VibeVoice

Privacy Policy

Last updated: 2026-09-09

1. Data Protection at a Glance

General Information

The following notes provide a simple overview of what happens to your personal data when you visit our website or use our service (such as uploading audio or video files as well as real-time voice streaming for transcription). Personal data is any data with which you could be personally identified. Detailed information on the subject of data protection can be found in our privacy policy listed below this text.

Data Collection on Our Website and in the Service

Who is responsible for data processing? Data processing is carried out by the operator of the website and the VibeVoice application. You can find their contact details in the "Note regarding the responsible party" section in this privacy policy.

How do we collect your data? On the one hand, your data is collected when you provide it to us. This could be, for example, data you enter during registration, in a support contact form, or via email. This includes master data such as your name, email address, and your specific request.

Other data is collected automatically or with your consent by our IT systems when you use our website or application. This is primarily technical data (e.g., IP address, date/time, browser used, operating system, pages/files accessed, referrer URL). This data is recorded automatically in server-side log files as soon as you visit our website.

When using VibeVoice, audio and video data are also collected to process your voice inputs. You can find more detailed information on this in the corresponding sections of this privacy policy.

What do we use your data for? Part of the data is collected to ensure the error-free provision of the website and the application (registration, authentication, transcription function via file upload or streaming, quota management). Other data is used for the security and stability of our offer (abuse/fraud detection, error analysis, defense against attacks). Furthermore, we process data to communicate with you and to comply with legal obligations.

What rights do you have regarding your data? You have the right to receive information about the origin, recipient, and purpose of your stored personal data free of charge at any time. You also have the right to request the correction or deletion of this data. If you have given your consent to data processing, you can revoke this consent at any time for the future. You also have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

You can contact us at any time regarding this and other questions on the subject of data protection.


2. General Notes and Mandatory Information

Data Protection

The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

We would like to point out that data transmission over the Internet (e.g., communication by email) can have security gaps. A complete protection of the data against access by third parties is not possible.

Note Regarding the Responsible Party (Data Controller)

The responsible party for data processing on this website and in the VibeVoice service is:

VibeVoice - Florian Schneider c/o Online-Impressum.de #37276 Europaring 90 53757 Sankt Augustin Germany

Email: [email protected] Secondary contact method: [email protected]

The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g., names, email addresses, etc.).

Storage Duration

Unless a more specific storage period has been specified within this privacy policy, your personal data will remain with us until the purpose for the data processing no longer applies. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, the deletion will take place after these reasons no longer apply. Server logs are kept for a maximum of 14 days and then automatically deleted. Uploaded or streamed audio and video data are deleted from our servers as soon as the transcription has been completed or has failed. Transcripts of transcription jobs are kept for 365 days from the day the job was created and are then deleted automatically; you can delete them earlier yourself at any time.

General Information on the Legal Basis for Data Processing

If you have consented to data processing, we process your personal data on the basis of Art. 6 Para. 1 lit. a GDPR. If your data is required for the fulfillment of a contract (e.g., for account creation, the processing of file uploads, or streaming for transcription) or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6 Para. 1 lit. b GDPR. Furthermore, we process your data if this is required to fulfill a legal obligation (e.g., statutory retention periods) on the basis of Art. 6 Para. 1 lit. c GDPR. Data processing may also be carried out on the basis of our legitimate interest (e.g., for IT security, the use of Cloudflare, fraud prevention, and stability) in accordance with Art. 6 Para. 1 lit. f GDPR.

Note on Data Transfer to Third Countries Not Secure Under Data Protection Law

Among other things, we use IT services from companies based in the USA (e.g., Cloudflare, Postmark). When these services are active, your personal data may be transferred to these countries and processed there. We base these transfers on appropriate safeguards such as the standard contractual clauses of the EU Commission or certifications under the EU-U.S. Data Privacy Framework (DPF).

Recipients of Personal Data

Within the scope of our business activities, we work together with various external bodies. In some cases, a transfer of personal data to these external bodies is also necessary. We only pass on personal data to external bodies if this is necessary within the framework of fulfilling a contract, if we are legally obliged to do so, or if we have a legitimate interest according to Art. 6 Para. 1 lit. f GDPR in the transfer. When using data processors, we only pass on the personal data of our customers on the basis of a valid Data Processing Agreement.

