VoxNote Privacy Policy

VoxNote Privacy Policy

Last updated: August 13, 2026

This Privacy Policy explains how VoxNote Softwares inc. ("VoxNote," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information when you use the VoxNote mobile application, web application, websites, telephone, transcription, summary, voicemail, support, billing, and organization services (collectively, the "Services").

It also applies to people who participate in a call with a VoxNote user, even if they do not have a VoxNote account.

VoxNote Softwares inc., based in Quebec, Canada, is responsible for the personal information described in this Policy unless another organization is identified as responsible. Our Privacy Officer is Tommy Villeneuve and can be reached at [email protected]. The Privacy Officer oversees compliance with Quebec’s Act respecting the protection of personal information in the private sector and VoxNote’s internal privacy policies and receives privacy questions and complaints.

1. Key points

  • VoxNote records calls that a user places or receives through a recording-enabled VoxNote call flow. The user is responsible for notifying other participants and obtaining any consent required by law.
  • Ordinary call audio is used to create a transcript and is then deleted from the temporary systems of our telephony and transcription providers as part of the automated transcription workflow. Voicemail audio is kept for up to 30 days so the user can play it back.
  • Transcripts, summaries, action items, and call metadata are retained as described in Section 9. Stored transcript, summary, and task content is encrypted at the application level.
  • Giving the mobile app access to contacts does not upload the entire address book. If the user separately enables Contact name sharing, VoxNote sends the matched contact's phone number and display name for calls involving that contact. A user may also add an email address to a VoxNote contact record.
  • We do not sell personal information for money. We use service providers to deliver the Services and use analytics and attribution tools as described below. Our mobile attribution provider may process device and usage data for advertising measurement, which may be considered "sharing" under some U.S. state laws.
  • VoxNote does not create voiceprints or use voices to identify people.

2. Personal information we collect

The information we collect depends on which Services and features are used.

Account, identity, and organization information

We may collect:

  • name, caller name, email address, telephone number, country, state or province, language, time zone, and job title;
  • account and authentication identifiers, verification status, password hash, session data, login IP address, browser or device user agent, and linked sign-in provider identifiers;
  • organization name, membership, role, invitations, work email domain, single sign-on configuration, and organization settings;
  • onboarding responses, such as how a user heard about VoxNote, typical call volume, intended use, phone provider, and summary preferences; and
  • communication, notification, voicemail, contact-sharing, summary, and CRM synchronization settings.

When a user signs in through a third-party or company identity provider, we receive the information that the user or identity provider authorizes, such as name, email address, provider account identifier, organization, and session information.

Calls, voicemails, transcripts, summaries, and tasks

We may collect and generate:

  • the telephone numbers of callers and recipients, VoxNote participant identifiers, call direction, status, provider identifiers, timestamps, duration, and cost and usage information;
  • temporary call recordings and voicemail recordings;
  • voicemail greetings uploaded by the user;
  • call transcripts, detected language, speaker labels, AI-generated titles and summaries, action items, reminders, and user edits; and
  • excluded or blocked telephone numbers and feedback about a call or generated result.

Conversations can reveal sensitive personal information. VoxNote does not ask users to provide health, financial, government identification, or other sensitive information during calls, but such information may be included in a recording, transcript, or summary because of what call participants choose to discuss.

Contacts

With device permission, the mobile app reads contact information such as names, telephone numbers, email addresses, company names, labels, and contact images. This information is used on the device to display contacts, match a telephone number to a name, and let the user create or edit native contacts.

VoxNote does not automatically upload the user's entire address book. If Contact name sharing is enabled, VoxNote sends the matched telephone number and display name for a person involved in a recent call. The user can turn this setting off. VoxNote's web contact features also let a user create or edit a server-side contact containing a name, telephone number, optional email address, and CRM sync preference.

