Foo AI Corp.
Privacy Policy
Voicecape has two features, and they treat your voice differently. Dictation keeps the audio on your Mac unless you switch on Cloud dictation. Recording uploads the audio, because that is what a recording is. This page sets out, for each of them, what leaves your device and why.
What stays on your device
With both cloud features off — the state every Voicecape installs in — nothing you say or write leaves your Mac, and dictation works with the Mac in airplane mode. You can confirm that yourself with a network monitor such as Little Snitch or LuLu. Turning either one on changes it, and the two sections below say exactly what goes where.
- Your dictation history, if you turn it on. It is off by default, and it never leaves your device at all.
- Audio captured while you dictate — unless you turn on Cloud dictation. With it off, the audio is processed in memory and discarded.
- The recognized text and the cleaned result — unless you turn on Cloud cleanup, which is off by default.
- Your settings. Your personal dictionary stays here too, except that the words in it are sent with each request when one of the two cloud features above is on, so that names and jargon come out right.
What the app does send, and when
Those three are everything the app does on its own while it is signed out of an account — which is how every Voicecape installs, and how it stays unless you create one. There is no analytics SDK, no crash reporter and no telemetry endpoint in it, and none of the three carries audio or text. Cloud polish, described next, is not one of them: it happens only if you turn it on, and only when you dictate. Signing in adds one more, described in the accounts section below. If we ever add a network call it will appear here and in the release notes.
Cloud polish — new on 2026-08-21, and off unless you choose it. The app gains a processing mode called cloud polish. It is not the default: your dictation is cleaned up on your Mac unless you open Settings and select it. If you never select it, your Mac makes exactly the requests listed above and no text of any kind leaves it.
When you do select it, the already-transcribed text of each dictation is sent to our relay, and from there to one language-model provider — whichever of the following is available, tried in this order: Cloudflare, Inc., Google LLC, OpenAI, L.L.C., Groq, Inc. Speech recognition happens on your Mac unless you switch on Cloud dictation, a separate setting. With it on, the audio of that dictation is streamed to our relay while you speak, and from there to one speech-recognition provider: Soniox Inc. For dictation that is the only one; recording uses a different provider, named in the processors section below. With Cloud dictation off, dictation audio never leaves your Mac. The two settings are independent: turning on cloud cleanup does not send audio.
What our contract with Soniox says, quoted rather than paraphrased. Our signed Data Processing Agreement states that audio is "processed transiently for transcription or translation" and that "Soniox does not store audio or text by default unless explicitly configured by the customer" (§11, §12). Storage can only be switched on by a customer setting; our requests carry no storage options. The same agreement states that customer data "is processed solely to provide the requested services" and that Soniox "does not use customer data to train models that serve other customers" (§11). We quote that last clause with its limit intact rather than shortening it to "does not train", because the limit is what the contract says.
That text is used to produce the cleaned-up result and for nothing else. We keep no copy of it: the relay stores nothing, and its logs record only which device made the request, which provider answered and how long it took. The providers process it under their own terms and may hold it briefly to detect abuse. The request is not tied to an account, and it carries no name, email address or licence key.
During the 14-day trial the same mode is available. To make that possible the app asks our activation endpoint for a short-lived permission token when you select cloud polish, and that request carries the device identifier and nothing else.
One exception worth stating rather than hiding: the speech model ships inside the app, so a normal install downloads nothing — but if the in-bundle file cannot be read, the app can fetch the same model from its public source. That path only runs on a damaged installation.
- Licence activation: your licence key, a device identifier generated by the app, and a device label. Sent when you press Activate after entering a key. The device identifier is what makes the three-Mac limit countable. The label is a fixed string in the current build, not the name you gave your Mac, so nothing you named is transmitted.
- Licence revalidation: on a Mac where a licence is already active, the app re-checks that licence in the background when you open it, sending the same licence key, the device identifier and the activation identifier from that first activation. It goes out at most once every seven days, never while you dictate, and never on a build that has not been activated. If it fails nothing locks — the app keeps working on the signed permission it already holds, which lasts ninety days.
- Update checks: the app asks our update feed once a day whether a newer version exists, sending its own version number. Updates download in the background and are never installed without you.
Accounts
From 2026-08-30 you can create a Voicecape account and sign in from the app. It is optional. The 14-day trial starts the moment you first launch the app, and a subscription is activated with a licence key on the Mac itself; neither needs an account, and this section describes only what happens if you make one.
