Privacy Policy
Last updated: July 15, 2026
Vocory ("the App," "we," "us") is developed by Brandon Kwai. This policy explains what data the App handles, how it's processed, who processes it, and your choices.
The short version
- No account is required. You can use the App fully as a guest — it identifies your device with a randomly generated anonymous identifier, nothing that names you personally. Creating an account (email, or Sign in with Apple or Google) is optional and simply lets your subscription and preferences follow you across devices.
- Your notes are stored on your device. We don't keep copies of your voice notes or their transcripts on our servers (with one narrow exception for podcast imports, described below).
- We never store your audio. Audio is sent for transcription and then discarded.
- We don't sell your data, and we don't track you or show you ads.
Information the App handles
Anonymous device identifier
The App generates a random identifier stored on your device and uses it to associate your requests and subscription status with your device. It is not your name, email, Apple ID, or advertising identifier, and it isn't linked to any personal profile.
Optional account information
If you choose to create an account, we store the information you provide: your email address, first name, and — for email sign-up — your password stored only as a salted cryptographic hash (never in plain text). During email verification we temporarily store a hashed one-time code, which expires within minutes. If you sign in with Apple or Google, we store the stable identifier those services provide (and your email/first name if shared) — never your Apple or Google password, which we never see. An account does not change where your notes live: they remain on your device. You can sign out at any time, and the App continues to work as a guest.
Audio you record
When you record a voice note, the audio is sent to our processing service and on to our speech-to-text provider(s) — OpenAI (Whisper) and/or Soniox — solely to produce a transcript. The audio is processed transiently and is not stored on our servers: it is held only in memory or in a temporary file for the duration of transcription and then deleted. Where a provider processes the audio, it is deleted from that provider after transcription as well.
Transcripts and note text
When you use AI features (such as Summary, Rewrite, Translate, Ask, or Custom actions) or chat about a note, the relevant transcript or note text is sent to OpenAI (GPT-4o-mini) to generate the result. Your notes themselves are stored on your device, not on our servers.
Podcast imports
If you import a podcast, we send the episode's audio URL to our speech-to-text provider (Soniox), which fetches and transcribes it. For podcast imports — and only podcast imports — we store the resulting transcript text and the episode URL on our servers to build and deliver the note. (Voice recordings and other imports are not stored this way.) Our retention policy for these stored podcast transcripts and episode URLs is a maximum of 30 days after the import completes.
Video-link imports
If you import from a video link, we send the video's URL to a third-party transcript provider (Supadata) and to the video platform's public information service to retrieve captions and the title. We do not store the video URL or its transcript on our servers; the transcript is returned to your device.
Subscription data
If you subscribe, the purchase is processed by Apple. We use RevenueCat to manage your subscription status. On our servers we store only whether your subscription is active and when it expires, associated with your anonymous device identifier — not your payment details, which are handled by Apple.
Usage information
To operate free-tier limits and monitor costs, we keep per-request and daily usage records (for example, transcription minutes and counts of AI actions), associated with your anonymous device identifier. These records contain no note content — only counts and metadata.
Third-party processors
We use the following processors, each only for the function described:
- OpenAI — speech-to-text (Whisper) and/or AI text features (GPT-4o-mini): receives audio and/or transcript text.
- Soniox — speech-to-text: receives audio, or a podcast episode URL it fetches itself.
- Supadata — video-link captions: receives a pasted video URL.
- The video platform's public oEmbed service — receives a video URL to return its title.
- Apple / iTunes — podcast lookup: receives podcast identifiers and RSS feeds.
- RevenueCat — subscription management, keyed to your anonymous identifier.
- Resend — transactional email: receives your email address (and first name) solely to deliver account verification codes, if you create an account.
- Railway — our hosting/infrastructure provider.
- Apple — processes your payment if you subscribe.
We do not sell your data, and we do not share it with third parties except these processors acting on our behalf to provide the App.
What we store, and for how long
- On our servers: your anonymous device identifier, subscription status, usage counters, and — for podcast imports only — the imported transcript text and episode URL.
- If you create an account: your email address, first name, hashed password, and (if used) your Apple/Google sign-in identifier — kept until you delete your account.
- On your device: your notes and their transcripts.
- We keep usage records for up to 365 days, after which they are automatically deleted.
- Stored podcast import data (transcript text and episode URL) is subject to a retention policy of no more than 30 days after the import completes.
- Notes on your device remain until you delete them or remove the App.
Tracking
We do not track you. The App does not use advertising identifiers, does not link your data to third-party data for advertising, and includes no ad or analytics-tracking SDKs. No App Tracking Transparency prompt is required.
Your choices and rights
- Delete any note at any time within the App.
- Sign out of your account at any time in Settings — the App keeps working as a guest.
- Request deletion of your account and its data (email, name, sign-in identifiers) by contacting [email protected] from the email on your account.
- Request deletion of the server-side data associated with your device — your subscription status, usage records, and any stored podcast-import transcripts — by contacting us at [email protected]. Because we identify you only by an anonymous device identifier, please include the device ID shown in the App's Settings so we can locate your data.
- Depending on where you live, you may have rights to access, correct, or delete your data, or to object to certain processing. Contact [email protected] to exercise them.
Children's privacy
The App is not directed to children under 16, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact [email protected] and we will delete it.
International processing
Your data may be processed in the United States and other countries where we and our processors operate. Where required, we rely on appropriate safeguards for international transfers.
Security
We use encryption in transit (HTTPS/TLS) for data sent between the App, our servers, and our processors. No method of transmission or storage is completely secure, but we take reasonable measures to protect your information.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above.
Vocory