---
title: "Privacy Policy & Product Data Flow | Voicetypr"
description: "See what Voicetypr processes locally, which features use the network, what license, analytics, and support data is handled, and how to make a privacy request."
image: "https://voicetypr.com/voicetypr-og.png"
canonical_url: "https://voicetypr.com/privacy"
md_url: "https://voicetypr.com/privacy.md"
last_updated: "2026-07-27"
language: "en"
---

# Privacy Policy

Last updated and verified: July 27, 2026

This policy explains the data boundary for Voicetypr's desktop app, website, licensing API, checkout, analytics, and support. The short version: local transcription keeps the speech-recognition step on your device, while several clearly separate features and operating services use a network.

Publisher and verification method

Ideaplexa LLC, the company behind Voicetypr, publishes this policy. We checked the current public desktop repository, this website's API and analytics configuration, the named service-provider policies, the GDPR text, European regulator guidance, California Attorney General guidance, and FTC children's-privacy material. Where a repository summary and the implementation differed, this page follows the implementation reviewed on the date above.

This source review is not an independent legal or security audit, has not been presented as legal advice, and does not certify any deployment or workflow.

## Role-based reading guide and verdicts

### Local-dictation user

Core verdict: with a downloaded local model selected, speech recognition runs on your computer. That does not make the whole app network-free; licensing, updates, diagnostics, and the website use separate paths.

### Privacy or security reviewer

Review the active model, desktop diagnostics setting, optional AI or cloud features, local history, destination app, backups, and license traffic. A local-model label answers only the speech-recognition question.

### Regulated-workflow owner

Local transcription can remove one hosted-audio transfer from a workflow. It does not certify Voicetypr, make a deployment compliant, or replace your legal, security, vendor, and risk review.

### Privacy-rights requester

Email support@voicetypr.com with the request and the account, purchase, or device context needed to locate records. Rights and exceptions depend on the law that applies.

## 1. Scope and who is responsible

This policy applies when you use voicetypr.com, purchase or activate a license, use the Voicetypr desktop app, send a support report, or communicate with us. It does not govern the destination app where you insert text or a third-party provider you choose for optional speech or formatting.

For personal data whose purposes and means Ideaplexa LLC determines, Ideaplexa LLC is the controller. Contact:  [support@voicetypr.com](mailto:support@voicetypr.com). A service provider or your employer can have a separate controller or processor role for its own activity. Polar states that it acts as the Merchant of Record for checkout and processes buyer data under its own terms.

## 2. Data-flow map: what leaves the device, when, and why

The most useful privacy question is not simply “Is Voicetypr offline?” It is which path is active for a particular action. These are the material paths verified for this update.

### Local transcription

When

When a downloaded Whisper or Parakeet model is selected

Data and purpose

Recorded audio is processed by the model on your computer and the generated text is handled locally by Voicetypr. This path does not send the audio or transcript to the Voicetypr API or a hosted speech provider.

Recipient or boundary

The transcript is inserted into the app where your cursor is. Local history, the destination app, its sync features, and device backups can still store or transmit that text.

Your control

Choose a local model and review local history, the destination app, operating-system permissions, disk encryption, sync, and backup settings.

### License and trial checks

When

During trial checks, activation, validation, and deactivation

Data and purpose

A device hash is sent for trial and license operations. Paid-license requests can also include the license key, app version, operating system and version, and an optional device name. Server records can include trial dates, activation and customer references, plan/device limits, last-check timestamps, and operational activity entries.

Recipient or boundary

Voicetypr's API and database; Polar participates in checkout and license-key operations.

Your control

These checks are part of trial and license delivery. They are separate from the audio and transcript handled by local speech recognition.

### Model downloads and app updates

When

When checking for or downloading a model, release, or update

Data and purpose

The request contains ordinary network metadata such as an IP address and user agent. The model-download request does not need the content you dictate.

Recipient or boundary

Release and model hosts, currently including GitHub and Hugging Face for public assets documented in the product source.

Your control

Download required models before an offline session and manage update checks according to your environment. The air-gapped guide explains the remaining deployment limits.

### Optional AI text formatting

When

Only when AI formatting is enabled and used

Data and purpose

The transcribed text and formatting instructions are sent to the provider or compatible endpoint you configure. The original recording is not the input to this formatting request.

Recipient or boundary

The configured text-model provider, such as OpenAI, Anthropic, Google Gemini, or a custom OpenAI-compatible endpoint. That provider's terms and privacy practices apply.

Your control

Leave AI formatting disabled when text must stay on the device, and do not send text that the selected provider is not approved to process.

### Optional hosted speech-to-text

When

Only when a cloud speech provider is selected

Data and purpose

Recorded audio is sent to the selected speech provider for transcription, with request settings needed for that service. This is a different data path from local-model transcription.

