Privacy Policy
Effective Date: March 26, 2026 · Last Updated: March 26, 2026
1. Introduction
This Privacy Policy explains how VoxPrompt (“we”, “us”, “our”) collects, uses, stores, and protects your personal data when you use our desktop application and related services (collectively, the “Service”).
VoxPrompt is a speech-to-text desktop application that records audio via your microphone, sends it to a transcription service, and returns the transcribed text. We are committed to protecting your privacy and processing your data in compliance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable data protection laws of the Republic of Cyprus.
This Privacy Policy should be read together with our Terms of Service, which govern your use of the Service.
By using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
The data controller responsible for your personal data is:
Aleksandr Popov
Limassol, 3012, Cyprus
Contact: [email protected]
For any questions or requests regarding your personal data, please contact us at the email address above.
3. What Data We Collect
We collect and process the following categories of personal data:
3.1 Account Data
If you create an account or authenticate with a license key:
- Email address — used for authentication (magic link login) and account identification
- Apple User ID — if you sign in via Sign in with Apple (App Store version only)
- License key — a unique key (format: VP-XXXX-XXXX-XXXX-XXXX) linked to your account
3.2 Device Data
- Device identifier — a locally generated, pseudonymous identifier (format:
device-{timestamp}-{process_id}), used solely for free-tier usage tracking. This identifier does not encode your name or any hardware serial numbers.
3.3 Server Log Data
When your device connects to our servers, we may process:
- IP address — for security, abuse prevention, and rate limiting
- Timestamps — when the request was made
- User-agent — app version and platform/architecture
- Request metadata — endpoint accessed, response status code
Server logs are retained for 14 days and used solely for security monitoring and debugging. They are not linked to your account or used for tracking.
3.4 Usage Data
- Daily word count — the number of words transcribed per day, tracked per user account or device identifier
- Daily request count — the number of transcription requests per day
- License key last-used timestamp — when your license key was last used for authentication
3.5 Subscription & Payment Data
If you subscribe to VoxPrompt Pro, payment is processed by Paddle.com Market Ltd.(“Paddle”), our Merchant of Record. We do not collect or store your credit card number, bank account details, or billing address. Paddle provides us with:
- Subscription status (active, canceled, expired)
- Subscription plan (monthly or yearly)
- Billing period dates
- Paddle subscription identifier
For information on how Paddle processes your payment data, please see Paddle's Privacy Policy.
3.6 Audio Data
When you use the Service to transcribe speech:
- Your audio is recorded locally on your device
- The audio is transmitted to our transcription service for processing
- We do not store, retain, or log your audio recordings on our servers. Audio is processed in real time and discarded immediately after transcription.
- The transcribed text is returned to your device and is not stored on our servers
3.7 Transcription History (Local Only)
If you enable the optional History feature in the app:
- Transcription text, timestamp, duration, and language are stored locally on your device in a SQLite database
- This data is never transmitted to our servers
- History is disabled by default. You can enable or disable it at any time in Settings
3.8 App Settings (Local Only)
Your preferences (hotkey, language, recording mode, etc.) are stored locally on your device and are never transmitted to our servers.
