Foo AI Corp.

Privacy Policy

New recordings keep their source audio on your device. If you choose workspace processing, the audio is streamed temporarily through Voicecape to Soniox for real-time transcription. Voicecape does not store the audio in the cloud, and Soniox does not retain the stream. The resulting workspace transcript and summary are stored as encrypted text.

Last updated 2026-09-22 · version 1.10 · this version takes effect on 2026-09-22

What stays on your device

With every cloud feature off — the state every Voicecape installs in — nothing you say or write leaves your Mac, and dictation works with the Mac in airplane mode. You can confirm that yourself with a network monitor such as Little Snitch or LuLu. There are three such switches: Cloud dictation, Polish with AI, and workspace processing for a Recording — turning any one of them on changes it, and the sections below say exactly what goes where.

  • Your dictation history, if you turn it on. It is off by default, and it never leaves your device at all.
  • Audio captured while you dictate — unless you turn on Cloud dictation. With it off, the audio is processed in memory and discarded.
  • Source audio for new recordings and imported audio. It stays in local storage on the device where you captured or selected it, including after optional workspace processing, until you delete it there.
  • The recognized text and the cleaned result — unless you turn on Cloud cleanup, which is off by default.
  • Your settings. Your personal dictionary stays here too, except that the words in it are sent with each request when one of the cloud features above is on, so that names and jargon come out right.

What the app does send, and when

Those three are everything the app does on its own while it is signed out of an account — which is how every Voicecape installs, and how it stays unless you create one. There is no analytics SDK, no crash reporter and no telemetry endpoint in it, and none of the three carries audio or text. Cloud polish, described next, is not one of them: it happens only if you turn it on, and only when you dictate. Signing in adds one more, described in the accounts section below. If we ever add a network call it will appear here and in the release notes.

Cloud polish — new on 2026-08-21, and off unless you choose it. The app gains a processing mode called cloud polish. It is not the default: your dictation is cleaned up on your Mac unless you open Settings and select it. If you never select it, your Mac makes exactly the requests listed above and no text of any kind leaves it.

When you do select it, the already-transcribed text of each dictation is sent to our relay, and from there to one language-model provider — whichever of the following is available, tried in this order: Cloudflare, Inc., Google LLC, OpenAI, L.L.C., Groq, Inc. Speech recognition happens on your Mac unless you switch on Cloud dictation, a separate setting. With it on, the audio of that dictation is streamed through our relay to Soniox Inc. in real time. With Cloud dictation off, dictation audio never leaves your Mac. The two settings are independent: turning on cloud cleanup does not send audio.

Workspace processing is optional and starts only after you choose it and confirm the workspace processing notice. Voicecape reads the saved local source in bounded pieces and streams it through the Relay to Soniox in real time. The Relay forwards audio without storing it; Voicecape requests Soniox’s no-storage real-time mode, and neither side keeps source audio from that stream. The transcribed text is then sent to the language-model provider our server is set to — currently OpenAI, L.L.C., reached through the Cloudflare AI Gateway — which produces the summary, decisions and action items. Audio is not sent to that provider.

What our contract with Soniox says, quoted rather than paraphrased. Our signed Data Processing Agreement states that audio is "processed transiently for transcription or translation" and that "Soniox does not store audio or text by default unless explicitly configured by the customer" (§11, §12). Storage can only be switched on by a customer setting; our requests carry no storage options. The same agreement states that customer data "is processed solely to provide the requested services" and that Soniox "does not use customer data to train models that serve other customers" (§11). We quote that last clause with its limit intact rather than shortening it to "does not train", because the limit is what the contract says.

That text is used to produce the cleaned-up result and for nothing else. We keep no copy of it: the relay stores nothing, and its logs record only which device made the request, which provider answered and how long it took. The providers process it under their own terms and may hold it briefly to detect abuse. The request is not tied to an account, and it carries no name, email address or licence key.

During the 14-day trial the same mode is available. To make that possible the app asks our activation endpoint for a short-lived permission token when you select cloud polish, and that request carries the device identifier and nothing else.

One exception worth stating rather than hiding: the speech model ships inside the app, so a normal install downloads nothing — but if the in-bundle file cannot be read, the app can fetch the same model from its public source. That path only runs on a damaged installation.

