhook deliveries already in flight or delivered to third parties, or backup expiry. EEA and UK users may also request restriction, objection, or portability.
6. Lawful bases and transfers
Acorn generally processes data to perform a contract, operate legitimate business interests such as security and fraud prevention, and comply with legal obligations.
7. Security
HTTPS in transit, access controls for the hosted coordinator, manager authentication with passkeys, logging, and operational safeguards. See the Security page for details.
8. Contact and updates
Material changes will be reflected on this page before broad public launch. Questions: privacy@acorncompute.com.