Revocation of Your Consent to Data Processing

Many data processing operations are only possible with your explicit consent. You can revoke consent you have already given at any time with effect for the future (Art. 7 Para. 3 GDPR). The legality of the data processing carried out until the revocation remains unaffected by the revocation.

Right to Object to the Collection of Data in Special Cases as well as Direct Advertising (Art. 21 GDPR)

IF THE DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR CONCERNED PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING SERVIES THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21 PARA. 1 GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT ADVERTISING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR THE PURPOSE OF SUCH ADVERTISING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS CONNECTED TO SUCH DIRECT ADVERTISING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT ADVERTISING (OBJECTION PURSUANT TO ART. 21 PARA. 2 GDPR).

Right to Lodge a Complaint with the Competent Supervisory Authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority. The data protection supervisory authority responsible for us is: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18 91522 Ansbach Germany

Right to Data Portability

Upon request, we will provide you with the personal data that you have provided to us – including your account data and your transcription history – in a structured, common, and machine-readable format (e.g., JSON, CSV) free of charge, or transmit it directly to another controller, provided this is technically feasible (Art. 20 GDPR). Please send such requests to [email protected].

Information, Correction, and Deletion

Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipient, and the purpose of the data processing, and, if necessary, a right to correction or deletion of this data (Art. 15, 16, 17 GDPR). You can contact us at any time regarding this.

Note on backup copies: We keep backup copies of our database to protect ourselves against data loss. If you request deletion, your data will be deleted from the live systems immediately; any copies still contained in backup copies will be locked for further processing and removed when the respective backup is overwritten in the normal rotation cycle.

Right to Restriction of Processing

You have the right to request the restriction of the processing of your personal data (Art. 18 GDPR). You can contact us at any time regarding this.

SSL and/or TLS Encryption

For security reasons and to protect the transmission of confidential content, such as file uploads, streams, or support inquiries, this site uses SSL and/or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes to "https://" and by the lock symbol in your browser line. If encryption is activated, the data you transmit to us cannot be read by third parties while in transit (Data in Transit). Data stored on our servers is also protected by strict access controls.


3. Hosting and Backend Services

We operate our infrastructure with the highest focus on security and performance.

Self-hosting & Nginx

We operate the website primarily via our own infrastructure using an Nginx reverse proxy. Access to our servers and databases is restricted to authorized persons based on a strict need-to-know principle.

Cloudflare

We use the Content Delivery Network (CDN) and DNS services of Cloudflare. The provider is Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA. Traffic between your device and our servers is routed through Cloudflare's infrastructure to optimize loading times and protect our systems from malicious attacks (e.g., DDoS). This applies not only to the website in your browser but to every connection our applications make, including the desktop client and the Android keyboard.

This means that the audio of a live dictation also passes through Cloudflare's network on its way to us, as does the text that comes back. Cloudflare acts solely as a processor on our behalf under a data processing agreement, forwards this content in order to deliver it, and does not use it for its own purposes. The content is not stored there; what Cloudflare retains are the access logs described below.

Server access logs (temporarily at Cloudflare) may contain IP addresses, date/time, requested resources, referrer URL, and user agent data, and are stored for a maximum of 14 days for security and operational purposes, after which they are automatically deleted. The use of Cloudflare is based on Art. 6 Para. 1 lit. f GDPR. We have a legitimate interest in providing our website as securely and reliably as possible. The data transfer to the USA is secured by the Data Privacy Framework (DPF) and/or standard contractual clauses.


4. Data Collection on Our Website and in the Service

Cookies and Storage on Terminal Devices (TDDDG)

Our website uses so-called "cookies" and similar technologies (like LocalStorage). Cookies are small data packets and do not cause any damage to your terminal device. We only access information on your terminal device or store it if this is strictly technically necessary to provide the telemedia service explicitly requested by you (Sec. 25 Para. 2 No. 2 TDDDG). Since we do not use any analytics, tracking, marketing cookies, or device fingerprinting beyond this, no cookie banner is required and none is displayed.

The following storage on your device is used exclusively because it is technically necessary:

NameTypePurpose
sessionCookieKeeps you logged in; session management and authentication.
vv_csrf_tokenCookieProtection against Cross-Site Request Forgery.
themeLocalStorageSaves your preferred view (light/dark).
vv_current_user, vv_api_key, vv_auth_last_checkLocalStorageKeep you logged in and authorize your requests to our API.