  • Licence activation: your licence key, a device identifier generated by the app, and a device label. Sent when you press Activate after entering a key. The device identifier is what makes the three-Mac limit countable. The label is a fixed string in the current build, not the name you gave your Mac, so nothing you named is transmitted.
  • Licence revalidation: on a Mac where a licence is already active, the app re-checks that licence in the background when you open it, sending the same licence key, the device identifier and the activation identifier from that first activation. It goes out at most once every seven days, never while you dictate, and never on a build that has not been activated. If it fails nothing locks — the app keeps working on the signed permission it already holds, which lasts ninety days.
  • Update checks: the app asks our update feed once a day whether a newer version exists, sending its own version number. Updates download in the background and are never installed without you.

Accounts

From 2026-08-30 you can create a Voicecape account and sign in from the app. The 14-day Mac trial does not require one. A new Paddle web subscription does: it is attached to the signed-in account. Only existing Polar or PortOne contracts bought before the Paddle change continue to activate with a licence key.

Creating an account with an email address and a password sends both to Supabase, the service that runs authentication for us. The password travels from the app to Supabase over HTTPS and does not pass through our own servers; Supabase keeps it hashed, so neither they nor we can read it back. Your email address is what identifies the account: we use it to confirm the address, to sign you in, and to send a reset link when you ask for one.

Signing in with Google or Apple sends no password at all. Your browser is sent to accounts.google.com, or macOS asks Apple on our behalf, and what comes back is a signed identity token. Google or Apple therefore learns that you signed in to Voicecape, and passes us the account identifier and the email address on it — or, with Apple, the private relay address you chose instead of it.

Signing in issues a pair of session tokens. They live in a file on your Mac and at Supabase, they are what proves it is you on the next request, and they carry nothing about what you dictate. While you are signed in the app makes an automatic request that is not among the three above: when you open it and the session is close to expiring, it renews that session with Supabase, sending the refresh token and nothing else. Signing out clears them on your Mac and asks Supabase to end the session.

An account handles sign-in, password recovery and a new Paddle web subscription bought while signed in. Existing Polar or PortOne contracts and their device registrations stay with their licence key. The account does not sync settings, dictionaries, recordings or dictated text between Macs, and signing in does not change how dictation works.

You can delete the account from the app: Settings → Account → Delete account. It asks you to prove it is you first — your password, or signing in with Google or Apple again — so that a session left open on a Mac you no longer have cannot erase it. The account record is then erased at Supabase. Deleting the account in the app or the web console cancels a web subscription paid through Paddle automatically, effective immediately; if you ask us by email to delete the account, we cancel it when we process the request. This covers your personal plan and the plan of a workspace deleted with the account. A workspace that remains keeps its subscription and keeps being billed; if you pay for one, change its payment method or cancel it before you leave. Cancel an App Store or Google Play subscription in that store. Deleting the account does not release a licence; for a licence, or for a subscription bought before web sales moved to Paddle, write to contact@voicecape.com.

What we hold, and why

Your dictation is not on this list: it does not reach us, with or without an account.

  • Workspace text — the transcript, summary, decisions and action items — is stored in encrypted envelopes in the Voicecape database operated by Supabase, Inc. (Seoul region, ap-northeast-2). Authorized Voicecape services open that text only while performing an allowed workspace operation. Source audio is not part of this storage.
  • Account — your email address, and either a password (kept hashed by Supabase, never readable by us) or the account identifier a Google or Apple sign-in returns instead. Used to create the account, sign you in and keep you signed in. Only if you create one.
  • Licence activation — your licence key, a device identifier generated by the app, and a device label. Used to check the licence is valid and to count how many Macs are on it.
  • Payment and subscription records — for a new web purchase: your email address, Paddle order and subscription references, country for tax purposes, plan, status and billing period. We use them to activate the plan, show its state and support refunds. Existing Polar or PortOne records remain only for the lifecycle of contracts bought before new sales moved to Paddle.
  • Store subscriptions — from 2026-09-11, if you buy a subscription as an in-app purchase in the iPhone or Android app: the transaction identifier the store issues, the account identifier we attach to that purchase so it can be matched to your Voicecape account, and the subscription status the store returns (whether it is active and when the period ends). Used to open the paid features for that account. It carries no card number — the store never gives us one — and no audio or dictated text. Only if you buy inside the app; those apps are not released yet.
  • Email you send us — the address and the message, used to answer you and to follow up.

On iPhone and Android

Voicecape is a Mac app today. The iPhone and Android apps are not released — there is no build in either store — and nothing in this section is happening yet. It is published in advance, taking effect 2026-09-11, because what an app collects has to be disclosed before it collects it.

