Privacy Policy
Last updated: June 12, 2026
VoiceToMail ("we," "us," "our," or the "Service") is a professional productivity suite engineered to facilitate advanced email composition through voice-to-text transcription and artificial intelligence-driven drafting. Operating as a Google Chrome browser extension integrated with the Gmail environment, we recognize that our functionality requires access to highly sensitive user data, including personal voice patterns and private email correspondence. We acknowledge the paramount importance of data privacy and are committed to a "Privacy by Design" and "Privacy by Default" philosophy. This Global Privacy Policy (the "Policy") constitutes a binding legal agreement describing the collection, processing, retention, and security of data. It is drafted to satisfy the rigorous transparency requirements of the European Union's General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the specific compliance mandates of the Google API Services User Data Policy, specifically regarding "Limited Use" scopes.
1. Preamble and Scope of Applicability
This Policy applies exclusively to the VoiceToMail ecosystem, which encompasses:
Scope of Service
- The VoiceToMail Chrome Extension: The client-side software installed in the user's browser that captures voice input and interacts with the Gmail interface.
- The VoiceToMail Web Platform: The cloud-based dashboard used for account management, subscription billing, and data rights administration, available at voicetomail.eu.
- Backend API Services: The secure infrastructure hosted on Google Cloud Platform (GCP) that facilitates AI inference, user authentication, and service administration.
2. Identification of the Data Controller
The Data Controller responsible for the processing of your personal data is:
Legal Entity
Daniele Donzello
Juliana Ursyna Niemcewicza 26 lok. 57, 02-306 Warszawa
NIP (Tax Identification Number): 7011250684
Jurisdiction: Poland (European Union)
Regulatory Authority: President of the Personal Data Protection Office (Prezes Urzedu Ochrony Danych Osobowych, UODO)
For the processing of Gmail message content and voice inputs, VoiceToMail acts primarily as a Data Processor (or Service Provider) on behalf of the user, who retains the role of Data Controller over their specific email content. However, VoiceToMail assumes Controller responsibilities regarding the security, retention, and sub-processing of this data while it is within our infrastructure.
Juliana Ursyna Niemcewicza 26 lok. 57, 02-306 Warszawa
NIP (Tax Identification Number): 7011250684
Jurisdiction: Poland (European Union)
Regulatory Authority: President of the Personal Data Protection Office (Prezes Urzedu Ochrony Danych Osobowych, UODO)
For the processing of Gmail message content and voice inputs, VoiceToMail acts primarily as a Data Processor (or Service Provider) on behalf of the user, who retains the role of Data Controller over their specific email content. However, VoiceToMail assumes Controller responsibilities regarding the security, retention, and sub-processing of this data while it is within our infrastructure.
Data Protection Contact
Inquiries regarding this Policy or the exercise of user rights should be directed to our privacy office:
- Email: legal@voicetomail.eu
- Subject Line: "Privacy Compliance Inquiry"
3. Google API Services & "Limited Use" Disclosure
CRITICAL COMPLIANCE NOTICE: VoiceToMail's integration with Gmail is the core of our functionality. We adhere strictly to the Google API Services User Data Policy.
The "Limited Use" Declaration
VoiceToMail's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
This signifies that our handling of data obtained through Google API scopes is governed by stricter standards than standard personal data.
This signifies that our handling of data obtained through Google API scopes is governed by stricter standards than standard personal data.
Specific Restrictions on Gmail Data
In strict adherence to Google's verification requirements for sensitive scopes, we legally bind ourselves to the following limitations:
- User-Visible Features Only: We only access Gmail data to provide features that are prominently visible and requested by you, the user. Specifically, this includes drafting emails from voice notes, generating AI replies based on thread context, and summarizing email threads. We do not use Gmail data for background processes unrelated to these explicit tasks.
- Prohibition on Advertising: We never use Gmail data for advertising. We do not sell, transfer, or analyze your email content or metadata for serving ads, including retargeting, personalized, or interest-based advertising.
