Privacy Policy
Last updated and verified:
This policy explains the data boundary for Voicetypr's desktop app, website, licensing API, checkout, analytics, and support. The short version: local transcription keeps the speech-recognition step on your device, while several clearly separate features and operating services use a network.
Role-based reading guide and verdicts
Local-dictation user
Core verdict: with a downloaded local model selected, speech recognition runs on your computer. That does not make the whole app network-free; licensing, updates, diagnostics, and the website use separate paths.
Privacy or security reviewer
Review the active model, desktop diagnostics setting, optional AI or cloud features, local history, destination app, backups, and license traffic. A local-model label answers only the speech-recognition question.
Regulated-workflow owner
Local transcription can remove one hosted-audio transfer from a workflow. It does not certify Voicetypr, make a deployment compliant, or replace your legal, security, vendor, and risk review.
Privacy-rights requester
Email support@voicetypr.com with the request and the account, purchase, or device context needed to locate records. Rights and exceptions depend on the law that applies.
1. Scope and who is responsible
This policy applies when you use voicetypr.com, purchase or activate a license, use the Voicetypr desktop app, send a support report, or communicate with us. It does not govern the destination app where you insert text or a third-party provider you choose for optional speech or formatting.
For personal data whose purposes and means Ideaplexa LLC determines, Ideaplexa LLC is the controller. Contact: support@voicetypr.com. A service provider or your employer can have a separate controller or processor role for its own activity. Polar states that it acts as the Merchant of Record for checkout and processes buyer data under its own terms.
2. Data-flow map: what leaves the device, when, and why
The most useful privacy question is not simply “Is Voicetypr offline?” It is which path is active for a particular action. These are the material paths verified for this update.
Local transcription
- When
- When a downloaded Whisper or Parakeet model is selected
- Data and purpose
- Recorded audio is processed by the model on your computer and the generated text is handled locally by Voicetypr. This path does not send the audio or transcript to the Voicetypr API or a hosted speech provider.
- Recipient or boundary
- The transcript is inserted into the app where your cursor is. Local history, the destination app, its sync features, and device backups can still store or transmit that text.
- Your control
- Choose a local model and review local history, the destination app, operating-system permissions, disk encryption, sync, and backup settings.
License and trial checks
- When
- During trial checks, activation, validation, and deactivation
- Data and purpose
- A device hash is sent for trial and license operations. Paid-license requests can also include the license key, app version, operating system and version, and an optional device name. Server records can include trial dates, activation and customer references, plan/device limits, last-check timestamps, and operational activity entries.
- Recipient or boundary
- Voicetypr's API and database; Polar participates in checkout and license-key operations.
- Your control
- These checks are part of trial and license delivery. They are separate from the audio and transcript handled by local speech recognition.
Model downloads and app updates
- When
- When checking for or downloading a model, release, or update
- Data and purpose
- The request contains ordinary network metadata such as an IP address and user agent. The model-download request does not need the content you dictate.
- Recipient or boundary
- Release and model hosts, currently including GitHub and Hugging Face for public assets documented in the product source.
- Your control
- Download required models before an offline session and manage update checks according to your environment. The air-gapped guide explains the remaining deployment limits.
Optional AI text formatting
- When
- Only when AI formatting is enabled and used
- Data and purpose
- The transcribed text and formatting instructions are sent to the provider or compatible endpoint you configure. The original recording is not the input to this formatting request.
- Recipient or boundary
- The configured text-model provider, such as OpenAI, Anthropic, Google Gemini, or a custom OpenAI-compatible endpoint. That provider's terms and privacy practices apply.
- Your control
- Leave AI formatting disabled when text must stay on the device, and do not send text that the selected provider is not approved to process.
Optional hosted speech-to-text
- When
- Only when a cloud speech provider is selected
- Data and purpose
- Recorded audio is sent to the selected speech provider for transcription, with request settings needed for that service. This is a different data path from local-model transcription.
