PRIVACY POLICY
Privacy Policy
Effective: 20 August 2026 · Version 1.7 · Plain English
SHORT VERSION (THE TLDR)
- We store your email, authentication record, memo transcripts and structured results. You can have raw transcripts and their search embeddings deleted after processing, after 7 days, or keep them.
- Recordings are sent transiently through our backend to OpenAI for transcription. voice.inbox does not save audio in its database or object storage. After STOP, Android widget recordings are automatically sent and processed in the background without keeping the app open. Offline, expired-session and failed attempts remain in a private, account-scoped queue on your device until saving is confirmed or you recover them in the app. Android encrypts a short-lived Supabase access token solely to authenticate that work; the widget receives no refresh token. Logout or local account purge clears that credential. Account deletion started on that Android purges its queue; a deletion started elsewhere cannot remotely erase offline device storage.
- Memo content is sent to Anthropic for AI features and to OpenAI for transcription and semantic-search embeddings. Under their default API policies, neither provider uses API content to train models. Provider retention is explained below.
- Pending memo text may be kept temporarily on your device while you write or while processing is incomplete, so a failure does not lose it. Each draft is removed after success or when cleared. After 24 hours the app will no longer use it and deletes it while open, or the next time the app checks local storage.
- We never sell your data. We do not run ads. We do not share with marketers.
- You can delete your active account and associated application records at any time from inside the app. Provider retention exceptions are explained below.
- Questions or complaints: bruno.a.g.mendes@gmail.com
01Who we are
voice.inbox is operated by Bruno Mendes, an individual developer based in Amsterdam, the Netherlands. I am the data controller for the purposes of the EU General Data Protection Regulation (GDPR) and the Dutch UAVG.
For any data protection matter, contact me directly at bruno.a.g.mendes@gmail.com.
02What this app does
voice.inbox is a personal capture tool. You record short voice memos. The transcript is sent to an AI model that extracts structured tasks, ideas, blockers and entities. You see the result on a dashboard.
To do this we need to process some personal data. This policy explains exactly what, why, for how long, and what your rights are.
03Data we collect
Account data
- Email address · so you can log in and so we can contact you about the service.
- Password · handled and hashed by Supabase Auth. voice.inbox application code does not store it in plain text.
- Account creation date and trial expiry date.
- Android background credential · when the widget is enabled, the app stores the current short-lived Supabase access token encrypted in Android's private app storage only to authenticate background memo processing. It does not give the widget a refresh token and is cleared on logout or local account purge.
Content data
- Voice memo transcripts (text only, transcribed from your audio by the OpenAI transcription API).
- AI extractions generated from those transcripts: tasks, entities, ideas, status updates, summaries.
- Semantic-search embeddings generated from transcript and summary text so the Ask feature can find related memos.
- Pending local drafts kept temporarily in your browser or app on this device while you write or while extraction is incomplete. They become invalid 24 hours after creation and are deleted while the app is open or when it next checks local storage.
- Pending Android widget recordings stored in the app's private, account-scoped device storage. After STOP, Android automatically sends and processes them in the background without requiring the app to stay open. They remain queued until the corresponding memo is saved, you explicitly discard it, or account deletion is started from that Android. Offline, expired-session and failed attempts preserve the audio for a later background retry or in-app recovery. If you delete the account from another device, clear voice.inbox app storage or uninstall it on this Android to remove any remaining local audio.
- Widget processing cache and duplicate-prevention record · a successfully generated widget transcript may be kept temporarily in a private server-side idempotency record until the memo save is confirmed. It is normally erased immediately at that point and has a maximum 24-hour backstop. A transcript-free status tombstone may then remain for up to 30 days to prevent a delayed retry from creating a duplicate memo or an unnoticed second transcription charge.
- Tags and other structured fields generated from your memos.
Usage data
- Memo count per user (to enforce the trial limit).
- Timestamps of memos and AI API calls, plus estimated usage cost used to enforce service limits.
- Short-lived per-account request counters used to enforce distributed abuse limits. Expired counters are removed by routine maintenance and all remaining counters are deleted with the account.
- Standard technical request logs, which may include IP address and browser or device details, generated by our hosting, authentication and AI providers for security and debugging. Their retention follows the applicable provider and account settings.
