The short version
Voxtiva joins your online meeting, listens to it, writes down what is said, and translates it. This is the honest 60-second summary. The detail is below, and the detail governs.
- We record and transcribe everyone in the meeting, including people who have never signed up for Voxtiva and have never agreed to anything with us. Their voices, words, translations and names are captured.
- Audio only. We do not record the video of a call and we do not record your screen. There is one narrow exception, a fault-diagnosis mode that is off by default, explained in section 5.1.
- Your meeting audio goes to companies outside Japan. It is streamed live to Modulate.ai for speech recognition. The resulting text is sent to DeepInfra for translation, highlights, answers and the post-meeting summary.
- We store a compressed audio recording of the meeting, plus the transcript, the translation, the summary and the questions people asked the panel.
- We label the emotion in people's voices. Our speech provider returns an emotion label for each finished utterance, and we store it and show it to the host as "Tone". This is on by default. It is more intrusive than transcription and you should know it is happening.
- Nothing deletes itself. There is no automatic expiry and none is being built. Meeting content stays until the host deletes the meeting or closes the account.
- The host is in charge of the recording, and the host, not us, is responsible for telling participants and getting whatever consent the law requires where they are.
- We do not sell your data and we do not run advertising trackers.
- You can ask us for your data or ask us to delete it, whether or not you have an account. Write to privacy@voxtiva.com.
If you are in a Voxtiva meeting and you do not want to be recorded, tell the host. They can remove the bot or stop the stream, and capture stops immediately.
1. Who we are
Voxtiva is operated by:
| Legal name (Japanese) | セノリティックラブ合同会社 |
| Legal name (English) | Senolytic Lab LLC (Senolytic Lab 合同会社) |
| Entity type | 合同会社 (gōdō kaisha, a Japanese limited liability company) |
| Registered address | Branz Yonbancho 503, 2-4 Yonbancho, Chiyoda-ku, Tokyo 102-0081, Japan |
| 登記上の住所 | 〒102-0081 東京都千代田区四番町2-4 ブランズ四番町503 |
| Representative | タイ・バン・デービッド (Thai Van David), 代表社員 (Representative Member) |
| Telephone | +81 90 6299 5920 |
Contact points:
| Purpose | Address |
|---|---|
| General enquiries and support | hello@voxtiva.com |
| Privacy, data subject requests, and complaints about how we handle personal data | privacy@voxtiva.com |
We are a Japan-only company. We have no establishment in the European Union, the European Economic Area, the United Kingdom or the United States. We have not appointed a representative in the Union under Article 27 GDPR, and we have not appointed a UK representative. We have not appointed a Data Protection Officer. Annex B explains what that means for people in the EEA and the UK.
In this policy, "we", "us" and "Voxtiva" mean Senolytic Lab LLC.
2. The words we use
- Host. The person with a Voxtiva account who starts a meeting. Hosts sign in and are our customer.
- Participant (also "guest"). Anyone else in the meeting. Participants have no account. If they open the Voxtiva panel they do so with a six-digit PIN, not a login.
- Shared viewer. Someone the host later invited by email, who has their own Voxtiva account, to look at a finished meeting.
- Visitor. Anyone reading voxtiva.com without signing in.
3. What happens to a meeting, in order
- The host starts a meeting in Voxtiva and gives us the meeting link, a title, and two languages.
- Google Meet and Microsoft Teams: a Voxtiva bot joins the call as a visible participant named "Voxtiva Bot". It appears in the participant list. It also posts a notice into the meeting chat saying the meeting is being recorded and transcribed, and linking to this page. If the chat is not available, the named participant is the only disclosure.
- Zoom: in the production configuration no bot joins. The host connects their own Zoom account and authorises Zoom to stream the meeting's audio to us through Zoom's Real-Time Media Streams. Zoom controls what in-meeting indication attendees see on that path. A browser-bot fallback exists in the software for diagnosis and is not used in production; on that path the bot joins as "Voxtiva Notetaker (recording)".