When those apps ship, five kinds of data can leave the phone. They are the same five we declare to Apple in the app’s privacy manifest, and none of them is used for advertising or shared with a data broker — there is no advertising SDK and no tracking identifier in the app:

  • Your email address, if you create an account or sign in. Same as on the Mac, and optional in the same way.
  • The audio of a dictation, only while Cloud dictation is on. It is off unless you turn it on; with it off the audio never leaves the phone.
  • The recognized text of a dictation, only while Cloud cleanup is on. Off unless you turn it on.
  • Your purchase, if you subscribe inside the app: the transaction identifier and the account identifier attached to it. Described below.
  • A device identifier the app generates for itself. It is not the advertising identifier and not a hardware serial — the app makes it, and it is what makes the trial and the device limit countable.

Buying inside the app

From 2026-09-11, a subscription bought inside the iPhone or Android app is an in-app purchase, and Apple Inc. or Google LLC is the seller and the payment processor for it. That is a different role from the one they already have on this page: Sign in with Apple and Sign in with Google are identity checks, and this is money. Both companies are named twice below for that reason.

What leaves the phone when you buy is the transaction identifier the store issues and an account identifier we attach to the purchase so that it can be matched to your Voicecape account. No audio, no dictated text and no email address is sent on that request.

Our server then asks the store directly — with our own developer credentials, not yours — whether that transaction is a live subscription, and the store answers with the status and the date the period ends. We do not receive your card number, your billing address or your store account name; the store does not give them to us.

What we keep from that is listed above under what we hold. The purchase itself, and the payment, live with Apple or Google under their own privacy policies.

What this website collects

This site uses no advertising trackers, no session recording, and no cross-site profiling. It has no analytics script and sets no cookies, so there is nothing to opt out of and blocking cookies entirely changes nothing about how it works. We also keep recordport.app online so installed copies of an earlier app can still find updates. That legacy domain does not load analytics now. From 2026-08-28 through 2026-09-13, recordport.app loaded Google Analytics 4 (measurement ID G-95YTVPD0E9). Google LLC retains that historical event-level data for 2 months and user-level data for 14 months. We continue to read only 28-day aggregates from the historical property and do not keep visitor-level records.

The hosting and CDN provider records ordinary connection logs — IP address, timestamp, requested path — for delivery and security. We do not query or combine those to identify anyone. What we do read is the count: how many requests reached a given path on a given day, so we can tell whether anyone is using the product. Those totals carry no IP address and name no one, and we never open an individual record.

Payments

New web purchases are handled by Paddle.com Market Ltd., our merchant of record. Card details are entered in Paddle’s checkout and never reach Voicecape. We receive the identifiers, plan, status, billing period, email address and tax country needed to activate and support the subscription.

Polar and PortOne no longer accept new Voicecape sales. We keep only the minimum records needed to cancel, refund or finish an existing contract on its original rail.

From 2026-09-11, there is a third rail: an in-app purchase made inside the iPhone or Android app, where Apple Inc. or Google LLC is the seller. The section above says what is sent and what comes back. Those apps are not released yet.

How long we keep things

  • New recording source audio has no Voicecape or Soniox cloud copy; you control the device copy. Encrypted workspace text remains until you delete it or the workspace retention policy removes it. Recordings made by retired versions may still have historical cloud-stored audio. Those historical objects remain covered by the workspace Trash and retention rules: deletion can be restored for up to 30 days unless a shorter retention policy applies, then the audio, transcript and summary are removed.
  • Account records: for as long as the account exists. Deleting the account erases them. Session tokens go when you sign out; the access token is short-lived and the app renews it, and if a renewal is refused the app deletes the stored session.
  • Licence records: for as long as the licence exists.
  • Domestic (KRW) subscription records: for as long as the subscription exists, and the contract and payment records Korean e-commerce law requires us to retain, for 5 years.
  • Store subscription records: for as long as the subscription exists. When it lapses and is not renewed we delete the transaction identifier and the status we cached for it; the store keeps its own record of the purchase under its own policy, which we cannot delete.
  • Support email: up to 3 years, so we can follow up on an earlier problem.
  • Records that tax or e-commerce law requires us to retain: for the period that law sets.

How we delete it

When the retention period ends or the purpose is met, we delete it without waiting to be asked. Electronic files are deleted by a means that does not leave them recoverable; anything printed is shredded.

