Privacy Policy
What VocalStack collects about you and the people you record, why, who processes it, how long it is kept, and the rights you have over it.
1. Overview
VocalStack processes your account details, your audio and transcripts, your billing records and, for broadcasts, some data about your listeners. We use it to run the Service, not to advertise. The company named below is the controller.
This policy explains how [company legal name], [registered address] (“VocalStack”, “we”) handles personal data when you use the VocalStack website, the Dashboard at app.vocalstack.com, the API, the SDKs, the MCP server and the broadcast pages (the “Service”). VocalStack is the controller of that data unless this policy says otherwise. [EU/UK representative and contact details, if one is appointed]
For most of what you upload, you decide what is recorded and who is in it. Where you transcribe other people's speech, you are responsible under data protection and recording laws for telling them and, where needed, obtaining their consent; see section 15 of the Terms of Service. We process that content on your instructions to provide the Service.
Questions and requests: support@vocalstack.com.
2. What we collect
Your email and name from sign-in; the audio you provide and everything made from it; voice samples if you clone a voice; usage and billing records; listener device identifiers and addresses for broadcasts; API key metadata. No card numbers, ever.
| Data | Where it comes from |
|---|---|
| Account: email address, display name, identity provider user id, time of last sign-in, organisation memberships and roles | Sign-in through WorkOS; what you enter in the Dashboard |
| Content: audio from your microphone, uploaded files, links and streams; transcripts, speaker names, corrections, translations, spoken translations, titles and summaries; exports; the reference scripts you add; the names you give transcriptions and broadcasts | You, and the people you record |
| Voice samples and the cloned voice made from them (biometric data) | You, only when you choose to clone a voice |
| Billing: plan, balance, ledger of credits and charges, audio seconds billed per transcription, subscription status, checkout and consent records (time, hashed network address, terms version, who consented) | Your use of the Service and the Polar checkout |
| Usage and security: API calls per minute and day by account and key, failed sign-ins grouped by hashed address, rate-limit counters, staff audit entries | Your use of the Service |
| Listeners of a broadcast: a device identifier, the network address, a device description, the languages listened to and when the device joined; a push token if the device opts into notifications | Devices that open a broadcast page or install the app |
| API keys: name, prefix, scopes, creator, last used; the secret is stored only as a salted hash. RTMP stream keys | You, when you create them |
| Support: the content of emails you send us | You |
We do not collect payment card numbers or bank details; Polar, our merchant of record, holds them. We do not buy data about you from third parties and we do not run advertising or behavioural analytics on the website or in the Dashboard.
3. Why we use it and on what legal basis
To provide and bill the Service (contract), with your consent for voice cloning and optional emails, and in our legitimate interest to keep the Service secure and improve it.
| Purpose | Legal basis |
|---|---|
| Creating and operating your account, transcribing, translating, summarising, reading aloud, broadcasting and sharing on your instructions, exporting | Performance of our contract with you (Terms of Service) |
| Billing: metering audio, keeping the ledger, taking payments through Polar, automatic top-ups and subscriptions you have set up, sending receipts and billing notices | Performance of the contract; legal obligation (accounting and tax records) |
| Recording your consents at checkout and for automatic top-up, with the time, a hashed address and the terms version | Legal obligation and legitimate interest in being able to prove the consent |
| Cloning a voice from a sample | Your explicit consent, which you can withdraw at any time by deleting the voice |
| Showing a broadcast host which devices are listening, in which language | Legitimate interest of the host in running their event; the listener is told on the broadcast page |
| Security: rate limiting, detecting abuse and failed sign-ins, auditing staff actions, hashing addresses | Legitimate interest in a secure Service; legal obligation |
| Service emails: low balance, out of credit, payment and subscription events, rate changes, retention warnings, changes to the terms | Performance of the contract; these are not marketing and cannot be opted out of while you have an account |
| Newsletter and product updates, where offered | Consent; unsubscribe at any time |
| Answering support requests | Performance of the contract; legitimate interest |
| Improving the Service: aggregate usage statistics, error analysis | Legitimate interest. We do not use your audio, transcripts or voices to train models |
Where we rely on legitimate interest we have balanced it against your interests and rights; you may object (section 10).