Support, email, and notifications

We may collect:

  • support requests and chats, feedback messages, attachments, and related correspondence;
  • email addresses and email preferences, the content of summary, reminder, verification, invitation, billing, and support emails, delivery status, and whether an email was opened; and
  • device push tokens and the content and delivery status of notifications.

Subscription and transaction information

We collect plan, product, entitlement, subscription status, billing interval, trial and renewal dates, store, seat count, and transaction and customer identifiers. Payment processors and app stores collect payment-card and billing information directly. VoxNote does not store full payment-card numbers.

Device, usage, diagnostics, and attribution information

We and our providers may automatically collect:

  • app-generated device identifier, advertising identifier where available, push token, IP address, device model, operating system, app version, language, time zone, country, network type, and app state;
  • screens viewed, app opens, sessions, feature interactions, onboarding progress, contact searches, calls initiated or completed, summary interactions, subscription events, referring pages, campaign and attribution information, and deep-link events;
  • crash reports, error messages, truncated stack traces and response bodies, performance data, and call quality and media diagnostics; and
  • call correlation identifiers, provider call identifiers, audio-route and registration state, network conditions, and troubleshooting metadata.

We do not intentionally include call audio, transcript text, summary text, contact names, or support content in product analytics events. An error report could nevertheless contain information present in an error message or technical context.

Information from other people and organizations

We may receive personal information from:

  • another call participant;
  • a VoxNote user who records a call, adds a contact, sends an organization invitation, or selects an email recipient;
  • the user's employer or organization administrator;
  • identity, telephony, app-store, billing, analytics, attribution, support, and integration providers; and
  • a customer-configured CRM or webhook destination.

If a user provides information about another person, the user must have the authority to do so and must provide any notice or obtain any consent required by law.

3. How we use personal information

We use personal information to:

  • create, authenticate, secure, and administer accounts and organization memberships;
  • route calls, provide telephone numbers, record eligible calls, receive voicemails, and deliver communications;
  • transcribe calls and voicemails and generate summaries, titles, tasks, reminders, classifications, and other requested AI outputs;
  • display call history, contacts, transcripts, summaries, voicemails, tasks, and subscription information;
  • send requested summaries, reminders, account messages, support messages, push notifications, and service or marketing communications in accordance with the user's preferences;
  • process purchases, manage subscriptions, provide entitlements, prevent duplicate transactions, and maintain financial records;
  • send call data to a customer-configured CRM or webhook when the relevant user and organization settings permit it;
  • provide support, investigate failures, repair failed workflows, enforce our terms, prevent fraud and abuse, and protect users and the Services;
  • understand feature use, measure campaigns and installations, diagnose crashes and call-quality issues, and improve the Services; and
  • comply with law, respond to lawful requests, establish or defend legal claims, and complete a corporate transaction.

4. Legal bases for processing in the EEA and United Kingdom

Where the GDPR or UK GDPR applies, our legal bases are:

  • Performance of a contract: to create and authenticate an account; provide calls, transcription, summaries, voicemail, contact, organization, billing, and support features; and deliver requested communications.
  • Consent: for optional contact access and contact name sharing, device permissions, certain marketing communications, advertising tracking where platform consent is required, and other processing for which we ask for consent. Consent can be withdrawn at any time without affecting earlier lawful processing.
  • Legitimate interests: to secure and operate the Services, troubleshoot and prevent abuse, provide customer support, understand product performance, improve features, and administer our business. We consider the sensitivity of call content and the reasonable expectations of users and participants before relying on this basis.
  • Legal obligations: to maintain required financial records, respond to valid legal process, and meet security, privacy, tax, and regulatory duties.

We do not use solely automated decision-making that produces legal or similarly significant effects. AI is used to transcribe, classify, and summarize communications and to suggest action items; users must review those outputs and should not treat them as professional advice or certified records.

