Voceris — Privacy Policy

DRAFT — not legal advice. This document was generated from the app's actual data practices as found in the codebase. Before publishing you MUST:

  1. Fill every [BRACKETED] placeholder.
  2. Have it reviewed by a qualified privacy lawyer for your target markets.
  3. Make sure the app's real behavior matches every claim here (see the "Known gaps" notes — some statements are only true after you ship the fixes listed in the app-store review).

Last updated: [EFFECTIVE DATE — e.g. 2026-05-29] Applies to: the Voceris mobile application ("App") and related backend services.


1. Who we are

Voceris ("Voceris", "we", "us", "our") provides a voice‑training application that records your voice, analyzes vocal characteristics, and returns a "charisma" score with personalized exercises.

If you have questions about this policy or your data, contact us at the address above.


2. Summary (the short version)

This summary is for convenience only; the full policy below governs.


3. The data we collect

3.1 Voice recordings and derived voice data

Note on biometric data: Because we create a voice profile used to help verify that recordings come from the same speaker, this data may qualify as biometric information under laws such as the EU/UK GDPR (Article 9), the Illinois Biometric Information Privacy Act (BIPA), Texas CUBI, and Washington law. We process it only with your consent and only to provide the features described above. We do not use it to identify you to third parties.

3.2 Profile and preferences

3.3 Account and device identifiers

3.4 Subscription and purchase data

3.5 Usage, analytics, attribution, and diagnostics

We do not knowingly collect more categories than those listed above. If we add new processing, we will update this policy.


4. How we use your data (purposes)

Purpose Examples
Provide the core service Record audio, transcribe it, analyze it, score it, generate your training plan and exercises, show your history.
Track progress & verify speaker Maintain your voice baseline and run the same‑speaker check.
Subscriptions Unlock Pro features, sync entitlements, enforce free‑trial and daily limits.
Notifications Send the practice reminders you enable.
Improve & secure the App Analytics, session replay, crash diagnostics, abuse/rate‑limit protection.
Marketing attribution Measure ad performance and install/purchase attribution (only with your tracking consent where required).
Legal & compliance Respond to legal requests, enforce our Terms, prevent fraud.

We do not use your voice recordings to train third‑party public AI models for purposes unrelated to providing you the service, and we instruct our AI providers accordingly to the extent their terms allow. [CONFIRM THIS MATCHES YOUR OPENROUTER / MODEL‑PROVIDER CONTRACTS BEFORE PUBLISHING.]


5. Legal bases (EEA / UK users)

Where the GDPR or UK GDPR applies, we rely on:

For special‑category (biometric) data, our legal basis is your explicit consent (GDPR Art. 9(2)(a)).


6. Who we share data with (sub‑processors and recipients)

We share data only with service providers that help us run Voceris, and only as needed. Key recipients:

Recipient Role Data involved
Apple App distribution, in‑app purchases, SKAdNetwork attribution Purchase/subscription data, attribution signals
Google / Firebase (Google LLC) Anonymous authentication, analytics, crash reporting Identifiers, usage events, crash data
RevenueCat Subscription management Subscriber ID, subscription status, purchase events
OpenRouter AI gateway that routes your audio/transcript to AI models Voice recording, transcript, analysis context
AI model providers via OpenRouter — currently Google (Gemini) for acoustic analysis and Xiaomi (MiMo) for transcription Generate transcript and acoustic analysis Voice recording and transcript
Cloudflare (R2) Stores your audio recordings Voice recordings
Mixpanel Product analytics + sampled session replay Usage events, (masked) session replays, identifiers
AppsFlyer Marketing attribution Install/purchase/attribution events, device identifiers
[HOSTING PROVIDER — e.g. Fly.io] / [DATABASE — MongoDB] App hosting and database All data needed to run the service

We may also disclose data: (a) to comply with law or valid legal process; (b) to protect our rights, users, or the public; and (c) in connection with a merger, acquisition, or sale of assets (you will be notified).

Important — AI processing of your voice: to analyze a recording, the audio file and a transcript of your speech are transmitted to OpenRouter and processed by the third‑party AI models named above. These providers may process the data outside your country. Do not record sensitive personal information you do not want processed in this way.

We do not sell your personal data for monetary consideration.


7. International data transfers

We and our providers may process your data in the United States and other countries that may not provide the same level of data protection as your home country. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. Contact us for more information. [CONFIRM TRANSFER MECHANISMS WITH COUNSEL — note that audio may be routed to AI models operated in multiple jurisdictions.]


8. How long we keep data

When you delete your account, we delete or de‑identify your personal data as described in Section 9.


9. Deleting your data and your choices


10. Your privacy rights

Depending on where you live, you may have the right to:

To exercise any right, contact [privacy@trainmyvoice.app]. We will verify your request and respond within the time required by law. We will not discriminate against you for exercising your rights.


11. US state privacy rights (California and others)

If you are a resident of California or another US state with a comprehensive privacy law, you have the rights to know, access, delete, and correct your personal information, and to opt out of "sales" and "sharing" of personal information for cross‑context behavioral advertising.

[ADD any state‑specific "categories collected / disclosed" table your counsel requires, e.g. for the CCPA/CPRA "categories" disclosure.]


12. Children's privacy

The App is not directed to children and is intended for users aged [17]+. We do not knowingly collect personal data from children under [13 / 16, per your markets]. If you believe a child has provided us data, contact us and we will delete it. [If you ever target minors, you must add COPPA / age‑appropriate‑design content.]


13. Security

We use reasonable technical and organizational measures to protect your data, including encryption in transit and access controls on our systems.

Known gap (fix before relying on this section): stored audio recordings are currently served from a publicly reachable URL rather than via authenticated, short‑lived links. Restrict access (private storage + signed URLs) before publishing this policy. No method of transmission or storage is 100% secure.


14. Changes to this policy

We may update this policy from time to time. We will revise the "Last updated" date and, for material changes, provide a more prominent notice in the App. Continued use after an update means you accept the revised policy.


15. Contact

[LEGAL ENTITY NAME] [COMPANY ADDRESS] Email: [privacy@trainmyvoice.app]


This policy is a working draft generated from the Voceris codebase and is provided for development purposes only. It is not legal advice.