Privacy Policy
Last Updated: October 2, 2026
This Privacy Policy applies to the VoxStudio application, the VoxStudio brand, and related VoxStudio services operated by GREATWAY GLOBAL PTE. LTD. on the voxstudio.me domain.
1. Scope of This Policy
This Privacy Policy applies to the VoxStudio application, the VoxStudio brand, and related VoxStudio services operated by GREATWAY GLOBAL PTE. LTD. The VoxStudio homepage is https://voxstudio.me, and this policy is available at https://voxstudio.me/privacy.
This Privacy Policy explains how VoxStudio ("we," "our," or "us") collects, uses, stores, discloses, and protects personal data and customer content when you use our websites, APIs, browser-based recording tools, meeting note workflows, and hosted processing services.
This Policy applies to account data, billing records, support communications, and content you submit, record, connect, or generate through the Service, including audio, video, transcripts, subtitles, summaries, notes, dubbing assets, vocal processing outputs, and metadata obtained through approved third-party integrations.
2. Information We Collect
We collect information directly from you, automatically through your use of the Service, and from connected third-party providers when you authorize them.
- Account and profile information, such as your name, email address, avatar, workspace membership, Apple or Google authentication data, and account preferences.
- Billing and transaction information, including plan selection, credit usage, invoices, payment status, and limited processor-provided payment metadata.
- Customer content you submit or generate, including uploaded files, browser recordings, meeting recordings, transcripts, subtitles, summaries, notes, dubbing assets, vocal separation outputs, vocal repair outputs, prompts, and related session artifacts.
- Network video content and metadata, including submitted links, source platform information, extracted audio, transcripts, translations, summaries, dubbed outputs, exports, and related artifacts from supported sources.
- Session and technical metadata, such as file names, mime types, duration, language settings, source type, processing stages, browser and device information, IP-based network logs, and product interaction events.
- Checkout attribution for Lifetime purchases, including the checkout IP address, approximate IP-based region, billing country supplied by the payment processor, referrer host, landing path, UTM parameters present on the current visit, client platform, app version, and purchase entry point. This attribution is collected in memory for the current browser visit and is not stored in cookies, localStorage, or sessionStorage.
- Connected provider data that you explicitly authorize us to access, including Apple and Google account identity data, limited Google Calendar event metadata, Zoom OAuth and Zoom App data, OAuth connection data, and similar data from other supported third-party integrations.
- Support and communications data, such as messages you send to us, bug reports, requests for deletion, and business contact details.
3. How We Use Information
We use personal data and customer content to operate, secure, support, and deliver the workflows you request.
If information comes from Google APIs, the Google-specific limitations in Sections 4, 5, and 6 control. The general descriptions in this Section 3 do not expand how we use Google user data.
- Authenticate users, manage accounts, workspace access, and session isolation.
- Store, process, and deliver recording, transcript, subtitle, summary, meeting note, translation, dubbing, vocal separation, vocal repair, and export features.
- Import and process data from supported third-party integrations when you enable them for meeting discovery, connection management, or meeting note workflows. For Google user data, the use is limited to the Google-specific purposes described in Sections 4, 5, and 6.
- Process payments, credits, subscriptions, usage limits, and fraud prevention controls.
- Understand Lifetime checkout conversion, approximate purchase geography, and the public page or app entry that started a paid checkout. Approximate IP region is derived from a local geolocation database and is not a precise street address.
- Monitor system health, detect abuse, troubleshoot failures, enforce product limits, and maintain security logs.
- Communicate with you about account activity, updates, invoices, policy changes, and support matters.
- Maintain service reliability, security, and internal operations. We do not use your customer content to train, fine-tune, or improve foundation models, generalized AI systems, advertising systems, or profiling systems.
4. Google User Data We Collect and How We Use It
If you sign in with Google or connect Google Calendar, we access only the Google user data covered by the
scopes you approve. VoxStudio currently uses the following Google scopes: openid,
https://www.googleapis.com/auth/userinfo.email,
https://www.googleapis.com/auth/userinfo.profile, and
https://www.googleapis.com/auth/calendar.events.readonly.
We use Google identity data only to sign you in, associate the Google account with your VoxStudio account, display the connected account inside the product, and support account linking or unlinking.
We use Google Calendar data only to read calendar event metadata and supported meeting links so VoxStudio can show candidate meetings that you can review or select. Calendar access does not give VoxStudio access to meeting audio, video, chat, screen share, participant content, Google Drive recording files, Gmail content, contacts, or other Google services.