5. Call recording and AI processing

Recording responsibility

Recording and transcription laws vary by location and context. The VoxNote user who initiates or receives a recording-enabled call is responsible for informing every participant that VoxNote will record, transcribe, and summarize the call and for obtaining any legally required consent. A user must not use VoxNote to record a person unlawfully or against an expressed refusal.

Automated processing

For ordinary calls, a telephony provider temporarily holds the audio while VoxNote transmits it to a transcription provider. After VoxNote saves the transcript, the workflow requests deletion of the temporary recording and the provider's transcript copy. Deletion normally occurs shortly after processing, but retries, provider outages, security incidents, or legal obligations can delay it.

For voicemails, the recording held by our telephony provider is retained for up to 30 days so the user can play it back. The transcription provider's copy is deleted after VoxNote saves the transcript. The voicemail recording is then deleted through a scheduled process.

Transcript text is transmitted to an AI processing provider and the language model needed to create the requested summary or other AI output. VoxNote may use different vetted model providers depending on language, availability, quality, and the requested feature. VoxNote does not use call content to build voiceprints, identify a speaker by biometric identity, or serve personalized advertisements.

VoxNote does not have employees routinely listen to recordings or read call content as part of transcription. Access is restricted, but a limited number of authorized personnel may access personal information when reasonably necessary to provide support requested by a user, investigate a security or service incident, comply with law, or maintain the Services.

6. When we disclose personal information

We disclose personal information only as described in this Policy.

Service providers

We use providers that process information for the following purposes:

  • Telephony and caller-verification providers — Calling, assigned numbers, caller verification, phone-verification codes, call routing, temporary recordings, voicemail, and call metadata.
  • Transcription and AI processing providers — Call audio, transcripts, prompts, and generated outputs for transcription, language detection, classification, summaries, and tasks.
  • Cloud hosting, database, storage, queue, and workflow providers — Hosting account, call, transcript, summary, support, voicemail-greeting, authentication, and operational data.
  • Authentication and identity providers — Authentication, SSO, account linking, organization provisioning, and session security.
  • App marketplace, subscription, and payment providers — Purchases, subscriptions, entitlements, billing, tax, fraud prevention, and customer support. Payment details are collected directly by the relevant provider.
  • Email-delivery providers — Delivery and open tracking for summaries, reminders, verification, invitation, service, and other emails.
  • Push-notification providers — Push tokens and notification content needed to deliver mobile notifications.
  • Customer-support and messaging providers — Identified or anonymous support chat, account and product attributes, support correspondence, and in-app or email messages.
  • Product-analytics providers — User or device identifiers, screens, product events, subscription events, general location derived from IP address, and technical context for product analytics.
  • Diagnostics and crash-reporting providers — User identifier, device and app details, errors, crashes, performance data, stack traces, and troubleshooting context.
  • Mobile attribution and advertising-measurement providers — Device or advertising identifiers, user identifier, installation, campaign, conversion, usage, and deep-link data for attribution and marketing measurement.

These providers may maintain their own records as required for security, billing, fraud prevention, legal compliance, or according to their published retention practices.

Specific providers may change as the Services evolve. VoxNote maintains current internal records of its providers and will provide additional information where required by law or a contractual commitment.

Other users and organizations

  • Other VoxNote users who participated in the same call may have access to that shared call record.
  • Organization administrators can manage organization membership, seats, billing, SSO, shared settings, and integrations and may see related account and usage information. Organization membership does not by itself make every private call available to every member.
  • If a user enables or manually triggers CRM synchronization, VoxNote sends the destination the summary title and content, call identifier and duration, the caller's and recipient's telephone numbers, available names and VoxNote user identifiers, and the event timestamp. The destination is selected and controlled by the customer's organization, and its own privacy terms apply.
  • If a user sends a summary or reminder to an email address, shares content, or chooses a notification recipient, the selected recipient receives that information.