What we do NOT collect
- Server-side stored audio files · voice.inbox does not save recordings in its database or object storage. Normal in-app recordings may remain temporarily in app cache for retry. Android widget recordings are automatically submitted after STOP and use a private, persistent queue on the device until confirmed memo saving, explicit discard, or account deletion started from that Android. Offline, authentication and provider failures preserve the recording for retry. Account deletion on another device cannot remotely erase its offline queue.
- Payment info · the alpha is free, there is no payment processor.
- Marketing trackers · no Google Analytics, no Meta Pixel, no third-party advertising cookies.
- Names, addresses, phone numbers, or any other personal info unless you type it inside a memo.
04Why we process your data (legal basis)
Under GDPR Article 6, we process your data on these legal bases:
- Contract (Art. 6(1)(b)) · to run the service you signed up for: store your memos, run AI extraction, show your dashboard.
- Legitimate interest (Art. 6(1)(f)) · to prevent abuse, enforce trial limits, secure the platform, and keep technical logs.
- Consent (Art. 6(1)(a)) · for the AI processing step. You consent at sign up by accepting this policy. You can withdraw consent at any time by deleting your account.
05AI processing (important)
When you stop a voice recording, the audio is uploaded through the voice.inbox backend to the OpenAI audio transcription API. The application does not deliberately persist that audio in a database or object store; it is handled for the duration of the transcription request. The returned text becomes the memo transcript. When you press STOP on the Android widget, the app schedules this upload, transcription and memo extraction automatically in the background, even when the app interface is closed. Widget audio remains in private device storage during this process and after an offline, expired-session or failed attempt; the app removes it only after the complete memo save is confirmed, explicit discard, or account deletion started from that Android. If deletion is started elsewhere, remove any remaining local audio by clearing app storage or uninstalling voice.inbox on the Android that holds it.
To make Android's at-least-once background delivery safe, voice.inbox may temporarily cache a successful widget transcript in a private server-side idempotency record. The transcript is normally erased as soon as the corresponding memo save is confirmed and is retained for no more than 24 hours. A status tombstone containing no transcript may be retained for up to 30 days so a delayed device retry can be recognised without silently repeating a paid transcription.
We also send text derived from the transcript and summary to theOpenAI embeddings API so semantic search can find related memos. The resulting numeric embedding is stored with the memo unless your transcript-retention setting removes it.
OpenAI states that API data is not used to train its models by default. At the date of this policy, its data-controls table lists audio transcription requests with no abuse-monitoring or application-state retention, while embeddings may be retained in abuse-monitoring logs for up to 30 days. Exceptions can apply for legal or safety reasons and provider policies can change. See OpenAI's API data controls.
When you submit a memo, the transcript is sent to Anthropic (Claude API) so the AI can extract structured information. This is a core part of the service.
What happens with your data at Anthropic:
- Anthropic processes the transcript and returns the structured output.
- Anthropic does not use API inputs to train its models (per Anthropic's Commercial Terms).
- Under Anthropic's standard API retention, inputs and outputs are deleted from its backend within 30 days. Anthropic lists exceptions for legal requirements, agreed retention settings, Files API use, and content retained longer to enforce its Usage Policy.
- Anthropic is a US-based company. See section 07 on international transfers.
For details, see Anthropic's commercial API retention policy.
06Sub-processors
We use these third parties to run the service. They process your data on our behalf, under written agreements.
| Provider | Purpose | Region |
|---|
| Supabase | Database and authentication | EU (Frankfurt) |
| Anthropic | AI extraction, summaries, digests and answers | USA |
| OpenAI | Audio transcription and semantic-search embeddings | USA |
| Vercel | Web hosting and CDN | EU + global edge |
07International transfers
Some processing happens outside the European Economic Area, specifically in the United States (Anthropic, OpenAI). When this happens, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- The EU-US Data Privacy Framework where applicable.
You can request a copy of these safeguards by emailing me.
08How long we keep your data
- Account and structured content · for as long as your account is active, unless you delete a memo sooner.
- Raw transcript and search embedding · according to the retention control described in section 11.
- Pending local drafts · until extraction succeeds, you clear them, or they become invalid 24 hours after creation. Physical deletion is performed while the app is open or when it next checks local storage.
- Pending Android widget recordings · in private, account-scoped device storage while automatic background upload and processing runs after STOP, until the memo save is confirmed, you explicitly discard the recording, or account deletion is started from that Android. Offline, expired-session and failed attempts stay queued so they can be retried or recovered in the app. Deletion started on another device cannot remotely purge this queue; clear app storage or uninstall voice.inbox on that Android.
