1. Data Controller
GuanWei ("we," "us," or "our"), an individual / sole trader doing business as Voxt, respects and protects your privacy. This Privacy Policy ("Policy") explains how we collect, use, store, and share personal information when you use Voxt (the "Service"), and the rights you may have under applicable law.
Please read this Policy before using the Service. By using the Service, you acknowledge this Policy. We may update it from time to time; material changes will be announced in advance by email or in-product notice when reasonably practicable.
Controller
GuanWei (doing business as Voxt)
Website
https://voxt.actnow.dev
Privacy contact
privacy@voxt.actnow.dev
Data protection officer
Not separately appointed / not applicable at this time
2. Personal Information We Collect
2.1 Information you provide
Account information
Name, email, password (stored hashed), avatar, email verification status, and related profile fields.
Payment information
Transaction amounts, payment status, plan type, billing email, taxes, refunds, and invoice records. We do not store full card numbers—card data is handled by the payment processor (see Section 5).
Communications
Emails, support tickets, in-app or website feedback, screenshots you attach, and our replies.
App configuration you sync or submit
When a feature requires it: feedback content and similar submissions. Everyday dictionaries, App Branch rules, and local model settings typically remain on your device unless you choose a cloud-related feature.
Download email (optional)
If you enter an email on the download page, we store the email, selected release version, channel, user agent, and timestamp to understand downloads and communicate Voxt product updates. Entering an email is not required to download the app.
2.2 Information we collect automatically
Device and network
IP address, device/OS or browser type, user agent, timezone, and similar technical data.
Usage
When you grant analytics consent, Google Analytics 4 may receive anonymous page views, page paths, page titles, download-click events, sponsor-start and sponsor-complete events, GitHub repository/release clicks, FAQ opens, SEO navigation clicks, sign-up completion events, and sign-in start events with a provider label. We do not send audio, transcripts, selected text, prompts, payment details, or API keys. We also use server-side download counters and security logs where applicable.
Logs
Request timestamps, error logs, performance signals, and security audit logs.
2.3 Optional / contextual data
Third-party login
If you sign in with GitHub, Google, or similar providers, we receive basic profile information authorized by that provider.
Local app content
Voice audio, transcripts, selected text, prompts, and enhancement results are processed on your Mac for local channels. They are not uploaded to Voxt solely because you dictate.
If you enable BYOK remote ASR/LLM providers, necessary audio/text/context is sent to those providers under their policies—not as Voxt-hosted model inference by default.
3. How We Use Your Information
Provide and maintain the Service
Contract performance
Billing and payment processing
Contract performance
Customer support and feedback
Contract performance / legitimate interests
Service notices (billing, security, policy updates)
Legitimate interests
Security and fraud prevention
Legitimate interests
Product improvement and analytics
Consent for optional analytics; legitimate interests for aggregate operational metrics
Legal compliance
Legal obligation
Marketing (only if we offer it and you opt in)
Consent
We may aggregate or de-identify data for statistics and product improvement. Such data is not used to identify a specific individual.
Without your explicit consent, we do not use your private voice, transcripts, or Outputs to train Voxt's own AI models.
4. Cookies and Similar Technologies
Strictly necessary
Maintain login, sessions, security, and core website functions. Generally cannot be disabled if you use those features.
Functional
Remember preferences such as theme or locale where offered. Usually controllable via browser settings.
Analytics
Optional Google Analytics 4 measurement for page views, download clicks, sponsor checkout/completion events, GitHub clicks, FAQ opens, SEO navigation clicks, sign-up completion events, and sign-in start events. It loads only after you choose Allow analytics; choosing Decline prevents the analytics script from loading. You can change your browser storage choice by clearing the site data.
The macOS app does not rely on website cookies for local voice processing. Disabling necessary cookies may prevent sign-in or account features from working correctly.
5. Information Sharing and Disclosure
We do not sell your personal information, including "sale" as defined under laws such as the CCPA where applicable. We share information only in these cases:
- Service providers: cloud hosting, database, email delivery, object storage, analytics, customer support, and security vendors bound by confidentiality and processing limits. Optional website analytics is provided by Google Analytics 4 only after consent. Payment card data is processed exclusively by our PCI-DSS compliant payment processor Waffo Pancake and is not stored on Voxt servers.
- AI providers you choose: when you enable BYOK remote models, necessary voice, text, prompts, and context are sent to those providers under their terms.
