Legal
Privacy Policy
What we collect, what we deliberately do not collect, and what rights you have over it.
Last updated: 21 July 2026
In short
Personal details spoken to a Voxide agent are removed before they are stored. Email addresses, phone numbers, payment card numbers, national ID numbers and bank account numbers are stripped out at the moment a conversation is saved. The original values never reach our database, so they are not visible to the business running the assistant, and not visible to us.
We do not sell personal data, and we do not use conversations to train AI models.
Voice and text are processed by Google's Gemini models to generate a reply. That happens live, during the conversation.
If you spoke to an assistant on someone else's website, that business decides what the assistant does and how long conversations are kept. Contact them first, we will help if you can't reach them.
This summary is for orientation only, the full text below is what governs.
1. Who we are
Voxide is a voice AI SDK. Businesses and developers (“Customers”) embed our assistant into their own websites so their visitors (“End Users”) can speak or type to get things done.
Voxide is operated by Miheretab Samson, a sole trader based in Ethiopia. There is no separate incorporated company at this time; the operator is the data controller for this website and for Customer accounts.
You can reach us about anything in this policy at support@voxide.app.
2. Our two different roles
This is the most important distinction in this policy, because it determines who you should contact about your data.
For Customer accounts, we are the controller. When a developer signs up for Voxide, we decide how their account data is handled, and this policy governs it directly.
For End User conversations, we are a processor. When somebody talks to an assistant embedded on a Customer's website, that Customer is the controller: they chose to deploy the assistant, they decide what it does, and they are responsible for telling their visitors about it and obtaining any consent required. We process that conversation on their instructions and do not use it for our own purposes.
3. What we collect
Customer account data (we are controller):
- Name and email address, used to create and secure your account.
- Authentication data, including any third-party sign-in identifiers you choose to use.
- Billing information. Payments are handled by our payment provider, we do not store full card numbers.
- Project configuration: assistant instructions, capabilities, appearance, and settings.
- Product usage and diagnostics such as session counts, error rates and request volumes.
End User conversation data (we are processor):
- Conversation transcripts, a text record of what was said, stored after the redaction described in section 4.
- Capability call records, which actions the assistant performed and the arguments passed to them, also redacted before storage.
- Session metadata, start and end time, duration, message count, the page origin, and a randomly generated identifier stored in the browser.
Audio is not stored. Speech is transcribed to text during the conversation and the audio itself is not written to our systems.
We do not use conversations to train AI models, ours or anyone else's.
4. Removing personal data before it is stored
Conversation content is filtered before it is written to our database, not hidden afterwards. This matters: the original values are never stored at all, so they cannot be read by the Customer, cannot be read by our staff, cannot appear in a backup, and cannot be produced in response to a legal request. This removal is permanent and cannot be reversed.
Always removed, and this cannot be disabled:
- Payment card numbers (validated to avoid removing ordinary reference numbers)
- National identification numbers
- International bank account numbers (IBANs)
Removed by default, and configurable by the Customer:
- Email addresses
- Phone numbers
- IP addresses
Customer-declared fields. Customers can mark specific pieces of information their assistant collects, a name or a delivery address, for example, as sensitive. Those are replaced before storage with no pattern matching involved.
5. Why we process it, and our lawful basis
For Customer account data, where we act as controller:
- To provide the service, performance of our contract with you.
- To take payment, performance of a contract, and compliance with tax and accounting obligations.
- To keep the service secure and reliable, our legitimate interest in preventing abuse and diagnosing faults.
- To send service messages such as billing and security notices, performance of a contract. Marketing email, if any, is sent only with consent and can be withdrawn at any time.
For End User conversation data we act on the Customer's instructions, and the lawful basis is the Customer's to establish as controller, they decided to deploy the assistant and they decide what it collects.
6. Who we share data with
We do not sell personal data and we do not share it for advertising. We use the following service providers to operate Voxide:
| Provider | Purpose |
|---|---|
| Runs the Gemini models that understand speech and generate replies. Voice and text are sent to Google during a conversation. Typed messages are also sent to Google to generate embeddings for document search. | |
| Supabase | Database, authentication and file storage. |
| Vercel | Hosting for the website and dashboard. |
| Render | Hosting for the real-time voice service. |
| Resend | Sending transactional email. |
| Polar | Subscription billing and payment processing. |
We may also disclose data where legally required, or as part of a merger or acquisition, in which case we will notify affected Customers. If we add a provider that handles personal data, we will update this list before doing so.
7. International transfers
Our providers operate globally, so personal data may be processed outside the country where it was collected, including in the United States. Where data is transferred out of the UK or European Economic Area, we rely on the UK International Data Transfer Agreement or the European Commission's Standard Contractual Clauses, as offered by each provider in their own data processing terms.
8. How long we keep it
- Conversation transcripts and capability records: 90 days, then deleted automatically. Customers can delete them sooner at any time, and deleting a project deletes its conversations immediately.
- Session metadata (timing, counts, page origin): 12 months, after which it is aggregated into figures that identify nobody.
- Customer account data: for as long as the account is open, and for 30 days after closure so it can be restored if the account was closed by mistake.
- Billing records: retained as long as tax and accounting law requires, which is longer than the periods above and outside our discretion.
9. Your rights
If you are in the UK or European Economic Area, you have the right to access your data; correct it; have it erased; restrict or object to how it is used; receive it in a portable format; and withdraw consent at any time where consent is the basis for processing.
To exercise any of these, email support@voxide.app. We respond within one month. We may need to verify your identity first.
If your data was collected by an assistant on a Customer's website, please direct your request to that Customer, since they control it, see section 2. We will assist them in responding.
You also have the right to complain to a supervisory authority, in the UK, the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to address your concern first.
11. Security
Data is encrypted in transit. Access to production systems is restricted to staff who need it. Customer data is separated so one Customer cannot access another's. The redaction described in section 4 is itself a security control: the most sensitive data is never collected, and data that does not exist cannot be breached.
If a breach occurs that is likely to result in a risk to people's rights, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and affected individuals where the risk is high.
12. Children
Voxide is not intended for children. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Changes to this policy
We will update the date at the top of this page when this policy changes. For changes that significantly affect how we handle personal data, we will notify Customers directly.
14. Contact
Questions, requests, or complaints: support@voxide.app.
See also our Terms of Service.