- Prohibition on Profiling: We do not use email content to build personal profiles of users for creditworthiness, lending, or marketing demographics.
- No Data Transfer: We do not transfer Gmail data to third parties, except as necessary to provide the features (e.g., sending text to our AI provider for drafting), for security purposes (investigating abuse), to comply with applicable law, or as part of a merger/acquisition where the successor entity agrees to these same terms.
Human Access Restriction
No human at VoiceToMail reads your emails. We strictly prohibit human access to user data unless:
- You have provided affirmative, specific consent for us to view a specific message (e.g., for a complex support ticket).
- It is necessary for security purposes, such as investigating a vulnerability or abuse.
- It is required to comply with applicable law or a valid legal process.
- The data is aggregated and fully anonymized for internal operations (e.g., statistics on average email length) and contains no personally identifiable information.
4. Comprehensive Data Inventory and Collection Methods
We employ a "data minimization" strategy, collecting only what is strictly necessary.
Audio and Voice Data (Client-Side Processing)
Data Type: Raw audio captured via the microphone.
Collection Method: Browser-native webkitSpeechRecognition API.
Processing Location: Voice data is processed using the browser's built-in speech recognition capabilities. In Google Chrome, the webkitSpeechRecognition API transmits audio data to Google's cloud-based speech recognition servers for transcription. The audio is processed by Google and the transcribed text is returned to the browser. VoiceToMail's own servers never receive raw audio data. See Section 10 (Sub-Processors) for Google's role as a sub-processor in this context.
Storage: None. VoiceToMail does not upload, store, or archive raw audio files on our servers. The audio data exists transiently in the browser's volatile memory and is discarded immediately after transcription by the browser's speech recognition service.
Collection Method: Browser-native webkitSpeechRecognition API.
Processing Location: Voice data is processed using the browser's built-in speech recognition capabilities. In Google Chrome, the webkitSpeechRecognition API transmits audio data to Google's cloud-based speech recognition servers for transcription. The audio is processed by Google and the transcribed text is returned to the browser. VoiceToMail's own servers never receive raw audio data. See Section 10 (Sub-Processors) for Google's role as a sub-processor in this context.
Storage: None. VoiceToMail does not upload, store, or archive raw audio files on our servers. The audio data exists transiently in the browser's volatile memory and is discarded immediately after transcription by the browser's speech recognition service.
Gmail Message Content
Data Type: Email subject lines, body text, recipient lists, sender information, and timestamps ("Thread Context").
Collection Method: Accessed via the Gmail API and secure reading of the Gmail interface (DOM) when you trigger a "Generate Reply," "Generate Email," or "Summarize" action. The extension reads the email thread currently visible in your Gmail compose or reading view.
Purpose: To allow the AI to understand the context of the conversation so it can generate a relevant response.
Storage: Ephemeral. This data is processed in real-time and transmitted to our AI sub-processors solely for the purpose of generating a response. We do not permanently store email content on our servers. Any temporary cache required for processing is automatically purged within 30 days or immediately upon session termination.
Collection Method: Accessed via the Gmail API and secure reading of the Gmail interface (DOM) when you trigger a "Generate Reply," "Generate Email," or "Summarize" action. The extension reads the email thread currently visible in your Gmail compose or reading view.
Purpose: To allow the AI to understand the context of the conversation so it can generate a relevant response.
Storage: Ephemeral. This data is processed in real-time and transmitted to our AI sub-processors solely for the purpose of generating a response. We do not permanently store email content on our servers. Any temporary cache required for processing is automatically purged within 30 days or immediately upon session termination.
User Interaction and Usage Telemetry
Data Type: Button clicks (e.g., "Start Recording," "Insert Draft"), feature usage counts, error logs, performance latency metrics, and application version information.
Collection Method: Captured via the PostHog analytics suite.
