Privacy Policy
Version 2026-07-26
This policy explains what Voice Studio collects, why it uses that data, and how you can exercise your privacy rights. Contact hello@proofof.tech from your account email for privacy requests.
Data we collect
We collect your email address and account profile, conversation transcripts, conversation titles, usage metrics, authentication records, and the technical information needed to operate and secure the service. Voice audio is processed during a live call and is not retained by the application.
How we use data
We use account data to authenticate you, provide conversations, preserve continuity, enforce usage and abuse controls, diagnose failures, secure the service, and communicate about your account. We do not use transcript text in server logs.
Storage and retention
Account, session, directory, acceptance, and usage data lives in Cloudflare D1. Raw conversation transcripts are retained in per-conversation Durable Object storage for 30 days. Semantic and episodic memory remains until you use the relevant forget control, delete the conversation, or delete your account. Voice audio is not retained by the application. Server logs contain identifiers, pipeline stages, durations, and error codes, not transcript text.
Safety reports preserve the selected assistant turn, the preceding user turn, and limited character context for 180 days. Private account-export archives are retained for seven days. Minimal deletion tombstones containing opaque account and Stripe identifiers are retained for 18 months for fraud prevention, payment-race correction, and deletion idempotency. Anonymous aggregate usage and provider-cost records may remain after account deletion without account, reservation, turn, prompt, or transcript identifiers.
Service providers and data location
Cloudflare processes and stores data through D1, Durable Objects, R2, Workers, Workers AI, Email Service, Queues, and related network services. Stripe processes payment, billing-address, tax, invoice, dispute, and subscription data. Cloudflare, Stripe, model providers, and email providers may retain records under their own legal, security, and operational policies. Data may be processed outside your country, subject to the provider’s transfer safeguards.
Your rights
Depending on where you live, including under the General Data Protection Regulation (GDPR), you may have rights to access, correct, export, restrict, object to processing of, or delete personal data. You may also withdraw consent and complain to your data-protection authority. Account settings provide a self-service export and deletion flow. You can also contact hello@proofof.tech from the account email.
Deletion
You can delete a conversation from the studio. This removes its raw transcript, episodic memory, and the related user-character semantic memory. You can delete your account from account settings after confirming a short-lived email challenge. Account deletion ends active calls, removes application account data and Durable Object state, and deletes private export objects. Limited tombstones, active report evidence, anonymous cost records, and records a provider must retain for law, fraud prevention, security, tax, or dispute resolution are exceptions to immediate deletion.
Changes
The version date identifies the policy accepted for your account. Material changes will be presented before they govern continued use.