Support Inquiries by Email or Contact Form

If you contact us by email or use a support form, your inquiry, including all resulting personal data (name, email address, request), will be stored and processed by us for the purpose of handling your request.

The processing of this data takes place on the basis of Art. 6 Para. 1 lit. b GDPR, provided your request is related to the fulfillment of a contract. In all other cases, processing is based on our legitimate interest (Art. 6 Para. 1 lit. f GDPR).

Bug Reports and Diagnostic Data

Our applications — the desktop client and the Android keyboard — contain a function for reporting a fault to us. It only ever sends anything when you use it yourself. Nothing is transmitted in the background, and there is no automatic crash or usage reporting.

When you send a report, it contains your description of the problem, the version of the application, the name and version of your operating system, technical details of your device (such as the model and available memory), technical information about the dictation session concerned (such as its length and the audio format), and the application's own log files.

Please note that these log files can contain text that you dictated. They are written so that we can reconstruct what went wrong, and a fault in the transcription is often only comprehensible together with the text it produced. If you would rather not send that, please describe the problem to us by email instead, at the address in our imprint.

Reports are stored in our own database and mirrored into our own storage, which runs on the same infrastructure; they are not passed to any third party. They are deleted when your account is deleted, and that deletion also reaches the mirrored copy. You may ask us to delete an individual report at any time.

The processing is based on Art. 6 Para. 1 lit. b GDPR (fixing faults in the service you are using) and on Art. 6 Para. 1 lit. f GDPR (our legitimate interest in finding and correcting defects in our software).

Registration and User Account

You can create a user account in our application. For this purpose, account data (name, email address, password hash) and service usage data (session IDs, timestamps, consumed minute quotas, billing metadata) are collected and processed. Processing is based on Art. 6 Para. 1 lit. b GDPR, as registration is necessary for the fulfillment of the contract.

Processing of Audio and Video Data & Transcripts

If you upload audio or video files or use real-time streaming for voice transcription, this content is processed exclusively for the immediate provision of the service. IMPORTANT: All audio data, video files, and generated text transcripts are under no circumstances used for the training, fine-tuning, or optimization of our own or third-party AI models. Raw audio and video files are deleted from our servers immediately after processing is complete (whether successful or failed). The generated transcript itself is kept in your account for 365 days, counted from the day the transcription job was created, and is then deleted automatically together with its stored result file. You can delete a transcript yourself at any time before that; that deletion takes effect immediately and is not reversible. The processing takes place on the basis of Art. 6 Para. 1 lit. b GDPR.

Voice Demo on the Home Page

Our home page lets you try the speech recognition without creating an account. The demo only runs once you start it yourself ("Try it with your mic"); until then no microphone is opened and nothing is transmitted.

Once you start it, your speech is transmitted to our servers and turned into text there. The raw audio is deleted immediately after the conversion. The resulting text is stored together with the recognised language, a truncated hash of your IP address, your browser identifier (user agent) and the referring page, so that we can tell whether the demo works for real visitors and so that we can detect abuse of the free demo. If you are turned away because the demo has been used too often from your connection, the same identifiers are recorded for that attempt.

This data is deleted automatically and in full after 30 days. It is not used for the training or optimization of AI models and is not passed on to third parties.

The legal basis is Art. 6 Para. 1 lit. f GDPR (legitimate interest in verifying that the demo works and in preventing its abuse). You may object to this processing under Art. 21 GDPR; please write to the address given in our imprint.


Ten Free Minutes in the Android Keyboard

The VibeVoice keyboard for Android lets you dictate for ten minutes before you create an account, so that you can see what it does before deciding whether to sign up.

To make that offer once per installation rather than once per tap, the app generates a random identifier when it is first started and sends it to us. It is chosen by the app itself and is not your Android ID, your advertising ID, or any other identifier that other apps can see or that follows you across them. We store it together with the minutes used and the dates of first and last use.

Once the trial is over, or after 30 days at the latest, everything except the identifier is erased: the trial's access key is deleted, the dates are removed, and what is left records only that this installation has already used its free minutes. That single fact is kept for as long as the offer exists, because it is the only thing preventing the same installation from claiming it again. There is nothing in it about when you used it or for how long.

If you later link an account, the trial is marked as spent and the record is deleted together with your account if you ask us to erase it.