We do not request Google Calendar write scopes, and we do not create, edit, move, or delete Google Calendar events through this integration.
Google Calendar data is not used to access meeting content. If you use a meeting bot workflow, the Google Calendar API is used only for meeting discovery based on the scopes you approved.
- Google identity data: Google account identifier, email address, display name, and profile image.
- Google Calendar event metadata: calendar identifier, event identifier, event title, start and end time, description or location fields when available, and supported meeting URLs.
- Google OAuth and integration data: access tokens, refresh tokens, authorized scopes, connection status, token expiry, last sync time, and disconnect or reauthorization status.
- Google meeting workflow data: selected meeting URLs, bot display name, meeting bot status, sync status, failure reasons, and operational logs needed to run or troubleshoot the workflow.
4A. Sign in with Apple User Data and App Store Purchases
When you choose Sign in with Apple, Apple provides an app-specific account identifier, an email address (which may be an Apple private relay address if you choose Hide My Email), and, if you share it, your name. Apple may provide the name only during the first authorization. Apple may also provide email verification and private-email indicators and the authentication time.
During sign-in, the iOS app sends an Apple identity token, an optional short-lived authorization code, your name if supplied, and a request nonce to VoxStudio. We validate the token and nonce to confirm the sign-in, then create or link your VoxStudio account and issue a VoxStudio session. We retain the Apple account identifier, email address, optional name, and relevant verification indicators with your account to support future sign-ins, account linking, and security. We do not receive or store your Apple Account password.
Signing in with Apple does not give VoxStudio access to your iCloud files, contacts, photos, mail, or other Apple services. Apple sign-in identity data and authentication credentials are not used as AI model inputs or sent to Modal, OpenRouter, OpenAI, or Google Gemini for AI processing. Content that you separately choose to record, upload, or enter is governed by the AI processing disclosure in Section 5.
If you buy Pro through Apple's App Store, StoreKit provides transaction and subscription information, such as product and transaction identifiers, purchase or renewal status, and expiration dates. VoxStudio sends transaction data to its billing service for verification with Apple and links the resulting entitlement to your VoxStudio account. We do not receive your payment card number from Apple. App Store purchase identity is separate from the Apple or Google account you use to sign in to VoxStudio.
Apple sign-in records and linked account data are protected under the safeguards in this Policy and retained while the VoxStudio account is active, subject to the retention exceptions below. You can delete your account in the iOS app's Settings or request deletion at [email protected]. Revoking Sign in with Apple in your Apple Account settings stops future Apple authorization but does not itself delete your VoxStudio account or prior content. Account deletion removes account-linked Apple identity records and content, subject to limited backup, security, billing, and legal retention described in Section 12.
5. AI Processing and Google User Data
Before sending content from the iOS app for cloud or third-party AI processing, VoxStudio shows a separate AI & Privacy disclosure and asks for your permission. Signing in or buying a subscription does not grant this permission. The choice is stored for that VoxStudio account on that device and is shared with the iOS Share Extension.
Data sent for a requested feature may include recorded or imported audio and video, meeting recordings, reference voice samples, dubbing scripts, transcripts, subtitles, chat messages, conversation history, and relevant project excerpts or metadata. This content can contain personal information or the voices and information of other people. We collect it when you record, import, enter a prompt, select project content, or enable a meeting workflow. Apple and Google sign-in identity data, account passwords, authentication tokens, and payment details are not AI model inputs.
Recipients depend on the requested feature and configured model. VoxStudio-managed audio and speech processing runs on Modal. The AI model providers used for these workflows are OpenAI and Google Gemini. Some requests pass through OpenRouter, a separate routing service that receives and processes the relevant content before forwarding it to OpenAI or Google Gemini. These services process the input to provide transcription, summaries, translation, answers about your projects, speech generation, or audio processing. This is cloud processing, not exclusively on-device processing.
We require service providers processing customer content on our behalf to provide the same or an equivalent level of protection as described in this Policy, including confidentiality, access restrictions, security safeguards, use limited to the requested service, and applicable retention and deletion obligations. We do not use your customer content to train general-purpose AI models. Provider processing and limited security or abuse-prevention retention are subject to the applicable service arrangements; turning permission off cannot retrieve content already transmitted. You may delete projects or your account or contact [email protected] for deletion assistance, subject to the retention exceptions described in this Policy.
You may choose Not now and continue browsing existing projects, exporting existing results, managing your subscription, or deleting your account. Change or withdraw permission in iOS Settings within VoxStudio, under AI & Privacy. Withdrawing permission stops new AI requests and uploads from that device, including the Share Extension; queued files remain on the device until you allow processing or remove them. It does not undo already-started processing or stop separately configured Google Calendar automations. Review or disable those automations in the Google Calendar settings. If the disclosed recipients or purposes materially change, we request permission again before new processing under the changed disclosure.