Creating an account with an email address and a password sends both to Supabase, the service that runs authentication for us. The password travels from the app to Supabase over HTTPS and does not pass through our own servers; Supabase keeps it hashed, so neither they nor we can read it back. Your email address is what identifies the account: we use it to confirm the address, to sign you in, and to send a reset link when you ask for one.
Signing in with Google or Apple sends no password at all. Your browser is sent to accounts.google.com, or macOS asks Apple on our behalf, and what comes back is a signed identity token. Google or Apple therefore learns that you signed in to Voicecape, and passes us the account identifier and the email address on it — or, with Apple, the private relay address you chose instead of it.
Signing in issues a pair of session tokens. They live in a file on your Mac and at Supabase, they are what proves it is you on the next request, and they carry nothing about what you dictate. While you are signed in the app makes an automatic request that is not among the three above: when you open it and the session is close to expiring, it renews that session with Supabase, sending the refresh token and nothing else. Signing out clears them on your Mac and asks Supabase to end the session.
What an account is for today is the account itself — creating it, signing in, staying signed in, resetting the password, and deleting it. It does not carry your licence, your subscription or your device registrations: those stay with the licence key on each Mac. It does not sync anything between Macs, and it changes nothing about how dictation works. If any of that changes, this page changes first.
You can delete the account from the app: Settings → Account → Delete account. It asks you to prove it is you first — your password, or signing in with Google or Apple again — so that a session left open on a Mac you no longer have cannot erase it. The account record is then erased at Supabase. Deleting the account does not cancel a subscription and does not release a licence; write to [email protected] for those.
What we hold, and why
Your dictation is not on this list: it does not reach us, with or without an account.
- Account — your email address, and either a password (kept hashed by Supabase, never readable by us) or the account identifier a Google or Apple sign-in returns instead. Used to create the account, sign you in and keep you signed in. Only if you create one.
- Licence activation — your licence key, a device identifier generated by the app, and a device label. Used to check the licence is valid and to count how many Macs are on it.
- Purchase and licence records — email address, order reference, and country for tax purposes, passed to us by Polar. Used to issue the licence and support it.
- Domestic (KRW) subscriptions — if you subscribe in Korean won on our own checkout page: your email address, the billing records of that subscription, a recurring-billing token issued by the payment gateway (a stand-in for your card — the card number itself never reaches us), a fingerprint (hash) of your licence key rather than the key itself, and the device registrations on it. Used to charge the cycle you chose, to count the three-Mac limit, and to process refunds.
- Store subscriptions — from 2026-09-11, if you buy a subscription as an in-app purchase in the iPhone or Android app: the transaction identifier the store issues, the account identifier we attach to that purchase so it can be matched to your Voicecape account, and the subscription status the store returns (whether it is active and when the period ends). Used to open the paid features for that account. It carries no card number — the store never gives us one — and no audio or dictated text. Only if you buy inside the app; those apps are not released yet.
- Email you send us — the address and the message, used to answer you and to follow up.
On iPhone and Android
Voicecape is a Mac app today. The iPhone and Android apps are not released — there is no build in either store — and nothing in this section is happening yet. It is published in advance, taking effect 2026-09-11, because what an app collects has to be disclosed before it collects it.
When those apps ship, five kinds of data can leave the phone. They are the same five we declare to Apple in the app’s privacy manifest, and none of them is used for advertising or shared with a data broker — there is no advertising SDK and no tracking identifier in the app:
- Your email address, if you create an account or sign in. Same as on the Mac, and optional in the same way.
- The audio of a dictation, only while Cloud dictation is on. It is off unless you turn it on; with it off the audio never leaves the phone.
- The recognized text of a dictation, only while Cloud cleanup is on. Off unless you turn it on.
- Your purchase, if you subscribe inside the app: the transaction identifier and the account identifier attached to it. Described below.
- A device identifier the app generates for itself. It is not the advertising identifier and not a hardware serial — the app makes it, and it is what makes the trial and the device limit countable.
Buying inside the app
From 2026-09-11, a subscription bought inside the iPhone or Android app is an in-app purchase, and Apple Inc. or Google LLC is the seller and the payment processor for it. That is a different role from the one they already have on this page: Sign in with Apple and Sign in with Google are identity checks, and this is money. Both companies are named twice below for that reason.
What leaves the phone when you buy is the transaction identifier the store issues and an account identifier we attach to the purchase so that it can be matched to your Voicecape account. No audio, no dictated text and no email address is sent on that request.
Our server then asks the store directly — with our own developer credentials, not yours — whether that transaction is a live subscription, and the store answers with the status and the date the period ends. We do not receive your card number, your billing address or your store account name; the store does not give them to us.
