Privacy Policy

Last updated: January 2025

1. Introduction

At TransVoice, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our voice training application. The data controller within the meaning of data protection laws is Kailar UG (haftungsbeschränkt), Viererblock 18a, 39326 Wolmirstedt, Germany.

2. Information We Collect

Personal Information

When you create an account, we may collect:

  • Name and email address
  • Profile information you choose to provide
  • Payment information (if you subscribe to premium features, processed securely by our payment provider)

Voice Data

To provide our voice training services, we may collect:

  • Voice recordings during exercises (stored locally by default)
  • Voice analysis metrics (pitch, resonance, etc.)
  • Practice session data and progress information

Usage Data

We automatically collect certain information when you use the Service, including device information, IP address, browser type, pages visited, and time spent on the app.

3. Legal Basis for Processing

We process your personal data on the following legal bases under Article 6 GDPR:

  • Contract Performance (Art. 6(1)(b) GDPR): For providing our services and managing your account
  • Consent (Art. 6(1)(a) GDPR): For processing voice recordings in the cloud, analytics cookies, and marketing communications. You may withdraw your consent at any time.
  • Legitimate Interests (Art. 6(1)(f) GDPR): For improving our services, fraud prevention, and IT security
  • Legal Obligation (Art. 6(1)(c) GDPR): For retention of billing data as required by tax regulations

4. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Personalize your voice training experience
  • Track your progress and provide feedback
  • Process transactions and send related information
  • Send you updates, security alerts, and support messages
  • Respond to your comments, questions, and requests
  • Analyze usage patterns to improve the Service
  • Protect against fraud and unauthorized access

5. Voice Recording Privacy

We understand the sensitive nature of voice data. By default, your voice recordings are processed locally on your device and are not uploaded to our servers. If you choose to enable cloud backup or certain advanced features, your recordings will be encrypted and stored securely. You can delete your voice data at any time from your account settings. We never sell or share your voice recordings with third parties for advertising purposes.

6. Information Sharing & Subprocessors

We do not sell your personal information. We may share your information with the following categories of recipients:

  • Service Providers: With trusted third parties who assist us in operating our Service
  • Legal Requirements: If required by law or in response to valid legal requests
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • With Your Consent: When you explicitly agree to share information

Subprocessors

We engage the following subprocessors:

  • Google LLC (Authentication via Google Sign-In) - USA, EU-US Data Privacy Framework
  • Apple Inc. (Authentication via Apple Sign-In) - USA, EU-US Data Privacy Framework
  • Vercel Inc. (Hosting and infrastructure) - USA/EU, Standard Contractual Clauses
  • DigitalOcean LLC (Cloud storage for audio files) - EU (Frankfurt), Standard Contractual Clauses
  • OpenAI LLC (AI-powered dialogue feature, speech transcription) - USA, Data Processing Agreement
  • Resend Inc. (Email delivery for verification) - USA, Data Processing Agreement

7. International Data Transfers

Our servers are located within the European Union. When data is transferred to service providers outside the EEA, we ensure your data is protected through appropriate safeguards:

  • EU-US Data Privacy Framework for certified US companies
  • Standard Contractual Clauses (SCCs) approved by the EU Commission
  • Adequacy decisions by the EU Commission

8. Your Rights Under GDPR

As a data subject, you have the following rights:

  • Right of Access (Art. 15 GDPR): You can request confirmation of whether we process your data and obtain information about this data
  • Right to Rectification (Art. 16 GDPR): You can request correction of inaccurate data
  • Right to Erasure (Art. 17 GDPR): You can request deletion of your data, unless legal retention requirements apply
  • Right to Restriction (Art. 18 GDPR): You can request restriction of processing under certain circumstances
  • Right to Data Portability (Art. 20 GDPR): You can receive your data in a structured, machine-readable format
  • Right to Object (Art. 21 GDPR): You can object to processing based on legitimate interests
  • Withdrawal of Consent: You can withdraw any given consent at any time with effect for the future
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority. The competent authority for us is the State Commissioner for Data Protection Saxony-Anhalt, Leiterstraße 9, 39104 Magdeburg, Germany.

To exercise your rights, contact us at privacy@transvoice.app

9. Data Retention

We retain your data only as long as necessary for the respective purposes:

  • Account data: Until deletion of your account, then maximum 30 days for technical cleanup
  • Voice recordings: According to your settings, deletable at any time via the app
  • Usage logs: 90 days, then anonymized for statistical purposes
  • Payment data (if applicable): 10 years as required by commercial and tax law retention requirements
  • Support requests: 3 years after case closure

10. Automated Decision-Making

We do not use fully automated decision-making within the meaning of Art. 22 GDPR. The AI features used in our app for voice analysis serve solely to provide feedback and do not make decisions that have legal or similarly significant effects on you.

11. Data Security & Encryption

We implement appropriate technical and organizational security measures to protect your personal information. Data transmission occurs exclusively via TLS/SSL-encrypted connections (HTTPS). Stored sensitive data is encrypted with AES-256. We conduct regular security audits and train our employees in data protection.

12. Children's Privacy

TransVoice is not intended for children under 16 years of age (in Germany). We do not knowingly collect personal information from children under 16. If we learn we have collected information from a child under 16, we will delete that information promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify you by email or through a prominent notice in the app. The current version is always available on this page with the date of the last update.

14. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at privacy@transvoice.app