VoxStudio uses both internal AI processing services and third-party AI model providers to provide user-facing features, including transcription, speech generation, vocal sound processing, summarization, translation, and related workflow outputs. We also integrate with third-party AI model providers, including Google Gemini and OpenAI.
Google user data obtained through Google APIs is used only to provide or improve user-facing VoxStudio features that the user requests or enables, such as Google sign-in, account linking, Google Calendar meeting discovery, and related meeting workflow preparation.
Google user data obtained through Google APIs is not sent to third-party AI model APIs, including Google Gemini or OpenAI, and is not sent to internal AI model execution environments or machines used to run VoxStudio AI processing services.
We do not use Google user data obtained through Google APIs to train, fine-tune, evaluate, test, improve, or modify VoxStudio's own AI systems, Google Gemini models, OpenAI models, or any other generalized, foundation, frontier, or third-party AI or machine learning models.
We do not sell Google user data, use it for advertising or marketing, create unrelated databases from it, or transfer it to AI providers for purposes unrelated to providing the user-facing VoxStudio functionality requested by the user.
When AI processing is used for a user-facing workflow, the AI input is user-provided content or content generated inside that workflow, not Google user data obtained through Google APIs. Google account identity data, OAuth credentials, Calendar metadata, and meeting URLs obtained through Google APIs are not included in prompts, model inputs, model context, or AI provider transfers.
AI service providers may process user-provided workflow content only as necessary to perform the requested workflow, subject to contractual, technical, and security controls. Google user data obtained through Google APIs is not used for model training, provider-side model improvement, or AI provider processing.
6. Google User Data Sharing, Protection, Retention, and Prohibited Uses
We do not sell, rent, or disclose Google user data except as described in this Policy. We share Google user data only with service providers acting on our behalf when necessary to provide Google sign-in, account linking, token storage, token refresh, or read-only calendar sync for the feature you enabled. We may also disclose Google user data when required by applicable law. Recipients may process Google user data only on our instructions and only for those limited purposes.
We protect Google user data with access controls, account and workspace isolation, encryption in transit where supported, protected storage of OAuth credentials, and limited employee or system access based on operational need.
We retain Google OAuth credentials only while the Google integration is connected and only as long as needed to provide the Google-enabled feature you requested. If you disconnect Google Calendar or request deletion, we stop future Google sync activity and revoke, delete, or disable stored Google connection credentials where supported. Calendar metadata and meeting workflow records already created inside VoxStudio remain until you delete the related sessions, delete your account, or request deletion, subject to limited backup and legal retention requirements.
We do not use Google user data for targeted advertising, user advertisements, personalized advertising, retargeted advertising, interest-based advertising, selling to data brokers, providing to information resellers, determining credit-worthiness, lending purposes, creating databases unrelated to VoxStudio user-facing features, or training, fine-tuning, evaluating, or improving AI or machine learning models.
We do not use Google user data for product analytics, generalized product improvement, user profiling, marketing, customer outreach, unrelated A/B testing, or any independent purpose not needed to provide the user-facing functionality you explicitly enabled.
VoxStudio's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including the Limited Use requirements.
7. Zoom App, Zoom Scopes, and Zoom User Data
If you connect a Zoom account, we access only the Zoom data covered by the scopes you approve. VoxStudio
currently requests the following Zoom scopes for the Zoom App: user:read:user,
meeting:read:list_meetings, meeting:read:local_recording_token,
user:read:zak, and user:read:token.
Zoom data we process may include Zoom user ID, account ID, display name, email address, meeting identifiers,
meeting topic, meeting start time, meeting URL, OAuth credentials, access and refresh tokens, ZAK or
on-behalf-of tokens, local recording tokens, Zoom webhook event data for meeting.created and
user.updated, bot join status, and related connection or operational metadata.
If you start or enable a Zoom meeting bot workflow, we may process meeting audio, video, screen content, participant speech events, generated transcripts, subtitles, summaries, translations, notes, media files, exports, and related session artifacts after the bot is admitted to the meeting and the requested capture workflow starts.
We use Zoom data only to maintain your Zoom connection, associate the connection with your VoxStudio account, validate authorized meeting access, list or identify meetings you submit or enable, route Zoom webhooks, create an authorized meeting bot join, request local recording tokens or short-lived meeting access tokens where required, and deliver the recording, transcription, subtitle, translation, summary, note, and export workflows you request.