- We capture the call's audio only. On the bot path the audio is taken from the browser's own audio output, converted to 16 kHz mono, and cut into 100 millisecond pieces. On the Zoom path we accept audio media and nothing else; the software refuses a Zoom media stream that offers transcript or other media types.
- That audio is streamed live over an encrypted connection to Modulate.ai in the United States, which turns speech into text, separates speakers, detects the language spoken, and returns an emotion label and an accent label for each finished utterance.
- The text is sent to DeepInfra, which runs the AI models that produce the translation, the live highlights, the answers to questions asked in the panel, and the post-meeting summary.
- The transcript, the translation, the speaker labels, the emotion labels and a compressed MP3 copy of the meeting audio are written to our database and file storage, run by Convex.
- When the meeting ends a summary is generated and, unless the host has switched it off, it is emailed to the host through Resend.
The audio is not held by us as a file during the call; it is streamed. The copy we keep afterwards is a compressed MP3 (mono, 16 kHz, 24 kbps by default) so the host can replay a moment next to the transcript. It is a review copy, not a master recording.
4. What we collect, by role
4.1 If you are a host
- Identity from sign-in. Your name and email address, and an internal user identifier, supplied by our sign-in provider WorkOS when you create an account or log in.
- Preferences. Your interface language, the two meeting languages you use, the language the panel assistant replies in, your transcript view setting, your time zone, and whether you want the post-meeting summary email.
- Meetings you create. The meeting link, title, the six-digit PIN, the two languages, the platform, start and end times, per-speaker talking time, and any folder you filed it under.
- Billing. Your plan, billing interval, currency, subscription state, trial state, and the identifier of your customer record at Stripe. Card numbers never reach us. You give them to Stripe directly.
- Zoom connection, if you make one. Your Zoom user and account identifiers, the email address and display name on that Zoom account, the permissions you granted, and your Zoom access and refresh tokens. Those two tokens are encrypted before they are stored.
- Everything in section 5 for every meeting you record.
4.2 If you are a participant or guest
You did not sign up for anything, so this is the part that matters most.
- Your voice, for as long as capture is running.
- What you said, as text, in the language you said it in.
- A translation of what you said into the other meeting language.
- A label for the emotion our speech provider hears in your voice, stored against the meeting. See section 5.6.
- Your name, from one of two places: the participant list of the meeting platform, which the bot reads, or your own typing if you open the Voxtiva panel and enter a name.
- Your talking time, and which lines are attributed to you.
- Anything you type into the Voxtiva panel, including questions to the assistant and any notes or flags you attach to a transcript line, along with the answers you receive.
- A browser access session, if you enter the PIN. We store a SHA-256 hash of a random access token, never the token itself, and the name you typed. Your browser stores the token, plus two cookies holding your name and your show-translation choice.
Your accent is also detected by our speech provider and returned to us. We do not store it and it is not shown anywhere in the product.
4.3 If you are a shared viewer
If a host invites your Voxtiva account to look at a finished meeting, we store the email address the invitation was sent to, your account's email address and display name, and whether the host allowed you to play the recording and to ask the assistant questions.
4.4 If you are a visitor to voxtiva.com
- Nothing you have to give us, unless you sign up or join the waitlist.
- Waitlist. If you join the pilot waitlist we store your email address and which page you joined from.
- Cookies and browser storage. A language cookie set by our translation system, and a currency cookie if you change the pricing currency. See section 15.
- Your browser fetches web fonts from Google, which discloses your IP address to Google. See section 15.
- Server and error logs. Ordinary request logs held by our hosting providers, and, when error monitoring is enabled, uncaught errors and a 10% sample of performance traces sent to Sentry.
5. Meeting content, in detail
5.1 Audio
We capture the audio of the call. We do not capture video and we do not capture screens. There is one narrow exception you should know about: a developer diagnostic mode exists for investigating capture faults. It is off by default, it can only be enabled with an expiry no more than two hours ahead, and in its higher settings it saves periodic screenshots of the meeting page to the temporary disk of the machine running that one meeting. Those images can show participants' video tiles. They are never uploaded to our database and they are destroyed with the machine when the meeting ends.
