Privacy Policy
Last updated: February 2026
Our Privacy Promise
- No transcript retention. Spoken words are processed then discarded.
- No audio storage. Voice recordings are never stored on our servers.
- Logging redaction by default. Logs contain metadata, never content.
What Data We Process
Vox Cloud manages API keys, authentication, and usage metering. Audio never passes through Vox servers.
- Audio is captured locally by the Mac app.
- The app sends audio directly to the configured speech provider (not routed through Vox servers).
- The speech provider performs speech-to-text and returns a transcript.
- If enabled, transcript is rewritten by an AI provider (also called directly by the app).
- Final text is returned to your Mac and pasted.
Vox Cloud receives only usage metadata (duration, character count, processing level) — never audio, transcripts, or rewritten text.
What We Log
We collect only operational metadata required for reliability and billing.
We DO log
- Character and byte counts
- Request duration and latency
- Request IDs (for troubleshooting)
- Account and token identifiers
- Error codes and HTTP status
- API endpoints accessed
We NEVER log
- Transcripts
- Audio data
- Rewritten text
- Raw user input
- Request/response bodies containing content
- LLM prompts or completions
Data Retention
| Data Type | Retention |
|---|---|
| Audio recordings | Never received — sent directly to speech provider |
| Transcripts | Zero retention — processed then discarded |
| Rewritten text | Zero retention — returned to client only |
| Usage metadata | 90 days for billing and quota enforcement |
| Account information | Duration of account plus 30 days |
API Tokens
API token is stored in your Mac Keychain and sent only as Bearer auth. Tokens can be revoked or regenerated at any time.
Third-Party Services
We use third-party AI providers under agreements that enforce:
- Zero retention by providers
- No model-training use of your data
- Processing only, no storage
Your Rights
Depending on jurisdiction, you may have rights to:
- Access personal data we hold about you
- Request deletion of account and associated data
- Export usage history
- Object to processing
To exercise rights: hello@mistystep.io
Changes to This Policy
Policy may be updated over time. Material changes are communicated via email or app notice. Continued usage means acceptance.
Contact
For privacy questions: hello@mistystep.io