Privacy Policy
Effective Date: December 2025 | Last Updated: December 2025
We take the protection of your personal data very seriously. This privacy policy informs you about how we collect, process, and protect your data when you use voca.talk.
1. Data Controller
Manuel Weichselbaum[Street Address]
[Postal Code] [City]
Austria
Email: office@voca.talk
2. Data We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Display name
- Profile picture (if provided)
- Authentication credentials (managed by Firebase)
2.2 Usage Data
When you use our service, we automatically collect:
- IP address
- Browser type and version
- Device information
- Pages visited and features used
- Date and time of access
- Language preferences
2.3 Video and Audio Data
During video learning sessions, we process:
- Audio streams (for real-time transcription)
- Video streams (for live communication)
- Transcriptions of conversations
- AI-generated translations
2.4 AI Training Data
Important Notice: We may use anonymized conversation data and transcriptions to improve our AI models and services. This data is processed in a way that does not identify individual users. You can opt out of AI training data usage in your account settings.
3. How We Use Your Data
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing the service | Contract performance (Art. 6(1)(b)) |
| Account management | Contract performance (Art. 6(1)(b)) |
| Real-time transcription & translation | Contract performance (Art. 6(1)(b)) |
| Analytics & service improvement | Legitimate interest (Art. 6(1)(f)) |
| AI model training | Consent (Art. 6(1)(a)) |
| Legal compliance | Legal obligation (Art. 6(1)(c)) |
4. Third-Party Services
We use the following third-party services to provide our platform. Your data may be processed by these providers:
4.1 Firebase (Google Cloud)
- Purpose: Authentication, database, hosting
- Data processed: Account data, usage data
- Location: Europe (europe-west1, Belgium)
- Privacy Policy: firebase.google.com/support/privacy
4.2 Google Analytics
- Purpose: Website analytics and usage statistics
- Data processed: Usage data, device information, IP address (anonymized)
- Privacy Policy: policies.google.com/privacy
You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
4.3 LiveKit
- Purpose: Real-time video and audio streaming
- Data processed: Audio/video streams, connection metadata
- Privacy Policy: livekit.io/privacy
4.4 Deepgram
- Purpose: Speech-to-text transcription
- Data processed: Audio streams
- Privacy Policy: deepgram.com/privacy
4.5 OpenAI
- Purpose: Speech-to-text (Whisper), AI translation
- Data processed: Audio streams, text for translation
- Privacy Policy: openai.com/privacy
4.6 Google Gemini
- Purpose: AI translation and language processing
- Data processed: Text for translation
- Privacy Policy: policies.google.com/privacy
5. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion + 30 days |
| Session transcripts | 90 days (or until manual deletion) |
| Analytics data | 14 months |
| Server logs | 30 days |
| Anonymized AI training data | Indefinitely (no personal data) |
6. Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the following rights:
- Right of Access (Art. 15): Request a copy of your personal data
- Right to Rectification (Art. 16): Correct inaccurate data
- Right to Erasure (Art. 17): Request deletion of your data ("right to be forgotten")
- Right to Restriction (Art. 18): Restrict processing of your data
- Right to Data Portability (Art. 20): Receive your data in a machine-readable format
- Right to Object (Art. 21): Object to processing based on legitimate interests
- Right to Withdraw Consent (Art. 7): Withdraw consent at any time
To exercise these rights, contact us at office@voca.talk.
7. Data Transfers
Your data is primarily stored and processed within the European Union (EU). However, some of our third-party service providers (OpenAI, Deepgram) may process data in the United States.
For transfers to the US, we rely on:
- EU-US Data Privacy Framework (where applicable)
- Standard Contractual Clauses (SCCs)
- Adequate safeguards as required by GDPR
8. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption in transit (TLS/HTTPS)
- Encryption at rest
- Access controls and authentication
- Regular security reviews
- Secure cloud infrastructure (Google Cloud)
9. Children's Privacy
voca.talk is intended for users aged 18 and older. We do not knowingly collect personal data from children under 18. If you believe we have inadvertently collected data from a minor, please contact us immediately.
10. Cookies
We use cookies and similar technologies. For detailed information, please see our Cookie Policy.
11. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes by posting a notice on our website or sending you an email. The "Last Updated" date at the top indicates when the policy was last revised.
12. Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. In Austria, this is:
Österreichische DatenschutzbehördeBarichgasse 40-42
1030 Vienna, Austria
www.dsb.gv.at
13. Contact
For any questions about this privacy policy or our data practices, please contact us:
Email: office@voca.talk
Last updated: December 2025