Privacy Policy

Last updated 7 October 2026

1. Who is responsible for your data

Vokx is the Data Fiduciary for personal data processed through Vokx under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), except as set out for organisations in section 9.

The short privacy notice shown before you consent summarises this policy; this policy is available at any time at https://vokx.tech/privacy-policy and in the app.

2. What we collect

  • Account data: email, name, nickname, mobile number, password hash, and the account id of any sign-in provider you use.
  • Content: the audio you record, import or have the meeting bot record, and the transcripts, speaker names, summaries, action items, notes, titles and answers made from it. Recordings can contain other people's voices and anything said, including identity numbers (see section 5).
  • Meetings and calendars, if you connect them: calendar account name, meeting titles, times, links, locations, and participants' names and email addresses.
  • Plan and payments: plan, billing period and payment reference (card, UPI and bank details go to the payment provider only).
  • Devices and security: device model, operating system, app version, push notification token, IP address and a log of access to your data.
  • Optional product analytics, only if you turn it on: a pseudonymous id and which sign-up steps you completed.

4. How AI is used, and where

  • Transcription, summaries, speaker naming, translations, search, Ask and other analysis are done by third-party speech-to-text and large language model (LLM) services, listed in section 6. To do this they receive the audio or text they need.
  • Depending on the provider and model in use, that data may be processed, and kept for a time under the provider's own terms (for example to detect abuse), outside India, including in the United States. Each provider's own privacy terms decide how long it keeps data and what else it may do with it. We do not control those providers' systems and we do not claim that their processing is secure, accurate or kept in India.
  • An organisation on Enterprise can choose India-only processing: transcription and summaries then use a provider that processes in India, and features that would need another provider are switched off for it.

5. Identity numbers and other sensitive details in recordings

  • The DPDP Act protects all personal data alike. Some details are especially harmful if misused, or are restricted by other laws (for example the Aadhaar Act, 2016, and Reserve Bank of India rules on card data), so we treat them separately when they are read out in a recording: Aadhaar numbers and Virtual IDs; debit and credit card numbers; OTPs, PINs, CVVs and passwords; PAN; phone numbers; passport numbers; voter ID (EPIC) numbers; driving licence numbers; bank account numbers; and UPI IDs.
  • We look for these automatically and mask them (for example ••••••3210) before the transcript is stored or sent to an AI model, in the transcript and in everything made from it. We record only how many of each kind were masked, never the values.
  • Aadhaar numbers and Virtual IDs, card numbers, OTPs, PINs, CVVs and passwords are always masked. The other kinds are kept unmasked only if you give your separate consent in Privacy & data, and, for an organisation's recordings, an admin of that organisation also allows it. If you keep them, they are stored like the rest of your transcript and are sent to the AI providers in section 6, which may be outside India. You can withdraw this consent at any time: everything kept under it is then masked, and the unmasked text is not kept anywhere in our systems after that, other than in backups until they expire.
  • Whether these details are kept is decided by you (and, for an organisation, its admin), not by us; we apply that choice. Masking does not change the audio of a recording, which still contains what was said until you delete the recording, and the speech-to-text provider hears the audio in order to transcribe it. Detection is automatic and may miss a number that is mis-heard, split up or said unusually.

6. Who we share it with

  • Service providers who process personal data for us, each under its own terms of service and data processing terms. They may be outside India where shown:
  • Speech-to-text (receives recording audio): OpenAI (USA), Deepgram (USA), AssemblyAI (USA), or Sarvam AI (India), whichever is in use. When OpenAI is used on a long recording, short voice samples of the speakers are also sent to keep their labels consistent.
  • Large language models (receive transcript and summary text, meeting titles, participant names and the questions you ask): Anthropic (USA), OpenAI (USA), Google Gemini (USA), Sarvam AI (India), or a model run on servers we choose, whichever is in use.
  • Search embeddings (receive transcript and summary text): OpenAI (USA) or Google (USA), when search by meaning is switched on.
  • Text-to-speech for audio recaps (receives the recap script): OpenAI (USA), only when you ask for an audio recap.
  • Meeting bot (joins the online meetings you send it to and records them): Attendee, run on our own servers or as a hosted service by its maker.
  • Hosting, database and file storage: our cloud provider, in India.
  • Payments: Razorpay (India); Apple App Store and Google Play (USA) for purchases in the phone app.
  • Email delivery: our email delivery provider. Push notifications: Google Firebase Cloud Messaging and Apple Push Notification service (USA), which carry each notification's text; by default that text does not include your recordings' titles or content.
  • Sign-in and calendars, only those you choose to connect: Google, Apple, Microsoft, Facebook (Meta) and LinkedIn (USA).
  • Error monitoring: Sentry (USA), if enabled; it receives technical error details and your account id, not your recordings. Product analytics: PostHog (EU), only with your separate consent; it receives a pseudonymous id and sign-up steps only.
  • Apps and addresses you connect or share with (for example Slack, Notion, Google Docs and Tasks, HubSpot, Salesforce, Jira, Asana, Todoist, Microsoft To Do, Linear, webhooks): they receive the summaries, action items and, for CRMs, attendee email addresses you choose to send them.
  • Public authorities, only when a valid legal order requires it, after we have checked that it is lawful, and only the minimum it covers. How we handle these requests is set out in our Government Requests Policy at https://vokx.tech/government-requests.
  • We transfer data outside India only to countries not restricted by the Central Government under section 16 of the DPDP Act.

7. What you share

Some features send your content to people or places you choose: public share links (which expire after 30 days unless you choose otherwise, and can be revoked at any time), recap emails (which, if you turn them on, can go to a meeting's invitees, including people who don't use Vokx), notes written into your calendar events (only if you turn this on; anyone who can see the event can then see them), and connected apps and webhooks. You can turn each of these off or revoke it in the app.

8. How we protect it

Content and personal details are encrypted with AES-256-GCM before they are stored, every connection uses TLS, encryption keys are kept apart from the data, and our own staff tools do not show your recordings, transcripts or summaries. Access through the app to your recordings is logged, and you can see that log.

The Service has to decrypt your data to process it for you, and no system is perfectly secure. If a personal data breach happens we will inform you and the Data Protection Board of India as the DPDP Act and its Rules require.

9. Organisations

When you use Vokx in an organisation's space, that organisation decides how the recordings made there are used, sets rules such as retention and whether admins can see members' recordings, and is responsible as Data Fiduciary for them; we process them on its behalf. Your own account data stays with us under this policy.

10. How long we keep it

Until you delete it. Deleted recordings are purged from our systems within 7 days, and a deleted account within 7 days; copies in our backups are removed within a further 35 days. Access logs are kept for 365 days, and payment records for as long as tax law requires. Service providers keep data under their own terms (section 4).

11. Your rights

You can access and download your data; correct your name, nickname, phone number, recording titles and speaker names (write to us to change your email); erase any recording or your whole account; withdraw any consent as easily as you gave it; nominate someone to act for you; and raise a grievance. All of this is in Privacy & data in the app or on the web.

Grievance Officer: Grievance Officer, grievance@vokx.app. We respond within 90 days. If you are not satisfied you may complain to the Data Protection Board of India.

12. Children

The Service is only for people aged 18 or over. We do not knowingly process children's data or track or target anyone with advertising.

13. Changes

When this policy changes in a way that affects your consent we will show you the new notice and ask again before relying on it.