Recipient or boundary

The configured hosted speech provider. Its retention, training, access, deletion, and contractual terms govern that request.

Your control

Keep a local model selected when audio must not be sent to a hosted speech service.

### Optional network transcription

When

When a user configures another Voicetypr machine as a transcription server

Data and purpose

Audio crosses the local network to the chosen machine. That can avoid a hosted speech provider, but the audio has still left the originating device.

Recipient or boundary

The Voicetypr server selected on the user's local network, not Voicetypr's hosted API.

Your control

Use only a trusted network and host, configure authentication, and review the network-transcription guide before treating the link as an approved security boundary.

### Desktop diagnostics and operational telemetry

When

In release builds, enabled by default unless disabled in app settings

Data and purpose

The current public implementation permits an install identifier, operating system, architecture, app version, release channel, curated lifecycle events, scrubbed error information, and a one-percent sample of performance transactions. It is designed not to attach raw audio or transcript fields. Structured secrets are redacted from free-form frontend errors, but ordinary prose can remain after that redaction.

Recipient or boundary

A self-hosted GlitchTip endpoint used for Voicetypr diagnostics and operational monitoring.

Your control

Disable diagnostics in the app settings to stop future telemetry egress. The implementation source was treated as authoritative where older repository summary wording differed.

### Support, bug, and crash reports

When

When you submit an in-app report or contact support

Data and purpose

A submitted report can include an optional name and email, your message, app and OS details, architecture, current model, device identifier, timestamp, a redacted app-log excerpt, and crash error or stack details. Automated desktop telemetry is the separate path described above.

Recipient or boundary

Voicetypr's API and a configured Discord webhook for in-app reports; email and other support systems for correspondence you send directly.

Your control

Review the report and avoid including confidential transcript text. Redaction reduces risk but is not a guarantee that every sensitive detail will be removed.

### Website analytics, checkout attribution, and marketing

When

When you visit voicetypr.com

Data and purpose

In production, OpenPanel records screen views, outgoing-link activity, and marked interactions. The OpenPanel device identifier can be attached to checkout metadata; after a completed order, Voicetypr's server sends OpenPanel a revenue-attribution event containing that identifier plus product, currency, subtotal, discount, tax, total, and revenue values. OpenPanel's current policy says it uses IP addresses transiently for approximate location and a daily identifier, then discards the raw IP. Marketing and affiliate tags load when the site's marketing-consent state is true; that state can follow a banner choice or region-aware consent logic.

Recipient or boundary

OpenPanel for site analytics and purchase attribution; Google Tag Manager and configured advertising tags; Affonso for affiliate attribution when marketing is allowed.

Your control

See the Cookie Policy. Browser controls can block or clear cookies, and clearing the Voicetypr consent cookie resets the stored choice.

### Checkout and purchase

When

When you start or complete a purchase

Data and purpose

Polar collects checkout, billing, payment, tax, and buyer information under its own terms. Voicetypr receives the customer, order, refund, product, and license references needed to deliver and support the purchase. When an OpenPanel device identifier is available, it can be carried into checkout metadata and used for the revenue-attribution event described above. Voicetypr's application database does not store full payment-card numbers.

Recipient or boundary

Polar, which states that it acts as Merchant of Record, and Voicetypr's license and support systems.

Your control

Review Polar's checkout notice and privacy policy before purchasing. Contact us if a purchase record needs to be located or corrected.

## 3. Information categories and purposes

### License, trial, and device records

We use device hashes, trial dates, license and activation references, limited OS/app metadata, plan information, and activity records to start and enforce trials, activate and validate licenses, apply device limits, prevent abuse, diagnose failures, process refunds, and support customers. A device hash is an identifier; calling it a hash does not make it anonymous in this operational context.

### Purchase and correspondence records

We use order, customer, product, refund, and license references to deliver the purchase and answer account questions. We use the name, email, message, and other information you send to respond to support, privacy, and business correspondence. Do not put sensitive material in a message unless it is needed for the request.

### Diagnostics, analytics, and attribution

We use the desktop diagnostic fields, site analytics events, consent state, referral information, and marketing events described above to find crashes and performance problems, understand site usage, measure referrals and campaigns, secure services, and improve the product. The desktop diagnostic setting and website marketing-consent state are separate controls.

## 4. What local transcription does and does not mean

- With a local model selected, the hosted Voicetypr API does not receive the raw microphone recording or generated transcript through the speech-recognition path.
- Audio or video files you deliberately transcribe with a local model stay in the local processing path.
- The resulting text can remain in local history and is sent to the destination app by design. That app, collaboration, sync, clipboard, backups, and device security remain outside Voicetypr's hosted-data boundary.
- Selecting cloud speech sends audio, enabling AI formatting sends text, and selecting a network server sends audio to another machine. Review the active configuration rather than relying on the product's default.
- Local processing is not the same as local encryption, zero telemetry, zero license traffic, zero retention on your computer, or a compliance guarantee.