Records the law requires us to keep are held apart from everything else until that period ends, then deleted the same way.

Sharing, and where the data goes

We do not sell personal data, and we do not share it for advertising. The processors below run the parts we do not run ourselves. All but the Korean card processor are in the United States, so activating a licence sends data outside Korea and outside the EEA — and so does using cloud polish, if you turn it on, and so does creating an account. For users in Korea: we transfer personal data abroad by way of the processing entrustment necessary to perform our contract with you, under PIPA Art.28-8(1)3(a). That is why this policy discloses the items below — the recipient, the country, the data transferred, the purpose and the retention — instead of asking you for a separate consent.

  • Paddle.com Market Ltd., United Kingdom, and Paddle.com Inc., United States — merchant-of-record payment processing for new web subscriptions; they receive payment details and issue receipts and tax documents.
  • Polar Software, Inc., United States, and PortOne Corp. (주식회사 코리아포트원), Republic of Korea — cancellation, refund and remaining paid-period support for existing legacy contracts only; no new Voicecape sales.
  • Supabase, Inc., United States — from 2026-08-30, the authentication service behind accounts: it holds the email address, the hashed password and the sessions, and it is where an account is erased when you delete it. From 2026-09-13 it also operates the database that holds workspace text — the transcripts, summaries, decisions and action items described above. That text is stored in encrypted envelopes whose keys are held by our Cloudflare worker, not by Supabase, so Supabase cannot open it on its own. The project itself runs in a Seoul region (ap-northeast-2), so the data sits in Korea; the company operating it is American, which is why it appears here. Only used if you create an account.
  • Apple Inc., United States — from 2026-08-30, identity verification for Sign in with Apple. Apple issues the identity token and passes us the email address on the account, or the private relay address you chose instead. Only used if you sign in with Apple.
  • accounts.google.com (Google LLC), United States — from 2026-08-30, identity verification for Sign in with Google. Your browser is sent there by the authentication service, and Google returns the account identifier and email address. We name the address rather than only the company because Google appears twice on this page in different roles, and this is the one you are redirected to. Only used if you sign in with Google.
  • Apple Inc., United States — from 2026-09-11, seller and payment processor for an in-app purchase made in the iPhone app. It receives the purchase itself, and it answers our question about whether that subscription is live. Only used if you buy inside the iPhone app; that app is not released yet.
  • Google LLC, United States — from 2026-09-11, seller and payment processor for an in-app purchase made in the Android app, in the same way. Only used if you buy inside the Android app; that app is not released yet.
  • Plus Five Five, Inc. (Resend), United States — from 2026-08-30, delivery of the account emails: the confirmation message when you sign up, and the link when you ask to reset a password. The authentication service hands each message to Resend, which receives your email address and the body of that message, including the link. Only used when an account email is sent to you. It also carries our own internal operational alerts to our address — a general alerting channel, not only delivery failures: error messages, stack traces (up to 1,500 characters), the request path on which an unhandled error occurred, scheduled-job and database failure text, and job or organization identifiers. Identifying details that happen to sit inside an error string travel with it. Audio, transcripts and summaries are not sent.
  • Notion Labs, Inc., United States — only when an administrator of your workspace turns the Notion integration on. The summary text — the points, decisions and action items — is written into the Notion database that administrator chose. Audio is never sent. The integration is off until someone turns it on, and turning it off stops it.
  • Slack Technologies, LLC (Salesforce, Inc.), United States — only when an administrator of your workspace turns the Slack integration on. Connecting Slack exchanges an authorisation code for a token; after that the summary text is posted to the channel behind the webhook address that administrator supplied. Audio is never sent. The integration is off until someone turns it on, and turning it off stops it.
  • Cloudflare, Inc., United States — website hosting and delivery, and relaying activation requests. For licences sold through Polar the activation endpoint keeps no database of its own, so it passes requests through rather than storing them. From 2026-08-21, if you turn on cloud polish, Cloudflare also runs the language model that cleans up your transcribed text, on its own network — and from 2026-09-02, the domestic (KRW) subscription records listed above are stored in a database on Cloudflare’s network.
  • Deepgram, Inc., United States — historical only. Retired Recording versions could upload source audio to Deepgram for speech-to-text. The current Recording flow does not send new source audio to Deepgram; optional workspace processing uses the Voicecape Relay and Soniox real-time mode. Historical cloud audio remains subject to the deletion and retention rules above.
  • Vercel Inc., United States — hosting for the web console. The console renders on the server, which means the text of a summary — its key points, decisions, action items, participant names and the recording title — is assembled on Vercel each time you open it. Functions run in the Seoul region.
  • Cloudflare, Inc. (AI Gateway), United States — the requests our server makes for workspace processing — summaries, answers to a question about a recording, follow-up drafts — pass through this gateway on their way to the model provider. Cloud polish does not use it: the relay calls the model provider directly. Its logging is on by default and would record the request and response bodies, so each of our requests carries headers that turn body logging and caching off. We cannot measure from outside whether Cloudflare honours them; we can only show that we send them.
  • Functional Software, Inc. (Sentry), United States — crash and error diagnostics. It receives the error itself: the type, the stack, the app version and an anonymous installation identifier. It does not receive audio, transcripts or summaries.
  • Expo (650 Industries, Inc.), United States, with Apple Inc. and Google LLC — delivery of push notifications to the phone apps. Expo holds the push token for a device and passes the notification to Apple or Google, who deliver it. The notification text says that something is ready, not what it says.
  • Paddle.com Market Ltd., United Kingdom, and Paddle.com Inc., United States — merchant of record for paid plans. They receive the billing details and issue the receipt and any tax; we never see the card.
  • Anthropic, PBC, United States — an alternative provider for summaries. Present in the code and reachable by a deployment-wide setting, which is currently not set to it. If that changes we will say so on this page before it does.
  • NAVER Cloud Corp. (CLOVA Speech), Republic of Korea — an alternative speech-to-text provider for Korean. Present in the code and reachable by a deployment-wide setting, which is currently not set to it. If that changes we will say so on this page before it does.
  • Google LLC, United States — from 2026-08-21, cleaning up transcribed text for cloud polish when Cloudflare is unavailable. Only used if you turn cloud polish on.
  • OpenAI, L.L.C., United States — from 2026-08-21, in two roles. For workspace processing of a Recording it is the provider our server is currently set to: the transcribed text is sent there to produce the summary, decisions and action items, and the same provider answers a question you ask about a recording and drafts a follow-up when you ask for one. For cloud polish it is the third choice, used when Cloudflare and Google are unavailable.
  • Groq, Inc., United States — from 2026-08-21, the same role when the three above are unavailable. Only used if you turn cloud polish on.
  • Soniox Inc., United States — from 2026-08-22, real-time speech recognition for Cloud dictation and, in the current Recording flow, optional workspace processing. It receives audio only while the selected real-time stream is open. Voicecape requests no storage; our signed DPA says Soniox does not store audio or text by default, and our requests do not enable storage.