Recording of the compressed MP3 copy is on unless it is switched off in our configuration.
5.2 Transcripts
Every utterance is written down in whatever language it was actually spoken in; the language is detected per utterance and nobody picks a language for the room. Each stored line carries the text, a speaker identifier and label, timestamps, the detected language, and the target language the line was translated into.
5.3 Translations
A meeting has exactly one translation pair, a primary language and a secondary language, chosen by whoever starts the meeting. If a line was spoken in the primary language it is translated into the secondary language. Otherwise it is translated into the primary language. Everyone in the meeting sees the same single translation. A guest cannot choose their own translation language; the only control a guest has is whether the translated line is shown at all.
To translate a line we send that line, plus a rolling window of the preceding lines of the same meeting for context, to DeepInfra.
5.4 Summaries, action items and highlights
When a meeting ends we send the whole transcript, with speaker labels, to DeepInfra in one request and store what comes back: a summary, a list of action items with an assignee and a description each, and a draft email. During a live meeting we also send a five-minute window of transcript to DeepInfra every five minutes to extract highlights such as figures, names, dates and decisions.
5.5 Questions and answers
When anyone asks the Voxtiva panel a question, we store the question, the name attached to it, the answer, and references to the transcript lines used to answer. The question and the relevant transcript passages are sent to DeepInfra to produce the answer.
There is a second, broader feature. The dashboard assistant lets a host ask a question across their past meetings. When they do, we search their meetings and send excerpts from up to eight different past meetings, together with those meetings' summaries, to DeepInfra in a single request, up to about 36,000 characters. Participants in one of those meetings will not know this has happened.
5.6 Emotion inference
We are putting this in its own section rather than burying it.
Our speech provider can infer things from the sound of a voice beyond the words. Two of those are switched on by default in our configuration:
- Emotion. For every finished utterance the provider returns an emotion label. We store that label against the meeting, with the speaker identifier, the timestamp and the language, and we show it to the host and to participants as "Tone" in the side rail, live during the meeting and afterwards.
- Accent. The provider also returns an accent label. We receive it and discard it. It is not stored and not displayed.
We do not enable the provider's deepfake detection, and we never ask it to tag personal or health information in the transcript.
Emotion inference is a different kind of processing from writing down words. It is an inference about a person's inner state, made from their voice, in a work setting, about people who did not choose the tool. If you are a host in the EEA or the UK, read Annex B, section B.6, before you use this feature on colleagues or counterparties, and contact privacy@voxtiva.com if you want it switched off for your account.
5.7 Capture diagnostics
Once a minute during a meeting, and whenever capture degrades, we record audio-quality measurements: signal levels, how much of the window was digital silence, dropout counts, and any recovery action taken. These rows contain numbers, not speech.
6. People in your meeting who never signed up
Most of the voices we process belong to people who have no relationship with us. This is the part of the service that carries the most responsibility.
6.1 Who decides what happens to a recording
For meeting content, the host decides: whether to record at all, which meeting, who can see the result, and when it is deleted. We act on the host's instructions and we do not use meeting content for our own purposes. We do not use it to train models (see section 12).
We are the one who decides, and therefore the controller, for our own account data, billing data, security and diagnostic data, analytics and marketing data.
We do not yet publish a standard data processing agreement. The split above is how we operate and how we describe ourselves, and Article 28 GDPR expects a business customer to be able to hold us to it in a written contract that lists the providers in section 11. That contract does not exist yet. If you are a business customer who needs one, write to privacy@voxtiva.com and we will deal with it directly rather than pointing you at a document that is not there.
6.2 What participants are actually shown
- On Google Meet and Microsoft Teams, and on the Zoom browser fallback, the bot is a visible, named participant in the participant list for the whole meeting.
- The bot also posts a short notice into the meeting chat saying the meeting is being recorded and transcribed by Voxtiva, with a link to this page. If the chat cannot be opened, that notice does not appear, and the named participant is the only disclosure.
- The chat notice can be switched off by configuration. Where it is off, the named participant is the only disclosure.