- Recipient or boundary
- The configured hosted speech provider. Its retention, training, access, deletion, and contractual terms govern that request.
- Your control
- Keep a local model selected when audio must not be sent to a hosted speech service.
Optional network transcription
- When
- When a user configures another Voicetypr machine as a transcription server
- Data and purpose
- Audio crosses the local network to the chosen machine. That can avoid a hosted speech provider, but the audio has still left the originating device.
- Recipient or boundary
- The Voicetypr server selected on the user's local network, not Voicetypr's hosted API.
- Your control
- Use only a trusted network and host, configure authentication, and review the network-transcription guide before treating the link as an approved security boundary.
Desktop diagnostics and operational telemetry
- When
- In release builds, enabled by default unless disabled in app settings
- Data and purpose
- The current public implementation permits an install identifier, operating system, architecture, app version, release channel, curated lifecycle events, scrubbed error information, and a one-percent sample of performance transactions. It is designed not to attach raw audio or transcript fields. Structured secrets are redacted from free-form frontend errors, but ordinary prose can remain after that redaction.
- Recipient or boundary
- A self-hosted GlitchTip endpoint used for Voicetypr diagnostics and operational monitoring.
- Your control
- Disable diagnostics in the app settings to stop future telemetry egress. The implementation source was treated as authoritative where older repository summary wording differed.
Support, bug, and crash reports
- When
- When you submit an in-app report or contact support
- Data and purpose
- A submitted report can include an optional name and email, your message, app and OS details, architecture, current model, device identifier, timestamp, a redacted app-log excerpt, and crash error or stack details. Automated desktop telemetry is the separate path described above.
- Recipient or boundary
- Voicetypr's API and a configured Discord webhook for in-app reports; email and other support systems for correspondence you send directly.
- Your control
- Review the report and avoid including confidential transcript text. Redaction reduces risk but is not a guarantee that every sensitive detail will be removed.
Website analytics, checkout attribution, and marketing
- When
- When you visit voicetypr.com
- Data and purpose
- In production, OpenPanel records screen views, outgoing-link activity, and marked interactions. The OpenPanel device identifier can be attached to checkout metadata; after a completed order, Voicetypr's server sends OpenPanel a revenue-attribution event containing that identifier plus product, currency, subtotal, discount, tax, total, and revenue values. OpenPanel's current policy says it uses IP addresses transiently for approximate location and a daily identifier, then discards the raw IP. Marketing and affiliate tags load when the site's marketing-consent state is true; that state can follow a banner choice or region-aware consent logic.
- Recipient or boundary
- OpenPanel for site analytics and purchase attribution; Google Tag Manager and configured advertising tags; Affonso for affiliate attribution when marketing is allowed.
- Your control
- See the Cookie Policy. Browser controls can block or clear cookies, and clearing the Voicetypr consent cookie resets the stored choice.
Checkout and purchase
- When
- When you start or complete a purchase
- Data and purpose
- Polar collects checkout, billing, payment, tax, and buyer information under its own terms. Voicetypr receives the customer, order, refund, product, and license references needed to deliver and support the purchase. When an OpenPanel device identifier is available, it can be carried into checkout metadata and used for the revenue-attribution event described above. Voicetypr's application database does not store full payment-card numbers.
- Recipient or boundary
- Polar, which states that it acts as Merchant of Record, and Voicetypr's license and support systems.
- Your control
- Review Polar's checkout notice and privacy policy before purchasing. Contact us if a purchase record needs to be located or corrected.
3. Information categories and purposes
License, trial, and device records
We use device hashes, trial dates, license and activation references, limited OS/app metadata, plan information, and activity records to start and enforce trials, activate and validate licenses, apply device limits, prevent abuse, diagnose failures, process refunds, and support customers. A device hash is an identifier; calling it a hash does not make it anonymous in this operational context.