How we protect it

  • Local by default: dictation stays on the Mac unless you choose a cloud feature, and new recording source audio stays on the device even when you choose workspace processing. Voicecape and Soniox retain no source-audio copy from the real-time stream; the resulting workspace text is stored in encrypted envelopes as described above.
  • All traffic between the app and our server is over HTTPS.
  • Activation responses are signed, and the app verifies the signature against a public key compiled into it before storing anything.
  • For licences sold through Polar, the activation service holds no database — there is no store of that licence data on our side to breach. Korean-won subscriptions do require a small store of ours (billing records, the recurring-billing token, a hash of the key, device registrations); it holds no card numbers and no plaintext licence keys.
  • Account passwords are never stored by us and never travel through our servers: the app sends them straight to Supabase, which keeps a hash. The session tokens on your Mac are held in the app’s own storage and are discarded when you sign out.
  • Access to what we do hold is limited to the people who need it to do the work.

No profiling, and no automated decisions

We do not collect special-category data, and we do not build profiles. Nothing about you is decided automatically in a way that has a legal or similarly significant effect: whether an activation succeeds turns on two facts, whether the key is valid and how many devices are already registered.

Your rights

You can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or object to a particular use. Write to contact@voicecape.com and we will respond within 30 days.

Because dictation data never reaches us, a deletion request covers your account, licence and support records — the dictation itself is deleted by you, on your device, whenever you choose. If you have an account you do not have to write to us to delete it: the app does it directly, from Settings → Account.

Children

Voicecape is not directed at children under 14, and we do not knowingly collect their personal data.

Changes to this policy

Changes are posted on this page with the date they take effect. Anything material goes up at least 7 days before it applies, and anything that reduces your rights at least 30 days before.