Legal, safety, and business disclosures

We may disclose information if reasonably necessary to comply with law or valid legal process; investigate fraud, abuse, security incidents, or violations of our terms; protect rights, safety, or property; obtain professional advice; or complete a financing, merger, acquisition, reorganization, or sale of assets. A successor must handle personal information consistently with this Policy and applicable law.

7. Analytics, attribution, advertising, and tracking choices

The production mobile app uses product-analytics, diagnostics, crash-reporting, and mobile-attribution providers. These providers collect the device, usage, diagnostic, and attribution information described above. An attribution identifier may be associated with subscription events to measure purchase attribution.

We do not use call audio, transcript text, summary text, or support content for personalized advertising. We do not sell personal information for money. However, disclosing device, advertising, campaign, and usage information to a mobile-attribution provider or advertising partners for cross-context advertising measurement may be considered a "sale," "sharing," or targeted-advertising disclosure under some U.S. state laws, even when no money is paid for the information.

Users can limit advertising tracking through iOS Settings > Privacy & Security > Tracking or the applicable Android advertising-privacy settings. Users may also request an opt-out by contacting [email protected]. Limiting advertising identifiers does not disable essential product analytics, security logs, or crash reporting.

Our web Services use local storage, authentication cookies, and similar technology to keep users signed in, remember settings, operate billing, and provide customer support. Browser controls can block or delete these technologies, but doing so may prevent parts of the Services from working. We do not currently respond to legacy browser "Do Not Track" signals. Mobile attribution choices must be exercised through the device settings or by contacting us as described above.

8. Security

Privacy by default and data minimization

In accordance with Quebec’s Act respecting the protection of personal information in the private sector, as amended by Law 25, we configure the privacy settings of technology products and services offered to the public to provide the highest level of confidentiality by default where that requirement applies, without action by the user. This does not mean that all processing is optional: information reasonably necessary to create an account, place and process calls, secure the Services, administer subscriptions, and provide requested features is handled as described in this Policy.

We design our collection to be limited to personal information reasonably necessary for the purposes identified in this Policy. Ordinary call audio is used to create the requested transcript and AI output and is then deleted through the automated process described in Sections 5 and 9.

Optional features that result in additional disclosure—such as contact name sharing, sending a summary or reminder to a selected email recipient, and CRM or webhook synchronization—require the user or the relevant organization to enable, configure, or initiate them. Available settings can be changed or disabled, although information already delivered to a recipient remains under that recipient’s control. Device permissions and advertising-attribution choices are also subject to the controls provided by the operating system.

Safeguards

We use administrative, technical, and physical safeguards designed for the sensitivity of the information, including:

  • HTTPS/TLS for information in transit where supported;
  • infrastructure and application-level encryption for stored call content and sensitive operational information;
  • managed authentication, strong protection for any legacy authentication credentials, operating-system-protected mobile token storage, and protected web session cookies;
  • access controls, signed provider webhooks, identity verification, rate limiting, and restricted administrative access; and
  • deletion and retention jobs, monitoring, error reporting, and incident response practices.

No security measure can guarantee absolute protection. Users should protect their devices and credentials and contact us promptly if they suspect unauthorized access.

9. Retention and deletion

We keep personal information only for as long as reasonably necessary for the purposes described above, subject to legal, security, billing, dispute, backup, and shared-record requirements.

  • Ordinary call audio — Until transcription is saved, then deletion is requested from the telephony and transcription providers, normally shortly after processing.
  • Voicemail audio — Up to 30 days for playback, then deleted by a scheduled process.
  • Voicemail greeting — Until replaced or deleted by the user, or the account is hard-deleted.
  • Call metadata, transcripts, summaries, and related generated tasks — Up to 36 months from the call, unless deleted earlier or a longer period is required by law.
  • Call diagnostic events — Usually 7 days. An incident record may remain for up to 180 days after it becomes inactive, with an absolute limit of approximately 36 months.
  • Account, settings, contacts, organization, subscription, and usage records — While the account or organization is active and as needed afterward for deletion, billing, security, legal, and dispute purposes.
  • Support records — While needed to provide support and maintain a reasonable business record. A user may request deletion.
  • Billing, transaction, and tax records — For the period required by tax, accounting, payment, and other applicable law.
  • Authentication records — Expired refresh tokens are deleted on a scheduled basis. Revoked or inactive identity-provider-linked sessions are generally deleted after 30 days.
  • Processed authentication webhook audit records — Usually 30 days. Failed records may remain longer for retry and investigation.
  • Analytics, attribution, crash, email-delivery, and provider logs — According to VoxNote's configured settings and each provider's retention controls, for as long as reasonably needed for the stated purpose.