Privacy Control: All telemetry is pseudonymized. Events are associated with your Firebase User ID (a persistent, unique account identifier) rather than your name or email address. This means that while your identity is not directly visible in our analytics dashboard, your behavioral patterns (such as which features you use and when) can be associated with your account. Pseudonymized data remains personal data under GDPR, and we process it under our legitimate interest in improving service quality and reliability (GDPR Art. 6(1)(f)).
Cookie Consent: On the VoiceToMail website (voicetomail.eu), PostHog uses cookies and local storage for session tracking. We will ask for your consent before placing analytics cookies. You can manage your analytics preferences at any time through our cookie settings. See Section 15 (Cookies and Tracking Technologies) for details.
Purpose: To identify bugs, optimize latency, understand feature adoption, and improve the service.
What We Do NOT Track: We do not track the content of your actions (i.e., we know you clicked "Generate," but we do not know what you generated or the content of your emails).
Collection Method: Captured via the PostHog analytics suite.
Privacy Control: All telemetry is pseudonymized. Events are associated with your Firebase User ID (a persistent, unique account identifier) rather than your name or email address. This means that while your identity is not directly visible in our analytics dashboard, your behavioral patterns (such as which features you use and when) can be associated with your account. Pseudonymized data remains personal data under GDPR, and we process it under our legitimate interest in improving service quality and reliability (GDPR Art. 6(1)(f)).
Cookie Consent: On the VoiceToMail website (voicetomail.eu), PostHog uses cookies and local storage for session tracking. We will ask for your consent before placing analytics cookies. You can manage your analytics preferences at any time through our cookie settings. See Section 15 (Cookies and Tracking Technologies) for details.
Purpose: To identify bugs, optimize latency, understand feature adoption, and improve the service.
What We Do NOT Track: We do not track the content of your actions (i.e., we know you clicked "Generate," but we do not know what you generated or the content of your emails).
Account and Identity Metadata
Data Type: Google User ID (UID), email address, display name, and profile picture URL.
Collection Method: Via Firebase Authentication (Google Sign-In).
Purpose: To authenticate your session, enforce subscription limits, and sync preferences across devices.
Collection Method: Via Firebase Authentication (Google Sign-In).
Purpose: To authenticate your session, enforce subscription limits, and sync preferences across devices.
Financial and Subscription Data
Data Type: Subscription tier, payment status, renewal dates, transaction history, and one-time purchase records (package type, purchase amount, payment status, generation credits granted).
Collection Method: Provided by Stripe, our payment processor.
Purchase Records: When you purchase a Generation Pack, we store a purchase record containing the Stripe session identifier, package details, generation credits granted, and timestamps. Purchased generation credits are tracked in your account balance and do not expire during active service.
Failed Purchase Handling: In the rare event that a purchase processing error occurs, the transaction details are stored in a dead letter queue for manual review. Dead letter records are automatically purged after 30 days.
Security Note: VoiceToMail never accesses, handles, or stores full credit card numbers or CVC codes. This data is handled exclusively by Stripe's PCI-DSS compliant infrastructure.
Collection Method: Provided by Stripe, our payment processor.
Purchase Records: When you purchase a Generation Pack, we store a purchase record containing the Stripe session identifier, package details, generation credits granted, and timestamps. Purchased generation credits are tracked in your account balance and do not expire during active service.
Failed Purchase Handling: In the rare event that a purchase processing error occurs, the transaction details are stored in a dead letter queue for manual review. Dead letter records are automatically purged after 30 days.
Security Note: VoiceToMail never accesses, handles, or stores full credit card numbers or CVC codes. This data is handled exclusively by Stripe's PCI-DSS compliant infrastructure.
User Preferences and Custom Instructions
Data Type: User-configured preferences including language, tone, auto-generate settings, and custom instructions (free-text, max 500 characters).
Storage Mechanism: Stored server-side in your account profile (Firestore).
Purpose: To personalize AI-generated email drafts according to your preferences. Custom instructions are incorporated into the AI generation prompt to tailor outputs to your needs.
Privacy Note: Custom instructions may contain personally identifiable information (e.g., your name, title, organization). This data is included in data exports and deleted upon account deletion.