We do not use the current Zoom scopes to create, edit, delete, or change Zoom meetings, to read Zoom cloud recordings, or to access Zoom data outside the permissions granted during authorization.
Zoom meeting content is processed only for the workflows you request. Meeting recording, transcription, and note-taking laws vary by jurisdiction and use case. You are responsible for ensuring you have all required notices, consents, permissions, and legal bases before using these workflows or processing participant audio, video, or related personal data.
8. Zoom Data Sharing, Protection, Retention, and Prohibited Uses
We do not sell, rent, or disclose Zoom user data except as described in this Policy. We share or transfer Zoom user data only with service providers acting on our behalf, Zoom services you authorize, or parties required for security, legal compliance, or protection of rights. These recipients may use Zoom user data only to provide, secure, maintain, or improve VoxStudio user-facing features.
We may use service providers acting on our behalf to support Zoom OAuth, webhook routing, authorized meeting bot entry, recording capture, storage, transcription, translation, summarization, and export workflows. These providers are required to process Zoom data only as needed to provide the Service to us and to you, and to protect it under appropriate confidentiality and security obligations.
We protect Zoom user data with access controls, account and workspace isolation, encryption in transit where supported, encrypted or otherwise protected storage of OAuth credentials and tokens, Zoom webhook signature verification where applicable, rate limits, audit or operational logging, and limited employee or system access based on operational need. We do not share Zoom API keys, OAuth credentials, access tokens, refresh tokens, ZAK tokens, on-behalf-of tokens, or local recording tokens except with systems and providers that need them to provide the user-requested workflow.
We retain Zoom OAuth credentials while the Zoom integration is connected and for as long as needed to provide the requested workflow, maintain security, comply with law, resolve disputes, or preserve backups. If you disconnect Zoom in VoxStudio, uninstall the VoxStudio Zoom App from Zoom App Marketplace, or request deletion, we stop future Zoom connection activity for that account and revoke, delete, or disable stored Zoom connection credentials where supported.
Content already created inside VoxStudio, such as sessions, recordings, transcripts, notes, summaries, translations, subtitles, media files, and exports, remains subject to our retention and deletion processes unless you delete it or request deletion, subject to backup, legal, and security limits. To request deletion of Zoom-related data, contact [email protected] from your VoxStudio account email.
We do not use or transfer Zoom user data for targeted advertising, user advertisements, personalized advertising, retargeted advertising, interest-based advertising, other advertising or marketing purposes, selling to data brokers, providing to information resellers, determining credit-worthiness, lending purposes, scraping, building databases unrelated to VoxStudio user-facing features, creating copies of Zoom API data outside authorized workflows, or training, fine-tuning, evaluating, testing, improving, or modifying AI or machine learning models.
9. Third-Party Integrations
You may choose to connect supported third-party providers. When you do, we process only the provider data reasonably necessary to deliver the feature you enabled.
- Google Calendar and Google account data: used for sign-in, account linking, and read-only meeting discovery based on authorized scopes.
- Zoom OAuth and Zoom App data: used for account linking, authorized meeting access, bot entry, webhook routing, recording capture, and meeting note workflows based on authorized scopes.
- Microsoft or Teams-related data: if enabled, may include account or meeting information needed to discover meetings, enter meetings, or run meeting note workflows.
- If you disconnect an integration, we stop future sync or connection activity for that integration, but content already created inside the Service remains until deleted under our retention and deletion processes.
10. Security Practices
We design the Service so that sessions, files, transcripts, subtitles, notes, exports, and generated outputs remain logically isolated by account and workspace. Private session data is intended to be visible only to the owning user or authorized workspace members.
We use account authentication, bearer-token based session access, logical account and workspace separation, rate limits, logging, and internal cache invalidation and cleanup routines to help protect data access boundaries. For Google and Zoom integrations, stored access tokens, refresh tokens, and other sensitive integration credentials are encrypted or otherwise protected, and access is limited to systems and providers that need the data to provide the user-requested integration and meeting workflows.
- Encryption in transit where supported and protected handling of data at rest.
- Encrypted or otherwise protected storage of sensitive integration credentials and refresh tokens.
- Monitoring, abuse detection, and operational logs to detect misuse or service failures.
- Deletion and cleanup routines that can remove stored files, video chunks, cached artifacts, and related derived assets after session or account deletion, subject to backup, legal, and security constraints.
11. Data Residency, Service Providers, and Sharing
We store user data, databases, media files, and related session artifacts in data-center infrastructure located in the European Union.