Purchase and correspondence records
We use order, customer, product, refund, and license references to deliver the purchase and answer account questions. We use the name, email, message, and other information you send to respond to support, privacy, and business correspondence. Do not put sensitive material in a message unless it is needed for the request.
Diagnostics, analytics, and attribution
We use the desktop diagnostic fields, site analytics events, consent state, referral information, and marketing events described above to find crashes and performance problems, understand site usage, measure referrals and campaigns, secure services, and improve the product. The desktop diagnostic setting and website marketing-consent state are separate controls.
4. What local transcription does and does not mean
- With a local model selected, the hosted Voicetypr API does not receive the raw microphone recording or generated transcript through the speech-recognition path.
- Audio or video files you deliberately transcribe with a local model stay in the local processing path.
- The resulting text can remain in local history and is sent to the destination app by design. That app, collaboration, sync, clipboard, backups, and device security remain outside Voicetypr's hosted-data boundary.
- Selecting cloud speech sends audio, enabling AI formatting sends text, and selecting a network server sends audio to another machine. Review the active configuration rather than relying on the product's default.
- Local processing is not the same as local encryption, zero telemetry, zero license traffic, zero retention on your computer, or a compliance guarantee.
5. Website cookies, analytics, and marketing controls
The website sets a region/session signal and can store a vt_consent cookie for up to 180 days. Where the site's region logic requires a prompt, marketing starts after acceptance. Where that logic records that a prompt is not required, it can set the marketing state automatically. Affonso is configured with a 30-day attribution window when loaded.
OpenPanel analytics is separate from those marketing tags and loads on the production site. Its provider policy currently describes cookieless analytics, transient IP use, approximate location, and a daily rotating identifier. Those are provider statements, not an independent audit by Voicetypr. Read the Cookie Policy and use browser settings to clear or block stored identifiers.
6. Purposes and legal bases where the GDPR applies
The appropriate basis depends on the activity and circumstances. The European Commission's legal-grounds overview explains the available bases. We generally rely on:
- Contract or steps you request: checkout handoff, trial and license delivery, activation, validation, refunds, and support related to the product you use or purchase.
- Legitimate interests: service security, abuse prevention, limited operational diagnostics, support, and cookieless site analytics, subject to the required necessity and rights-balancing assessment.
- Consent: marketing or similar storage/access where consent is required, and any activity for which we specifically ask for consent. Consent can be withdrawn for future processing.
- Legal obligation: records needed for tax, accounting, fraud response, valid legal process, or other duties that apply to us.
7. Recipients and service-provider categories
- Polar: checkout, payment, tax, customer/order records, refunds, and license-key operations as Merchant of Record.
- Hosting, database, and cache providers: operation and security of the website, licensing API, trials, and related records.
- GlitchTip: self-hosted desktop diagnostic and operational telemetry described in the data-flow map.
- Discord and support systems: delivery and handling of reports or messages you submit.
- OpenPanel: production website analytics and purchase-attribution events using a carried device identifier and order-value fields.
- Google Tag Manager, configured ad tags, and Affonso: marketing, conversion, and affiliate attribution when the marketing state permits loading.
- GitHub and Hugging Face: current public release and model-download hosting.
- Providers you choose: optional text-formatting, cloud speech, custom endpoints, and the destination app where Voicetypr inserts text.
Providers can change as the service changes. We will update this policy when a change materially affects the disclosures here. Third parties process data under their own terms and, depending on the activity, may be our processor, subprocessor, or an independent controller.
8. Retention
We use the purpose, license lifecycle, legal duties, security need, and dispute/support context to decide how long server-side records are kept:
- License, purchase, and refund records are kept while needed to deliver and support the license and to meet accounting, tax, fraud, and dispute obligations.
- Trial, device, validation, and activity records are kept while needed for trial enforcement, license operation, abuse prevention, debugging, and support.
- Support and privacy-request records are kept while handling the request and for reasonable follow-up, security, and recordkeeping needs.
