Privacy Policy
VoxPulse is a digital assistant that books meetings over email and turns recorded meetings into transcripts, summaries, action items and follow-ups. This policy explains what data we collect, how we use and share it, how we protect it, how long we keep it, and how you can have it deleted. It includes a dedicated section on data we receive from Google APIs.
- Audio is deleted right after transcription. We keep the text, not the recording.
- We never sell your data and never use it for advertising.
- Your content is not used to train AI models — not by us, and not by our providers.
- Calendar access is used only to schedule meetings and connect recordings to them, and you can disconnect at any time.
1. Who we are
VoxPulse is provided by Diu terminus AB (Swedish company registration number 559359-8690), Marielunds Gård 10, 373 33 Nättraby, Sweden. Diu terminus AB is the data controller for the personal data described in this policy.
For any privacy question or request, email privacy@diuterminus.se.
2. Data we collect
Account data
Your email address and basic account settings. You sign in with a one-time code sent to your email — we do not store passwords.
Recordings and transcripts
Audio you record or upload, and the text transcript we produce from it. The audio is temporary by design (see section 7). The transcript stays in your account until you delete it.
Meeting details and AI results
Meeting title, time, duration, language, labels and participants, and the summaries, action items, analyses and drafts generated from a transcript.
Booking assistant data
When you use the assistant to book meetings, we process the emails exchanged in that booking conversation, the names and email addresses of the people you are meeting (“counterparts”), and proposed and confirmed meeting times.
Business context
Documents or information you choose to provide so the assistant understands your business (for example price lists or previous quotes), and a structured profile derived from them.
Calendar data
If you connect a Google or Microsoft calendar, we access limited calendar data as described in section 3 and section 4.
Bot protection at sign-in
When you request a sign-in code, Cloudflare Turnstile checks that the request comes from a person and not an automated script. To do this, Cloudflare processes technical signals from your browser and your IP address. We only receive the result of the check (passed or not) and the website it was made on. Most people never see the check. If Cloudflare needs more information, it shows a single checkbox.
Technical logs
Operational and security events (with request and account identifiers). We never write transcripts, AI results or email content to logs.
3. Google user data
Connecting a Google Calendar is optional. VoxPulse works without it — the assistant then proposes times based on working hours. If you connect, you grant access through Google's consent screen, and we request only the permissions below.
What we access and why
| Permission (scope) | What we access | What we use it for |
|---|---|---|
openid, email |
The email address of the Google account you connect | Showing which calendar account is connected to your VoxPulse account. |
calendar.freebusy |
Busy/free time blocks in your calendar (not event contents) | Finding times when you are available, so the assistant only proposes and confirms slots that are actually free. |
calendar.events.owned |
Events in calendars you own | Creating the calendar event for a meeting the assistant has booked for you (title, time, location, description and attendees), and checking whether that event was later cancelled, moved or declined so we can let you know. |
calendar.events.readonly |
Title, start and end time, organizer, and attendee names, email addresses and response status of events | Showing you the meetings around the time of a recording so you can pick which meeting it belongs to, and automatically linking a recording to a clearly matching meeting. Only events within a short window around the recording time are read. |
calendar.readonly (optional) |
Read-only access to your calendars | Requested only if you explicitly opt in to extended calendar reading; used solely for the same scheduling and meeting-linking purposes described above. |
What we store
- OAuth tokens that let VoxPulse access your calendar on your behalf, encrypted with AES-256-GCM before they are stored.
- The connected account's email address and your calendar time zone.
- For booked meetings: the ID of the calendar event we created, so we can detect changes to it.
- For a recording you link to a calendar event: the event's title, time, organizer, and attendee names and email addresses, saved as the recording's meeting details and participant list.
Busy/free information and events that are not linked to a recording are used at the moment they are needed and are not stored.
How we share it
We share Google user data only as needed to provide features you use:
- Transcription (Soniox, EU): attendee names from a linked meeting may be sent as vocabulary hints so names are transcribed correctly.
- AI analysis (Anthropic): a linked meeting's title and participant names may be included as context when generating summaries, action items and follow-up drafts for that recording.
- Email (inbound.new): when the assistant books a meeting, confirmation emails to you and your counterpart include the meeting time you agreed on.
These providers act on our instructions under data processing agreements and may not use the data for their own purposes. We do not share Google user data with anyone else, except where required by law or to protect the security of the service.
What we never do with Google user data
- We do not sell it, and we do not use or transfer it for advertising, including retargeting or personalised ads.
- We do not use it to determine creditworthiness or for lending purposes.
- We do not transfer it to data brokers or information resellers.
- We do not use it to develop, improve or train generalised AI or machine-learning models.
- Humans at VoxPulse do not read it, unless you give us explicit permission for specific data (for example, in a support request), it is necessary for security purposes such as investigating abuse, or it is required to comply with applicable law.
VoxPulse's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting and deleting Google data
- Disconnect in VoxPulse: in the app's calendar settings, choose to disconnect your calendar. VoxPulse immediately stops accessing it.
- Revoke in Google: you can remove VoxPulse's access at any time at myaccount.google.com/permissions.
