Last updated
VoiceSnap Pro listens to a microphone for a living, so this document exists to be specific rather than reassuring. It says what is captured, when, where it goes, who else handles it, how long it survives, and what we are never going to do with it. Where something is less private than you might assume, it says that too.
VoiceSnap Pro is a voice-to-text dictation app for macOS and Windows, published at voicesnap.pro. It is run by Iaroslav Morgunov, a sole trader (empresário em nome individual) established in Portugal. VoiceSnap Pro is the name of the product, not a separate company. He is the controller of the personal data described below, except where a section names another company as responsible for its own records. In this document, “we” and “us” mean him.
Parts of this website, such as the About page, call the founder “Morgan”. That is the name he uses in public; it is the same person and the same business. We have not appointed a data protection officer, because the law does not require one for the kind of processing we do; write to support@voicesnap.pro instead. Our full business details are in the Legal Notice.
This policy covers three things: the desktop app, the server the app talks to, and the marketing website you are reading it on. Where the answer differs between them, it says so.
It applies to everyone who uses VoiceSnap Pro or this website, on the free allowance or on Pro. Accounts, notes and subscriptions all live in the app and on the server it talks to; the website itself processes only the technical request data every website handles, such as your IP address and browser, described in sections 10 and 11.
The app has two modes. Dictation types what you say into whatever field your cursor is in. Voice notes saves what you say as a note in VoiceSnap Pro's own library instead. They are handled very differently, which is why this policy keeps them apart.
The microphone opens only for a session you start, in one of these ways:
A single recording can last up to four hours. The app warns you five minutes before that, and at four hours the recording stops and is transcribed like any other. On the free allowance, a recording also stops when your remaining transcription time runs out, with a warning shortly before. During a long recording, the app sends the audio for transcription in parts while you are still speaking, so the text is ready soon after you stop. There is no wake word, no always-on listening and no background recording. While a session is running, a small status pill shows on screen, and macOS and Windows show their own microphone-in-use indicator.
Because the microphone opens as soon as the key goes down, it can open for a fraction of a second when you did not mean to dictate: a hold shorter than a quarter of a second, typing an Option or AltGr character, or using a Right-Command keyboard shortcut. In those cases, and whenever you press another key, click or scroll while holding, press Escape, or the microphone disappears, the recording is cancelled. The audio held in memory is thrown away, and nothing is uploaded, typed or saved.
The microphone does not open at all if you are not signed in, if your account has used its free transcription time and has no Pro subscription, if you have paused dictation, or if a previous session is still finishing. In Dictation mode it also stays closed while macOS Secure Input is on (see password fields below) and, on Windows, when the window you are typing into is running as administrator.
While the microphone is open, VoiceSnap Pro records whatever it picks up: normally your voice, sometimes whatever else was audible around you. If someone else is talking near you, or a video is playing, that audio is in the recording too. This is worth being blunt about, because it is the part people forget. The audio is compressed on your computer and held in memory while you speak. For a voice note, the app also writes the compressed audio to a recovery file on your computer as you speak, so that a crash or a power cut does not lose it; the file is removed once the note has been saved (see section 8).
Your keyboard. To notice a global shortcut, the app's shortcut listener sees every key event on the system. It keeps only the set of keys held down right now, in memory, reads no characters and writes nothing to disk. It acts only on your shortcuts, on Escape while a session is running, and on any other key you press while holding a shortcut, which cancels that recording. It listens to the mouse only so that a click or scroll can cancel a hold, and never reads where the pointer is.
The app you dictate into. When a session starts, the app learns the name of the application in front. In Dictation mode that name is shown on the status pill and stored with the dictation in your history on your computer. It is never sent to us. In Voice notes mode it is thrown away.
Your clipboard. The text is inserted by pasting. For that moment, VoiceSnap Pro copies your current clipboard into memory, puts the dictated text on the clipboard marked so that clipboard managers and clipboard history skip it, presses Command-V or Ctrl+V, and puts your previous clipboard back about half a second later if nothing else has changed it. If your clipboard held more than 64 MB, it is not restored; the dictated text is cleared from it instead. Copying a note from the library is an ordinary copy.
Password fields. On macOS, password fields turn on Secure Input, and VoiceSnap Pro refuses to start a dictation while it is on: no microphone, no upload, nothing stored. Windows has no equivalent signal that VoiceSnap Pro detects today, so a password dictated into a Windows password field is handled like any other dictation: the recording goes through Cloudflare and our server to OpenAI to be transcribed (section 3), and the text is pasted and saved to your dictation history. Type passwords by hand.
VoiceSnap Pro does not transcribe on your computer, which is why it needs an internet connection. When you finish speaking, the app uploads the recording over an encrypted connection to our server at api.voicesnap.pro, which runs on Amazon Web Services in Ireland. That address sits behind Cloudflare, a network provider that decrypts the traffic at its edge to route and protect it before passing it on to our servers in AWS over a new encrypted connection (see section 18).
Our server sends the audio to OpenAI's speech-to-text service, using OpenAI's gpt-transcribe model, and returns the text to the app. Both modes, Dictation and Voice notes, are transcribed the same way. So is a note you re-transcribe: the app sends each of the note's recordings to our server again, from your computer or after downloading it from your account, and our server passes it to OpenAI.
What OpenAI receives: the audio file, the model name, the response format, if you chose a language rather than automatic detection (in Settings, or when you re-transcribe a note), a two-letter language code, and, if you keep a personal vocabulary, that list of words as spelling hints. Nothing else: not your name, email address, account or device identifier, or IP address. OpenAI sees our server's network address, not yours.
What our server receives with each recording: the audio, your language setting, the recording's length as measured by the app, a random identifier for the request, so that an upload the app retries is not counted twice, and the device identifier, session token and signature described in section 6. While you are editing your personal vocabulary on that computer, it also receives the list being edited. Cloudflare also adds your real IP address and your country to each request in headers; our logs record Cloudflare's address instead (see section 7). It never receives the contents of the field you are dictating into, your dictation history, or the name of the app you are using.
What our server keeps: during transcription, the audio and the transcript are held in memory while the request is handled, and are not written to our database, our file storage or our logs. For a note, the app then uploads the note's text and its recording separately, and those are stored (section 5). One caveat: our web server buffers any upload larger than about 112 KB (roughly 37 seconds of speech) in a temporary file on the server's disk. The file is unlinked the moment it is created and disappears when the request ends. What we do record for each transcription is its length, added to your account's usage counts (section 6), and a log line with its status, size, language, length and processing time, never its words (see section 7).
If you press Escape while the pill says “Transcribing”, the app discards the result, but some or all of the audio may already have reached our server and OpenAI, and may still be transcribed there.
Personal vocabulary (Settings) is a list of words and names, such as colleagues, products or technical terms, that you want transcription to spell your way: up to 100 entries of up to 80 characters each. It belongs to your account, so every computer you sign in on uses it. It is stored in your account, encrypted like a note's text, and with each transcription our server sends the list to OpenAI as spelling hints, in the same request as the audio and under the same terms (see what OpenAI does with it, below). It adds no separate request. Our logs record only how many entries the list has, never the words. An empty list sends nothing, and you can change or clear it in Settings at any time.
OpenAI also writes the titles of notes, while the AI titles setting is on, which it is unless you turn it off. For a title, our server sends OpenAI a note's text, never its recordings, taken from the copy of the note in your account: the first 6,000 characters of the text, the note's language code if it has one, the model name and our instruction to write a title of a few words. Nothing else: not your name, email address, account or device identifier, or IP address. OpenAI sends back a title, which our server stores with the note (section 5). Our server does not log the text it sends or the title it gets back. Dictations never get titles, and their text is never sent for one.