What we keep from that is listed above under what we hold. The purchase itself, and the payment, live with Apple or Google under their own privacy policies.
What this website collects
This site uses no advertising trackers, no session recording, and no cross-site profiling. There is no analytics script on it, and it sets no cookies — so there is nothing to opt out of, and blocking cookies entirely changes nothing about how it works. One other domain of ours, recordport.app, is kept online so that copies of an earlier app can still find their updates; that site does load Google Analytics 4 (measurement ID G-95YTVPD0E9, from 2026-08-28), and it does not load it at all if your browser sends Do Not Track or Global Privacy Control. Retention there is set in the Analytics property and we check it daily against our own code — Event-level data: 2 months. User-level data: 14 months. Google LLC holds it; we retrieve only 28-day aggregates and keep no per-visitor record.
The hosting and CDN provider records ordinary connection logs — IP address, timestamp, requested path — for delivery and security. We do not query or combine those to identify anyone. What we do read is the count: how many requests reached a given path on a given day, so we can tell whether anyone is using the product. Those totals carry no IP address and name no one, and we never open an individual record.
Payments
Purchases are handled by Polar Software, Inc. (Polar) as merchant of record. Card details are entered on Polar’s systems and are never seen by us. We receive the information needed to issue and support your licence — typically your email address, order reference and country for tax purposes.
From 2026-09-02, subscriptions purchased in Korean won on our own checkout page are different: Foo AI Corp. sells those directly, and the payment is processed on our behalf by PortOne Corp. (주식회사 코리아포트원), a Korean payment gateway. Your card details are entered in the payment window PortOne opens and never pass through our page or our servers; what we receive and keep is a recurring-billing token, your email address and the billing records.
From 2026-09-11, there is a third rail: an in-app purchase made inside the iPhone or Android app, where Apple Inc. or Google LLC is the seller. The section above says what is sent and what comes back. Those apps are not released yet.
How long we keep things
- Account records: for as long as the account exists. Deleting the account erases them. Session tokens go when you sign out; the access token is short-lived and the app renews it, and if a renewal is refused the app deletes the stored session.
- Licence records: for as long as the licence exists.
- Domestic (KRW) subscription records: for as long as the subscription exists, and the contract and payment records Korean e-commerce law requires us to retain, for 5 years.
- Store subscription records: for as long as the subscription exists. When it lapses and is not renewed we delete the transaction identifier and the status we cached for it; the store keeps its own record of the purchase under its own policy, which we cannot delete.
- Support email: up to 3 years, so we can follow up on an earlier problem.
- Records that tax or e-commerce law requires us to retain: for the period that law sets.
How we delete it
When the retention period ends or the purpose is met, we delete it without waiting to be asked. Electronic files are deleted by a means that does not leave them recoverable; anything printed is shredded.
Records the law requires us to keep are held apart from everything else until that period ends, then deleted the same way.
Sharing, and where the data goes
We do not sell personal data, and we do not share it for advertising. The processors below run the parts we do not run ourselves. All but the Korean card processor are in the United States, so activating a licence sends data outside Korea and outside the EEA — and so does using cloud polish, if you turn it on, and so does creating an account. For users in Korea: we transfer personal data abroad by way of the processing entrustment necessary to perform our contract with you, under PIPA Art.28-8(1)3(a). That is why this policy discloses the items below — the recipient, the country, the data transferred, the purpose and the retention — instead of asking you for a separate consent.
- Polar Software, Inc. (Polar), United States — payment processing, licence key issue and activation records.
- Supabase, Inc., United States — from 2026-08-30, the authentication service behind accounts: it holds the email address, the hashed password and the sessions, and it is where an account is erased when you delete it. The project itself runs in a Seoul region (ap-northeast-2), so the data sits in Korea; the company operating it is American, which is why it appears here. Only used if you create an account.
- Apple Inc., United States — from 2026-08-30, identity verification for Sign in with Apple. Apple issues the identity token and passes us the email address on the account, or the private relay address you chose instead. Only used if you sign in with Apple.
- accounts.google.com (Google LLC), United States — from 2026-08-30, identity verification for Sign in with Google. Your browser is sent there by the authentication service, and Google returns the account identifier and email address. We name the address rather than only the company because Google appears twice on this page in different roles, and this is the one you are redirected to. Only used if you sign in with Google.
- Apple Inc., United States — from 2026-09-11, seller and payment processor for an in-app purchase made in the iPhone app. It receives the purchase itself, and it answers our question about whether that subscription is live. Only used if you buy inside the iPhone app; that app is not released yet.