- On the Zoom native path, Zoom itself controls the in-meeting indication that an app is receiving meeting media.
- The host can remove the bot, or stop the Zoom stream, at any moment. Capture stops immediately.
6.3 What the host has to do
A visible bot is not consent. The host is responsible for telling participants that the meeting is being recorded, transcribed and translated, for telling them that emotion labelling is running, and for obtaining whatever consent the law requires where those participants are. In several places every participant must agree before a call may be recorded, and in some countries recording a private conversation without permission is a crime, not just a civil wrong. See Annex C, section C.6, for the United States position. We give hosts the tools to disclose. We cannot obtain consent on their behalf.
6.4 If you are a participant and you want your data removed
Ask the host first. They can delete the meeting from their dashboard, which erases the transcript, translation, summary, chat, notes, participant records, emotion labels and the audio file, for everyone.
If that is not possible, write to privacy@voxtiva.com with the meeting date, the meeting title or PIN, and the host's name. We will act on the request and tell the host we have done so. Because participants join by PIN rather than by account, we usually need those details to find the right meeting. We do not charge for this.
7. What we do not do
- We do not sell personal data.
- We do not share it with advertising networks and we run no advertising cookies, tracking pixels or cross-site profiling.
- We do not capture video or screens (with the narrow diagnostic exception in section 5.1).
- We do not enable deepfake scoring or automatic personal or health information tagging at our speech provider.
- We do not create anonymously processed information (匿名加工情報) or pseudonymously processed information (仮名加工情報) under Japanese law.
- We do not make automated decisions that produce legal or similarly significant effects about anyone.
8. Why we process your data, and on what legal basis
The table below gives the purpose, and, for people in the EEA and the UK, the Article 6 GDPR basis. Annex A, section A.2, gives the Japanese purpose-of-use statement.
| What we do | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Transcribe, translate, summarise and answer questions about a meeting | It is the product the host asked for | Performance of our contract with the host, Art. 6(1)(b). For participants, who are not our customer, we act on the host's instructions and the host relies on their own basis |
| Store the transcript, translation, summary and audio in the host's account | So the host can review the meeting afterwards | Art. 6(1)(b) |
| Separate speakers and attach names and talking time | So the transcript is readable and attributable | Art. 6(1)(b) |
| Label the emotion in a speaker's voice and show it as "Tone" | A meeting-intelligence feature the host has switched on | Our legitimate interest in providing a feature the host enabled, Art. 6(1)(f). See Annex B, section B.6. Where this reveals special category data in your context we have no Article 9 condition, and it must be disabled for your account on request |
| Run the host's account, sign-in and preferences | To give the host an account | Art. 6(1)(b) |
| Take payment and manage subscriptions | To be paid | Art. 6(1)(b), and legal obligation for tax and accounting records, Art. 6(1)(c) |
| Send the post-meeting summary email | Part of the service; the host can switch it off | Art. 6(1)(b) |
| Send a meeting-share invitation email | The host asked us to share a meeting with that person | Art. 6(1)(b) |
| Keep the service secure, rate-limit PIN guessing, detect abuse | So meetings are not accessible to people who should not see them | Our legitimate interest in a secure service, Art. 6(1)(f) |
| Record capture-quality measurements and error reports, and diagnose faults | So we can fix broken audio and broken software | Our legitimate interest in a working service, Art. 6(1)(f) |
| Product analytics | To understand how the product is used | Our legitimate interest in improving the product, Art. 6(1)(f). See section 15 |
| Waitlist emails | You asked to be told when the pilot opens | Your consent, Art. 6(1)(a), withdrawable at any time |
9. Special category data
Speech is not automatically special category data, but a meeting can contain anything, and two features touch the edge of Article 9 GDPR:
- Emotion labels can, in some contexts, amount to data about a person's mental or physical state.
- Accent can indirectly indicate ethnic or national origin. This is why we discard it rather than store it.
We do not claim an Article 9 condition, because none is available to us. Participants have not given explicit consent to us; they have, at most, been shown a notice by the host. If the processing in your meeting would reveal special category data, do not use the emotion feature, and ask us to disable it for your account.