And OpenAI runs the AI actions you choose, while the AI actions setting is on. For an action, the app sends our server the text you run it on (the part of a note or a dictation you selected, or all of it, up to 20,000 characters), its language code if it has one, and which action it is: for one of your custom actions, the app also sends that action's prompt, and for Translate, the language you chose. Our server passes these to OpenAI with the model name, its own instruction for a built-in action and its own rules for the answer, and sends the result back to the app. Nothing else: not the name of the app a dictation went into, your name, email address, account or device identifier, or IP address. Our server does not store or log the text, the prompt, the language or the result; it only counts the action (see section 5).
And OpenAI reads the time out of a request to be reminded, while the Reminders from your voice setting is on. When a voice note contains words such as “remind me”, the app sends our server only the few sentences around them, never the whole note, up to 2,000 characters, with your computer's current date and time, the name of its time zone, whether it shows a 12- or 24-hour clock, and the note's language if it is known. Our server passes these to OpenAI with a calendar of the next 14 days, the model name and our instructions, and OpenAI answers whether a reminder was asked for and when. Nothing else: not the rest of the note, its recordings, your name, email address, account or device identifier, or IP address. Our server does not store or log the text, the time zone or the answer; the reminder it leads to is stored with the note like any other (see section 5).
OpenAI processes the audio, and any personal vocabulary sent with it, on our behalf as a data processor, under its Data Processing Addendum. OpenAI's API data-controls documentation says data sent to its API is not used to train its models unless the customer opts in, and lists the speech-to-text endpoint we use as having no abuse-monitoring retention and no stored application state. OpenAI's terms still allow it to keep content where the law requires it, or where reasonably necessary to prevent abuse or protect its services or others from harm. We do not claim a “zero data retention” arrangement with OpenAI; if we obtain one, this page will say so. Any change of transcription provider will be published here first.
Titles, tags, AI actions and reminders from your voice go through a different OpenAI endpoint, Chat Completions, whose data OpenAI keeps for longer. The same documentation lists it as not used for training, but with abuse-monitoring logs kept for up to 30 days, longer only where the law requires it, so text sent for a title, for tags, for an AI action or for a reminder, your tag names, a custom action's prompt and the date, time and time zone sent with a reminder can stay in those logs for up to 30 days. We send each of these requests with OpenAI's option to store it turned off, and the documentation lists no other stored application state for our requests apart from temporary caches. Any change of the provider that writes titles, picks tags, runs AI actions or reads reminders will be published here first too.
Dictation audio is not kept. On your computer it is held in memory while you speak and while it is uploaded, and the app never saves it to a file. (Like anything in memory, it can be paged to disk temporarily by the operating system or by the browser engine the app is built on, which the app does not control.) On our server it is discarded as soon as the transcript comes back. There is no archive of dictation audio anywhere, and no way for us to play back something you dictated.
Dictation text stays on your computer. The text is inserted where your cursor was, and a copy goes into the Dictation history on your computer: the text, the date and time, how long you spoke, the language, and the name of the app you dictated into. The history is never uploaded to our servers. The app keeps the newest 1,000 dictations outside the Trash and drops older ones automatically. A dictation's text can leave your computer in two ways, both only if you choose: when you run an AI action on a dictation, its text, or the part you selected, goes through our server to OpenAI, which our server does not keep, and the result is saved as a new note; and through an AI assistant you connect, if you allow that separately (see AI assistants in section 5).
The History pop-up (Control-Option-H on macOS, Ctrl+Alt+H on Windows) lets you search, copy and paste your history, and Paste last dictation (Control-Option-V or Ctrl+Alt+V) pastes your latest dictation again at the cursor. Both work on your computer only and send nothing to us. One thing in the History pop-up does: Save as note turns a dictation's text into a note, which is stored in your account like any other note (section 5).
You control the history in the app. Deleting a single dictation moves it to the Trash on your computer, the same Trash that holds deleted notes, which you open with the trash icon in the sidebar, just above Settings. A dictation in the Trash stays on your computer like the rest of the history and never reaches our servers. It is left out of the history, its search and what an AI assistant can read, and until you restore it, it can only be read or copied. After 30 days in the Trash it is deleted for good, the next time the app checks: when it starts, and about once an hour while you use it. You can delete it sooner with Delete forever, or with Empty Trash for everything in the Trash.
Settings → Clear history… still deletes every dictation at once, those in the Trash included. You can also turn off Keep dictation history so new dictations are typed but not stored. Turning it off keeps the existing entries until you clear them. None of this touches your notes, in the Trash or not.
A note is what Voice notes mode produces, what you type into the library by hand, a dictation you save as a note, a copy made with Duplicate Note, or the result of an AI action saved as a new note. Notes are stored in your account on our servers, as well as on your computer, so that every computer you sign in on shows the same notes and can play their recordings. Your account is what you sign in to with Google or an emailed code (section 6).
For each note, the account holds:
The account also holds your tags, your folders and your custom AI actions (see below), your personal vocabulary, the hash of your notes PIN, and these settings for the whole account: Keep recordings, AI titles, AI tags, AI actions, Reminders from your voice, and which built-in AI actions you hid from the app's menus. An account holds at most 20,000 notes, notes in the Trash included, 10 GB of recordings, 100 tags, 100 folders and 30 custom AI actions; on the free allowance, at most 20 notes outside the Trash (section 6).
When notes are uploaded. Only while you are signed in. New notes and their recordings go up shortly after they are made, and edits about half a second after you stop typing; titles you give notes, pins, folders, locks, reminders, moves to the Trash, restores, the tags and folders you make and give notes, your custom AI actions, and changes to your account's settings go up the same way. Notes you type while signed out stay on your computer only, up to 20 of them; the next time you sign in, the app asks whether to add them to that account, and uploads them only if you agree. If someone else signs in on the same computer, your notes are hidden there and are never uploaded into their account: any of yours that had not yet reached your account are kept aside on the computer until you sign in again.
Duplicate Note makes a copy of a note in your account, with its text, title, tags, folder and lock; our server copies its recordings itself. A copy has no reminder and no earlier versions.
Sensitive content. We never ask for health details or other sensitive information, but a note holds whatever you say or type into it, and its recording can include the voices of people near you. If you put health information or other sensitive details in a note, it is stored in your account like any other note, where our server holds the keys. Locking a note hides it on screen; it does not encrypt it any further. If you would rather not have that on our servers, use Dictation for it: its audio still goes through our server to OpenAI to be transcribed, but it is then discarded, and the text is kept only on your computer. Setting Keep recordings to Don't keep stops recordings being kept, but a note's text is still stored. And while AI titles and AI tags are on, a note's text is also sent to OpenAI to write its title and pick its tags; turn them off if you would rather it were not. An AI action sends text only when you run one.
We do not look at the contents of your notes, except to act on a request from you or where the law requires it. Our server holds the encryption keys, though, so this is a promise about what we do, not a technical impossibility.
When you add to a note by voice, the new recording is transcribed like any other (section 3), its text is added to the end of the note, and the recording is kept as one more of the note's recordings, unless Keep recordings is set to Don't keep. If that transcription fails, the recording is kept anyway, so what you said is not lost. Re-transcribing a note sends its recordings through our server to OpenAI again and replaces the note's text with the result; the text it replaces is kept as an earlier version. Re-transcribing works only while you are signed in and online, and on the free allowance it counts against your transcription time like any other recording.
A note is titled with its first sentence until it has a title of its own. You can write one yourself, in the title above the note or with Rename in its ⋯ menu, and clear it to go back to the first sentence. A title of its own is kept in your account with the note, encrypted like its text, until you change it or the note is deleted for good. Earlier titles are not kept as versions.