- Google LLC, United States — from 2026-09-11, seller and payment processor for an in-app purchase made in the Android app, in the same way. Only used if you buy inside the Android app; that app is not released yet.
- Plus Five Five, Inc. (Resend), United States — from 2026-08-30, delivery of the account emails: the confirmation message when you sign up, and the link when you ask to reset a password. The authentication service hands each message to Resend, which receives your email address and the body of that message, including the link. Only used when an account email is sent to you. It also carries our own internal operational alerts to our address — a general alerting channel, not only delivery failures: error messages, stack traces (up to 1,500 characters), the request path on which an unhandled error occurred, scheduled-job and database failure text, and job or organization identifiers. Identifying details that happen to sit inside an error string travel with it. Audio, transcripts and summaries are not sent.
- Notion Labs, Inc., United States — only when an administrator of your workspace turns the Notion integration on. The summary text — the points, decisions and action items — is written into the Notion database that administrator chose. Audio is never sent. The integration is off until someone turns it on, and turning it off stops it.
- Slack Technologies, LLC (Salesforce, Inc.), United States — only when an administrator of your workspace turns the Slack integration on. Connecting Slack exchanges an authorisation code for a token; after that the summary text is posted to the channel behind the webhook address that administrator supplied. Audio is never sent. The integration is off until someone turns it on, and turning it off stops it.
- PortOne Corp. (주식회사 코리아포트원), Republic of Korea — from 2026-09-02, processing the recurring card payments of subscriptions purchased in Korean won, which can involve passing the charge to a Korean payment-gateway network it works with. Only used if you pay in Korean won.
- Cloudflare, Inc., United States — website hosting and delivery, and relaying activation requests. For licences sold through Polar the activation endpoint keeps no database of its own, so it passes requests through rather than storing them. From 2026-08-21, if you turn on cloud polish, Cloudflare also runs the language model that cleans up your transcribed text, on its own network — and from 2026-09-02, the domestic (KRW) subscription records listed above are stored in a database on Cloudflare’s network.
- Tailwind Labs Inc., United States — our API and MCP documentation pages load their styling script from cdn.tailwindcss.com. Opening either page makes your browser request that host; it happens whether or not you have an account, which is why it is named here.
- Deepgram, Inc., United States — speech-to-text for recordings (not for dictation, which uses Soniox). It receives the audio of a recording you upload. Our request carries the flag that opts the audio out of being used to train their models.
- Vercel Inc., United States — hosting for the web console. The console renders on the server, which means the text of a summary — its key points, decisions, action items, participant names and the recording title — is assembled on Vercel each time you open it. Functions run in the Seoul region.
- Cloudflare, Inc. (AI Gateway), United States — every summary and cleanup request passes through this gateway on its way to the model provider. Its logging is on by default and would record the request and response bodies, so each of our requests carries headers that turn body logging and caching off. We cannot measure from outside whether Cloudflare honours them; we can only show that we send them.
- Functional Software, Inc. (Sentry), United States — crash and error diagnostics. It receives the error itself: the type, the stack, the app version and an anonymous installation identifier. It does not receive audio, transcripts or summaries.
- Expo (650 Industries, Inc.), United States, with Apple Inc. and Google LLC — delivery of push notifications to the phone apps. Expo holds the push token for a device and passes the notification to Apple or Google, who deliver it. The notification text says that something is ready, not what it says.
- Paddle.com Market Ltd., United Kingdom, and Paddle.com Inc., United States — merchant of record for paid plans. They receive the billing details and issue the receipt and any tax; we never see the card.
- Anthropic, PBC, United States — an alternative provider for summaries. Present in the code and reachable by a deployment-wide setting, which is currently not set to it. If that changes we will say so on this page before it does.
- NAVER Cloud Corp. (CLOVA Speech), Republic of Korea — an alternative speech-to-text provider for Korean. Present in the code and reachable by a deployment-wide setting, which is currently not set to it. If that changes we will say so on this page before it does.
- Google LLC, United States — from 2026-08-21, cleaning up transcribed text for cloud polish when Cloudflare is unavailable. Only used if you turn cloud polish on.
- OpenAI, L.L.C., United States — from 2026-08-21, the same role when the two above are unavailable. Only used if you turn cloud polish on.
- Groq, Inc., United States — from 2026-08-21, the same role when the three above are unavailable. Only used if you turn cloud polish on.
- Soniox Inc., United States — from 2026-08-22, speech recognition for cloud dictation. It receives the audio of that dictation. Only used if you turn cloud dictation on.
