Privacy policy
Last updated 29 August 2026.
In short
- Your meetings are stored in your account so your phone and your browser see the same thing. Delete any of them, or all of them, whenever you want. Deleted content can persist in backups for up to 30 days before it is gone from storage.
- Audio and transcript text are processed by the speech and language services that produce the transcription and the notes. Account data also goes to the processors needed for payments, email, sign-in and optional Android notifications; section 3 lists them.
- You can ask us to delete your whole account and its associated data at any time; section 7 gives the request path and retention details.
1. Who is responsible
All Voices, operated out of Switzerland, is responsible for the data described here. Write to about anything on this page.
2. What is stored
| What | Why |
|---|---|
| Email address, the name you gave, your username | To create the account, send the access link, and answer support mail |
| Your name and email address as held by Google, if you connect a Google account | Used only to recognise you when you sign in |
| Purchase records: what was bought, when, the transaction reference, the remaining hour balance and how it was spent (session start and end times, minutes billed) | To give you what you paid for, to show you your balance, and for accounting |
| Referral records: who referred a new account, when that account first used transcription or made its first purchase, rewards or reversals, and the resulting time balance | To attribute referrals, add each reward exactly once, prevent abuse, and let us explain or correct a reward |
| Your IP address at sign-up, sign-in and while recording, and a log of the requests your app makes to our servers (which operation, when, success or failure; never the content) | To limit abuse of the free trial and of the service, and to investigate a fault you report. Kept for 180 days |
| Approximate country, region and city derived at the network edge; network category and automated-review classification; app platform and version; device form factor; browser and operating-system family; interface language and time zone; and the referrer host, landing path and campaign parameters that led to sign-up | To understand how people find and use the service, measure conversion and retention, support an account, and keep automated reviews out of customer statistics and free-trial use. Account context is kept while the account exists; copies in operational event logs are kept for 180 days |
| Meeting content: audio recordings, transcripts, translations, speaker labels, your own notes, summaries, and meeting chat | This is the product. It is stored so it survives a lost phone and appears in both the app and the browser |
| An identifier for each installation or browser, and the time of the last recording session | To enforce one recording session at a time on an account |
| A random Android app-installation identifier and push-notification token, when referral notifications are enabled | To send a notification when referral time is added, keep it with the correct signed-in account, and avoid sending the same reward twice |
| Preferences: interface language, base language, text size, engine choice | To keep the app as you set it |
We never see your card details. Web and direct-Android payments are handled by Paddle, the merchant of record. In the Google Play version, Google Play handles payment. We receive the product, transaction or order reference, purchase status and opaque purchase reference needed to verify, fulfil, refund or reverse the purchase.
Diagnostic traces stay on your device. They are only shared if you export them yourself and send them to us.
We do not store a full browser user-agent string or precise location. We keep only a browser and operating-system family and coarse location at city-level precision. We do not send an IP address to a separate lookup service to produce these account details.
3. Who processes it, and where
Your account data and meeting content are stored with a cloud services provider. The following categories of processor are involved, under contract and only to deliver the service:
- Hosting, storage and delivery. A cloud services provider.
- Speech recognition. The meeting audio is streamed to a speech-to-text provider to produce the transcript, the language labels, the speaker separation and the live translation.
- Language model. Transcript text is sent to a language-model provider to produce titles, summaries, enhanced notes, answers in the meeting chat, and translations the live service did not produce.
- Payments. Paddle.com Market Limited (Paddle.com Inc. for buyers in the United States) handles web and direct-Android checkout and receives your email and billing details directly from you. Its checkout may set cookies for fraud prevention and opens only when you choose to pay. Google Play handles purchases made in the Play-distributed Android app; Google sends us purchase status and references so we can add or reverse the purchased time.
- Email delivery. An email delivery service, for the access link and support mail.
- Sign-in. Google, if you connect a Google account. Google acts as the identity provider, and the sign-in token it issues is sent back to Google for verification.
- Android notifications. Firebase Cloud Messaging, operated by Google, receives an app-instance token and the referral-reward message needed to deliver an optional Android notification. Meeting content, account names and email addresses are not included in that message.
Processing may take place outside Switzerland and the European Economic Area, under the transfer safeguards in the respective contracts. We will name any individual provider on request.
4. Other people in your meetings
A meeting recording contains other people's voices and words. You decide to record them, so you are responsible for having their consent and for telling them what happens to the recording. For that content we act on your instructions. If someone in one of your meetings asks us to delete their data, we will refer them to you and help you carry it out.
5. Legal basis
We process account and purchase data to perform the contract you entered into, and meeting content on your instruction as part of that contract. Where the law where you live requires consent for something, we ask for it and you can withdraw it.
6. Security
Everything travels over encrypted connections. Service credentials live on the server and are never present in the app or in the web page. Access links are stored in a form that cannot be turned back into the link, which is also why we can only replace a lost link, not resend it.
7. Delete your account and data
You can request deletion from the Android app under Settings → Support → Delete account, or without the app by writing from an email address associated with the account to . Say that you want your All Voices account deleted and include your username. Never send your personal access link.
After we verify the request, we delete the account credentials, linked sign-in identities, settings, meetings, audio, transcripts, notes and voice samples, and confirm completion. Personal referral links, pending referral claims, referral notifications and registered notification devices are also removed, and the account cannot earn or receive later referral rewards. Deleted content can remain in encrypted backups for up to 30 days. We retain only pseudonymized purchase and reward accounting records, and limited security or fraud records, where the law or a legitimate security need requires it; deleted-account identity is removed where it is no longer needed. Operational event logs expire after 180 days.
8. Children
All Voices is not intended for anyone under 16, and accounts should not be created for them.