AI titles (Settings → AI) lets OpenAI write a short title of a few words, in the note's language. It belongs to your account, so it applies on every computer you sign in on. It is on by default, and it can be changed only while you are signed in. AI titles never count against the free allowance. While it is on, the app asks our server for a title:
A typed note, including one an AI action saves as a new note, is never sent for a title on its own: it gets an AI title only when you choose Regenerate title. Adding to a note by voice never asks for a title.
Each time, our server sends the note's text to OpenAI as described in section 3, and stores the title it gets back with the note. The app never asks AI to replace a title you wrote, except when you choose Regenerate title, and our server does not store an AI title over a title you changed while it was being written. No title is asked for a note with fewer than 20 characters of text, a note in the Trash, a locked note, or while you are signed out. A request made offline waits until the computer is back online.
Turning AI titles off stops our server sending any note's text to OpenAI for a title, for every computer on your account, and the app drops the title requests still waiting. Titles AI has already written stay until you rename the note or clear its title, or the note is deleted for good.
Tags are yours: only you can create one, with Add tag on a note or in Settings → Tags, where you can also rename, recolour, merge and delete them. A tag has a name of up to 40 characters, kept in lower case, and one of eight colours. An account can have up to 100 tags and a note up to 10; dictations cannot be tagged. Your tags, their colours and which notes have each one are kept on your computer and in your account, so every computer you sign in on shows the same tags. Each tag's name is encrypted like a note's text. So that our database can refuse two tags with the same name without decrypting them, it also keeps a keyed one-way code of each name, from which the name cannot be read back. Tags made while you are signed out stay on that computer until you sign in. Deleting a tag removes it from every note that had it, on every computer, and the notes stay; merging a tag into another gives its notes the other tag and deletes it. Changing a note's tags does not add a version to its history.
AI tags (Settings → AI) lets OpenAI pick up to three of your existing tags for a note. It belongs to your account, so it applies on every computer you sign in on. It is on by default, and it can be changed only while you are signed in. AI tags never count against the free allowance. AI never creates a tag: it can only choose among the tags you made, and it may choose none. While it is on, the app asks our server for tags at most once for each note: for a voice note when it is made, and for a typed note when you stop editing it, or when an AI action saves it as a new note, and its text has reached two sentences or 120 characters. It never asks for a note that already has tags, a note in the Trash, a locked note, a note with fewer than 20 characters of text, while you have no tags, or while you are signed out. Each time, our server sends the note's text and your tag names to OpenAI as described in section 3, and gives the note the tags it picked, unless you changed the note's tags in the meantime. You can remove or change them like any other tag. A request made offline waits until the computer is back online.
Turning AI tags off stops our server sending any note's text or your tag names to OpenAI to pick tags, for every computer on your account, and the app drops the requests still waiting. Tags already given stay.
Folders are yours, like tags: a flat list you create, rename, reorder and delete in the sidebar, up to 100 of them. A note is in at most one folder. Each folder's name is encrypted like a note's text, and, so that our database can keep names unique without decrypting them, it also keeps a keyed one-way code of each name, from which the name cannot be read back. Folders and which notes are in them are kept on your computer and in your account, so every computer you sign in on shows the same folders. Deleting a folder moves its notes back to All notes; it never deletes them.
AI actions rework text with OpenAI when you ask: Rewrite, Summarize, Fix grammar & spelling, Make shorter, Turn into bullet points, Extract action items, Translate to…, and custom actions you write yourself. You choose one from the AI menu when you right-click in a note or a dictation, from the AI actions button above it, or with ⌘J (Ctrl+J on Windows). Nothing is sent until you choose an action, and running one needs an internet connection and you to be signed in. Actions are not offered on a locked note. On the free allowance, each action that gives you a usable result counts as one of your 50 (section 6).
An action works on the text you selected, or on the whole note or dictation when nothing is selected, up to 20,000 characters. The app sends that text through our server to OpenAI as described in section 3, and the result comes back to your computer. The action decides where the result goes: it replaces the text, is added below it, or is saved as a new note, which is where a dictation's result always goes. Running an action stores nothing on our server but the day's count described below: not the text, the result, or the prompt sent with it. What you keep of the result is stored like any other change to a note. When a result changes a note, our server keeps the note's previous text as an earlier version (see version history), so the change can be undone or the earlier text restored. A dictation itself is never changed and never uploaded: only the text you ran the action on goes to OpenAI, and only the new note made from the result is stored in your account.
Custom actions, made in Settings → AI actions, have a name, a prompt that tells the AI what to do, and where the result goes. They are kept on your computer and in your account, the name and prompt encrypted like a note's text, so they appear on every computer you sign in on, until you delete them. An account can have up to 30. Which built-in actions you hide from the menus is kept in the account too.
A daily limit. Each account can run a limited number of AI actions a day, on any plan, which keeps their cost in check. For this our server keeps, for each account and day (in UTC), how many AI actions it ran and how much text OpenAI read and wrote for them, counted in tokens, never what that text was. On the free allowance it also counts, per day, the AI titles, AI tags and reminders from your voice it asked for, which have a daily limit of their own. These counts have no automatic expiry today; they are deleted with your account.
Turning AI actions off (Settings → AI) stops our server running any action, for every computer on your account, so no text is sent for one. It is on by default, and it can be changed only while you are signed in. Your custom actions stay stored until you delete them.
When you edit a note, add to it by voice, re-transcribe it, apply an AI action to it or restore an earlier version, our server keeps the text being replaced as an earlier version, so you can go back to it. Typing does not add a version for every change: an ordinary edit adds one only when the newest version is more than 10 minutes old or came from another kind of change. The server keeps the 50 newest versions of each note, deletes older ones as new ones are added, and keeps the rest until the note is deleted for good, including while it is in the Trash. Versions are encrypted like the note's text. The app reads them from our server when you open a note's version history, and does not store them on your computer.
The Keep recordings setting (Settings → Voice notes) decides how long the recordings of your voice notes are kept. It belongs to your account, so it applies to every computer you sign in on, and it never affects a note's text. It can be changed only while you are signed in.
Recordings deleted this way leave storage within about 10 minutes, the same way as below, and switching back to Forever does not bring them back.
Deleting a note moves it to the Trash, on your computer at once and then in your account, so it moves to the Trash on your other computers too. A note in the Trash keeps its text, earlier versions and recordings, so that you can restore it, and cannot be changed until you do. After 30 days in the Trash it is deleted for good: our server checks every hour, and the app does the same on each computer. You can also delete a note for good at any time with Delete forever, or everything in the Trash with Empty Trash. The Trash, opened with the trash icon in the sidebar, also holds the dictations you delete; those stay on your computer only (see section 4).
Deleting a note for good removes it from your computer, including its recordings, and from your account. The note's text, its earlier versions and its details are deleted from our database as soon as our server gets the request, or runs its hourly check. Its recordings are queued for deletion and removed from storage by a cleanup job that runs every 10 minutes, so they are gone within about 10 minutes, or later if the storage service keeps failing, in which case it is retried. The storage bucket keeps no older versions of files, so a deleted recording cannot be restored from it. Your other computers drop the note and their copies of its recordings the next time they refresh.
Two things outlive that. Our encrypted database backups keep deleted or edited note text and titles, earlier versions included, for up to about 16 days: they cover the last 14 days, and the daily snapshot taken just before that window is kept until the next one replaces it. Our server logs, which never contain note text, titles or audio, record note identifiers for 30 days.
