PRIVACY POLICY
Privacy Policy
Effective: 11 June 2026 · Version 1.2 · Plain English
SHORT VERSION (THE TLDR)
- We store your email, password (hashed), and the text of your voice memos. We do not store the audio. You can choose to have transcripts deleted immediately or after 7 days.
- Memo text is sent to Anthropic (US) so the AI can extract tasks. Audio is sent to OpenAI (US) for transcription and discarded right after. Neither company trains on this data.
- We never sell your data. We do not run ads. We do not share with marketers.
- You can delete your account and all your data at any time, from inside the app.
- Questions or complaints: bruno.a.g.mendes@gmail.com
01Who we are
voice.inbox is operated by Bruno Mendes, an individual developer based in Amsterdam, the Netherlands. I am the data controller for the purposes of the EU General Data Protection Regulation (GDPR) and the Dutch UAVG.
For any data protection matter, contact me directly at bruno.a.g.mendes@gmail.com.
02What this app does
voice.inbox is a personal capture tool. You record short voice memos. The transcript is sent to an AI model that extracts structured tasks, ideas, blockers and entities. You see the result on a dashboard.
To do this we need to process some personal data. This policy explains exactly what, why, for how long, and what your rights are.
03Data we collect
Account data
- Email address · so you can log in and so we can contact you about the service.
- Password · stored as a hash (we never see your actual password).
- Account creation date and trial expiry date.
Content data
- Voice memo transcripts (text only, transcribed from your audio by OpenAI Whisper or by your browser).
- AI extractions generated from those transcripts: tasks, entities, ideas, status updates, summaries.
- Optional tags you add manually.
Usage data
- Memo count per user (to enforce the trial limit).
- Timestamps of memos and dashboard views.
- Standard technical logs (IP address, browser type) kept for 14 days for security and debugging.
What we do NOT collect
- Stored audio files · your recording is used once for transcription and immediately discarded. We never keep audio.
- Payment info · the alpha is free, there is no payment processor.
- Marketing trackers · no Google Analytics, no Meta Pixel, no third-party advertising cookies.
- Names, addresses, phone numbers, or any other personal info unless you type it inside a memo.
04Why we process your data (legal basis)
Under GDPR Article 6, we process your data on these legal bases:
- Contract (Art. 6(1)(b)) · to run the service you signed up for: store your memos, run AI extraction, show your dashboard.
- Legitimate interest (Art. 6(1)(f)) · to prevent abuse, enforce trial limits, secure the platform, and keep technical logs.
- Consent (Art. 6(1)(a)) · for the AI processing step. You consent at sign up by accepting this policy. You can withdraw consent at any time by deleting your account.
05AI processing (important)
When you submit a memo, the transcript is sent to Anthropic (Claude API) so the AI can extract structured information. This is a core part of the service.
What happens with your data at Anthropic:
- Anthropic processes the transcript and returns the structured output.
- Anthropic does not use API inputs to train its models (per Anthropic's Commercial Terms).
- Anthropic retains inputs and outputs for up to 30 days for trust and safety purposes, then deletes them.
- Anthropic is a US-based company. See section 07 on international transfers.
For details, see Anthropic's Privacy Policy.
06Sub-processors
We use these third parties to run the service. They process your data on our behalf, under written agreements.
| Provider | Purpose | Region |
|---|
| Supabase | Database, authentication, file storage | EU (Frankfurt) |
| Anthropic | AI extraction and daily digest | USA |
| OpenAI | Audio transcription (Whisper API) | USA |
| Vercel | Web hosting and CDN | EU + global edge |
07International transfers
Some processing happens outside the European Economic Area, specifically in the United States (Anthropic, OpenAI). When this happens, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- The EU-US Data Privacy Framework where applicable.
You can request a copy of these safeguards by emailing me.
08How long we keep your data
- Account and content · for as long as your account is active.
- After you delete your account · 30 days, then permanent deletion from production. Backups are rotated within 90 days.
- Technical logs · 14 days.
- Email correspondence · up to 2 years (for support history and legal compliance).
09Your rights under GDPR
You can ask us to:
- Access your data · download a copy of everything we hold about you.
- Correct any inaccurate or incomplete information.
- Delete your account and data (available directly in the app).
- Restrict processing or object to specific uses.
- Port your data to another service in machine-readable format (JSON).
- Withdraw consent at any time, with no effect on past processing.
Email bruno.a.g.mendes@gmail.com. We will respond within 30 days.
You also have the right to lodge a complaint with a data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). Outside the Netherlands, you can contact your local DPA.
10Security
- All connections use HTTPS / TLS.
- Passwords are stored as bcrypt hashes, never in plain text.
- Data at rest is encrypted by Supabase using AES-256.
- Database access is restricted by Row Level Security (RLS) policies, so users can only read or modify their own data.
This is an alpha. We do our best, but no system is 100% secure. If you discover a vulnerability, please report it privately to the email below.
11Transcript retention controls
You choose what happens to the raw text of your voice memos after the AI finishes extracting tasks, entities, and summaries. You can change this at any time in Settings > Privacy inside the app.
- Process and forget · the raw transcript is permanently deleted immediately after AI extraction completes. Only the structured output (summary, tasks, entities, ideas) is kept.
- Auto-purge after 7 days (default) · transcripts are kept for 7 days so you can review and search them. After 7 days they are automatically and permanently deleted.
- Keep everything · transcripts are stored until you delete them manually or delete your account.
In all three modes, the structured data (summary, tasks, entities, ideas, status updates) is retained for as long as your account is active. Deleting your account removes everything.
12Operator access commitment
As the sole developer and operator, I (Bruno Mendes) have technical access to the production database. I commit to the following:
- I will never read individual user memos or transcripts unless legally required or explicitly asked by the user to debug an issue.
- I may run aggregate queries (total memo count, error rates) to monitor service health. These never expose individual content.
- If you enable Process and forget, the raw transcript is deleted server-side before I could ever see it.
13Cookies
We only use cookies that are strictly necessary to run the service:
- An authentication cookie so you stay logged in.
- A CSRF token to protect against cross-site request forgery.
We do not use analytics, advertising, or tracking cookies. Because of this, we do not show a cookie banner under EU rules (essential cookies do not require consent).
14Children
voice.inbox is not intended for users under 16. If you are under 16, please do not create an account. If we learn we collected data from someone under 16, we will delete it.
15Changes to this policy
If we make material changes, we will notify you by email at least 14 days before they take effect. The current version is always available at this URL.
16Contact
This policy is provided in English. A Portuguese translation may be added later. In case of conflict, the English version prevails.