Storage Mechanism: Stored server-side in your account profile (Firestore).
Purpose: To personalize AI-generated email drafts according to your preferences. Custom instructions are incorporated into the AI generation prompt to tailor outputs to your needs.
Privacy Note: Custom instructions may contain personally identifiable information (e.g., your name, title, organization). This data is included in data exports and deleted upon account deletion.
Local Browser Storage Data
Data Type: User preferences (e.g., theme selection, onboarding completion status), extension session data.
Storage Mechanism: chrome.storage.local (for the extension) and localStorage (for the website).
Access: This data resides physically on your device. VoiceToMail servers do not access this data unless you explicitly initiate a synchronization action.
Storage Mechanism: chrome.storage.local (for the extension) and localStorage (for the website).
Access: This data resides physically on your device. VoiceToMail servers do not access this data unless you explicitly initiate a synchronization action.
Generation Metadata
Data Type: When you generate an email, we create a generation record containing: a unique generation ID, your pseudonymized user identifier, identifiers of the prompt template and AI model used, input and output measurements (character counts, token counts, processing time, estimated cost), your satisfaction rating (if provided), and whether the generation used "Thinking Mode."
What We Do NOT Store: We do not store your actual input text, email context, or the generated email content. Only metadata and measurements are retained in generation records.
Purpose: To optimize prompt and model selection (see Section 5.3), monitor service quality, calculate usage costs, and improve the service over time.
Retention: Generation records are retained for 12 months and then automatically deleted.
What We Do NOT Store: We do not store your actual input text, email context, or the generated email content. Only metadata and measurements are retained in generation records.
Purpose: To optimize prompt and model selection (see Section 5.3), monitor service quality, calculate usage costs, and improve the service over time.
Retention: Generation records are retained for 12 months and then automatically deleted.
User Feedback Data
Data Type: Like/dislike ratings on generated emails, linked to generation IDs. Aggregate feedback statistics: total ratings count, pending bonus credits, and bonus generation balance.
Purpose: To improve the quality of AI-generated emails through service optimization, and to provide bonus generation credits as an incentive for feedback (1 free generation for every 5 ratings).
Lawful Basis: Contractual necessity (the feedback incentive system is part of the service) and legitimate interest (improving service quality).
Purpose: To improve the quality of AI-generated emails through service optimization, and to provide bonus generation credits as an incentive for feedback (1 free generation for every 5 ratings).
Lawful Basis: Contractual necessity (the feedback incentive system is part of the service) and legitimate interest (improving service quality).
Contact Form Submissions
Data Type: Name, email address, message content, and IP address.
Collection Method: Via the contact form on the VoiceToMail website.
Purpose: To respond to your inquiry, prevent abuse, and maintain correspondence records.
IP Address: Your IP address is collected for fraud prevention and abuse detection purposes. IP addresses are personal data under GDPR. The lawful basis for this processing is our legitimate interest in preventing abuse (Art. 6(1)(f)).
Collection Method: Via the contact form on the VoiceToMail website.
Purpose: To respond to your inquiry, prevent abuse, and maintain correspondence records.
IP Address: Your IP address is collected for fraud prevention and abuse detection purposes. IP addresses are personal data under GDPR. The lawful basis for this processing is our legitimate interest in preventing abuse (Art. 6(1)(f)).
Browser Locale Detection
Data Type: Your browser's language preference (navigator.language).
Collection Method: Read from the browser's API when you first access the website or extension.
Purpose: To set the default display language for the Service interface.
Storage: Stored locally on your device as a preference setting. Not transmitted to our servers unless you explicitly change your language preference in account settings.
Legal Basis: This is strictly necessary for providing the Service in your preferred language and does not require consent under the ePrivacy Directive.
Collection Method: Read from the browser's API when you first access the website or extension.
Purpose: To set the default display language for the Service interface.
Storage: Stored locally on your device as a preference setting. Not transmitted to our servers unless you explicitly change your language preference in account settings.