A change made on one computer, such as moving a note to the Trash, restoring it or deleting it for good, can fail to reach the server in three cases: if you are signed out at the time, the change waits until you sign in to the same account on that computer again; if, before it is sent, you sign out and remove that account's notes from the computer, or sign in to a different account there, the pending change is dropped, and the app warns you first; and if our server answers with an error eight times in a row, the app gives up. In those cases your account keeps the note as it was. Make the change again from another computer signed in to the same account, or ask us (see section 17).
Signing out, using up the free allowance, or the end of a Pro subscription does not delete your notes. They stay in your account until you delete them or delete your account, with two automatic exceptions that keep applying: a note already in the Trash is deleted 30 days after it was moved there, and recordings are deleted as your account's Keep recordings setting says. Whatever your plan, you can sign in to read, edit, export and delete your notes; the free allowance limits only new transcription, the AI actions you run and how many notes you keep outside the Trash.
You can lock a note behind a 4-digit notes PIN, which is the same on every computer you sign in on. The app turns the PIN into a salted one-way hash on your computer; our server stores only that hash, encrypted, never the PIN, and every computer checks the PIN against it. Locking is a privacy screen in the app, not extra encryption: a locked note's text, title, tags and recordings are stored on our servers exactly like any other note's, so a forgotten PIN never loses anything. While a note is locked, the app shows only its title until you enter the PIN, AI titles, AI tags and AI actions are never run on it, and an AI assistant you connect sees only its title. If you forget the PIN, you can set a new one after entering a code we email to your account's address (section 6).
You can set a reminder on any note, once or repeating every day, weekday, week or month. A reminder is kept with its note in your account, so every computer you sign in on shows it, and marking it done on one clears it on the others. For each reminder our server stores when it is next due, or snoozed until, the repeat rule with its local time of day, the name of the time zone your computer worked it out in (such as Europe/Lisbon, which says roughly where your computer is set to be), when it was marked done and when it last changed. These are not encrypted individually: like a note's pinned date, they sit in the encrypted database storage described in section 18. They stay until you clear the reminder or the note is deleted for good.
When a reminder is due, the app shows a notification through macOS or Windows with the note's title only, or “A locked note” for a locked one. VoiceSnap Pro has to be running for that. Notifications are produced on your computer by its operating system; we send none. You can turn them off on each computer in Settings (Reminder notifications).
Reminders from your voice (Settings → AI) lets you set a reminder by saying it in a voice note, such as “remind me tomorrow at 9”. It belongs to your account and is on by default. The app first looks for words such as “remind me” on your computer; only when it finds them does it send the few sentences around them through our server to OpenAI to read the time, as described in section 3, and it never runs on a locked note. It does not count against the free allowance. Turning it off stops any text being sent for it, for every computer on your account; reminders already set stay.
VoiceSnap Pro includes a small server that AI assistant apps on your computer can connect to, using the Model Context Protocol (MCP), so that you can ask an assistant such as Claude Desktop about your notes. It is off by default. It works only while Let AI assistants read my notes is on in Settings → AI assistants, on that computer, and it includes your dictation history only if you also turn on Also let them read my dictation history.
When it is on and you have added VoiceSnap Pro to an assistant app, that app starts VoiceSnap Pro in a mode with no window, which reads the notes stored on your computer without changing anything and without connecting to the internet. Our server is not involved: we do not receive what is read, or learn that you use it. The assistant can search your notes, by words, by tag or by folder, list the most recent ones, read one in full, and list your tags and folders. For each note it receives the text and title, the names of its tags and its folder, when the note was created and last edited, whether it was spoken or typed, its language, whether it is pinned and its reminder, if it has one (when it is due, whether it repeats and whether it is done); with the dictation history, each dictation's text, date and language and the name of the app it went into. It never receives recordings, or anything in the Trash, and for a locked note it receives only the title and the fact that it is locked.
What the assistant reads is sent to the assistant's provider (Anthropic, for Claude Desktop) as part of your conversation, and handled under that provider's terms, including how long it is kept and whether it may be used to train models. That provider is not our processor: you choose it, and your relationship with it is governed by its terms. Turning the setting off stops any further reading; it does not recall what an assistant has already read.
Export Notes (in Settings, and in the File menu on macOS) writes your notes to a folder you choose on your computer: one Markdown file for each note outside the Trash, with its dates, tags, folder and pin, an index file, and the recordings this computer has a copy of. It works from the copy on your computer, on any plan, offline too, and sends nothing to us. Locked notes are included only if you enter the notes PIN. What you export is yours: it is not covered by anything this policy says about deletion.
To transcribe, keep notes in your account or use the AI features, you sign in to a VoiceSnap Pro account, with Google or with a one-time code we email you. There are no passwords. Every new account starts with a one-time free allowance, and a Pro subscription, sold by Polar, removes its limits. Signed out, the app is a notebook on your computer: you can type, edit, search and export up to 20 notes there, and nothing reaches our server.
You type your email address in the app, and we email you a 6-digit code. It works once, for 10 minutes, and only on the computer that asked for it. The email comes from signin@voicesnap.pro and is sent through Cloudflare’s email sending service, which receives your address and the email itself, code included (see section 14). Before it asks for a code, the app solves a small computing puzzle, which costs your computer a moment and makes sending codes in bulk expensive; it reveals nothing about you.
To check the code, and to stop people guessing codes or flooding a mailbox, our server keeps a record of each code it sends: your email address, encrypted; a keyed one-way code of the address; a keyed one-way code of the code itself, never the code; one-way codes of the asking computer's key and device name; a keyed one-way code of your IP address, when Cloudflare has passed it on in a way we can verify; how many wrong codes were tried; and when the code was sent, expires and was used. After 24 hours the address and the one-way codes of the code and of the IP address are erased from the record, and after 30 days the record is deleted. If many wrong codes are tried for one address, codes for it can be requested for a while only from computers already signed in to that account.
The same kind of code, sent to your account's address, confirms that it is you when you reset a forgotten notes PIN or delete your account.
If you choose Google, the app opens Google's own sign-in page in your browser. We ask Google only for your email address: we do not ask for, and do not receive, your name, profile photo, contacts or anything else in your Google account. Google tells us your email address, whether Google has verified it, a fixed identifier for your Google account (Google's “subject” identifier) and, for a Google Workspace address, the Workspace domain. We use the identifier to recognise you the next time, even if the address on your Google account changes. An existing VoiceSnap Pro account with the same address is joined to your Google sign-in only when Google is responsible for that address, as it is for a Gmail address or an address on the Workspace's own domain; otherwise the app asks you to use an emailed code for it. Any record of a sign-in still in progress is deleted within 24 hours. Google handles your sign-in under its own privacy policy, and can see that you signed in to VoiceSnap Pro.
We do not store your name, a password, your photo or your payment details.
An account can be signed in on up to three computers at a time. For each one, our server keeps:
VoiceSnap- followed by your Mac's Hardware UUID (the one shown in System Information) or your Windows installation's MachineGuid, and a random part the app adds once, so that two people who use one computer are told apart. It is not hashed: it is a stable identifier for that computer, which lets it count as one computer even if the app is reinstalled. If the app cannot read the hardware ID, it uses the first 16 characters of a SHA-256 hash of the computer's name, your username, the platform and the processor type, and failing that a random value. The app sends it with every request, our server stores it, and it appears in our logs when the app signs in.Like any network request, each request from the app also carries standard headers that reveal the app version, your operating system version and your system language. Our logs do not record them.
