This Privacy Policy explains how ProxVox collects, uses, stores, and protects your personal data. By using ProxVox you agree to the practices described here. If you do not agree, please do not use the Service.
1. Who We Are
ProxVox ("we," "us," "our") operates the real-time speech translation platform available at proxvox.app. For questions about this policy, contact us at privacy@proxvox.app.
2. Data We Collect
2.1 Account data
- Email address — required to create an account and send transactional emails (password reset, billing receipts).
- Name and organisation — optional fields provided during registration.
- Password — stored as a one-way bcrypt hash. We never store or transmit your password in plain text.
2.2 Session and usage data
- Audio — presenter audio is streamed in real time to our speech-to-text provider (Microsoft Azure). Audio is processed in transit only; we do not store raw audio.
- Transcripts and translations — generated text is stored per-session and retained for 30 days after the session ends, then permanently deleted. You may delete a session and its transcript at any time from your dashboard.
- Session metadata — session name, start/end times, language selections, and attendee counts are retained for billing and support purposes.
2.3 Billing data
Payments are processed by Stripe, Inc. We never see or store your full card number. We retain Stripe customer IDs and billing history (credit top-ups, session charges) to support disputes and refunds.
2.4 Technical data
- IP address and browser/device type, collected in server logs and retained for up to 30 days.
- We do not use third-party analytics trackers or advertising cookies.
3. How We Use Your Data
- To deliver the Service: authenticate you, run sessions, generate transcripts and translations.
- To process billing: charge for session usage, send receipts, handle disputes.
- To send transactional emails: password reset, billing alerts, service notices. We do not send marketing emails without your explicit consent.
- To maintain security: detect abuse, investigate incidents, enforce our Terms of Service.
- To improve the Service: aggregate, anonymised usage metrics (no personal data).
4. Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases:
- Contract — processing your account data and session data to fulfil the service you requested.
- Legitimate interests — server logs and security monitoring, fraud prevention.
- Legal obligation — retaining billing records as required by applicable law.
- Consent — where you have explicitly opted in (e.g. marketing communications).
5. Sub-processors
We share your data with the following third-party sub-processors to deliver the Service:
- Microsoft Azure (Speech-to-Text) — audio is streamed to Azure for transcription. Azure processes data under its Data Processing Agreement and is GDPR-compliant. Region: EU data centres available on request.
- Google Cloud (Translation API) — translated text is sent to Google for multilingual output. Google processes data under its Data Processing Agreement.
- Stripe, Inc. (Payments) — billing and payment processing. Stripe is PCI-DSS Level 1 certified.
- Fly.io, Inc. (Hosting) — the application and database run on Fly.io infrastructure in the EU (Amsterdam) and US (Virginia) regions.
- SendGrid / Twilio (Transactional email) — used to deliver password reset and billing emails.
6. Data Retention
- Account data: retained while your account is active. On deletion, personal identifiers are immediately anonymised (email replaced with a non-reversible placeholder, name cleared, password invalidated).
- Session transcripts: retained for 30 days after the session ends, then automatically and permanently deleted. You may delete a session and its transcript at any time from your dashboard.
- Billing records: retained for 7 years as required by financial regulations. These records are decoupled from your personal identifiers upon account deletion.
- Server logs: retained for 30 days, then purged.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate data.
- Erasure — request deletion of your account and associated personal data (subject to legal retention obligations).
- Portability — request your data in a machine-readable format.
- Restriction — request that we restrict processing of your data in certain circumstances.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
To exercise any of these rights, email privacy@proxvox.app. We will respond within 30 days. EEA users also have the right to lodge a complaint with their local data protection authority.
8. No AI Training
Your audio, transcripts, and translations are processed solely to deliver the real-time translation service you requested. Specifically:
- Audio is streamed to Microsoft Azure Speech Services for transcription and is not retained by Azure beyond the immediate request under our Data Processing Agreement.
- Transcripts and translations are never used to train, fine-tune, or improve any AI or machine-learning model — by ProxVox or any of our sub-processors.
- We do not sell, licence, or share your content with any third party for AI training purposes.
- The legal basis for processing your audio is contract performance (Article 6(1)(b) GDPR) — not consent — meaning we could not use it for AI training even if we wanted to without your explicit opt-in.
10. Cookies
We use a single session cookie (session_token) to keep you logged in. This cookie is strictly necessary for the Service to function and does not track you across other websites. We do not use advertising cookies, third-party analytics cookies, or fingerprinting.
11. Data Security
- All data in transit is encrypted using TLS 1.2 or higher.
- Passwords are hashed with bcrypt (cost factor 12).
- Database access is restricted to application servers within the private network.
- We conduct periodic security reviews and respond to disclosed vulnerabilities promptly.
To report a security issue, email security@proxvox.app.
12. International Transfers
Our sub-processors (Microsoft, Google, Stripe) may process data outside the EEA. Where this occurs, transfers are covered by Standard Contractual Clauses (SCCs) or equivalent safeguards as required by GDPR Article 46.
13. Children
The Service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided personal data, contact us at privacy@proxvox.app and we will delete it promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page and, for material changes, notify registered users by email. Continued use of the Service after the effective date constitutes acceptance of the revised policy.
15. Contact
For privacy-related questions or to exercise your rights: