Privacy Policy
Last updated 7 October 2026
1. Who is responsible for your data
Vokx is the Data Fiduciary for personal data processed through Vokx under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), except as set out for organisations in section 9.
The short privacy notice shown before you consent summarises this policy; this policy is available at any time at https://vokx.tech/privacy-policy and in the app.
2. What we collect
- Account data: email, name, nickname, mobile number, password hash, and the account id of any sign-in provider you use.
- Content: the audio you record, import or have the meeting bot record, and the transcripts, speaker names, summaries, action items, notes, titles and answers made from it. Recordings can contain other people's voices and anything said, including identity numbers (see section 5).
- Meetings and calendars, if you connect them: calendar account name, meeting titles, times, links, locations, and participants' names and email addresses.
- Plan and payments: plan, billing period and payment reference (card, UPI and bank details go to the payment provider only).
- Devices and security: device model, operating system, app version, push notification token, IP address and a log of access to your data.
- Optional product analytics, only if you turn it on: a pseudonymous id and which sign-up steps you completed.
3. Why we use it (purposes and legal basis)
- To provide the Service you asked for (record, transcribe, summarise, analyse and keep your conversations) on the basis of your consent under section 6 of the DPDP Act, which you can withdraw at any time.
- To run your account, take payment, keep the Service secure and meet legal obligations (for example tax records), as permitted by section 7 of the DPDP Act.
- To understand which parts of sign-up work, only with your separate, optional analytics consent.
- We do not sell personal data, do not show ads, and do not use your content to train AI models.
4. How AI is used, and where
- Transcription, summaries, speaker naming, translations, search, Ask and other analysis are done by third-party speech-to-text and large language model (LLM) services, listed in section 6. To do this they receive the audio or text they need.
- Depending on the provider and model in use, that data may be processed, and kept for a time under the provider's own terms (for example to detect abuse), outside India, including in the United States. Each provider's own privacy terms decide how long it keeps data and what else it may do with it. We do not control those providers' systems and we do not claim that their processing is secure, accurate or kept in India.
- An organisation on Enterprise can choose India-only processing: transcription and summaries then use a provider that processes in India, and features that would need another provider are switched off for it.
5. Identity numbers and other sensitive details in recordings
- The DPDP Act protects all personal data alike. Some details are especially harmful if misused, or are restricted by other laws (for example the Aadhaar Act, 2016, and Reserve Bank of India rules on card data), so we treat them separately when they are read out in a recording: Aadhaar numbers and Virtual IDs; debit and credit card numbers; OTPs, PINs, CVVs and passwords; PAN; phone numbers; passport numbers; voter ID (EPIC) numbers; driving licence numbers; bank account numbers; and UPI IDs.
- We look for these automatically and mask them (for example ••••••3210) before the transcript is stored or sent to an AI model, in the transcript and in everything made from it. We record only how many of each kind were masked, never the values.
- Aadhaar numbers and Virtual IDs, card numbers, OTPs, PINs, CVVs and passwords are always masked. The other kinds are kept unmasked only if you give your separate consent in Privacy & data, and, for an organisation's recordings, an admin of that organisation also allows it. If you keep them, they are stored like the rest of your transcript and are sent to the AI providers in section 6, which may be outside India. You can withdraw this consent at any time: everything kept under it is then masked, and the unmasked text is not kept anywhere in our systems after that, other than in backups until they expire.
- Whether these details are kept is decided by you (and, for an organisation, its admin), not by us; we apply that choice. Masking does not change the audio of a recording, which still contains what was said until you delete the recording, and the speech-to-text provider hears the audio in order to transcribe it. Detection is automatic and may miss a number that is mis-heard, split up or said unusually.
8. How we protect it
Content and personal details are encrypted with AES-256-GCM before they are stored, every connection uses TLS, encryption keys are kept apart from the data, and our own staff tools do not show your recordings, transcripts or summaries. Access through the app to your recordings is logged, and you can see that log.
The Service has to decrypt your data to process it for you, and no system is perfectly secure. If a personal data breach happens we will inform you and the Data Protection Board of India as the DPDP Act and its Rules require.
9. Organisations
When you use Vokx in an organisation's space, that organisation decides how the recordings made there are used, sets rules such as retention and whether admins can see members' recordings, and is responsible as Data Fiduciary for them; we process them on its behalf. Your own account data stays with us under this policy.
10. How long we keep it
Until you delete it. Deleted recordings are purged from our systems within 7 days, and a deleted account within 7 days; copies in our backups are removed within a further 35 days. Access logs are kept for 365 days, and payment records for as long as tax law requires. Service providers keep data under their own terms (section 4).
11. Your rights
You can access and download your data; correct your name, nickname, phone number, recording titles and speaker names (write to us to change your email); erase any recording or your whole account; withdraw any consent as easily as you gave it; nominate someone to act for you; and raise a grievance. All of this is in Privacy & data in the app or on the web.
Grievance Officer: Grievance Officer, grievance@vokx.app. We respond within 90 days. If you are not satisfied you may complain to the Data Protection Board of India.
12. Children
The Service is only for people aged 18 or over. We do not knowingly process children's data or track or target anyone with advertising.
13. Changes
When this policy changes in a way that affects your consent we will show you the new notice and ask again before relying on it.