When the app talks to our server. When you sign in or out; at startup and when you come back to the app, to read your account, your plan and what is left of the free allowance; for each transcription; in the background, to upload, fetch, edit and delete notes, tags, folders, reminders and custom AI actions, to ask for a note's AI title and AI tags, and to read and change your account's settings, which it also does when you open the Notes list or switch back to the app, and to retry anything that failed; and when you open a note's version history, restore a version, play a recording that is not on the computer, re-transcribe or duplicate a note, regenerate its title, run an AI action, set a reminder by voice, start a checkout or open the subscription portal.
Signing out (Settings → Account) ends the computer's session, makes the app create a new key pair, and stops the app contacting our server. Your notes stay in your account and, unless you tick the box to remove them, on the computer too; your dictation history always stays. After you sign out, the app remembers that account's email address on the computer, so that it can warn you before someone else signs in there. The computer's record stays with your account until you delete the account. From Settings you can also sign out all your other computers.
Every new account gets a one-time free allowance, shared by all the computers you sign in on, which never resets: 20 minutes of transcription (dictation, voice notes, adding to a note by voice and re-transcribing, together), 50 AI actions that you run, and up to 20 notes outside the Trash. AI titles, AI tags and reminders from your voice do not count. To apply it, our server keeps for your account:
The number of your notes is counted from the notes themselves. These counts keep counting while you have Pro, and they are kept until you delete your account; a subscription that ends does not bring the allowance back. They never include what you said or wrote.
Pro is sold by Polar (Polar Software, Inc.), our reseller and merchant of record (section 10). A free account never becomes a Polar customer. When you choose to subscribe in the app, our server creates or finds your customer record at Polar, giving Polar your email address and your account's identifier in our system, and asks Polar for a checkout, which the app opens in your browser. Everything you enter there, such as your name, billing address and payment details, goes to Polar, not to us.
From Polar, our server keeps a record of your subscription: Polar's identifiers for you as a customer, for your subscription and for the plan; whether it is monthly or yearly; its status; whether Pro is active; when the current period ends; whether it is cancelled at the end of the period, and when it ends; when a payment first failed; when you last started a checkout, with that checkout's identifier; and when we last checked with Polar. When Polar notifies our server that something changed, we keep the notification's identifier and type, your customer identifiers and when it arrived, for 90 days, never its contents. We never see your card number.
To change or cancel the subscription, update a card or download invoices, the app asks our server for a link to Polar's customer portal, which opens in your browser. Polar sends receipts and payment notices by email itself.
Installed copies of the app check for updates on GitHub, where our releases are published: 10 seconds after launch, every six hours after that, and when you choose Check for Updates, whether or not you are signed in. Updates download automatically and install when you quit the app. Each check shows GitHub your IP address, a generic user agent, and a random identifier the update library creates and stores on your computer to stage roll-outs. That identifier is not derived from your hardware, and no account or device identifier is sent. GitHub handles that request data under its own privacy statement.
The app opens voicesnap.pro pages in your browser only when you click a link that points there. It contains no analytics, no telemetry and no crash reporter.
Request logs. Our server logs each request it receives: the method and path (which, for notes, includes the note's identifier and, where there is one, the identifier of a recording or an earlier version), query values such as the language setting and the recording's length, the response status and timing, and the network address the request came from. Because every request arrives through Cloudflare, that address is currently a Cloudflare address, not yours. Email addresses, sign-in codes, Google sign-in tokens, public keys, note text, note titles, tag and folder names, the names and prompts of custom AI actions, personal vocabulary, the notes PIN hash, reminder times and time zones and the text sent for a reminder, and the text, results and translation languages of AI actions are filtered out of the logged request details, and audio and transcripts are never logged. The device identifier is logged in plain text when the app signs in, and some usage warnings name the computer's internal record identifier. For each transcription we log its status, size, language, length and processing time; for each title, choice of tags or AI action OpenAI is asked for, OpenAI's response status, the model, how long it took, how many tokens it used and, if it failed, OpenAI's error code and request reference, never the text, the title, a tag name, a prompt or a result; for tags, also how many were picked, for an AI action, which built-in action it was (a custom one is logged only as custom), whether it worked, and the account's number of actions that day and the day's limit, and for a reminder, whether one was found and what kind of time and repeat it was; when Keep recordings changes, its new value and how many recordings were deleted; when AI titles, AI tags, AI actions or Reminders from your voice is switched, its new value; when you hide or show built-in AI actions, how many are hidden; when the notes PIN is set or cleared, only that; and for your personal vocabulary, only how many entries it has. Logs are kept for 30 days in Amazon CloudWatch in Ireland and then deleted automatically.
Rate limiting. To stop abuse, our server counts recent requests per incoming network address (in practice, Cloudflare's) and, for transcriptions, notes, tags, folders, AI features and settings, per device identifier. Sign-in codes have limits of their own, kept in the code records described in section 6. The counters live on the running server's temporary disk, not in the database, and do not outlast it.
Cloudflare sees the real IP address of your computer and the full content of each request as it passes through, because it decrypts traffic to route it. It processes that content for us, and keeps some traffic data, such as IP addresses, under its own privacy policy.
Error reports. Our server is set up to send reports of server errors, and a sample of about one in ten requests for performance monitoring, to Sentry. It is configured not to send personal data by default: request bodies, query strings, cookies, authorization headers and the usual IP-address fields are left out. The remaining request headers can still be included, and those carry your device identifier, your app version and operating-system details, and a header Cloudflare adds with your IP address and country. A report also carries a trail of what the server logged just before it, which includes the request's parameters after the filtering described above: when a computer signs in, that means its device identifier in plain text, and for a note, its identifier and details, never its text or title; never an email address, a sign-in code, a tag or folder name, a prompt, an AI result, your personal vocabulary or a reminder's text, time or time zone either. The database queries recorded alongside an error can include internal record identifiers. Sentry (Functional Software, Inc.) stores these reports in its EU region, in Germany, and keeps them for up to 90 days.
The app keeps its data in ~/Library/Application Support/VoiceSnap Pro/ on macOS and in %APPDATA%\VoiceSnap Pro\ on Windows:
recordings folder. A recording stays until it has been uploaded; after that, recordings form a cache of at most 500 MB, least recently played first out. Keep recordings applies here too: under 30 days or Don't keep, the app deletes the recordings that setting no longer keeps. Notes and recordings of another account that never reached it are set aside on the computer for when that account signs in again. Earlier versions of notes are not stored on your computer.recording-drafts folder: the audio of a voice note while it is being recorded, removed once the note has been saved, or kept after a crash so that the note can be recovered.~/Library/Caches/voicesnap-pro-updater or %LOCALAPPDATA%\voicesnap-pro-updater.Set-aside recordings, and a library file the app ever finds damaged, are kept under a new name rather than deleted, and nothing removes them automatically.
None of these files are encrypted by the app. On macOS the app's own files are readable only by your user account; on Windows they are protected by your user profile's permissions. Full-disk encryption (FileVault or BitLocker) is the control that protects them if your computer is lost. The app writes no log files.
When an AI assistant app starts VoiceSnap Pro to read your notes (section 5), VoiceSnap Pro only reads the notes and settings files above and changes nothing in them. Its browser engine's working files go to a temporary folder that is removed when it exits. It sends the assistant app short status messages on its error output, never your questions or the text of your notes; whether the assistant app keeps those, or its own record of what it asked and received, is up to that app.
Uninstalling does not remove this data. On macOS, deleting the app leaves the data folder, the update cache, the permissions you granted and any login item behind. The Windows uninstaller keeps the data folder by default and leaves the update cache. To remove everything, delete those folders yourself. Uninstalling also changes nothing on our server and does not sign the computer out of your account, so sign out first, or sign it out later from another computer (see section 6).
