VSIP

Legal

Privacy Policy

Effective [EFFECTIVE DATE]

This policy explains what VSIP collects, what it does not, and how long anything is kept. The short version: we process voice audio in memory and never store it.

01

Who we are

VSIP (“we”, “us”) is operated by [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS]. For any privacy question, or to exercise the rights described below, contact [PRIVACY CONTACT EMAIL].

Where this policy refers to a data controller and a data processor: for your account data we are the controller. For the voice data you send through the API on behalf of your own end users, you are the controller and we act as your processor.

02

What we collect

  • Account data — your name, email address, and a hashed password. If you sign in with Google, we receive your email and name from Google, not your password.
  • API keys — stored hashed. We cannot recover the plaintext value of a key after it is created.
  • Voice audio — streamed or uploaded audio is processed in memory to compute events and embeddings, and is then discarded. We do not store audio recordings.
  • Voiceprint embeddings — only if you enroll a speaker profile. An embedding is a 192-number mathematical representation of a voice. It cannot be played back or converted back into audio.
  • Analysis results — for batch jobs, the resulting timeline (turn timings, speaker labels, silences) is stored for 30 days. The source audio file is not.
  • Usage records — minutes of audio processed and counts of API calls, for billing and quota enforcement.
  • Operational logs — request metadata and errors, used to keep the service running. Logs do not contain audio.
03

Biometric data

A voiceprint embedding may constitute biometric data under laws including the GDPR, the Illinois Biometric Information Privacy Act (BIPA), and the CCPA/CPRA. We treat it as such.

  • We only create a voiceprint when you explicitly call the enrollment endpoint. Streaming audio through the API does not create a stored profile.
  • Each profile records a consent flag. By setting it, you confirm that you have obtained any consent required from the individual whose voice it is.
  • Each profile may carry a retention window, after which it is automatically and permanently deleted.
  • We do not sell biometric data, and we do not use it to train models. It is used only to answer the verification and identification calls you make.

Obtaining lawful consent from your end users is your responsibility. We give you the mechanisms; we cannot obtain consent on your behalf.

04

How we use it

We use the data above to provide the service, to authenticate you, to meter and bill usage, to prevent abuse, and to keep the system reliable and secure. We do not sell personal data, we do not serve advertising, and we do not use your audio, voiceprints or analysis results to train models.

05

Sub-processors

We rely on a small number of providers to run the service. Each processes only what it needs to:

  • [HOSTING PROVIDER] — infrastructure hosting and database storage, located in [REGION].
  • Stripe — payment processing and usage billing. We never see or store your card details.
  • Resend — transactional email (password resets, account notices).
  • Google — optional sign-in, if you choose to use it.
  • Sentry — error monitoring. Reports contain request metadata, not audio.
06

Retention

  • Audio — not retained at all.
  • Voiceprints — until you delete them, or until their retention window expires, whichever comes first.
  • Batch results — 30 days, then purged automatically.
  • Account and billing records — for the life of the account, and afterwards only as long as tax and accounting law requires.
07

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to withdraw consent. You can delete voice profiles and API keys yourself from the dashboard at any time. For anything else, contact [PRIVACY CONTACT EMAIL] and we will respond within the period required by applicable law.

If you are in the EEA or UK and believe we have handled your data improperly, you also have the right to complain to your local data protection authority.

08

Security

Traffic is encrypted with TLS. Passwords and API keys are stored hashed. Every tenant's data is isolated. A fuller description of our technical controls is on the security page. No system is perfectly secure, and we do not claim otherwise.

09

Changes

We may update this policy. If a change materially affects how we handle your data, we will notify account holders by email before it takes effect.