The legal basis is Art. 6 Para. 1 lit. b GDPR (steps taken at your request before entering into a contract) and Art. 6 Para. 1 lit. f GDPR (legitimate interest in offering the trial once per installation). Speech dictated during the trial is treated exactly like any other dictation: it is converted to text and not stored.


5. Analytics Tools, Security, and Communication

Internal Reach Measurement (Without Third-Party Providers)

We do not use Google Analytics or a comparable analytics service from third-party providers. When you visit the site, no analytics data about you is transmitted to third parties for advertising or analytics purposes.

To understand which of our pages are used, we operate our own reach measurement on our own servers. This exclusively counts page views. It does not store anything on your end device, sets no cookies, does not use your IP address, creates no user profiles, and cannot recognize you. The data is purely aggregated. The legal basis for this is Art. 6 Para. 1 lit. f GDPR (legitimate interest in measuring and improving reach). Since no storage takes place on the end device, no consent according to Sec. 25 TDDDG is required.

Cloudflare Turnstile

On our pages for registration, login, password resets, and cancellation, we additionally use Cloudflare Turnstile to distinguish human users from automated attacks. For this purpose, Turnstile evaluates browser characteristics and stores nothing on your end device on our domain. The use is absolutely necessary to protect these forms against misuse (Sec. 25 Para. 2 No. 2 TDDDG; Art. 6 Para. 1 lit. f GDPR).

Sign in with Google

You can create an account and sign in with Google. This is optional; the email and password route stays open, and nothing changes for you if you do not use it.

We load no Google script and no Google SDK. The sign-in is a redirect you start by clicking the button: your browser goes to Google, you sign in there, and Google sends you back to us with a one-time code that our server exchanges for your data on its own. Until you click, nothing on our pages contacts Google, and nothing is stored on your end device on our domain beyond the session cookie already described above. This is the reason this feature does not oblige us to ask you for consent under Sec. 25 TDDDG.

We receive from Google: your Google account ID, your email address, whether Google has verified that address, and your name. We send Google nothing about you — only the identifier of our application.

For users in the EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland is the controller for the sign-in on its own pages; transfers to Google LLC are covered by the EU-US Data Privacy Framework. The legal basis on our side is Art. 6 Para. 1 lit. b GDPR (performance of the contract you are asking us to enter into), not consent.

Transactional Emails (Postmark)

For the sending of transactional emails (e.g., password resets, confirmation emails), we use the service provider Postmark. The provider is Active Campaign, LLC, 1 N Dearborn, 5th Floor Chicago, Illinois 60602, USA. Processing of email addresses and metadata outside the EU (e.g., in the USA) may occur; appropriate safeguards (such as standard contractual clauses or certification under the Data Privacy Framework / DPF) are contractually guaranteed.


6. eCommerce, Payment Providers, and Messengers

Processing of Customer and Contract Data

We collect, process, and use personal customer and contract data to establish, design the content of, and amend our contractual relationships (Art. 6 Para. 1 lit. b GDPR). We only process personal data concerning the use of our application (usage data) to the extent necessary to enable the user to utilize the service or for billing purposes.

Stripe (Payment Processing)

We integrate the payment service Stripe for subscriptions, checkout, and the billing portal. Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland, is responsible for data processing for individuals residing in the EU. Stripe receives your email address, billing metadata, subscription status, and payment details. Payment card data is entered directly into Stripe and is never processed on our servers. This use takes place on the basis of Art. 6 Para. 1 lit. b GDPR. Any transfers to the USA are secured by the Data Privacy Framework (DPF).

WhatsApp Bot Integration

If you use our WhatsApp service for transcriptions, Meta Platforms Ireland Ltd. processes your messages and your phone number via the WhatsApp Business Cloud API before these are forwarded to our VibeVoice servers. For your use of WhatsApp, the terms of use and privacy notices of Meta additionally apply. Here, too, raw audio files are deleted from our servers immediately after the transcript is generated. As a user, you are responsible for obtaining the express consent of third parties before transmitting their voice messages.


7. Social Media

We may link to our social media presences on our website. We do not integrate any social plugins (such as share buttons or the Meta Pixel) that automatically transmit data to these platforms simply by loading the page. A data transmission to the respective networks only occurs if you actively click on the external links.


8. Central Point of Contact According to the Digital Services Act (DSA)

Central point of contact for authorities and users according to the Digital Services Act for reporting potentially illegal content: [email protected] (Supported languages: German, English).