4. Voice samples
A cloned voice is biometric data. We only make one when you ask, with the speaker's explicit consent, we use it only to read that speaker's lines aloud, and you can delete it at any time.
When you clone a voice, the recording you provide and the voice model derived from it are stored in our media storage and used only to synthesise speech for the transcriptions you assign the voice to. The Dashboard records that the speaker's permission stands; withdrawing it, or deleting the voice, deletes the sample and the model. We never use voice samples for identification, for training or for anything other than the speech you ask for.
You must have the speaker's explicit consent before cloning their voice. If you are the speaker, your consent is given when you record the sample. Voices on Pay as you go are deleted automatically after 7 days; see section 7.
5. Who processes your data
We use a small set of providers to sign you in, take payments, host the Service, store media, send email and run some AI models. Speech recognition and voice synthesis run on our own servers; only text goes to AI model providers.
| Provider | What it does | Data it processes |
|---|---|---|
| WorkOS, Inc. (US) | Sign-in and identity (AuthKit) | Email, name, sign-in events, the network address of a sign-in for its bot and risk checks |
| Polar Software Inc. (US) | Merchant of record: checkout, payment methods, tax, invoices, refunds, customer portal | Name, email, billing address, payment details, purchase history. Polar is an independent controller for the sale itself |
| Fly.io, Inc. (US) | Hosting of the API, the Dashboard, the transcription engines and the broadcast pages | All data in transit and in process, including audio and transcripts, in the regions listed in section 8 |
| Tigris Data, Inc. (US) | Object storage for audio, exports and voice samples | Audio, exports, voice samples and voice models |
| Neon, Inc. (US) | The database | Account, content metadata, transcripts, billing and usage records |
| Resend, Inc. (US) | Transactional email | Email address, the content of service emails |
| OpenAI, L.L.C. (US) | AI model provider for translation, titles and summaries, and some corrections | Transcript text (never audio, never your identity) |
| Fireworks AI, Inc. (US) | AI model provider for live corrections of transcript lines | Short excerpts of transcript text (never audio, never your identity) |
| Google LLC (Firebase Cloud Messaging) and Apple Inc. (APNs) | Push notifications to devices that opted in | Push token and the notification text |
Speech recognition, speaker recognition, speaker naming and speech synthesis run on servers we operate at Fly.io; your audio is not sent to any AI model provider. The AI model providers receive text under contracts that forbid training on it and require its deletion after processing.
We also disclose data where the law requires, to our professional advisers under confidentiality, and to a successor of the business if it is sold or merged, under this policy. We never sell personal data.
We will update this list before adding a provider that processes personal data.
6. Broadcast listeners
If you open someone's broadcast, the host can see your device identifier or network address, your device description, the language you read in and when you joined. Nothing is shown to anyone else, and it is deleted with the recording.
A broadcast page needs no account. When a device opens one, we store a random device identifier, the network address, a short description of the device and browser, the languages it listens in and the time it joined, so that the host can see who is following their event and tell listeners apart. This “audience” list is visible only to the owner of the recording and is deleted when the recording is deleted. Listener addresses are not used for anything else.
If a device subscribes to notifications for a broadcast, we store its push token until the device unsubscribes or the app is uninstalled, and send the token to Google or Apple to deliver the notification.
The host is responsible for telling their audience about the broadcast and for any further use of the audience list.
