DRAFT — not legal advice. This document was generated from the app's actual data practices as found in the codebase. Before publishing you MUST:
- Fill every
[BRACKETED]placeholder.- Have it reviewed by a qualified privacy lawyer for your target markets.
- Make sure the app's real behavior matches every claim here (see the "Known gaps" notes — some statements are only true after you ship the fixes listed in the app-store review).
Last updated: [EFFECTIVE DATE — e.g. 2026-05-29] Applies to: the Voceris mobile application ("App") and related backend services.
Voceris ("Voceris", "we", "us", "our") provides a voice‑training application that records your voice, analyzes vocal characteristics, and returns a "charisma" score with personalized exercises.
If you have questions about this policy or your data, contact us at the address above.
This summary is for convenience only; the full policy below governs.
Note on biometric data: Because we create a voice profile used to help verify that recordings come from the same speaker, this data may qualify as biometric information under laws such as the EU/UK GDPR (Article 9), the Illinois Biometric Information Privacy Act (BIPA), Texas CUBI, and Washington law. We process it only with your consent and only to provide the features described above. We do not use it to identify you to third parties.
We do not knowingly collect more categories than those listed above. If we add new processing, we will update this policy.
| Purpose | Examples |
|---|---|
| Provide the core service | Record audio, transcribe it, analyze it, score it, generate your training plan and exercises, show your history. |
| Track progress & verify speaker | Maintain your voice baseline and run the same‑speaker check. |
| Subscriptions | Unlock Pro features, sync entitlements, enforce free‑trial and daily limits. |
| Notifications | Send the practice reminders you enable. |
| Improve & secure the App | Analytics, session replay, crash diagnostics, abuse/rate‑limit protection. |
| Marketing attribution | Measure ad performance and install/purchase attribution (only with your tracking consent where required). |
| Legal & compliance | Respond to legal requests, enforce our Terms, prevent fraud. |
We do not use your voice recordings to train third‑party public AI models for purposes unrelated to providing you the service, and we instruct our AI providers accordingly to the extent their terms allow. [CONFIRM THIS MATCHES YOUR OPENROUTER / MODEL‑PROVIDER CONTRACTS BEFORE PUBLISHING.]
Where the GDPR or UK GDPR applies, we rely on:
For special‑category (biometric) data, our legal basis is your explicit consent (GDPR Art. 9(2)(a)).
We share data only with service providers that help us run Voceris, and only as needed. Key recipients:
| Recipient | Role | Data involved |
|---|---|---|
| Apple | App distribution, in‑app purchases, SKAdNetwork attribution | Purchase/subscription data, attribution signals |
| Google / Firebase (Google LLC) | Anonymous authentication, analytics, crash reporting | Identifiers, usage events, crash data |
| RevenueCat | Subscription management | Subscriber ID, subscription status, purchase events |
| OpenRouter | AI gateway that routes your audio/transcript to AI models | Voice recording, transcript, analysis context |
| AI model providers via OpenRouter — currently Google (Gemini) for acoustic analysis and Xiaomi (MiMo) for transcription | Generate transcript and acoustic analysis | Voice recording and transcript |
| Cloudflare (R2) | Stores your audio recordings | Voice recordings |
| Mixpanel | Product analytics + sampled session replay | Usage events, (masked) session replays, identifiers |
| AppsFlyer | Marketing attribution | Install/purchase/attribution events, device identifiers |
| [HOSTING PROVIDER — e.g. Fly.io] / [DATABASE — MongoDB] | App hosting and database | All data needed to run the service |
We may also disclose data: (a) to comply with law or valid legal process; (b) to protect our rights, users, or the public; and (c) in connection with a merger, acquisition, or sale of assets (you will be notified).
Important — AI processing of your voice: to analyze a recording, the audio file and a transcript of your speech are transmitted to OpenRouter and processed by the third‑party AI models named above. These providers may process the data outside your country. Do not record sensitive personal information you do not want processed in this way.
We do not sell your personal data for monetary consideration.
We and our providers may process your data in the United States and other countries that may not provide the same level of data protection as your home country. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. Contact us for more information. [CONFIRM TRANSFER MECHANISMS WITH COUNSEL — note that audio may be routed to AI models operated in multiple jurisdictions.]
When you delete your account, we delete or de‑identify your personal data as described in Section 9.
Known gap (fix before publishing): the current build's "Delete My Data" control and the server deletion routine do not yet remove all of the above (stored audio files and the voice baseline are not deleted, and the in‑app button does not call the deletion endpoint). This section must not be published until the App actually performs a complete deletion.
Depending on where you live, you may have the right to:
To exercise any right, contact [privacy@trainmyvoice.app]. We will verify your request and respond within the time required by law. We will not discriminate against you for exercising your rights.
If you are a resident of California or another US state with a comprehensive privacy law, you have the rights to know, access, delete, and correct your personal information, and to opt out of "sales" and "sharing" of personal information for cross‑context behavioral advertising.
[ADD any state‑specific "categories collected / disclosed" table your counsel requires, e.g. for the CCPA/CPRA "categories" disclosure.]
The App is not directed to children and is intended for users aged [17]+. We do not knowingly collect personal data from children under [13 / 16, per your markets]. If you believe a child has provided us data, contact us and we will delete it. [If you ever target minors, you must add COPPA / age‑appropriate‑design content.]
We use reasonable technical and organizational measures to protect your data, including encryption in transit and access controls on our systems.
Known gap (fix before relying on this section): stored audio recordings are currently served from a publicly reachable URL rather than via authenticated, short‑lived links. Restrict access (private storage + signed URLs) before publishing this policy. No method of transmission or storage is 100% secure.
We may update this policy from time to time. We will revise the "Last updated" date and, for material changes, provide a more prominent notice in the App. Continued use after an update means you accept the revised policy.
[LEGAL ENTITY NAME] [COMPANY ADDRESS] Email: [privacy@trainmyvoice.app]
This policy is a working draft generated from the Voceris codebase and is provided for development purposes only. It is not legal advice.