- Widget transcript idempotency cache · until the corresponding memo save is confirmed (normally within seconds), with a hard maximum of 24 hours. Its transcript is then erased. A transcript-free status tombstone may remain for up to 30 days to prevent duplicate delivery and duplicate transcription charges.
- After you delete your account · the active Supabase account and associated application records are removed when the in-app deletion request succeeds. Provider-managed backups and operational logs may retain limited copies according to provider schedules and legal or security obligations.
- AI provider copies · according to the provider retention periods and exceptions described in section 05.
- Technical logs · according to hosting, authentication and AI provider account settings and policies.
- Email correspondence · for as long as reasonably needed to handle support and legal obligations.
09Your rights under GDPR
You can ask us to:
- Access your data · receive a copy of the information we hold about you.
- Correct any inaccurate or incomplete information.
- Delete your account and data (available directly in the app).
- Restrict processing or object to specific uses.
- Port your data to another service in machine-readable format (JSON).
- Withdraw consent at any time, with no effect on past processing.
Account deletion is available in the app. Access, correction, restriction and portability requests are currently handled by email; there is no self-service export tool yet. Email bruno.a.g.mendes@gmail.com. We will respond within 30 days.
You also have the right to lodge a complaint with a data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). Outside the Netherlands, you can contact your local DPA.
10Security
- All connections use HTTPS / TLS.
- Password authentication is handled by Supabase Auth and passwords are not stored in plain text by voice.inbox.
- Hosted data is protected by the security and encryption controls of our infrastructure providers.
- Database access is restricted by Row Level Security (RLS) policies, so users can only read or modify their own data.
This is an alpha. We do our best, but no system is 100% secure. If you discover a vulnerability, please report it privately to the email below.
11Transcript retention controls
You choose what happens to the raw text of your voice memos after the AI finishes extracting tasks, entities, and summaries. You can change this at any time in Settings > Privacy inside the app.
- Process and forget · the raw transcript and its semantic-search embedding are deleted from the voice.inbox database immediately after AI extraction completes. The structured output (summary, tasks, entities, ideas) is kept.
- Auto-purge after 7 days (default) · the raw transcript and its semantic-search embedding are kept for 7 days so you can review and search, then deleted from the voice.inbox database.
- Keep everything · transcripts and semantic-search embeddings are stored until you delete the memo or your account.
In all three modes, the structured data (summary, tasks, entities, ideas, status updates) is retained until you delete the memo or your account. These settings control voice.inbox database storage; temporary provider processing and retention are described in section 05.
12Operator access commitment
As the sole developer and operator, I (Bruno Mendes) have technical access to the production database. I commit to the following:
- I will never read individual user memos or transcripts unless legally required or explicitly asked by the user to debug an issue.
- I may run aggregate queries (total memo count, error rates) to monitor service health. These never expose individual content.
- If you enable Process and forget, the raw transcript is removed from the application database after extraction. It is still handled transiently by our backend and AI providers while processing the memo, as described in section 05.
13Cookies and local device storage
We use the following browser and device storage to run the service:
- Authentication cookies managed by Supabase so you stay logged in and protected pages can verify your session.
- Local preferences, such as language and onboarding or install prompt state.
- Pending memo drafts may be stored temporarily on your device while you write or while extraction is incomplete, then removed after success, when cleared, or invalidated after 24 hours and deleted while the app is open or when it next checks local storage.
- Android widget recordings are stored in a private queue tied to the active account and are automatically sent for background processing after STOP. They remain available across app restarts and offline or failed attempts until confirmed success, explicit discard, or account deletion started on that Android. Account deletion elsewhere does not remotely erase this offline queue; clear app storage or uninstall voice.inbox on the device.
- Android background access token · a short-lived Supabase access token is encrypted in the app's private Android storage only to authenticate the widget's background processing. The widget is not given a refresh token. The encrypted credential is replaced when the signed-in session refreshes and cleared on logout or local account purge; an expired credential leaves the audio queued for in-app recovery.
We do not use these mechanisms for analytics, advertising, or cross-site tracking.
14Children
voice.inbox is not intended for users under 16. If you are under 16, please do not create an account. If we learn we collected data from someone under 16, we will delete it.
15Changes to this policy
If we make material changes, we will notify you by email at least 14 days before they take effect. The current version is always available at this URL.
16Contact
This policy is provided in English. A Portuguese translation may be added later. In case of conflict, the English version prevails.