We do not use anything you dictate to train AI models. Not your audio, not your transcripts, not your notes or their recordings. We do not train models on customer data, and we do not contribute customer data to anyone else's training set. OpenAI's API terms say data sent to its API is not used to train or improve its models unless the customer explicitly opts in to share it, and we have not opted in. That covers the text, tag names, prompts and personal vocabulary we send it for titles, tags, AI actions, reminders and transcription as well as the audio.
This is not a setting you have to find and switch off. It is the only mode VoiceSnap Pro has.
One thing is up to you: if you let an AI assistant read your notes (section 5), what it reads is handled under that assistant provider's terms, including whether it may be used for training.
You cannot create an account or buy anything on the website: accounts and Pro live in the app. The one place it asks for your email address is voicesnap.pro/download, and only while no installer has been published there: you can leave your address to be told when one is. (Before 2 October 2026 the same page took addresses to announce VoiceSnap Pro's release; those records are handled in exactly the same way.) If you leave your address, we hold it (in lower case), a short label for the page that sent you, and the date and time, in a private storage area on Vercel, in the United States (Washington, D.C. region), that is not publicly readable, each record filed under a one-way hash of the address. We use these records only to send you one email saying that the download is ready, and then delete them. We do not sell them, rent them, share them with advertisers, or add them to any other list. No email-sending service is connected for that email yet; we will name the one we use on this page before it goes out, and it will carry an unsubscribe link. You can have your record erased at any time at voicesnap.pro/account-delete-request.
Pro is bought in the app (section 6), not on this website. It is sold by Polar (Polar Software, Inc., Dover, Delaware, USA), which acts as our reseller and merchant of record: you buy from Polar, and Polar handles the checkout, the payment (through its payment processor, Stripe), sales tax, renewals, receipts and the customer portal. Polar collects your name, email address, billing details and payment information and processes them under its own privacy policy. Polar shows us your orders and your subscription in its seller dashboard so we can support you. We never see or store your card number, and our own server keeps only the subscription details listed in section 6.
Email to support@voicesnap.pro is received in a Proton Mail mailbox (Proton AG, Switzerland). We receive whatever you send: usually your name, email address, your message and any attachments, and sometimes your account's email address or order details. We keep it, and our replies, to answer you and to keep a record of what we agreed. There is no automatic deletion; ask us and we will delete it, unless we need it for a legal claim or a legal duty.
Pages under /blog are hosted on a blogging platform, Lunroo, and served through this website. Many posts embed YouTube videos in YouTube's privacy-enhanced mode, which load when the page does; loading a player sends your IP address and browser details to Google, and the player may store data in your browser.
The free browser tools never send what you paste, record or open to us. Two kinds involve someone else: the voice-typing tools use your browser's built-in speech recognition, which in Chrome sends your audio to Google; and the audio-to-text converters download a speech model from Hugging Face and a code library from jsDelivr, which see your IP address when they do. Each tool's page says which applies.
The website is hosted by Vercel, which processes your IP address and request details to serve pages. The request logs we can see there are kept for one day.
The website sets no cookies. Page views are counted with Fathom Analytics, which is cookieless, assigns you no cross-site identifier and builds no profile. To count unique visitors, Fathom briefly processes your IP address and browser details and turns them into a hash that changes every day; for visitors in the EU that happens on EU servers before anything reaches Fathom's servers in the United States. What we see is aggregate: how many people opened a page, which page referred them, roughly which country they were in. Analytics load in production only, including on the blog, and not on these legal pages.
The free tools write values to your browser's localStorage to remember your choices. These values are never sent to a server. The teleprompter also keeps the script you typed. The audio-to-text converters also cache the downloaded speech model in your browser. The cookie policy names each one and explains how to clear it.
Where the EU GDPR or the UK GDPR applies to how we handle your data (for example, because you are in the EU, the EEA or the UK), our legal bases are:
| What | Why | Legal basis |
|---|---|---|
| Your account's email address, Google account identifier, keys and sessions | To create your account, let you sign in, and make sure requests really come from your computer | Performance of a contract |
| Sign-in code records, with keyed one-way codes of your address, computer and IP address | To check codes, and to stop codes being guessed or sent in bulk | Legitimate interests (keeping accounts and the service secure) |
| Your email address given to Cloudflare to send a code | To send you the sign-in or confirmation code you asked for | Performance of a contract |
| Audio sent for transcription, in both modes, and again when you re-transcribe a note, with your personal vocabulary | To deliver the dictation or note you started, or the re-transcription you asked for, spelled the way you asked | Performance of a contract |
| Notes, their titles, tags, folders, reminders, earlier versions and recordings stored in your account, your tags, folders and custom AI actions, your personal vocabulary, the notes PIN hash, the Trash, and your account's settings | To keep your notes and settings on every computer you sign in on, replay recordings for as long as you choose, remind you, and let you restore a deleted note or earlier text | Performance of a contract |
| A note's text sent to OpenAI to write its title, while AI titles is on | To give your notes short titles without you having to write them | Legitimate interests, for the titles the app asks for on its own; you can object at any time by turning AI titles off. Performance of a contract, when you choose Regenerate title |
| A note's text and your tag names sent to OpenAI to pick tags, while AI tags is on | To give your notes some of your own tags without you having to add them | Legitimate interests; you can object at any time by turning AI tags off |
| Text you run an AI action on, with the action's prompt or the language to translate into, sent to OpenAI | To carry out the action you chose | Performance of a contract |
| The sentences around a request to be reminded, with your computer's date, time and time zone, sent to OpenAI, while Reminders from your voice is on | To set the reminder you asked for in a voice note | Performance of a contract; you can turn it off at any time |
| Free allowance counts, and request identifiers and hashes kept for 7 days | To apply the free allowance you signed up for, and not count a retried request twice | Performance of a contract |
| Daily counts of AI actions, automatic AI requests and tokens for each account | To apply the daily limits and keep the cost of AI features in check | Performance of a contract; legitimate interests |
| Device identifier read from your computer's hardware ID | To recognise each computer you sign in on, even after a reinstall, and to apply the account's limit of three computers | Performance of a contract. Reading the identifier from your computer is done only to provide the service you signed up for |
| Monthly usage totals per computer and rate-limit counters | To watch our costs and stop abuse of the service | Legitimate interests |
| Your email address and account identifier given to Polar when you start a checkout, and the subscription record our server keeps | To sell you Pro, know whether it is active, and let you manage it | Performance of a contract (steps you asked for before entering into it, and the contract itself) |
| Server logs and error reports | To keep the service working and secure, and to fix faults | Legitimate interests |
| Update checks | To deliver fixes and security updates to installed copies | Legitimate interests |
| Your account's email address, for messages about your account | To send you sign-in and confirmation codes, and notices of a material change to our terms, to the app or its services, or to this policy | Performance of a contract; legitimate interests (telling you about changes that affect you) |
| Subscriber details Polar shows us in its dashboard | To answer questions about a subscription, arrange refunds, and deal with fraud and chargebacks | Performance of a contract; legitimate interests (preventing fraud and misuse) |
| Email addresses left on the download page | To tell you once that the download is ready | Consent, withdrawable at any time |
| Website request logs | To serve the website and keep it secure | Legitimate interests |
| Aggregate website analytics | To know which pages are worth keeping | Legitimate interests, with no cookies or profiling |
| Files the free tools download from Hugging Face and jsDelivr | To run the tool you opened | Legitimate interests; the tool cannot work without them |
| Notes an AI assistant you connect reads | To answer the assistant app you connected, while you have the setting on | We never receive them. VoiceSnap Pro hands them to that app on your computer, at your request, and the app sends them to its provider, which handles them under its own terms |
| Speech recognition in the voice-typing tools | To run the tool when you press start | We never receive that audio. Your browser sends it to its own speech service (Google, in Chrome), which handles it under its own terms |
| Video players in blog posts (YouTube) | To show the video embedded in the post | Legitimate interests, for loading the player. Google is responsible for what the player itself collects and stores in your browser, under its own privacy policy. We do not currently ask for your consent before a player loads (see the cookie policy) |
| Support email | To answer you, and keep a record of what we agreed | Legitimate interests; performance of a contract when it concerns your account or subscription |
| Accounting and tax records we hold ourselves, such as the records of what Polar pays us | To meet our accounting, tax and other legal duties | Legal obligation (Art. 6(1)(c) GDPR). Portuguese law requires some of these records to be kept for up to 10 years. The records of each sale are Polar's, as merchant of record |
| The records relevant to a dispute | To establish, exercise or defend legal claims | Legitimate interests |
Polar processes your purchase as merchant of record, on its own legal bases, including the tax and accounting obligations that apply to the sale. Google processes your sign-in with Google on its own legal bases.