When a user requests account deletion, we first deactivate the account, invalidate sessions, and unassign its VoxNote telephone number. We generally hard-delete the account and associated account data after a one-month recovery and safety period. Our customer-support provider is instructed to archive the user, and user-owned files are removed from object storage.

Some information may remain after account deletion:

  • a call shared with another VoxNote participant may remain for that participant; the deleted user's account link is removed or anonymized where appropriate;
  • an organization owned by the user must be transferred or closed before the user record can be hard-deleted;
  • information already sent to an email recipient, CRM, webhook, app store, payment processor, or other recipient is controlled by that recipient;
  • backups and provider logs may remain for a limited period before rotation; and
  • records may be retained when required for law, security, fraud prevention, billing, disputes, or the establishment or defence of legal claims.

10. International transfers

VoxNote is based in Canada. Our providers and their subprocessors operate in Canada, the United States, the European Economic Area, the United Kingdom, and other countries. Personal information may therefore be processed outside the user's province, state, or country, where courts, law-enforcement authorities, or regulators may lawfully access it.

Before communicating personal information outside Quebec, or entrusting a provider outside Quebec to collect, use, disclose, or retain it on our behalf, VoxNote conducts and maintains a privacy impact assessment as required by section 17 of Quebec’s Act respecting the protection of personal information in the private sector. The assessment considers the sensitivity and purpose of the information, the destination’s legal framework, and the technical, administrative, and contractual safeguards that will apply. It covers the relevant providers and subprocessors within the assessed transfer.

We proceed with a transfer only where the assessment supports an adequate level of protection. The transfer is governed by a written agreement that takes the assessment into account and requires appropriate privacy and security commitments. Other safeguards may include data-processing agreements, Standard Contractual Clauses, the UK Addendum, reliance on an adequacy decision, or a recognized transfer framework.

Information about an applicable assessment and its safeguards may be requested from our Privacy Officer. We may provide a summary or redact information where necessary to protect security, confidential commercial information, or the privacy of another person.

11. Privacy rights

Depending on where a person lives and subject to legal exceptions, they may have the right to:

  • know whether we process their personal information and obtain access to it;
  • obtain information about the categories, sources, purposes, retention, and recipients of personal information;
  • correct inaccurate or incomplete information;
  • delete personal information;
  • receive certain information in a structured, commonly used format and request portability;
  • withdraw consent;
  • object to or restrict certain processing, including direct marketing;
  • opt out of sale, sharing, targeted advertising, or certain profiling;
  • lodge a complaint with a privacy regulator; and
  • exercise privacy rights without discriminatory treatment.

Users can update certain profile information and preferences, manage device permissions, unsubscribe using an email link, disable contact name sharing, manage CRM sync settings, and request account deletion in the app or web settings. Other requests can be sent to [email protected].

We may ask for information needed to verify identity and authority. An authorized agent may make a request where permitted by law, but we may require proof of authorization. We will respond within the period required by applicable law. If we deny a request, we will explain the reason and any available appeal or complaint process.

Canada and Quebec

Canadian residents may request access and correction, withdraw consent subject to legal or contractual restrictions, and challenge our compliance. Quebec residents may also have rights to data portability and, in applicable circumstances, to request cessation of dissemination or de-indexation.