Legal Basis: This is strictly necessary for providing the Service in your preferred language and does not require consent under the ePrivacy Directive.
5. Artificial Intelligence (AI) Processing Transparency
VoiceToMail utilizes advanced Large Language Models (LLMs) to provide its core drafting capabilities. We believe in radical transparency regarding how your data interacts with AI.
Approved AI Sub-Processors
We transmit text transcripts and email context to the following providers for AI processing:
- OpenAI, L.L.C. (United States): For high-complexity drafting and summarization.
- Google Gemini (via Google Cloud Vertex AI): For specific processing tasks.
No Training on User Data
We strictly prohibit the use of your data for model training.
- VoiceToMail accesses OpenAI and Google Gemini services via their Enterprise/API endpoints, not their consumer interfaces.
- Under our contractual agreements and their respective enterprise privacy policies, OpenAI and Google do not use data sent via our API integration to train or improve their foundation models.
- Your email content and voice transcripts are treated as confidential inputs, processed to generate a response, and then discarded by the AI provider.
Automated Prompt and Model Selection
We use statistical optimization (Thompson Sampling) to automatically select the best-performing prompt templates and AI models for each email generation request. This automated selection is based on aggregate user satisfaction data across all users, not on your individual profile or personal characteristics. You retain full control over all generated content: you can reject any generated result and request a different version (which will use a different prompt and model combination), edit the result, or discard it entirely.
Zero-Day Retention (Where Applicable)
We configure our AI integrations to minimize data retention.
- Abuse Monitoring: AI providers may retain inputs for a maximum of 30 days solely for the purpose of monitoring for abuse (e.g., generating illegal content). This data is encrypted, accessible only to authorized security personnel, and is deleted automatically after the retention window.
- No Secondary Use: The AI providers are contractually restricted from using your data for profiling, advertising, or any purpose other than returning the generated text to VoiceToMail.
Thinking Mode
VoiceToMail offers an optional "Thinking Mode" feature. When enabled, the AI performs a two-step process: first analyzing the email situation, then generating a reply based on that analysis. The analysis output ("thinking") is streamed to you in real time but is not stored on our servers. Only token counts and performance measurements from the thinking step are retained for cost analysis. Thinking Mode consumes two (2) quota units per generation.
6. Lawful Basis for Processing (GDPR)
In compliance with Article 6 of the GDPR, we process your personal data under the following specific legal bases:
Consent (Article 6(1)(a))
Scope: We rely on your explicit, affirmative consent for the processing of Gmail data and voice data.
Mechanism: This consent is obtained through the Google OAuth consent screen (where you grant specific permissions) and the browser permission prompt (for microphone access).
Revocability: You may withdraw this consent at any time by revoking the OAuth token in your Google Account settings or removing the extension.
Mechanism: This consent is obtained through the Google OAuth consent screen (where you grant specific permissions) and the browser permission prompt (for microphone access).
Revocability: You may withdraw this consent at any time by revoking the OAuth token in your Google Account settings or removing the extension.
Contractual Necessity (Article 6(1)(b))
Scope: Processing your account credentials, subscription status, preferences, custom instructions, and facilitating the technical transmission of data to the AI provider.
Justification: This processing is strictly necessary to deliver the service you have subscribed to (i.e., we cannot generate an email draft without processing the text).
Justification: This processing is strictly necessary to deliver the service you have subscribed to (i.e., we cannot generate an email draft without processing the text).
Legitimate Interests (Article 6(1)(f))
Scope: Collecting pseudonymized usage telemetry (PostHog analytics), enforcing security protocols, preventing fraud, IP address collection from the contact form, and generation metadata storage for service optimization.
Justification: We have a legitimate interest in ensuring our Service is secure, bug-free, and operational. We have balanced this interest against your privacy rights by strictly pseudonymizing analytics data, minimizing data collection, and providing opt-out mechanisms where feasible.