Do you have to give us this? Using the app's online features means signing in with an email address, sending each computer's device identifier, and sending the audio you want transcribed; without them the app cannot sign you in or transcribe anything. Signed out, the app shows only its sign-in screen. Everything else is your choice. Voice notes are optional: if you want no notes stored in your account, use Dictation only and do not create notes. If you want notes but no recordings kept, set Keep recordings to Don't keep. AI titles, AI tags and Reminders from your voice are on unless you turn them off; with them off, no note's text is sent to OpenAI for a title, tags or a reminder. AI actions send text only when you run one, and can be turned off too. A personal vocabulary is optional. Letting an AI assistant read your notes is off unless you turn it on. Subscribing to Pro, which gives Polar your details, and writing to us are optional too.
Automated decisions. A few things happen automatically. Our server stops transcribing, running AI actions you choose and accepting new notes for an account when that part of its free allowance is used up and it has no active Pro subscription; treats Pro as active or not from what Polar reports, including a payment that has not gone through after the grace period; refuses AI requests beyond the day's limits; signs a computer out when an account goes over its limit of three computers; restricts sign-in codes for an address after many wrong guesses; and slows down a computer or network address that sends too many requests. These apply the plan you chose and protect the service. We do not profile you, and we make no other decisions about you by automated means that have legal or similarly significant effects. If you think one of these went wrong, write to us and a person will look at it.
These companies handle personal data for VoiceSnap Pro. The table gives each one's role. A processor acts only on our instructions and only for the job listed, under a data processing agreement. An independent controller decides for itself how it handles the data it receives, under its own privacy policy. Where we have not yet confirmed a company's terms, the table says so.
| Company | What it does | What it receives | Role | Where |
|---|---|---|---|---|
| OpenAI | Transcribes speech to text; writes note titles and picks among your tags while AI titles and AI tags are on; runs the AI actions you choose; reads the time out of a request to be reminded | Each recording, the language code if you set one, and your personal vocabulary; for a title, the first 6,000 characters of a note's text and its language code; for tags, the first 6,000 characters of a note's text and your tag names; for an AI action, the text you run it on, its language code, and a custom action's prompt or the language to translate into; for a reminder, the sentences around the request, your computer's date, time, time zone and clock format, and the note's language | Processor, under the data processing addendum that forms part of OpenAI's terms | United States and other countries where OpenAI processes data |
| Amazon Web Services | Runs our server, database, recordings storage, backups and logs | Everything our server handles or stores | Processor, under the data processing addendum in the AWS service terms | Ireland (EU) |
| Cloudflare | Sits in front of our server; sends sign-in and confirmation codes by email; also runs the website's DNS | All traffic between the app and our server, decrypted at its edge, including your IP address; for each code email, your email address and the email, code included | Processor for the traffic passing through and the emails it sends; independent controller for some traffic data, such as IP addresses | Global network |
| Polar (Polar Software, Inc.) | Sells Pro as our reseller and merchant of record; runs the checkout, the subscription, renewals and the customer portal | Your purchase details at checkout; from our server, when you start a checkout, your email address and your account's identifier | Merchant of record, responsible for its own records under its privacy policy | United States |
| Google (Google LLC, or Google Ireland Limited in the EEA) | Lets you sign in with your Google account, if you choose to | Your sign-in, on Google's own page in your browser | Independent controller, under its own privacy policy | United States and other countries where Google processes data |
| Sentry (Functional Software, Inc.) | Error and performance monitoring for our server | The error reports described in section 7 | Processor | Sentry's EU region (Germany) |
| GitHub | Hosts app updates | Your IP address and a random update identifier, on each update check | Independent controller for that request data | United States |
| Vercel | Hosts the website and stores the addresses left on the download page | Website requests, including your IP address; addresses left on the download page | Processor, under Vercel's data processing addendum | United States (download-page addresses) and a global network |
| Fathom Analytics | Counts website visits | Your IP address and browser details, briefly, turned into aggregate counts | Processor under Fathom's terms. We have not yet signed its separate data processing agreement | Canada and the United States; EU visitors' IP addresses are hashed in the EU |
| Lunroo | Hosts the blog's content | Requests for blog pages, including your browser's user agent | Not yet confirmed | Not yet confirmed |
| Proton (Proton AG) | Hosts the support mailbox | Email you send us | Processor, under the data processing agreement that forms part of Proton's terms | Switzerland |
AI assistants you connect. If you let an AI assistant read your notes (section 5), the assistant app and its provider receive what it reads. They are not in the table because they do not work for us: we do not choose them, send them anything or receive anything from them. You connect them, and they handle your notes under their own terms.
Beyond that, we disclose personal data only where the law requires it (for example to tax authorities or courts), to professional advisers such as an accountant or lawyer who are bound by confidentiality, or to establish or defend legal claims. We will tell you if the law ever requires us to hand over your data, unless we are legally prevented from doing so. We do not sell personal data, and we do not share it for cross-context behavioural advertising.