- Delete stored data: meeting details saved from a calendar event are deleted when you unlink the event or delete the recording. To have your stored tokens and all other calendar-derived data deleted, email privacy@diuterminus.se — we complete such requests within 30 days. Deleting your account deletes all of it.
4. Microsoft calendar data
If you connect a Microsoft (Outlook / Microsoft 365) calendar instead, we request User.Read (your account's email address), Calendars.ReadWrite and offline_access, and use, store, share and delete that data in exactly the same limited ways as described for Google in section 3.
5. How we use data
We use personal data only to provide and improve the features you use, and to keep the service secure:
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Transcribing and analysing your meetings and showing the results | Performance of our contract with you |
| Booking meetings for you, including with counterparts, and connecting recordings to calendar events | Contract with you; legitimate interest in coordinating the meeting (for counterparts) |
| Using your business context to improve analyses and drafts | Performance of our contract with you |
| Security, abuse prevention (including bot protection at sign-in), operations and troubleshooting | Legitimate interest |
| Accounting and invoicing | Contract and legal obligation |
We do not sell personal data and we do not use your content to train AI models.
6. Sharing and service providers
We use a small number of carefully chosen providers (sub-processors). Each receives only the data needed for its part of the service, processes it only on our behalf, and is bound by a data processing agreement.
| Provider | What they process | Location |
|---|---|---|
| Hetzner Online | Hosting of our servers and database | Finland (EU) |
| Google Cloud Storage | Temporary storage of audio until transcription; storage of business context files | EU |
| Soniox | Speech-to-text transcription; does not retain audio or use it for training | EU |
| Anthropic (Claude) | AI analysis of transcripts, booking emails and business context; does not train on API data | United States |
| OpenAI | Creating embeddings (numeric representations) of your business context, used to find relevant material; does not train on API data | United States |
| inbound.new | Sending and receiving email: sign-in codes, assistant emails and result notifications | United States |
| Cloudflare (Turnstile) | Bot protection on the sign-in page: browser signals and IP address, used only to check that a sign-in request comes from a person | United States (global network) |
Where data is transferred outside the EU/EEA, the transfer is protected by the EU–US Data Privacy Framework where the provider is certified, or by the European Commission's Standard Contractual Clauses.
We may also disclose data if required by law, or as part of a merger or acquisition, in which case this policy continues to apply to your data.
7. Audio deletion
- Audio is permanently deleted immediately after a successful transcription. Only the text remains.
- As a safety net, a storage rule removes any leftover audio after at most 30 days, even if something in our application fails.
- The recording view shows exactly when the audio file was deleted.
- No one receives your audio except our transcription provider, and only during transcription.
8. Retention and deletion
| Data | How long we keep it |
|---|---|
| Audio | Deleted right after transcription (at most 30 days as a safety net) |
| Transcripts, AI results, meeting details | Until you delete them or your account |
| Business context | Until you delete it or your account |
| Full bodies of booking emails | At most 90 days; after that only the structured booking information is kept |
| Calendar connection (tokens) | While connected; deleted on request or with your account |
| Counterpart data | For the life of the booking, or until the counterpart deletes it |
| Accounting records | As long as Swedish bookkeeping law requires |
Deleting a recording in the app removes everything belonging to it — audio, transcript, results and participant data — within seconds. To delete your whole account, email privacy@diuterminus.se from the address you sign in with; we delete all your data, including calendar tokens and data derived from Google or Microsoft, within 30 days and confirm when it is done. Backups containing deleted data are overwritten in their normal rotation.
9. If an assistant emailed you
If someone who uses VoxPulse books a meeting with you, you may receive email from their assistant:
- The email always says, in its first line, that it comes from an AI assistant acting for the person who invited you.
- We process your name, email address, the emails you send to the assistant and the times discussed, only to coordinate that meeting.
- The assistant's emails contain a personal link where you can see the data we hold about you and delete it.
- If you ask the assistant to stop, it stops emailing you.
- You can also contact us directly at privacy@diuterminus.se.
10. Security
- All traffic is encrypted in transit with TLS.
- Calendar OAuth tokens are encrypted with AES-256-GCM before storage.
- Sign-in is passwordless with one-time codes, with rate limiting and lockout after repeated failed attempts; sessions can be revoked.
- Requests for sign-in codes are protected against automated abuse with Cloudflare Turnstile.
- Every account is isolated in our backend — access control is enforced on every request.
- Webhooks from our providers are signature-verified, and transcripts and results are never written to logs.
11. Your rights
Under the GDPR you have the right to access, correct and delete your personal data, to receive a copy in a portable format, to restrict or object to certain processing, and to withdraw consent at any time. You can export a recording with its transcript and results directly in the app; for anything else, email privacy@diuterminus.se. We respond within one month.
If you are unhappy with how we handle your data, you can lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local data protection authority.
12. Children
VoxPulse is a service for businesses and professionals. It is not directed at children, and we do not knowingly collect data from anyone under 16.
13. Changes
We will update this policy when our data practices change. The date at the top shows the latest version. If a change is significant, we will notify you in the app or by email before it takes effect.
14. Contact
Diu terminus AB · Marielunds Gård 10, 373 33 Nättraby, Sweden · Reg. no. 559359-8690
privacy@diuterminus.se