Justification: We have a legitimate interest in ensuring our Service is secure, bug-free, and operational. We have balanced this interest against your privacy rights by strictly pseudonymizing analytics data, minimizing data collection, and providing opt-out mechanisms where feasible.
Legal Obligation (Article 6(1)(c))
Scope: Retaining financial transaction records, including subscription invoices and one-time purchase records.
Justification: We are required by EU tax laws and Polish accounting standards to retain invoice and payment data for a statutory period (typically 5-7 years).
Justification: We are required by EU tax laws and Polish accounting standards to retain invoice and payment data for a statutory period (typically 5-7 years).
7. Data Retention and Lifecycle Management
We adhere to a policy of "storage limitation," retaining data only for as long as necessary.
| Data Category | Retention Period | Deletion Mechanism |
|---|---|---|
| Raw Audio | 0 Days (Immediate) | Discarded from browser memory immediately after transcription. |
| Gmail Content | Max 30 Days | Processed in real-time; any temporary cache is automatically purged. |
| AI Drafts | Max 30 Days | Purged from server cache; persists in user's Gmail drafts. |
| Generation Metadata | 12 Months | Automatic TTL-based deletion. |
| User Feedback (Ratings) | Duration of Account | Deleted upon account deletion. |
| PostHog Analytics Events | 12 Months | Configured via PostHog project retention settings. |
| Local Preferences | User Controlled | Stored locally until user deletes extension or clears browser data. |
| Server-Side Preferences | Duration of Account | Deleted upon account deletion. |
| Account Info | Duration of Account | Deleted upon "Delete Account" request. |
| Billing Records | 7 Years | Retained as required by Polish tax law (blocked from general access). |
| Purchase Records | 7 Years | Retained as required by tax law. |
| Contact Form Submissions | 12 Months | Deleted after resolution and retention period. |
| Dead Letter Queue | 30 Days | Automatically purged after resolution or retention period. |
User-Initiated Deletion
You may trigger the deletion of your data through the following methods:
- Web Dashboard: Selecting the "Delete Account" option will immediately scrub your identity from our active databases, delete all associated generation records, feedback data, preferences, and custom instructions, and revoke our access tokens.
- Data Export: You may request a complete export of your personal data (account metadata, preferences, generation history metadata, feedback statistics, subscription history) via the Settings dashboard before deletion.
- Extension Interface: You may manually clear your local preferences and session data at any time via the extension settings or by removing the extension.
8. International Data Transfers
VoiceToMail is based in Poland (EU), but our sub-processors may process data outside the European Economic Area (EEA). We ensure these transfers are lawful under GDPR Chapter V.
Data Privacy Framework (DPF)
We prioritize vendors who are certified under the EU-U.S. Data Privacy Framework, the UK Extension, and the Swiss-U.S. Data Privacy Framework.
- Google LLC: Certified.
- OpenAI, L.L.C.: Certified (or ensuring equivalent protection).
- Stripe, Inc.: Certified.
- PostHog, Inc.: EU-hosted instance (see Section 10).
Standard Contractual Clauses (SCCs)
Where a vendor is not certified under the DPF, or where the DPF does not apply, we rely on the European Commission's Standard Contractual Clauses (SCCs) as a legal transfer mechanism. These clauses contractually bind the vendor to protect your data to European standards, including requirements for encryption and government access challenges.
9. Security Measures and Architecture
We employ enterprise-grade security controls to protect your data integrity and confidentiality.
Encryption
- In Transit: All data transmission occurs over HTTPS/TLS 1.2+ (Transport Layer Security). We enforce Strict Transport Security (HSTS) to prevent downgrade attacks.
- At Rest: All database volumes (Firestore) and backups are encrypted using AES-256 (Advanced Encryption Standard).
Access Control and Authentication
- Stateless Authentication: We use secure JSON Web Tokens (JWT) for session management.
- Inactivity Timeout: Sessions automatically expire after 30 days of inactivity, requiring re-authentication to protect data on shared devices.
