Sidecallby Candlefish

Sidecall

Privacy policy

How Sidecall and Candlefish’s default hosted service handle calls.

Last updated 30 September 2026.

Information we handle

Sidecall stores recordings, transcripts, meeting titles, participant names, dates, notes, questions, coaching, summaries, and follow-ups. People and organization pages are derived from calls you can access. Imported recordings include source links and processing details.

With Sign in with Apple, the service receives your Apple account identifier and the name and email Apple makes available. Your email may be an Apple private relay address. The service stores your profile, organization, room memberships, device description, and sign-in activity.

The hosted service and AI

Candlefish stores recordings and call information received by its connected service. The Mac app can also capture locally. Its local recording is distinct from the information sent to the service.

Live transcription, coaching, ordinary post-call transcription and summaries, and answers about saved or shared calls run on machines Candlefish controls. A question about a saved or shared call sends selected transcript lines, the question, and relevant context to those machines. Sidecall shows an unavailable result if they cannot answer. Earlier service versions could send saved-call questions to Anthropic or Google Gemini. Other connected context may come from meeting, relationship, email, or knowledge services.

Adding a call to Suite makes another copy available to people with Suite access. It can include audio, title, date, linked people or organizations, transcript, summary, chapters, and meeting moments. Private notes, preparation, and coaching stay in Sidecall. Company names and domains can be sent to Exa for public company news. Cloudflare handles the public connection. Candlefish backs up call media and imported source files to Cloudflare R2.

The service keeps operational logs to diagnose failures. The app sends launch timing, and the service keeps aggregate counts of recording and sharing actions.

Who can access a call

New calls recorded in Sidecall are personal by default and available to their owner and service administrators. Choosing a room gives its members access. Adding a person’s name to a personal recording does not give that person access.

Older recordings may retain room or matched-participant access. Imports keep their existing access settings. People, organizations, and search results follow the calls the signed-in account can access.

A share link is optional. Anyone who has it can open the shared content without signing in and can forward the link. Private notes, preparation, and coaching are excluded unless you choose to include them. Review the content before creating a link. Revoking a link stops later access through it, but cannot remove copies someone already saved. A link does not change room access or separate Suite settings.

Correcting a displayed name does not change access to a recording. A clip sent through the iPhone share sheet goes to the destination you choose.

Voice samples

If you add your voice, the phone uploads a short recording. The service uses it to create a voice profile, then removes the temporary enrollment recording. The profile stores a numerical representation of the voice, its name, and sample-quality information so the service can try to recognize it later.

Forget removes the current voice profile. Names already saved on recordings remain, and recovery copies may retain earlier profiles. Voice recognition can make mistakes.

Imported media

For a direct media link, the service downloads and processes the source, saves the resulting audio recording, and removes temporary download files. The call retains its source link and import date.

For a public YouTube link, the service downloads the video, creates audio for processing, and retains imported media and the resulting transcript and notes. Public captions may also be stored. Timestamps and speaker labels can be estimates. The original remains on YouTube under its own terms and privacy practices.

What stays on the phone

The iPhone app keeps its service address and optional connection settings on the phone. Its sign-in token is stored in the iPhone keychain. During recording, the phone keeps audio for recovery. A failed upload may remain queued locally until it succeeds or local data is cleared.

Signing out attempts to revoke the service token and clears the visible account and call cache. The phone may still hold audio for the same owner, including uploads waiting to send. Connection settings retain the service address and Cloudflare Access credentials until they are removed there. Recordings on the service, exports, and shared copies remain.

iOS asks for microphone access when you first start a recording. Sidecall uses it during recording or voice enrollment. The iPhone app does not directly capture another app’s internal audio or cellular-call audio.

The Mac app can capture microphone and system audio locally. Native capture uses AES-GCM encryption for local artifacts, with a key held in the Mac’s device-only keychain. That key is not used for connected service storage or Cloudflare R2 backups.

Deletion and recovery copies

Deleting a call removes it from the active library and search. The service keeps a recoverable archive of the recording and related records.

Deleting an account begins removal of its sign-in records, profile, voice profiles, and calls it owns from Sidecall and storage Candlefish manages. The app tracks the request and shows when it is complete. Active storage, snapshots, backups, share storage, and Suite exports can take longer to clear. Candlefish marks the request complete only after checking the stores it controls. Calls owned by other people and copies saved by recipients remain.

Other service operators

Sidecall can connect to a separate compatible service. Its operator controls storage, access, processors, integrations, and retention. Ask that operator about its practices before sending call information.

Children

Sidecall is not directed at children under 13.

Changes and contact

When this page changes, its date is updated. For privacy questions, write to team@candlefish.ai. For app help, see support.