VOXLY Privacy Policy
Effective 15 September 2026
Who we are
VOXLY Studio LLC is responsible for the personal data described in this policy. Contact us at hello@getvoxlystudio.com, or write to Kralinger Esch 150, 3063 NB, Rotterdam, Netherlands. This policy covers the VOXLY app, our website and support.
Visiting our website
Our website is hosted and delivered by Cloudflare. To deliver pages and protect the service, Cloudflare processes technical request information, which may include your IP address, requested URL, browser information and request timing. We use this hosting for our legitimate interests in providing a reliable and secure website. We have not added advertising trackers or optional website analytics.
Cloudflare may process information internationally and may use security cookies when needed to protect the service. See Cloudflare’s privacy policy for its processing practices. Website infrastructure records are separate from the app’s optional usage analytics and are not covered by its 90-day cleanup schedule. Contact us with questions or to exercise your rights.
Your recordings stay under your control
VOXLY processes imported video, audio and new recordings on your device. The current app does not upload those recordings to our servers to process them or train AI models. Saved projects, project names, editing settings and custom presets are stored locally.
When you choose to save or share a finished file, it goes to the destination you select. That destination’s privacy practices apply. Device or cloud backups you enable may also contain local app data. Deleting your VOXLY account does not remove files already saved, shared or backed up elsewhere.
We request camera, microphone or photo access when relevant to the feature you choose. You can change permissions in iOS Settings. Refusing a permission may prevent the related recording or import feature from working.
Information used to provide VOXLY
Account: We use your email address, account identifier, optional display name and sign-in/session information to create and secure your account. Supabase provides authentication and our account database. Resend delivers sign-in emails.
Export access: Our server receives your account identifier, an export request identifier, the clip duration, request timestamps and completion/allowance status. This lets us apply free-export limits, check access and handle retries. It does not receive the recording itself through this process.
Membership: RevenueCat processes your account identifier and purchase/subscription information to check membership and restore purchases. In the current beta, purchases use RevenueCat’s Test Store and do not charge money. When App Store purchases become available, Apple will process payments. VOXLY does not receive your full payment-card details.
Support: If you contact us, we receive your email address and the messages or attachments you choose to send. Our support mailbox uses Microsoft 365 through GoDaddy. Please avoid sending recordings or personal information that are not needed to resolve your request.
Service operations: Our infrastructure providers may process network and service records, such as IP addresses, request times, authentication events and delivery logs, to operate and protect their services. These are separate from optional product analytics.
Optional usage analytics
Optional usage analytics is disabled in this launch build, including for accounts that previously opted in during testing. Editing, account access, subscriptions and export allowances continue to work independently.
Earlier opted-in test events may remain until the scheduled 90-day cleanup or account deletion. Those records contain event names, identifiers, an account identifier, environment and timestamp; they do not contain media, filenames, email addresses or slider values. Contact us to request deletion sooner.
Why we process personal data
We use account, export-access and membership data to provide the service you request (performance of our contract with you). Earlier optional test analytics was collected with consent. New optional analytics is disabled. You can request erasure of earlier events without affecting the lawfulness of their prior collection. We use necessary security and support information for our legitimate interests in operating a secure, reliable service and responding to requests. Where required, we process information to meet legal obligations. You may object to processing based on legitimate interests.
Who receives information
We use Supabase for account, export-access and opted-in analytics data; RevenueCat for membership; Resend for sign-in email; and Microsoft 365/GoDaddy for support email. Apple receives information when you use its platform or payment services. Providers may use subprocessors to deliver their services. We may disclose information when required by law or necessary to protect legal rights. We do not sell your recordings or use them for advertising.
International processing
Our service providers may process information outside the European Economic Area, including in the United States. Supabase, RevenueCat and Resend include data-processing terms and standard contractual clauses for relevant international transfers in their agreements. The safeguards applicable to a transfer depend on the provider, recipient and destination; this does not mean all data stays in the EU. Contact us to request information about applicable safeguards or a copy, subject to necessary redactions.
How long information is kept
- Local media and projects: Until removed from the device or app storage. Copies you export, share or back up are separate.
- Account and export-access records: While your account exists, to provide the account, preserve your export allowance and handle retries. Deleting your account removes these records from the active Supabase database.
- Optional analytics: Removed from the active database at the first successful daily cleanup after becoming 90 days old. The scheduled cleanup runs at 03:15 UTC. Account deletion also removes linked analytics.
- Support correspondence: Only as needed to resolve and follow up on your request, manage a dispute, or satisfy an applicable legal obligation. Retention depends on whether the request is resolved and whether a dispute or legal obligation remains.
- Provider logs, backups and purchase records: Governed by the applicable service configuration, recovery needs and legal obligations. The 90-day analytics cleanup does not delete provider logs, backups or RevenueCat/Apple purchase records. Account deletion in the app requests deletion of the linked RevenueCat customer record before deleting the VOXLY account. RevenueCat processes that request asynchronously. It does not cancel an Apple subscription or erase records Apple independently retains. Contact us if deletion fails or you need assistance.
Your choices and rights
You can change your display name or delete your account through Account. Account deletion does not cancel a subscription; manage any App Store subscription through Apple’s subscription settings.
Depending on the applicable law, you may request access, correction, deletion, restriction or portability of your personal data, and object to certain processing. Contact hello@getvoxlystudio.com. We may request information needed to verify your identity. We normally respond within one month; if a lawful extension is needed, we will explain it. You may complain to the Dutch Autoriteit Persoonsgegevens or your local data-protection authority.
Age eligibility
VOXLY is intended for people aged 13 and over. It is not intended for children under 13. If you believe a child under 13 has provided account information, contact hello@getvoxlystudio.com so we can investigate and address it.
Changes
We will update this policy when our practices change. Material changes will be made available in the app. New optional processing requiring consent will not be enabled merely because the policy changes.