## 5. Website cookies, analytics, and marketing controls

The website sets a region/session signal and can store a  `vt_consent` cookie for up to 180 days. Where the site's region logic requires a prompt, marketing starts after acceptance. Where that logic records that a prompt is not required, it can set the marketing state automatically. Affonso is configured with a 30-day attribution window when loaded.

OpenPanel analytics is separate from those marketing tags and loads on the production site. Its provider policy currently describes cookieless analytics, transient IP use, approximate location, and a daily rotating identifier. Those are provider statements, not an independent audit by Voicetypr. Read the  [Cookie Policy](https://voicetypr.com/cookies) and use browser settings to clear or block stored identifiers.

## 6. Purposes and legal bases where the GDPR applies

The appropriate basis depends on the activity and circumstances. The European Commission's  [legal-grounds overview](https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/legal-grounds-processing-data_en) explains the available bases. We generally rely on:

- Contract or steps you request: checkout handoff, trial and license delivery, activation, validation, refunds, and support related to the product you use or purchase.
- Legitimate interests: service security, abuse prevention, limited operational diagnostics, support, and cookieless site analytics, subject to the required necessity and rights-balancing assessment.
- Consent: marketing or similar storage/access where consent is required, and any activity for which we specifically ask for consent. Consent can be withdrawn for future processing.
- Legal obligation: records needed for tax, accounting, fraud response, valid legal process, or other duties that apply to us.

## 7. Recipients and service-provider categories

- Polar: checkout, payment, tax, customer/order records, refunds, and license-key operations as Merchant of Record.
- Hosting, database, and cache providers: operation and security of the website, licensing API, trials, and related records.
- GlitchTip: self-hosted desktop diagnostic and operational telemetry described in the data-flow map.
- Discord and support systems: delivery and handling of reports or messages you submit.
- OpenPanel: production website analytics and purchase-attribution events using a carried device identifier and order-value fields.
- Google Tag Manager, configured ad tags, and Affonso: marketing, conversion, and affiliate attribution when the marketing state permits loading.
- GitHub and Hugging Face: current public release and model-download hosting.
- Providers you choose: optional text-formatting, cloud speech, custom endpoints, and the destination app where Voicetypr inserts text.

Providers can change as the service changes. We will update this policy when a change materially affects the disclosures here. Third parties process data under their own terms and, depending on the activity, may be our processor, subprocessor, or an independent controller.

## 8. Retention

We use the purpose, license lifecycle, legal duties, security need, and dispute/support context to decide how long server-side records are kept:

- License, purchase, and refund records are kept while needed to deliver and support the license and to meet accounting, tax, fraud, and dispute obligations.
- Trial, device, validation, and activity records are kept while needed for trial enforcement, license operation, abuse prevention, debugging, and support.
- Support and privacy-request records are kept while handling the request and for reasonable follow-up, security, and recordkeeping needs.
- Analytics, telemetry, marketing, and provider-side records follow the applicable configuration and provider retention. You can ask us for current details relevant to your request.
- Local recordings, files, transcripts, and history are controlled by the app and device rather than this server-side retention schedule.

Retention can be extended where law requires it or a record is needed to establish, exercise, or defend a legal claim. A deletion request can be subject to those and other lawful exceptions.

## 9. Security and local-device responsibility

We use technical and organizational measures intended to protect the server-side information we handle and limit access to people and providers who need it for the purposes above. No service can promise perfect security. Local transcription also does not secure the computer, encrypt its disk, control clipboard managers, or change the security of the destination app, synced folder, backup, or network server you choose.

Review operating-system account security, full-disk encryption, permissions, backups, destination applications, and organizational controls before dictating confidential or regulated material.

## 10. Your privacy rights

Depending on where you live, the processing involved, and applicable exceptions, you may be able to request access, correction, deletion, restriction, objection, or portability; withdraw consent for future consent-based processing; and complain to a competent privacy authority. The  [European Data Protection Board](https://www.edpb.europa.eu/topics/key-gdpr-concepts/data-subject-rights_en) summarizes GDPR rights.

Submit a request to  [support@voicetypr.com](mailto:support@voicetypr.com). Describe the request and provide enough account, purchase, or device context for us to find the relevant records. We may need to verify your identity and authority before disclosing or changing data. We will assess the request under the law that applies rather than assuming every right applies to every record.