Questions or complaints may be directed first to our Privacy Officer. A person may also contact the Office of the Privacy Commissioner of Canada or, for Quebec matters, the Commission d'accès à l'information du Québec.

EEA and United Kingdom

People in the EEA or United Kingdom may have rights of access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. They may complain to the supervisory authority where they live or work, or where an alleged infringement occurred. UK residents may contact the Information Commissioner's Office.

United States and California notice at collection

Residents of California and other states with comprehensive privacy laws may have the rights listed above where those laws apply to VoxNote. During the preceding 12 months, we collected and disclosed for business purposes the following categories of personal information:

  • IdentifiersExamples: Name, email, telephone number, IP address, account, device, provider, and advertising identifiers — Categories of recipients: Hosting, identity, telephony, support, analytics, attribution, billing, email, push, and customer-selected integration providers
  • Customer-record informationExamples: Contact details, account details, organization and subscription information — Categories of recipients: Identity, support, billing, hosting, and organization providers
  • Commercial informationExamples: Plans, purchases, entitlements, renewal state, and usage — Categories of recipients: App marketplace, subscription, payment, support, analytics, and hosting providers
  • Internet or electronic-network activityExamples: Screens, sessions, feature events, campaign attribution, interactions, and diagnostics — Categories of recipients: Analytics, attribution, diagnostics, support, and hosting providers
  • Audio and electronic informationExamples: Temporary call and voicemail recordings, voicemail greetings, transcripts, summaries, and support content — Categories of recipients: Telephony, transcription, AI processing, storage, hosting, email, support, and notification providers; other call participants; and recipients selected by the user
  • Professional or employment-related informationExamples: Job title, organization, role, work domain, and SSO membership — Categories of recipients: Identity, support, hosting, and billing providers and the user's organization
  • InferencesExamples: Summary classifications, generated action items, preferences, and product-use patterns — Categories of recipients: AI, analytics, and hosting providers
  • Sensitive personal informationExamples: Account credentials, contents of calls, and sensitive facts a participant chooses to discuss — Categories of recipients: Service providers needed to provide, secure, and support the Services, plus recipients selected by the user

We have not sold personal information for money. We may have "shared" device, advertising, campaign, and usage information through a mobile-attribution provider for cross-context advertising attribution as that term is defined by California law. We do not knowingly sell or share the personal information of anyone under 16. We do not use sensitive personal information to infer characteristics beyond what is necessary to provide the requested communication and AI features.

California residents may request to know, access, correct, or delete personal information; opt out of sale or sharing; limit certain uses of sensitive personal information where applicable; and receive equal service and pricing when exercising their rights. Requests may be submitted at [email protected].

12. Children

The Services are intended for business and professional users and are not directed to minors. We do not knowingly create accounts for or collect personal information directly from a child under 14 without legally valid parental or guardian consent. In Quebec, this is subject to the limited statutory exception for a collection that is clearly for the minor’s benefit. We do not knowingly sell or share personal information of anyone under 16. If a parent or guardian believes a child has provided personal information, they should contact us so we can investigate and delete it as appropriate.

13. Third-party services and links

The Services may link to or integrate with third-party sites, app stores, identity providers, CRMs, and other services that VoxNote does not control. Their privacy policies apply to their independent handling of personal information. Users should review those policies before enabling an integration or sending information to a third party.

14. Changes to this Policy

We may update this Policy to reflect changes to the Services, our practices, or applicable law. We will post the revised Policy and update the date above. Where required, we will provide additional notice or obtain consent before a material new use of personal information.

15. Contact us

Privacy Officer: Tommy Villeneuve

VoxNote Softwares inc.

Quebec, Canada

[email protected]

Please write Privacy Request in the subject line and describe the request and the VoxNote account or call involved. Call participants who do not have an account may provide the telephone number involved and an approximate call date; please do not send a recording or other sensitive content unless we ask for it securely.