- Analytics, telemetry, marketing, and provider-side records follow the applicable configuration and provider retention. You can ask us for current details relevant to your request.
- Local recordings, files, transcripts, and history are controlled by the app and device rather than this server-side retention schedule.
Retention can be extended where law requires it or a record is needed to establish, exercise, or defend a legal claim. A deletion request can be subject to those and other lawful exceptions.
9. Security and local-device responsibility
We use technical and organizational measures intended to protect the server-side information we handle and limit access to people and providers who need it for the purposes above. No service can promise perfect security. Local transcription also does not secure the computer, encrypt its disk, control clipboard managers, or change the security of the destination app, synced folder, backup, or network server you choose.
Review operating-system account security, full-disk encryption, permissions, backups, destination applications, and organizational controls before dictating confidential or regulated material.
10. Your privacy rights
Depending on where you live, the processing involved, and applicable exceptions, you may be able to request access, correction, deletion, restriction, objection, or portability; withdraw consent for future consent-based processing; and complain to a competent privacy authority. The European Data Protection Board summarizes GDPR rights.
Submit a request to support@voicetypr.com. Describe the request and provide enough account, purchase, or device context for us to find the relevant records. We may need to verify your identity and authority before disclosing or changing data. We will assess the request under the law that applies rather than assuming every right applies to every record.
11. California privacy notice
The categories we may handle include identifiers, device and internet activity information, commercial information, and support or correspondence content, for the purposes and recipients described above. We do not sell personal information for money. Advertising and affiliate disclosures can potentially be treated as “sharing” for cross-context behavioral advertising under California law even when no money is paid for the data.
If the CCPA applies to our processing, California residents can request to know, access, delete, or correct eligible information, opt out of sale or sharing, limit certain uses of sensitive personal information where the right applies, and receive nondiscriminatory treatment for exercising those rights. The California Attorney General's CCPA page explains these rights. Send a request or opt-out instruction to support@voicetypr.com. You can also block marketing tags with browser controls and clear the stored consent cookie.
12. International transfers
Ideaplexa LLC is in the United States, and providers or user-selected endpoints can process data in other countries. Where the GDPR restricts a transfer outside the EEA, the available mechanisms can include an adequacy decision, approved Standard Contractual Clauses, another appropriate safeguard with enforceable rights, or a specific lawful derogation. The mechanism depends on the recipient and transfer; this policy does not claim that one mechanism covers every path. See the European Commission's transfer overview.
13. Children's privacy
Voicetypr is not directed to children under 13, and we do not knowingly collect personal information online from a child under 13 without the authorization required by applicable law. If you believe a child has provided information to us, contact support@voicetypr.com so we can investigate and take appropriate action. The FTC's COPPA resources explain the United States under-13 framework.
14. Changes to this policy
We may update this policy when the product, providers, data practices, or law changes. We will change the date above and provide additional notice when appropriate for a material change. Previous wording should not be treated as evidence that a current build has the same settings or data paths.
15. Contact
For privacy questions, requests, or complaints:
Ideaplexa LLC30 N Gould St Ste N
Sheridan, WY 82801
United States
Email: support@voicetypr.com
Related privacy and deployment guides
Verification sources
These primary product, provider, statutory, and regulator sources were reviewed for this update. A link is evidence for the specific point in its label, not an endorsement or a substitute for checking the source again when you make a decision.
- Voicetypr public product repository and processing overview
- Desktop telemetry defaults, fields, scrubbing, and consent gates
- Optional cloud speech provider implementations
- Optional AI formatting provider catalog
- License client implementation
- Whisper model download hosts and checksum validation
- Polar buyer terms and Merchant of Record role
- Polar privacy policy
- OpenPanel privacy policy and analytics-data description
- Official text of the GDPR
- European Commission: legal grounds for processing
- European Data Protection Board: data-subject rights
- European Commission: international-transfer safeguards
- California Attorney General: CCPA rights
- Federal Trade Commission: children's privacy and COPPA