Every version of this page, newest published first. The date shown is when that version takes effect, which can be later than when it went up:

  • v1.10 — 2026-09-22. Corrects what this policy said about deleting the account. It said that deleting the account does not cancel a subscription. Deleting the account in the app or the web console now cancels a web subscription paid through Paddle automatically, effective immediately, and when you ask us by email to delete the account we cancel it as part of processing the request. This covers your personal plan and the plan of a workspace deleted with the account. A workspace that remains keeps its subscription and keeps being billed. An App Store or Google Play subscription is still canceled in that store, and a licence or a subscription bought before web sales moved to Paddle is still handled by email. The Terms of Use are corrected the same way. Nothing changes about who receives your data or why, so this correction takes effect on the day it is published.
  • v1.9 — 2026-09-17. Corrects three statements about who processes your text, with no change to the recipients themselves. OpenAI, L.L.C. was described as used only when you turn cloud polish on; in fact it is the provider our server is currently set to for workspace processing of a Recording, so the transcribed text of a recording is sent there to produce the summary, and the same provider answers a question about a recording and drafts a follow-up. The Cloudflare AI Gateway entry said every summary and cleanup request passes through it; cloud polish does not — the relay calls the model provider directly. The workspace-processing description named Soniox but stopped there, and now states the transcript-to-language-model step. Tailwind Labs Inc. is removed: our documentation pages no longer load anything from that host, so it receives nothing. The Supabase, Inc. entry is widened: besides running authentication it has, since the workspace database moved on 2026-09-13, also operated the database that holds workspace text, and that storage sentence now names it. This correction takes effect on the day it is published, because leaving a published statement false for a notice period is worse in only one direction.
  • v1.8 — 2026-09-13. Corrects the current Recording description in all five languages. New source audio stays on the device; optional workspace processing streams it transiently through the Voicecape Relay to Soniox in real time; neither Voicecape nor Soniox retains the source audio; and the resulting workspace transcript and summary are stored as encrypted text. It also distinguishes historical cloud audio created by retired versions and keeps that data under the existing deletion and retention rules. No recipient or processing purpose changes in this correction.
  • v1.7 — 2026-09-07. Two processors were added to the policy: Notion Labs, Inc. and Slack Technologies, LLC. This was a correction, not a new feature — the web console had already been able to send a summary to Notion or Slack, and the integrations remain off until an administrator turns them on.
  • v1.6 — 2026-09-06. The former Recording service became part of Voicecape. At that time, Recording used the then-current upload path and Deepgram, and this policy disclosed that behavior. That historical description does not describe new recordings in v1.8; the current device-source and Soniox real-time path is stated above. This version also disclosed Vercel, Cloudflare AI Gateway, Sentry, Expo, Apple, Google, Paddle, Anthropic, NAVER CLOVA, Tailwind Labs and legacy-site analytics.
  • v1.5 — 2026-09-11. In-app purchase on iPhone and Android. Apple Inc. and Google LLC gain a second role, seller and payment processor, alongside the identity check they already did; the transaction identifier, the account identifier attached to it and the subscription status are added as things we hold; and what the phone apps collect is set out as the same five items we declare in the app’s privacy manifest. Nothing here is running yet — neither app is released — and it is posted seven days before it takes effect for that reason.
  • v1.4 — 2026-08-30. Accounts. You can create a Voicecape account and sign in; Supabase, Inc., Plus Five Five, Inc. (Resend), Apple Inc. and accounts.google.com are added as processors, the email address, password and session tokens are added as things we hold, and the automatic session renewal that happens while you are signed in is described. The sentence saying there was no account to create is gone, in all five languages.
  • v1.3 — 2026-09-02. Subscriptions in Korean won, sold by us directly. PortOne Corp. added as a processor; billing records, the recurring-billing token, a hash of the licence key and the device registrations added as things we hold.
  • v1.2 — 2026-08-22. Cloud dictation. Soniox Inc. added as a processor: with the setting on, the audio of that dictation leaves your Mac.
  • v1.1 — 2026-08-21. Cloud polish. Google LLC, OpenAI, L.L.C. and Groq, Inc. added as processors, and Cloudflare, Inc.'s role widened to running the language model that cleans up transcribed text.

Who is responsible

The person accountable for personal data at Foo AI Corp., and the person who handles privacy questions, complaints and requests, is JEEHO SONG, our representative director.

Privacy questions and requests: contact@voicecape.com, or 02-581-3001.

Back to voicecape.com