Do not put protected health information through Voxtiva. See section 14.
10. Where your data goes
We are based in Japan. Almost all processing happens outside Japan, principally in the United States. Our own database, our speech provider, our AI inference provider, our sign-in provider, our payment provider, our email provider, our meeting-bot machines and our website hosting are all operated by companies established outside Japan.
Section 11 names each one and what it receives. Annex A, section A.4, gives the disclosure Japanese law requires about foreign transfers. Annex B gives the position for the EEA and the UK.
11. Who we send data to
Each of these companies receives only what its job needs.
| Provider | What it receives | Where it processes it | Transfer mechanism |
|---|---|---|---|
| Modulate.ai (Velma-2 streaming speech recognition) | The live meeting audio, streamed during the call, over wss://modulate-developer-apis.com. Returns transcript text, speaker separation, detected language, an emotion label and an accent label | United States (the provider's default; we have not configured a regional deployment). No region is selectable in our configuration | The provider's standard data processing terms |
| DeepInfra (AI inference) | Transcript text: individual lines plus context for translation, five-minute windows for highlights, the full transcript for the summary, and questions plus transcript passages for answers. For the dashboard assistant, excerpts from up to eight of a host's past meetings in one request. Endpoint https://api.deepinfra.com | United States (the provider's default; we have not configured a regional deployment). No region is selectable in our configuration | The provider's standard data processing terms |
| Convex (database and file storage) | Everything we store: transcripts, translations, summaries, action items, highlights, panel questions and answers, notes and flags, participant records, emotion labels, capture telemetry, host account records, billing state, encrypted Zoom tokens, and the compressed meeting audio file | United States (the provider's default; we have not configured a regional deployment) | The provider's standard data processing terms |
| Fly.io (meeting bot runtime) | Runs one machine per meeting. During the meeting that machine holds the live audio in memory, holds the transcript in transit, and, in diagnostic mode only, writes temporary artefacts to its own disk. The machine is released and deleted when the meeting ends | Our configured default region is lax, Los Angeles, United States | The provider's standard data processing terms |
| Vercel (website and application hosting) | Web requests to voxtiva.com and the application, including IP addresses and ordinary server logs | United States (the provider's default; we have not configured a regional deployment) | The provider's standard data processing terms |
| WorkOS (host sign-in, AuthKit) | Host name, email address, authentication events, session management. Endpoint https://api.workos.com | United States (the provider's default; we have not configured a regional deployment) | The provider's standard data processing terms |
| Stripe (payments) | Host email address, name, our internal user identifier, plan, interval and currency. Card details go from you to Stripe directly and never reach us | United States (the provider's default; we have not configured a regional deployment) | The provider's standard data processing terms |
| Resend (transactional email) | Recipient email address and message content. For the summary email that content is the summary of the meeting. For a share invitation it is the meeting title and a single-use link | United States (the provider's default; we have not configured a regional deployment) | The provider's standard data processing terms |
| PostHog (product analytics, only when enabled) | A fixed set of product events with an account identifier or a random browser identifier. The sign-up event carries the account's email address. Endpoint https://us.i.posthog.com, PostHog's United States cloud | United States | The provider's standard data processing terms |
| Sentry (error monitoring, only when enabled) | Uncaught errors, stack traces, technical context, and a 10% sample of performance traces, from the website, the meeting bot and the backend. Session replay is not enabled | United States (the provider's default; we have not configured a regional deployment). The region follows the DSN in use | The provider's standard data processing terms |
| Google, Microsoft, Zoom (meeting platforms) | They already hold your meeting. On the Zoom native path Zoom additionally delivers the meeting's audio to us under permissions the host granted from their own Zoom account | Per each platform's own terms | Per each platform's own terms |
| Google Fonts (browser font delivery) | Your browser requests fonts from fonts.googleapis.com and fonts.gstatic.com on every page, which discloses your IP address and request headers to Google | Per Google's terms | The provider's standard data processing terms. Your browser makes this request directly, so it does not pass through our systems |
About the last two columns, said plainly. We rely on each provider's published data processing terms. We have not completed our own record of the specific Article 46 GDPR safeguard that applies to every provider, and we are not going to name one we cannot evidence. Each of the ten providers we send data to is a company established in the United States, and we have not configured a regional deployment with any of them, which is why the region column says what it says. We do not claim to know how any of them sub-processes internally. If you want the current position on a named provider, ask privacy@voxtiva.com and we will tell you what we actually hold.