7. How long we keep data
Content follows your plan: 7 days of audio and voices and 30 days of transcriptions on Pay as you go, the life of the account on Premium and Enterprise. Account data goes when you delete the account. Billing records stay 7 years, anonymised.
| Data | Kept for | Then |
|---|---|---|
| Account (email, name, memberships) | Life of the account | Deleted when you delete the account; the identity provider is asked to delete your sign-in |
| Source audio and cloned voices | Pay as you go: 7 days. Premium and Enterprise: life of the account | Deleted, including the stored files |
| Transcriptions and everything attached to them | Pay as you go: 30 days, then 30 days in the archive. Premium and Enterprise: life of the account | Permanently deleted with their media and exports |
| Anything you delete yourself | 30 days in the archive | Permanently deleted |
| Content older than the Pay as you go periods after a downgrade | 30 days of grace, with three warning emails | Deleted as above |
| Broadcast listener records (device id, address, languages) | Life of the recording | Deleted with it |
| Push tokens | Until the device unsubscribes or the owner is deleted | Deleted or detached |
| API keys | Until the account is deleted; revoked keys stay for the audit trail | Deleted with the account |
| Billing ledger, charges and consent records | 7 years, for accounting and to evidence consents | The link to your account is removed when you delete it; the rows are deleted after the period |
| Usage counters per account and key | 7 days per minute, 13 months per day | Deleted |
| Hashed network addresses (failed sign-ins, staff audit) | The daily hashing key is destroyed after two days, after which no one, including us, can link the hash to an address | Kept only as an unlinkable hash |
| Rate-limit counters with raw addresses | Minutes | Swept automatically; never backed up |
| Stored responses of idempotent API calls | 24 hours | Deleted |
| Support emails | As long as needed to handle the request, then up to [support retention period] | Deleted |
Backups of the database are kept by our database provider for a short rolling period and are overwritten in the ordinary course.
8. Where data is processed
Our providers are mostly US companies and our servers run in the regions below. Transfers out of the EU and UK rely on standard contractual clauses or the EU-US Data Privacy Framework where the provider is certified.
The Service runs on Fly.io in [hosting regions, e.g. Europe and North America]; the database is hosted by Neon in [database region] and media by Tigris in [storage region]. The providers listed in section 5 are established in the United States and may process data there.
Where personal data of people in the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission's standard contractual clauses (and the UK addendum) in our data processing agreements with the provider, or on the provider's certification under the EU-US Data Privacy Framework. You can ask for a copy of the relevant safeguards at support@vocalstack.com.
9. Security
Data is encrypted in transit (TLS) and at rest by our hosting, storage and database providers. API key secrets are stored only as salted hashes. Network addresses in security logs are hashed with a key that changes every day and is destroyed afterwards. Access to production systems is limited to the people who operate the Service and every administrative action is logged. No system is perfectly secure; if we learn of a breach affecting your data we will tell you and the authorities as the law requires.
10. Your rights
You can see, export, correct and delete your data, mostly from the Dashboard yourself. Write to us for anything else. In the EU and UK you can also complain to a supervisory authority.
Depending on where you live you may have the right to access the personal data we hold about you, to have it corrected or deleted, to receive it in a portable form, to restrict or object to its processing, to withdraw a consent you gave, and not to be subject to automated decisions with legal effects (we make none).
Much of this you can do yourself: the Dashboard shows your account, your transcriptions and your billing ledger; every transcription can be exported as SRT, PDF, Excel or JSON with its audio; voices can be deleted; the account can be deleted outright, which removes everything described in section 7. Deleting your account forfeits any remaining balance (Terms, section 14).
For anything else, or if you are a person who was recorded or a listener of a broadcast and want to exercise rights over data a host holds about you, write to support@vocalstack.com. We answer within one month. We may ask you to prove who you are. Where the data belongs to one of our customers' transcriptions we will forward your request to that customer, who is the controller of what they record.
If you believe we have handled your data unlawfully you can complain to [name and website of the competent data protection supervisory authority], or to the authority where you live or work.
12. Children
The Service is not intended for children under 16 and we do not knowingly collect their data as account holders. If you believe a child has created an account, write to support@vocalstack.com and we will delete it. Audio of children recorded by a customer, for example in a classroom, is the customer's responsibility as controller.
13. Changes to this policy
We will post any change here with a new “Last updated” date and, for changes that matter to you, email account holders before the change takes effect. We will not use your data for a materially new purpose without telling you and, where needed, asking you.
14. Contact
[company legal name], [registered address]. Privacy: support@vocalstack.com. General support: support@vocalstack.com. [EU/UK representative and contact details, if one is appointed]