Your data
The short version: the results are yours and live in your storage. Our copies are working copies, and they expire on a timer we can show you.
How long we keep things
| Call audio | Not kept. It is recognised as it arrives and never written down as a recording. |
|---|---|
| Transcript, summary, analysis — our copy | 7 days from the end of the call, then deleted. Long enough for your side to collect them even if it was offline for a few days. |
| The analyser's working copy | 30 days, then deleted with everything it produced. |
| Speaker profiles | Kept while at least one of that person's meetings is still stored. When the last one expires, the profile goes with it. |
| In your Nextcloud | As long as you keep it. Those files are yours; we neither delete them nor can we. |
About the audio
Recognition is not instant, so speech is held in memory in short pieces while it is being processed. Under memory pressure a piece can briefly go to disk, and it is deleted as soon as it has been recognised — including any leftovers, on restart. What never happens is a recording being saved: there is no file of your meeting anywhere on our side, and no way for us to produce one after the fact.
Who can see what
- Between customers — every meeting belongs to one workspace, and a request carrying one workspace's key can only ever reach that workspace's meetings.
- Inside your Nextcloud — files are shared with the people who were in the call, and Nextcloud's own permissions decide the rest. We do not know who your users are; only your Nextcloud does.
- Speaker portraits — a person's own analysis file is shared with the people who were in that meeting, like the rest of it.
Deleting things earlier
A meeting can be dropped from our side before its seven days are up — the copy in your Nextcloud is unaffected, because deleting there is your business, not ours. Write to hello@voxonta.com with the workspace and what you want gone; there is no self-service button for it yet, and pretending otherwise would be worse than saying so.
What we do not do
- Train models on your meetings.
- Read your transcripts, except when you ask us to look at something specific.
- Sell or share anything with anyone. There are no advertising integrations and no analytics inside the product.
Where it runs
Speech recognition runs on our own servers, on a model we host ourselves. Your audio does not go to a third-party speech API.
The analysis step uses a language model, reached through OpenRouter. The text of the meeting — never the audio — is sent to be summarised. Two things constrain who can see it:
- Only providers whose policy is not to retain or train on request data are eligible; the rest are excluded at the request level, not by trusting a setting somewhere.
- Providers we have specifically ruled out — for quality or uptime — never receive anything either.
Which of the remaining providers serves a given request is decided per request, so we cannot promise you one name in advance. What we can promise is the rule they all satisfy. If your security people need the current list rather than the rule, ask and we will send it — it changes as providers come and go.