- OAuth providers: authentication with GitHub, Google, or similar is handled under their policies.
- Legal and regulatory requirements: to comply with law, court orders, or lawful government requests, or to protect Voxt, users, and the public.
- Business transactions: in a merger, acquisition, financing, or asset transfer, we will require the recipient to continue protecting your information.
- With your consent: for other purposes only with your prior clear consent.
6. Data Security
- Transmission: HTTPS / TLS for the website and API.
- Storage: passwords and sensitive credentials are hashed, encrypted, or access-restricted using common industry practices.
- Access control: least privilege for production systems; necessary security logs are retained.
- Payments: full card details are handled by Waffo Pancake; Voxt does not store full card numbers or security codes on its own servers.
If a security incident may affect your rights, we will investigate and remediate, and notify affected users and regulators as required by applicable law—aiming for notice without undue delay and, where GDPR applies, within 72 hours of becoming aware when notification to authorities is required. Keep your account credentials and API keys secure and do not share them.
7. Data Retention
Account information
While the account is active; after closure or deletion, typically deleted or anonymized within 90 days unless law requires longer retention.
Transaction records
As needed for tax, accounting, payment disputes, and compliance—typically up to 7 years—then deleted or archived per legal requirements.
Support and feedback
Typically 3 years for follow-up, audit, and service improvement, then securely deleted (or sooner if you delete eligible items in-product).
Security audit logs
Typically 12 months; may be extended if anomalies, fraud, or incidents are under investigation.
Aggregate download counters
May be retained indefinitely in non-identifying form.
Download email leads
Retained until you ask us to delete the record, or until it is no longer reasonably needed for download follow-up and product updates.
On-device app content
Controlled by you on your Mac until you clear data or uninstall.
8. Your Data Rights
Subject to applicable law, you may request the rights below. Contact privacy@voxt.actnow.dev; we aim to respond within 30 calendar days and may need to verify your identity.
Right to be informed
Understand what data we collect and how we use it.
Access
Obtain a copy of your personal information.
Rectification
Correct inaccurate or incomplete information.
Erasure
Request deletion in circumstances allowed by law.
Restriction
Ask us to limit processing in certain cases.
Portability
Receive data in a machine-readable format where applicable.
Objection
Object to processing based on legitimate interests or to marketing.
Withdraw consent
Withdraw consent-based processing without affecting prior lawful processing.
If you believe we have not handled your request properly, you may lodge a complaint with your local data-protection authority. Requests about third-party model providers or OAuth accounts may need to be made directly to those parties.
9. Marketing and Opt-Out
If we send marketing emails or product promotions in the future, we will do so with your consent where required. You can unsubscribe via the email link, account settings, or by contacting us. Opting out of marketing does not affect necessary service notices (such as billing, security, or policy updates).
10. Cross-Border Transfers
Our servers, vendors, payment processor (Waffo Pancake), and AI providers you enable may be located outside your country or region (for example in the United States, Singapore, or other regions used by those providers). When we transfer personal information internationally for website, account, or billing operations, we use reasonable safeguards such as:
- Data-processing agreements that incorporate Standard Contractual Clauses (SCCs) where appropriate.
- Transfers only to recipients that provide an adequate level of protection, or other lawful transfer mechanisms.
- Access controls and data minimization.
11. Children
The Service is intended for users who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided information to us, contact privacy@voxt.actnow.dev and we will delete it promptly.
12. Third-Party Links and Services
The Service may link to GitHub, model providers, Waffo Pancake checkout, email services, or other third-party sites. This Policy applies only to information Voxt processes directly. We are not responsible for third-party privacy practices—review their policies before use, including any BYOK provider you enable.
13. Changes to This Policy
If we make material changes, we will provide at least 15 days' notice via website announcement and/or your registered email when available, and update the "Last updated" date on this page. Continued use after the effective date constitutes acceptance of the updated Policy.
14. Contact Us
- Privacy contact: privacy@voxt.actnow.dev
- Customer support: support@voxt.actnow.dev
- Security issues: security@voxt.actnow.dev
- Controller / brand: GuanWei
- Website: https://voxt.actnow.dev
- Project homepage: https://github.com/hehehai/voxt
This Privacy Policy is provided for transparency and compliance readiness with payment-provider account review. It is not legal advice. Have qualified counsel review it for your jurisdiction before relying on it for regulated filings.
Last updated: August 3, 2026 · GuanWei · https://voxt.actnow.dev