How we protect it
- Local by default: with both cloud settings off, neither audio nor text leaves the Mac, so the data most worth protecting is not somewhere it can be taken from. When you turn one on, what it sends is named above, and no copy is retained.
- All traffic between the app and our server is over HTTPS.
- Activation responses are signed, and the app verifies the signature against a public key compiled into it before storing anything.
- For licences sold through Polar, the activation service holds no database — there is no store of that licence data on our side to breach. Korean-won subscriptions do require a small store of ours (billing records, the recurring-billing token, a hash of the key, device registrations); it holds no card numbers and no plaintext licence keys.
- Account passwords are never stored by us and never travel through our servers: the app sends them straight to Supabase, which keeps a hash. The session tokens on your Mac are held in the app’s own storage and are discarded when you sign out.
- Access to what we do hold is limited to the people who need it to do the work.
No profiling, and no automated decisions
We do not collect special-category data, and we do not build profiles. Nothing about you is decided automatically in a way that has a legal or similarly significant effect: whether an activation succeeds turns on two facts, whether the key is valid and how many devices are already registered.
Your rights
You can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or object to a particular use. Write to [email protected] and we will respond within 30 days.
Because dictation data never reaches us, a deletion request covers your account, licence and support records — the dictation itself is deleted by you, on your device, whenever you choose. If you have an account you do not have to write to us to delete it: the app does it directly, from Settings → Account.
Children
Voicecape is not directed at children under 14, and we do not knowingly collect their personal data.
Changes to this policy
Changes are posted on this page with the date they take effect. Anything material goes up at least 7 days before it applies, and anything that reduces your rights at least 30 days before.
Every version of this page, newest published first. The date shown is when that version takes effect, which can be later than when it went up:
- v1.7 — 2026-09-07. Two processors are added: Notion Labs, Inc. and Slack Technologies, LLC. This is a correction, not a new feature — the web console has been able to send a summary to Notion or Slack since before this page existed, and the integrations are off until an administrator turns them on, but this document did not name either company. It does now, in all five languages. Nothing about how the integrations behave has changed. It takes effect the day it is posted: there are no users to give notice to, and delaying a correction only lengthens the time a published page says something untrue.
- v1.6 — 2026-09-07. RecordPort becomes part of Voicecape: one service with two features, Dictation and Recording. Eight processors are added — Deepgram, Inc., Vercel Inc., Cloudflare, Inc. (AI Gateway), Functional Software, Inc. (Sentry), Expo with Apple Inc. and Google LLC, Paddle.com, Anthropic, PBC and NAVER Cloud Corp. — and Tailwind Labs Inc. alongside them. Two sentences that were only true while there was one surface are corrected: "Soniox Inc., and no other" now says so of dictation, because a recording goes to a different provider; and audio staying on your Mac is now stated per feature, since a recording is uploaded to be processed. It also discloses that recordport.app loads Google Analytics and honours Do Not Track and Global Privacy Control. This takes effect the day it is posted: there are no users to give notice to, and waiting would only lengthen the time this page says less than the product does.
- v1.5 — 2026-09-11. In-app purchase on iPhone and Android. Apple Inc. and Google LLC gain a second role, seller and payment processor, alongside the identity check they already did; the transaction identifier, the account identifier attached to it and the subscription status are added as things we hold; and what the phone apps collect is set out as the same five items we declare in the app’s privacy manifest. Nothing here is running yet — neither app is released — and it is posted seven days before it takes effect for that reason.
- v1.4 — 2026-08-30. Accounts. You can create a Voicecape account and sign in; Supabase, Inc., Plus Five Five, Inc. (Resend), Apple Inc. and accounts.google.com are added as processors, the email address, password and session tokens are added as things we hold, and the automatic session renewal that happens while you are signed in is described. The sentence saying there was no account to create is gone, in all five languages.
- v1.3 — 2026-09-02. Subscriptions in Korean won, sold by us directly. PortOne Corp. added as a processor; billing records, the recurring-billing token, a hash of the licence key and the device registrations added as things we hold.
- v1.2 — 2026-08-22. Cloud dictation. Soniox Inc. added as a processor: with the setting on, the audio of that dictation leaves your Mac.
- v1.1 — 2026-08-21. Cloud polish. Google LLC, OpenAI, L.L.C. and Groq, Inc. added as processors, and Cloudflare, Inc.'s role widened to running the language model that cleans up transcribed text.
Who is responsible
The person accountable for personal data at Foo AI Corp., and the person who handles privacy questions, complaints and requests, is JEEHO SONG, our representative director.
Privacy questions and requests: [email protected], or 02-581-3001.