We do not sell personal information, customer content, Google user data, or Zoom user data. We share, transfer, or disclose information only in limited circumstances consistent with providing the Service or complying with law. For Google user data, the narrower limitations in Sections 4, 5, and 6 apply and control.
We do not transfer Google or Zoom user data to third parties for targeted advertising, selling to data brokers, providing to information resellers, determining credit-worthiness, lending purposes, user advertisements, personalized advertisements, retargeted advertisements, interest-based advertisements, creating databases unrelated to VoxStudio user-facing features, or training, fine-tuning, evaluating, testing, improving, or modifying AI or machine learning models.
- Infrastructure, storage, database, queueing, and delivery providers acting on our behalf and under instructions that limit use to providing the Service.
- Processing providers needed to perform transcription, translation, summarization, dubbing, vocal tools, or similar user-requested workflows.
- Payment and billing providers for subscriptions, invoices, and credit purchases.
- Third-party platforms you explicitly connect, when needed to complete authentication, token refresh, connection validation, webhook routing, meeting discovery, recording authorization, or meeting-entry workflows.
- Professional advisors, auditors, insurers, acquirers, regulators, law enforcement, or other parties when required by law or reasonably necessary to protect rights, safety, or the Service.
12. Data Retention and Deletion
We retain account data, billing records, logs, and customer content for as long as reasonably necessary to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, maintain backups, and protect against abuse or fraud.
Full checkout IP addresses used for Lifetime purchase analytics are retained for 90 days, then deleted. Approximate region statistics and the fact that an IP expired may be retained with billing records. Source fields such as UTM parameters, referrer host, landing path, client platform, and entry point are retained with the purchase analytics record.
If you disconnect Google Calendar or another Google integration, we stop future Google sync or connection activity for that integration and revoke, delete, or disable stored Google connection credentials where supported. Calendar event metadata and meeting workflow records already created inside VoxStudio remain subject to the retention and deletion rules in this Policy unless you delete them or request deletion.
If you disconnect Zoom or uninstall the VoxStudio Zoom App from Zoom App Marketplace, we stop future Zoom connection activity for that account and revoke, delete, or disable stored Zoom connection credentials where supported. Zoom meeting workflow records and content already created inside VoxStudio remain subject to the retention and deletion rules in this Policy unless you delete them or request deletion.
When an account deletion request in VoxStudio account settings is accepted, your account is disabled immediately. Account records and associated customer content, including stored files and derived artifacts, are then permanently deleted in the background. Completion time depends on the amount of content and service availability. Contact [email protected] if you need an update on the deletion status. Account deletion cannot be undone.
Web-billed subscriptions, including trials and scheduled subscriptions, are canceled as part of the background account deletion process. Account deletion does not cancel subscriptions billed by Apple; these continue to renew until you cancel them in the App Store. You can manage Apple subscriptions at https://apps.apple.com/account/subscriptions and still choose to delete your VoxStudio account immediately.
Deleting a session or account triggers cleanup of stored files, transcripts, notes, caches, video chunks, and other derived artifacts. Limited data may remain in encrypted backups, security logs, or billing records where retention is necessary for legal, security, tax, or fraud-prevention purposes. These retained records remain subject to access restrictions and applicable retention requirements. Deletion of the live account and content does not mean every backup or legally required record is erased at the same time.
Account deletion does not automatically refund paid fees, remaining plan time, or unused credits. For purchases billed by Apple, you may request a refund from Apple under its applicable refund rules. Your statutory consumer rights are unaffected. See the Terms of Service for billing and refund details.
Share links, exports, copied transcript text, and other user-initiated disclosures are controlled by the user action that created them. Once you export or share content outside the Service, that disclosure is outside our direct control.
13. Your Choices
- You may update profile information from your account settings.
- You may delete sessions, disconnect integrations, or request account deletion. Accepted account deletion requests immediately end account access and start permanent data cleanup, subject to the retention exceptions above. Deletion does not automatically issue a refund.
- You may choose whether to enable share links or collaborative access.
- You may contact us to exercise privacy rights, subject to verification and applicable law.
14. Changes and Contact
We may update this Privacy Policy from time to time. If we make material changes, we may provide notice through the Service, by email, or by another reasonable method. The updated version will be indicated by the Last Updated date above.
If we materially change how VoxStudio accesses, uses, stores, shares, or protects Google or Zoom user data, we will update this Policy and provide notice where required before the change applies.
For privacy questions, deletion requests, or Google, Zoom, or other integration data questions, contact [email protected].