voice.inbox← back to home
PRIVACY POLICY

Privacy Policy

Effective: 20 August 2026 · Version 1.7 · Plain English

SHORT VERSION (THE TLDR)
  • We store your email, authentication record, memo transcripts and structured results. You can have raw transcripts and their search embeddings deleted after processing, after 7 days, or keep them.
  • Recordings are sent transiently through our backend to OpenAI for transcription. voice.inbox does not save audio in its database or object storage. After STOP, Android widget recordings are automatically sent and processed in the background without keeping the app open. Offline, expired-session and failed attempts remain in a private, account-scoped queue on your device until saving is confirmed or you recover them in the app. Android encrypts a short-lived Supabase access token solely to authenticate that work; the widget receives no refresh token. Logout or local account purge clears that credential. Account deletion started on that Android purges its queue; a deletion started elsewhere cannot remotely erase offline device storage.
  • Memo content is sent to Anthropic for AI features and to OpenAI for transcription and semantic-search embeddings. Under their default API policies, neither provider uses API content to train models. Provider retention is explained below.
  • Pending memo text may be kept temporarily on your device while you write or while processing is incomplete, so a failure does not lose it. Each draft is removed after success or when cleared. After 24 hours the app will no longer use it and deletes it while open, or the next time the app checks local storage.
  • We never sell your data. We do not run ads. We do not share with marketers.
  • You can delete your active account and associated application records at any time from inside the app. Provider retention exceptions are explained below.
  • Questions or complaints: bruno.a.g.mendes@gmail.com

01Who we are

voice.inbox is operated by Bruno Mendes, an individual developer based in Amsterdam, the Netherlands. I am the data controller for the purposes of the EU General Data Protection Regulation (GDPR) and the Dutch UAVG.

For any data protection matter, contact me directly at bruno.a.g.mendes@gmail.com.

02What this app does

voice.inbox is a personal capture tool. You record short voice memos. The transcript is sent to an AI model that extracts structured tasks, ideas, blockers and entities. You see the result on a dashboard.

To do this we need to process some personal data. This policy explains exactly what, why, for how long, and what your rights are.

03Data we collect

Account data

Content data

Usage data

What we do NOT collect

04Why we process your data (legal basis)

Under GDPR Article 6, we process your data on these legal bases:

05AI processing (important)

When you stop a voice recording, the audio is uploaded through the voice.inbox backend to the OpenAI audio transcription API. The application does not deliberately persist that audio in a database or object store; it is handled for the duration of the transcription request. The returned text becomes the memo transcript. When you press STOP on the Android widget, the app schedules this upload, transcription and memo extraction automatically in the background, even when the app interface is closed. Widget audio remains in private device storage during this process and after an offline, expired-session or failed attempt; the app removes it only after the complete memo save is confirmed, explicit discard, or account deletion started from that Android. If deletion is started elsewhere, remove any remaining local audio by clearing app storage or uninstalling voice.inbox on the Android that holds it.

To make Android's at-least-once background delivery safe, voice.inbox may temporarily cache a successful widget transcript in a private server-side idempotency record. The transcript is normally erased as soon as the corresponding memo save is confirmed and is retained for no more than 24 hours. A status tombstone containing no transcript may be retained for up to 30 days so a delayed device retry can be recognised without silently repeating a paid transcription.

We also send text derived from the transcript and summary to theOpenAI embeddings API so semantic search can find related memos. The resulting numeric embedding is stored with the memo unless your transcript-retention setting removes it.

OpenAI states that API data is not used to train its models by default. At the date of this policy, its data-controls table lists audio transcription requests with no abuse-monitoring or application-state retention, while embeddings may be retained in abuse-monitoring logs for up to 30 days. Exceptions can apply for legal or safety reasons and provider policies can change. See OpenAI's API data controls.

When you submit a memo, the transcript is sent to Anthropic (Claude API) so the AI can extract structured information. This is a core part of the service.

What happens with your data at Anthropic:

For details, see Anthropic's commercial API retention policy.

06Sub-processors

We use these third parties to run the service. They process your data on our behalf, under written agreements.

ProviderPurposeRegion
SupabaseDatabase and authenticationEU (Frankfurt)
AnthropicAI extraction, summaries, digests and answersUSA
OpenAIAudio transcription and semantic-search embeddingsUSA
VercelWeb hosting and CDNEU + global edge

07International transfers

Some processing happens outside the European Economic Area, specifically in the United States (Anthropic, OpenAI). When this happens, we rely on:

You can request a copy of these safeguards by emailing me.

08How long we keep your data

09Your rights under GDPR

You can ask us to:

  • Access your data · receive a copy of the information we hold about you.
  • Correct any inaccurate or incomplete information.
  • Delete your account and data (available directly in the app).
  • Restrict processing or object to specific uses.
  • Port your data to another service in machine-readable format (JSON).
  • Withdraw consent at any time, with no effect on past processing.

Account deletion is available in the app. Access, correction, restriction and portability requests are currently handled by email; there is no self-service export tool yet. Email bruno.a.g.mendes@gmail.com. We will respond within 30 days.

You also have the right to lodge a complaint with a data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). Outside the Netherlands, you can contact your local DPA.

10Security

This is an alpha. We do our best, but no system is 100% secure. If you discover a vulnerability, please report it privately to the email below.

11Transcript retention controls

You choose what happens to the raw text of your voice memos after the AI finishes extracting tasks, entities, and summaries. You can change this at any time in Settings > Privacy inside the app.

In all three modes, the structured data (summary, tasks, entities, ideas, status updates) is retained until you delete the memo or your account. These settings control voice.inbox database storage; temporary provider processing and retention are described in section 05.

12Operator access commitment

As the sole developer and operator, I (Bruno Mendes) have technical access to the production database. I commit to the following:

13Cookies and local device storage

We use the following browser and device storage to run the service:

We do not use these mechanisms for analytics, advertising, or cross-site tracking.

14Children

voice.inbox is not intended for users under 16. If you are under 16, please do not create an account. If we learn we collected data from someone under 16, we will delete it.

15Changes to this policy

If we make material changes, we will notify you by email at least 14 days before they take effect. The current version is always available at this URL.

16Contact

DATA CONTROLLER

Bruno Mendes
Amsterdam, Netherlands
Email: bruno.a.g.mendes@gmail.com

This policy is provided in English. A Portuguese translation may be added later. In case of conflict, the English version prevails.