## 11. California privacy notice

The categories we may handle include identifiers, device and internet activity information, commercial information, and support or correspondence content, for the purposes and recipients described above. We do not sell personal information for money. Advertising and affiliate disclosures can potentially be treated as “sharing” for cross-context behavioral advertising under California law even when no money is paid for the data.

If the CCPA applies to our processing, California residents can request to know, access, delete, or correct eligible information, opt out of sale or sharing, limit certain uses of sensitive personal information where the right applies, and receive nondiscriminatory treatment for exercising those rights. The  [California Attorney General's CCPA page](https://oag.ca.gov/privacy/ccpa) explains these rights. Send a request or opt-out instruction to  [support@voicetypr.com](mailto:support@voicetypr.com). You can also block marketing tags with browser controls and clear the stored consent cookie.

## 12. International transfers

Ideaplexa LLC is in the United States, and providers or user-selected endpoints can process data in other countries. Where the GDPR restricts a transfer outside the EEA, the available mechanisms can include an adequacy decision, approved Standard Contractual Clauses, another appropriate safeguard with enforceable rights, or a specific lawful derogation. The mechanism depends on the recipient and transfer; this policy does not claim that one mechanism covers every path. See the  [European Commission's transfer overview](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/rules-international-data-transfers_en).

## 13. Children's privacy

Voicetypr is not directed to children under 13, and we do not knowingly collect personal information online from a child under 13 without the authorization required by applicable law. If you believe a child has provided information to us, contact support@voicetypr.com so we can investigate and take appropriate action. The  [FTC's COPPA resources](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/kids-privacy-coppa) explain the United States under-13 framework.

## 14. Changes to this policy

We may update this policy when the product, providers, data practices, or law changes. We will change the date above and provide additional notice when appropriate for a material change. Previous wording should not be treated as evidence that a current build has the same settings or data paths.

## 15. Contact

For privacy questions, requests, or complaints:

Ideaplexa LLC

30 N Gould St Ste N

Sheridan, WY 82801

United States

Email:  [support@voicetypr.com](mailto:support@voicetypr.com)

## Related privacy and deployment guides

[Local data-flow boundaries Why local speech recognition is narrower than a zero-total-collection claim.](https://voicetypr.com/zero-knowledge)[Offline dictation buyer guide Compare what offline means across setup, transcription, licensing, and optional features.](https://voicetypr.com/best/offline-dictation)[Air-gapped deployment limits Plan downloads, activation, updates, and validation before a disconnected session.](https://voicetypr.com/air-gapped)[Network transcription Understand the separate boundary created when audio moves to another machine on a LAN.](https://voicetypr.com/network-transcription)[GDPR workflow guide Use local processing as one input to a broader controller, processor, and risk assessment.](https://voicetypr.com/gdpr-compliant)[HIPAA-conscious dictation Review healthcare workflow responsibilities without treating product architecture as certification.](https://voicetypr.com/hipaa-compliant-dictation)

## Verification sources

These primary product, provider, statutory, and regulator sources were reviewed for this update. A link is evidence for the specific point in its label, not an endorsement or a substitute for checking the source again when you make a decision.

- [Voicetypr public product repository and processing overview](https://github.com/ideaplexa/voicetypr)
- [Desktop telemetry defaults, fields, scrubbing, and consent gates](https://github.com/ideaplexa/voicetypr/blob/main/src-tauri/src/telemetry.rs)
- [Optional cloud speech provider implementations](https://github.com/ideaplexa/voicetypr/tree/main/src-tauri/src/cloud_stt)
- [Optional AI formatting provider catalog](https://github.com/ideaplexa/voicetypr/blob/main/src-tauri/catalog/catalog.generated.json)
- [License client implementation](https://github.com/ideaplexa/voicetypr/blob/main/src-tauri/src/license/api_client.rs)
- [Whisper model download hosts and checksum validation](https://github.com/ideaplexa/voicetypr/blob/main/src-tauri/src/whisper/manager.rs)
- [Polar buyer terms and Merchant of Record role](https://polar.sh/legal/checkout-buyer-terms)
- [Polar privacy policy](https://polar.sh/legal/privacy-policy)
- [OpenPanel privacy policy and analytics-data description](https://openpanel.dev/privacy)
- [Official text of the GDPR](https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng/)
- [European Commission: legal grounds for processing](https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/legal-grounds-processing-data_en)
- [European Data Protection Board: data-subject rights](https://www.edpb.europa.eu/topics/key-gdpr-concepts/data-subject-rights_en)
- [European Commission: international-transfer safeguards](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/rules-international-data-transfers_en)
- [California Attorney General: CCPA rights](https://oag.ca.gov/privacy/ccpa)
- [Federal Trade Commission: children's privacy and COPPA](https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/kids-privacy-coppa)