- Least Privilege: Access to production servers is restricted to a minimal set of authorized engineering staff, protected by Multi-Factor Authentication (MFA).
- Administrative Access: Authorized service administrators may access your account information (subscription status, usage statistics, generation metadata) for support, billing, and service improvement purposes. Administrative access is controlled via an application-level authorization system and limited to designated personnel.
Infrastructure Security
- Cloud Provider: Our infrastructure is hosted on Google Cloud Platform (GCP), which holds certifications for SOC 2 Type II, ISO 27001, and FedRAMP.
- Isolation: Customer data is logically isolated within our database architecture.
- Environment Separation: Development and production environments are fully separated, using distinct databases and payment processor credentials, to prevent accidental exposure of production data during development.
Incident Response
In the event of a confirmed data breach affecting personal data, VoiceToMail will:
- Notify the Polish supervisory authority (UODO) within 72 hours of becoming aware of the breach, where feasible.
- Notify affected users without undue delay if there is a high risk to their rights and freedoms.
- Execute a containment and remediation plan to mitigate harm.
10. Third-Party Sub-Processors
We use the following trusted third-party processors. By using the Service, you authorize us to engage these partners:
We do not share your data with any party not listed here without your prior consent or as required by applicable law.
| Processor | Purpose | Data Location | Adequacy Mechanism |
|---|---|---|---|
| Google Cloud Platform | Infrastructure, Database (Firestore), Authentication (Firebase Auth) | EU / US | DPF / SCCs |
| OpenAI | AI Text Generation | US | DPF / SCCs |
| Google Gemini (Vertex AI) | AI Text Generation | EU / US | DPF / SCCs |
| Stripe | Payment Processing (subscriptions and one-time purchases) | Global | DPF / SCCs |
| Google Speech Recognition | Voice-to-text transcription via browser's webkitSpeechRecognition API (Chrome transmits audio to Google servers) | US / EU | DPF / SCCs |
| PostHog | Product Analytics (pseudonymized usage telemetry) | EU (Frankfurt, Germany) | EU hosting; DPF for US parent entity |
| Google Workspace (Gmail SMTP) | Transactional Email (welcome emails, payment confirmations, contact form notifications) | EU (European data region) | EU data processing; DPF for US parent entity |
We do not share your data with any party not listed here without your prior consent or as required by applicable law.
11. Your Rights and Controls
You have extensive rights regarding your data. We provide tools to exercise these rights directly.
Right to Access and Portability (GDPR Art. 15, 20)
You may request a complete export of your personal data (account metadata, preferences, custom instructions, generation history metadata, feedback statistics, subscription history) in a machine-readable format (JSON) via the Settings dashboard.
Right to Rectification (GDPR Art. 16)
You can update your profile information, display name, and preferences directly within the application settings (both the extension popup and the web dashboard).
Right to Erasure ("Right to Be Forgotten") (GDPR Art. 17)
You may request the permanent deletion of your account. Upon this request:
- We delete your account metadata from Firebase.
- We delete your generation records, feedback data, preferences, and custom instructions.
- We delete your Stripe customer token (subject to legal retention of invoice records for up to 7 years).
- We purge any cached email context.
- We remove your pseudonymized identifier from PostHog analytics.
Right to Restrict Processing (GDPR Art. 18)
You may choose to disable specific features (e.g., auto-generate, Thinking Mode) which restricts our processing of your data. You may also opt out of analytics tracking on the website via the cookie consent settings.
Right to Object (GDPR Art. 21)
You have the right to object to processing based on our legitimate interests (Section 6.3). Upon receiving an objection, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
Right to Revoke OAuth Consent
You can stop all Gmail data collection immediately by revoking VoiceToMail's access to your Google Account. Go to https://myaccount.google.com/permissions, select "VoiceToMail," and click "Remove Access."
