Legal

Privacy Policy

Last updated 2026-08-09

This policy explains what Voxcene collects, why, who else sees it, and how long it is kept. It is written to be read rather than to be survived, and it describes what the product actually does today — not what it might do later.

Who is responsible

Voxcene is operated by [REGISTERED COMPANY NAME — TO BE COMPLETED], registered at [REGISTERED ADDRESS — TO BE COMPLETED]. Under the GDPR we are the data controller for the information described below.

For anything in this policy, write to privacy@voxcene.com. We have not appointed a data protection officer; our processing does not meet the threshold in Article 37 that requires one.

What we collect

Your account

An email address, and a password held by our authentication provider in hashed form — we never see it. If you sign in with Apple, we receive the identifier Apple gives us and the email you chose to share, which may be a private relay address.

What you make

The video and audio you upload or record, and everything derived from it: transcripts, translations, captions, generated images, synthetic voiceovers, project names, and any brand kits you save (colours, fonts and logo files).

Your subscription

Which plan you are on and whether it is active. We never see your card. Payment is handled entirely by Apple; we receive only a subscription status from our billing provider.

Usage

A ledger of what you have used — transcription minutes and AI credits — so that both of us can see what a plan has actually bought. Plus ordinary server logs: request identifiers, timestamps, error traces, and the IP address the request arrived from.

Your video is the sensitive part, so read this bit

Recordings of people are personal data, and a recording of someone speaking is biometric-adjacent: it carries their voice and their face. We treat it accordingly.

  • Your media is stored in the European Union, in a bucket partitioned per workspace so one workspace cannot read another's files.
  • Transcription sends your audio to ElevenLabs, in the United States. There is no way to caption a video without a speech-to-text service hearing it, and we would rather say so plainly than bury it.
  • Translation, caption emphasis and image generation send text — not video — to OpenAI, in the United States.
  • We do not use your content to train any model, ours or anyone else's, and we do not sell it or share it for advertising.
  • If you record other people, you are responsible for having their consent. We cannot obtain it for you.

Why we are allowed to (lawful bases)

WhatWhyBasis
Account, projects, media, processing To provide the service you asked for Contract — Art. 6(1)(b)
Subscription and usage records Billing, and proving what a plan included Contract, and legal obligation for tax records
Server logs and abuse prevention Keeping the service up and unabused Legitimate interests — Art. 6(1)(f)
Support correspondence Answering you Contract, and legitimate interests

Who else processes it

These are the only third parties involved, and each one is a live integration in the product rather than an aspiration:

WhoWhat forWhere
Supabase Database, authentication and file storage European Union (eu-west-3)
Fly.io Application hosting and video processing European Union (Paris)
Cloudflare Website hosting and content delivery Global edge network
ElevenLabs Speech-to-text transcription and synthetic voice United States
OpenAI Translation, caption emphasis and image generation United States
RevenueCat Subscription status and receipt validation United States
Apple App distribution, payment and billing Per Apple's own terms

Where a processor is outside the EEA, the transfer relies on the European Commission's Standard Contractual Clauses.

Analytics

There are no advertising trackers, no third-party cookies and no cross-site tracking anywhere in the app or on this site.

The product can report anonymous counters — how often an export succeeds, which provider handled it, roughly how long videos are. That reporting is restricted by code to six non-identifying properties (plan tier, a duration bucket, language code, provider name, failure category, platform), it is sent under a single constant identifier rather than one per person, and any value containing a path or URL is discarded before sending. It is currently switched off in production.

How long we keep things

WhatHow long
Uploaded source video, after it processes successfully 24 hours
Uploaded source video, after a failure 72 hours — long enough to retry or diagnose
Finished exports 30 days
Projects, transcripts and settings Until you delete them, or the account closes
Billing and usage records As long as tax law requires, typically several years

Source media is deleted early on purpose. It is the largest and most sensitive thing we hold, and once your export exists we have no reason to keep the original.

Your rights

If you are in the EU or UK, you have the right to:

  • get a copy of what we hold about you;
  • correct anything wrong;
  • have it erased;
  • receive it in a portable format;
  • restrict or object to processing based on legitimate interests;
  • withdraw consent where consent was the basis, without affecting what came before.

Ask at privacy@voxcene.com and we will answer within one month. There is no charge.

Deleting your account. Email us and we will delete the account and everything in it. We are building this into the app itself; at the time of writing it is a request by email, and we would rather tell you that than describe a button that is not there yet.

If you think we have handled your data badly, please tell us first — but you can complain to a supervisory authority regardless, in your case [SUPERVISORY AUTHORITY — TO BE COMPLETED].

Children

Voxcene is not for children under 16. We do not knowingly collect their data; if you believe a child has an account, write to us and we will remove it.

Security

Traffic is encrypted in transit. Files are partitioned per workspace and served through short-lived signed links rather than public URLs. Access to production data is limited to people who need it and is logged. No system is perfectly secure and we will not pretend otherwise; if a breach affects your rights we will tell you and the supervisory authority within the 72 hours the GDPR requires.

Changes

If this policy changes materially we will say so in the app before the change takes effect, rather than quietly editing the page. The date at the top always reflects the last substantive revision.