| What | Where | How long |
|---|---|---|
| Dictation audio | Your computer's memory; our server's memory; OpenAI | Discarded once the transcript is produced. OpenAI as described in section 3 |
| Dictation history (text and app name), including dictations in the Trash | Your computer only | Until the dictation is deleted for good: when you choose Delete forever, Empty Trash or Clear history…, or 30 days after you move it to the Trash. Only the newest 1,000 outside the Trash are kept |
| Your account: email address, Google account identifier, sign-in dates and settings, including personal vocabulary and the notes PIN hash | Our servers; settings also on your computer | Until you delete your account, including after a subscription ends. No automatic expiry |
| Notes (text, title, tags, folder, reminder and details) | Your computer, and your account on our servers | Until the note is deleted for good: when you choose Delete forever or Empty Trash, or 30 days after you move it to the Trash. Kept when you sign out, use up the free allowance or your subscription ends, with no automatic expiry outside the Trash; deleted with your account |
| Earlier versions of a note's text | Your account on our servers | The 50 newest per note, until the note is deleted for good |
| Tags and folders (names, colours, order, and which notes have each) | Your computer, and your account on our servers | Until you delete the tag or folder, or merge the tag into another; a note's tags go when the note is deleted for good. Deleted with your account |
| Custom AI actions (name, prompt, where the result goes, order) | Your computer, and your account on our servers | Until you delete them, or your account |
| Text sent to OpenAI for a title, for tags, for an AI action or for a reminder, with your tag names, an action's prompt or your computer's date, time and time zone | Our server's memory; OpenAI | Our server keeps no separate copy: it discards the request once OpenAI has answered, and what an AI action returns is kept only where you put it. OpenAI can keep it in its abuse-monitoring logs for up to 30 days, as described in section 3 |
| Free allowance counts | Our servers | Until you delete your account. They never reset |
| Request identifiers and hashes used to count the free allowance | Our servers | 7 days |
| Daily counts of AI actions, automatic AI requests and tokens | Our servers | No automatic expiry today. Deleted with your account |
| Note recordings | Your computer, and your account on our servers | As Keep recordings says: until the note is deleted for good (Forever, the default), 30 days after each recording was added, or not kept at all (Don't keep). They leave storage within about 10 minutes of deletion. On your computer, also within the 500 MB cache described in section 8 |
| Voice note recovery files | Your computer only | Until the note has been saved, or until it is recovered after a crash |
| Deleted or edited note text, titles and tags, earlier versions, deleted or edited tags, folders and custom AI actions, and deleted accounts, in database backups | Our servers | Up to about 16 days (a 14-day backup window, plus the daily snapshot taken just before it) |
| Device records, sessions and monthly usage totals | Our servers | Until you delete your account, including after you sign a computer out. No automatic expiry |
| Request nonces | Our servers | Until that computer's next request, normally about 10 minutes; for a computer that stops contacting us, until its records are deleted |
| Sign-in code records | Our servers | 24 hours with your email address and the code's one-way code; after that only one-way codes and attempt counts, deleted after 30 days |
| Records of a Google sign-in in progress | Our servers | Up to 24 hours |
| Sign-in and confirmation emails | Cloudflare | As long as Cloudflare keeps its email sending logs. Not yet confirmed |
| Your subscription record (Polar identifiers, plan, status and dates) | Our servers | Until you delete your account, including after the subscription ends |
| Notifications from Polar (identifier, type, customer identifiers, time) | Our servers | 90 days |
| Server logs | Our servers | 30 days |
| Error reports | Sentry (EU region, Germany) | Up to 90 days |
| What an AI assistant you connect reads from your notes | That assistant app and its provider | As set out in that provider's terms. It never reaches us |
| Traffic data, such as IP addresses | Cloudflare | As set out in Cloudflare's privacy policy |
| Addresses left on the download page | Vercel | Until we have sent the one email saying the download is ready, or until you ask for deletion, whichever comes first |
| Purchase and subscription records, and the details Polar shows us | Polar | As set out in Polar's privacy policy, including what tax law requires. When you delete your account, we ask Polar to delete your customer record and remove your personal details from it; Polar keeps the orders and invoices the law requires |
| Website request logs we can see | Vercel | One day |
| Accounting and tax records we hold ourselves | Our own records | As long as Portuguese tax and accounting law requires, up to 10 years. The records of each sale are Polar's, as merchant of record (see Purchase and subscription records, above) |
| Support email | Proton | In our mailbox, with no automatic deletion. Ask us and we will delete it, unless we need it for a legal claim or a legal duty |
Our server, database, recordings and logs are in Ireland, inside the EU, and our server's error reports are stored in Sentry's EU region, in Germany. Some of our providers are based outside the European Economic Area, process data there, or may access it from there:
Email us if you want a copy of these safeguards, or want to know which one applies to a specific provider.
Depending on where you live, you have some or all of the following rights: to know what we hold, to get a copy of it, to correct it, to have it deleted, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent. If you are in California, you also have the right not to be discriminated against for exercising them — and since we neither sell nor share personal data, there is nothing to opt out of.
Anything else goes to support@voicesnap.pro: a copy of what we hold about you, including the copy of your notes on our servers and the records described in section 6, in a portable format if you want; a correction, for example of your email address; a restriction or an objection; or deleting your account if you cannot use the app. The steps are at voicesnap.pro/account-delete-request. For an address you left on the download page, writing from that address is enough.
Checking it is you. We act on a request about an account only when it comes from that account's email address, or after you enter a code we send there. If you no longer have access to that address, we will ask for details only the person using the account would know, such as details of recent notes; on that basis we may delete the account, but we will not hand over what is in it.
What we delete. When you delete your account, in the app or through us, we first cancel any Pro subscription at Polar and ask Polar to delete your customer record and remove your personal details from it. If that fails, nothing is deleted and the app asks you to try again later. Then we delete your account record, with your email address and Google account identifier; every note in it, the Trash included, with its earlier versions and recordings; your tags, folders, custom AI actions, reminders, personal vocabulary, notes PIN hash and settings; your free allowance counts and daily AI counts; your subscription record and sign-in code records; and the records and sessions of every computer signed in to it. Recordings leave storage within about 10 minutes of that; copies in database backups expire within about 16 days, and server logs within 30. Error reports at Sentry expire within 90 days; we do not search them one by one. Polar keeps the orders and invoices the law requires it to keep, as merchant of record; ask Polar directly about those.
Your computers. Deleting your account signs out every computer that was signed in to it. Our deletion does not reach the copies of your notes on your other computers: the app there is signed out and shows only its sign-in screen, so remove them by removing the app's folders (section 8). Your dictation history is never touched. Signing in again with the same address creates a new, empty account.
How long it takes. Deleting your account in the app happens at once. We acknowledge an emailed request within two business days and reply within one month. If a request is complex, we may extend this by up to two more months, and we will tell you why within the first month. Requests are free, unless they are clearly unfounded or excessive. Some data cannot be deleted straight away, for example records we must keep for tax purposes; if we cannot do what you ask, we will tell you why.
You can complain to the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD), Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, www.cnpd.pt, or to the data protection authority in the country where you live or work. We would appreciate the chance to sort it out with you first.
No system is perfect, and we are not going to pretend otherwise. If a breach affects your personal data, we will notify the relevant authority within the time the law sets. Where it puts you at high risk, we will also tell you, by the means we have: an email to your account's address, and a notice on this website.
VoiceSnap Pro is not directed at children and is not intended for use by anyone under 16. You must be at least 16 to create an account, and if you are under 16, please don't give us personal data, for example your email address. To subscribe to Pro you must be at least 18 or have a parent's or guardian's permission (see our Terms of Use). We do not knowingly collect personal data from children. If you believe a child has created an account or given us their email address, write to us and we will delete what we hold.
When this policy changes, the date at the top changes with it. If a change materially affects how we handle your data — a new transcription provider, a new category of data, a new purpose — we will say so plainly here, with a summary of what changed, and email it to the address of every account, and to the addresses left on the download page that we still hold, rather than relying on you to re-read the page.
What changed, newest first:
Compared with the version of 3 October 2026. We collect nothing new:
signin@voicesnap.pro. The previous version wrongly gave signin@mail.voicesnap.pro.Compared with the version of 2 October 2026. We collect nothing new:
Compared with the third update of 29 September 2026. Licence keys are replaced by accounts, VoiceSnap Pro is sold as a subscription, and features added since then bring new data and new purposes:
Compared with the second update of 29 September 2026. We collect nothing new, and a note's text is sent to OpenAI for a title less often:
Compared with the first update of 29 September 2026. This update adds tags and AI actions, and with them new data and new purposes:
Compared with the fourth update of 28 September 2026. We collect nothing new, and dictations still never reach our servers:
Compared with the third update of 28 September 2026. We collect nothing new. This update says who we are, fills in facts the policy had marked as unconfirmed, and makes a few changes to whom we may share data with, how long we keep support email, and how we tell licence holders about changes:
Compared with the second update of 28 September 2026:
Compared with the first version of 28 September 2026:
Compared with the version of 19 August 2026:
Questions, requests, or a claim in this document you want us to prove: support@voicesnap.pro. A person reads that inbox.
Iaroslav Morgunov (VoiceSnap Pro)
Rua Alfredo Keil 571, 4150-047 Porto, Portugal
Privacy and support: support@voicesnap.pro · Phone: +351 924331054