3.9 Error Reporting Data
We may use Sentry for error monitoring of our backend infrastructure. When enabled:
- Crash reports, error traces, and performance metrics are collected
- We configure Sentry to avoid collecting direct personal identifiers
- No audio, transcription text, or email addresses are included in error reports
- Technical data such as IP addresses may be processed transiently by Sentry as part of error reporting
4. How We Use Your Data
We process your personal data for the following purposes and lawful bases:
| Purpose | Data Used | Lawful Basis (GDPR) |
|---|---|---|
| Provide the transcription service | Audio (transient), device ID | Art. 6(1)(b) — Contract performance |
| Authenticate your account | Email, license key, Apple User ID | Art. 6(1)(b) — Contract performance |
| Send login emails (magic links) | Email address | Art. 6(1)(b) — Contract performance |
| Manage your subscription | Subscription data from Paddle | Art. 6(1)(b) — Contract performance |
| Enforce free-tier usage limits | Device ID, daily word/request count | Art. 6(1)(f) — Legitimate interest (service integrity) |
| Prevent abuse and enforce rate limits | IP address (server logs), request frequency | Art. 6(1)(f) — Legitimate interest (security) |
| Monitor and fix errors in our infrastructure | Error traces, technical metadata | Art. 6(1)(f) — Legitimate interest (service reliability) |
| Deliver software updates | App version, platform/architecture | Art. 6(1)(b) — Contract performance |
| Comply with tax and legal obligations | Subscription records | Art. 6(1)(c) — Legal obligation |
Regarding legitimate interest (Art. 6(1)(f)): Where we rely on legitimate interest, we have assessed that our interest in maintaining service integrity, security, and reliability does not override your rights and freedoms. For free-tier usage limit enforcement, this processing is necessary to prevent abuse and ensure fair access to the Service — without it, we would be unable to offer a free tier. You may object to processing based on legitimate interest (see Section 9).
Automated Processing
We use automated rules to enforce daily usage limits (e.g., blocking recording when the free-tier word limit is reached) and to prevent abuse (e.g., rate limiting authentication requests). These measures are necessary for operating the Service and do not produce legal or similarly significant effects on you within the meaning of GDPR Art. 22.
We do not use your data for:
- Advertising or marketing (we send no marketing emails)
- Profiling or behavioral analysis
- Selling or renting to third parties
- Training AI or machine learning models (we instruct our sub-processors not to use your data for model training)
5. Audio & Voice Data
We want to be especially clear about how we handle audio:
- Voice recordings are personal data under GDPR. We acknowledge this.
- Audio is processed solely for the purpose of transcription — we do not analyze voice for biometric identification, speaker recognition, emotional analysis, or any purpose other than converting speech to text.
- Audio is transmitted over an encrypted connection (TLS) to our transcription provider, processed, and immediately discarded. No audio is stored at any point in our infrastructure.
- Transcription results are returned to your device and are not retained on our servers.
- If you enable local History, transcription text (not audio) is stored on your device only.
6. Third-Party Service Providers
We share personal data with the following service providers (“sub-processors”) only as necessary to operate the Service:
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Our own Whisper infrastructure (primary) | Speech-to-text transcription | Audio file (transient, discarded after processing) | EU (Germany) |
| OpenAI (fallback only) | Speech-to-text transcription | Audio file, language preference (transient) | United States |
| Paddle.com Market Ltd. | Payment processing (Merchant of Record) | Email, subscription plan, billing metadata | United Kingdom / EU |
| Brevo (Sendinblue) | Transactional email delivery | Email address, magic link URL | EU |
| Sentry (if enabled) | Error monitoring | Error traces, technical metadata (may include IP) | EU / United States |
| Hetzner | Server infrastructure hosting | All server-side data as described in this policy | EU (Germany) |
Each provider processes data solely on our instructions and is bound by data processing agreements. We do not sell, rent, or trade your personal data.
Regarding OpenAI (Fallback Transcription)
OpenAI is used only as a fallback when our primary transcription service is unavailable. When your audio is processed by OpenAI:
- It is governed by OpenAI's API data usage policy, which states that API inputs and outputs are not used to train their models
- Audio is processed and discarded; it is not retained by OpenAI beyond the processing request
7. International Data Transfers
Our primary infrastructure and database are located in the European Union (Germany).
In limited circumstances, personal data may be transferred outside the EU/EEA:
- OpenAI (United States) — used as a fallback transcription provider only. We rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) and/or adequacy decisions where applicable. See OpenAI's data processing terms for details on their transfer mechanisms.
- Sentry (United States) — if error monitoring is enabled. Technical metadata may be transferred; we configure Sentry to minimize personal data collection. See Sentry's sub-processors list for their safeguards.
Where data is transferred outside the EEA, we ensure appropriate safeguards are in place as required by GDPR Chapter V, including Standard Contractual Clauses where applicable.
