Privacy Policy

Last updated: February 2026

Our Privacy Promise

  • No transcript retention. Spoken words are processed then discarded.
  • No audio storage. Voice recordings are never stored on our servers.
  • Logging redaction by default. Logs contain metadata, never content.

What Data We Process

Vox Cloud manages API keys, authentication, and usage metering. Audio never passes through Vox servers.

  1. Audio is captured locally by the Mac app.
  2. The app sends audio directly to the configured speech provider (not routed through Vox servers).
  3. The speech provider performs speech-to-text and returns a transcript.
  4. If enabled, transcript is rewritten by an AI provider (also called directly by the app).
  5. Final text is returned to your Mac and pasted.

Vox Cloud receives only usage metadata (duration, character count, processing level) — never audio, transcripts, or rewritten text.

What We Log

We collect only operational metadata required for reliability and billing.

We DO log

  • Character and byte counts
  • Request duration and latency
  • Request IDs (for troubleshooting)
  • Account and token identifiers
  • Error codes and HTTP status
  • API endpoints accessed

We NEVER log

  • Transcripts
  • Audio data
  • Rewritten text
  • Raw user input
  • Request/response bodies containing content
  • LLM prompts or completions

Data Retention

Data TypeRetention
Audio recordingsNever received — sent directly to speech provider
TranscriptsZero retention — processed then discarded
Rewritten textZero retention — returned to client only
Usage metadata90 days for billing and quota enforcement
Account informationDuration of account plus 30 days

API Tokens

API token is stored in your Mac Keychain and sent only as Bearer auth. Tokens can be revoked or regenerated at any time.

Third-Party Services

We use third-party AI providers under agreements that enforce:

  • Zero retention by providers
  • No model-training use of your data
  • Processing only, no storage

Your Rights

Depending on jurisdiction, you may have rights to:

  • Access personal data we hold about you
  • Request deletion of account and associated data
  • Export usage history
  • Object to processing

To exercise rights: hello@mistystep.io

Changes to This Policy

Policy may be updated over time. Material changes are communicated via email or app notice. Continued usage means acceptance.

Contact

For privacy questions: hello@mistystep.io