Right to Complain
You have the right to lodge a complaint with the supervisory authority:
Prezes Urzedu Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
Website: https://uodo.gov.pl
Prezes Urzedu Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
Website: https://uodo.gov.pl
Exercising Your Rights
To exercise any of your rights, contact us at legal@voicetomail.eu. We will respond within 30 days as required by GDPR. We may need to verify your identity before fulfilling certain requests.
12. Automated Decision-Making (GDPR Art. 22)
VoiceToMail uses automated systems to select prompt templates and AI models for email generation (see Section 5.3). This automated selection:
- Is based on aggregate performance data across all users, not on your individual profile.
- Does not produce legal effects concerning you or similarly significantly affect you.
- Results in outputs that you have full control over (you can reject, edit, or retry any generated email).
13. California Resident Rights (CCPA/CPRA)
If you are a resident of California, the following additional disclosures apply:
Categories of Information Collected
In the past 12 months, we have collected:
- Identifiers (Name, Email, IP Address from contact form).
- Commercial Information (Subscription purchase history, one-time purchase history).
- Internet Activity (Extension interaction logs, pseudonymized usage telemetry).
- Sensitive Personal Information (Gmail content, strictly for service functionality under user control).
No Sale or Sharing
VoiceToMail does not sell your personal information. We do not "share" your personal information for the purpose of cross-context behavioral advertising.
Right to Limit Use of Sensitive Information
You have the right to limit the use of your sensitive personal information (Gmail content) to that which is necessary to perform the services. We automatically adhere to this limitation by default (see Section 3 "Limited Use").
Exercising Rights
California residents may designate an authorized agent to make a request on their behalf. We will verify the agent's authority and your identity before processing such requests. We will not discriminate against you for exercising your privacy rights.
14. Children's Privacy
VoiceToMail is a professional tool intended for use by adults.
- Age Limit: The Service is not directed to children under the age of 13 (or 16 in the EEA/UK).
- No Collection: We do not knowingly collect personal data from children.
- Action: If we discover that a child has created an account, we will immediately delete the account and all associated data. If you believe we have inadvertently collected data from a child, please contact legal@voicetomail.eu.
15. Cookies and Tracking Technologies
Website (voicetomail.eu)
Our website uses the following categories of cookies and similar technologies:
Essential (Always Active):
Analytics (Requires Consent):
Essential (Always Active):
- Authentication session tokens (Firebase Auth)
- CSRF protection tokens
- Theme and language preferences (stored in localStorage)
Analytics (Requires Consent):
- PostHog tracking cookies and localStorage entries for session identification, feature usage analysis, and performance monitoring.
- These are placed only after you grant consent via our cookie banner.
Chrome Extension
The Chrome Extension uses chrome.storage.local to store your preferences, session data, and extension settings. This storage is governed by the Chrome Web Store policies and your installation consent, and is necessary for the extension to function.
Managing Cookie Preferences
You can manage your cookie preferences at any time by clicking the "Cookie Settings" link in our website footer. You may also configure your browser to reject all cookies or to notify you when a cookie is set, though this may affect website functionality.
16. Changes to This Privacy Policy
We may update this Policy to reflect changes in our service, laws, or data handling practices.
Notification Procedure
- Minor Changes: Updates to wording or clarification will be effective immediately upon posting. The "Last Updated" date at the top will be updated.
- Material Changes: If we make significant changes that expand our use of your data (e.g., adding a new AI provider, changing retention periods, or adding new data categories), we will notify you via: (1) An email to your registered address. (2) A prominent notification within the Extension or on the Web Platform.
- Re-Consent: If we add new Google API scopes or significantly change how we use Limited Use data, we will prompt you to re-authorize permissions via the OAuth consent screen.
17. Contact Us
If you have questions about this Policy, or if you wish to exercise your rights, please contact us. We are committed to resolving complaints about your privacy and our collection or use of your personal information.
Daniele Donzello
Daniele Donzello
- Email: legal@voicetomail.eu
- Online: Via the "Support" form on the VoiceToMail Web Platform
- Mailing Address: Juliana Ursyna Niemcewicza 26 lok. 57, 02-306 Warszawa