8. Data Retention
We retain your personal data only for as long as necessary for the purposes described in this policy:
| Data | Retention Period |
|---|---|
| Account data (email, Apple User ID) | Until you request account deletion |
| License keys | Until deactivated or account deletion |
| Usage data (daily word/request counts) | 30 days — automatically deleted |
| Server logs (IP, user-agent, timestamps) | 14 days |
| Subscription records | Duration of subscription + as required by tax law (up to 7 years for financial records) |
| Audio recordings | Not retained — processed in real time and immediately discarded |
| Transcription text (server-side) | Not retained — returned to your device and not stored |
| Local transcription history | Stored on your device until you delete it or disable History |
| Local app settings & secrets | Stored on your device until you uninstall the app |
| JWT authentication tokens | Expire after 7 days |
| Magic link tokens | Expire after 15 minutes |
Data held by our sub-processors (Paddle, Brevo, Sentry, OpenAI) is subject to their own retention policies. We minimize the data we share with each provider and contractually require them to process it only for the specified purposes.
When you delete your account, we remove your personal data from our active systems. Some data may be retained in encrypted backups for a limited period (up to 30 days) before being permanently deleted.
9. Your Rights Under GDPR
As a data subject, you have the following rights under GDPR. To exercise any of these rights, contact us at [email protected].
- Right of Access (Art. 15) — You can request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16) — You can request correction of inaccurate or incomplete personal data.
- Right to Erasure(Art. 17) — You can request deletion of your personal data (“right to be forgotten”). We will delete your account and all associated data, except where retention is required by law.
- Right to Restriction of Processing (Art. 18) — You can request that we restrict processing of your data in certain circumstances (e.g., while we verify accuracy of data you have contested).
- Right to Data Portability (Art. 20) — You can request your personal data in a structured, commonly used, machine-readable format (JSON).
- Right to Object (Art. 21) — You can object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds.
- Right Related to Automated Decision-Making (Art. 22) — We do not make automated decisions that produce legal or similarly significant effects on you.
- Right to Withdraw Consent (Art. 7(3)) — Where processing is based on consent, you can withdraw consent at any time. This does not affect the lawfulness of processing before withdrawal.
Response timeframe: We will respond to your request within 30 days. If the request is complex, we may extend this by up to 60 additional days, with notice.
Supervisory authority: You have the right to lodge a complaint with a data protection authority. Our lead supervisory authority is:
Office of the Commissioner for the Protection of Personal Data
1 Iasonos Street, 1082 Nicosia, Cyprus
Website: www.dataprotection.gov.cy
You may also lodge a complaint with the supervisory authority in your EU/EEA member state of residence.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption in transit: All data transmitted between your device and our servers uses TLS (HTTPS)
- Encryption at rest: Database and backups are encrypted
- Access controls: Backend administrative access is restricted and password-protected
- Data minimization: We collect only the data necessary to provide the Service
- Pseudonymization: Free-tier device identifiers are pseudonymous and cannot identify you personally
- Rate limiting: Authentication endpoints are rate-limited to prevent brute-force attacks
- Automatic cleanup: Usage data older than 30 days is automatically deleted
In the event of a personal data breach that is likely to pose a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with GDPR Art. 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected individuals without undue delay, in accordance with GDPR Art. 34.
11. Children's Privacy
The Service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided us with personal data, please contact us at [email protected], and we will promptly delete such data.
12. Cookies and Tracking
The VoxPrompt desktop application does not use cookies or web-based tracking technologies.
Our internal administrative panel (not accessible to end users) uses a session cookie solely for administrator authentication. This is strictly necessary for system administration and does not involve end-user tracking.
We do not use any analytics, advertising, or third-party tracking technologies in the desktop application or on our website.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the “Last Updated” date at the top of this page
- Notify you via email (if you have an account) or through the application
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
14. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
Email: [email protected]
Website: https://voxprompt.app