One point worth spelling out, because the previous version of this page got it wrong. Google appears twice above for two unrelated reasons: Google operates Google Meet, and separately one of the translation models we use is a Google-authored open-weights model. That model runs on DeepInfra's infrastructure. Running it does not send your transcript to Google.
If we add a provider that receives meeting content, we will update this page before the change takes effect.
12. AI models and training
We train no models of our own. We do not use your meeting audio, transcripts, translations or summaries to train, tune or evaluate any model. We use models built by other companies, through the two providers named in section 11.
One related thing, so this section is complete. When we are investigating a capture fault we can switch on the developer diagnostic mode described in section 5.1. In that mode our engineers can end up holding a record of one real meeting's audio events and transcript for as long as the investigation runs. That is fault diagnosis, not training, and it is off by default.
Translations, answers, highlights and summaries are produced by AI models. They can be wrong, and they can be confidently wrong. Do not rely on a Voxtiva translation or summary for anything that matters without checking it.
What our two providers do with what we send them is a separate question, and we cannot answer it yet. Whether Modulate.ai and DeepInfra retain the audio and text we send, or may train on it, is settled by our contract with each of them and not by anything in our code. We have asked both for a written commitment and we do not have one. So we cannot promise you that they neither keep nor train on what passes through them, and we are not going to make that promise on the strength of a marketing page. If you need it before you put a sensitive meeting through Voxtiva, write to privacy@voxtiva.com first and we will tell you where we have got to.
13. How long we keep things
We would rather be accurate here than reassuring.
Meeting content does not expire on its own. There is no automatic deletion and none is being built. Transcripts, translations, summaries, action items, highlights, panel questions and answers, participant records, notes, flags, emotion labels, capture telemetry and the compressed meeting audio stay in the host's account until one of two things happens:
- The host deletes the meeting. Everything listed above for that meeting is erased, including the stored audio file, and including data belonging to participants who are not Voxtiva users.
- The host closes the account. We hold the account for seven days and then delete the account and every meeting in it. The seven days exist so an accidental or disputed closure can be reversed.
Some things do have their own limits, and these are enforced automatically:
| Item | Limit |
|---|---|
| Live capture of a single meeting | 60 minutes on Free; 4 hours on Standard and Pro |
| A participant's PIN access to a meeting | Stops working the moment the meeting ends |
| The browser access token behind that PIN session | Expires after 30 days |
| A meeting-share invitation, if unclaimed | Expires 7 days after it is sent |
| Developer diagnostic capture | Off by default, and cannot be set to expire more than 2 hours ahead |
| Billing and tax records | Kept as long as Japanese tax law requires, currently seven years, and not deleted when an account is closed |
One limit on deletion, stated plainly. When we delete something it goes from our database and our file storage. It can survive for a period afterwards in a provider's own backups. We have not established the backup retention window at Convex or at any other provider that holds a copy, so we cannot tell you how long that period is. We would rather say that than give you a number we made up.
14. Security
Described honestly, which means describing what exists rather than what sounds reassuring.
What we do:
- All traffic between you, our bot, our backend and our providers runs over TLS.
- Zoom access and refresh tokens are encrypted with AES-GCM before they are stored, using a key that is never stored alongside them.
- Participant access tokens and meeting-share invitation tokens are stored as SHA-256 hashes. The tokens themselves exist only in your browser and in the invitation email.
- Meeting PINs are rate-limited: five wrong attempts lock that meeting's PIN for 15 minutes.
- Requests from the meeting bot to our backend are authenticated with a shared secret.
- Access to a meeting's transcript, recording, emotion data, highlights and chat is checked on every single read against the host's identity, a valid participant session, or an explicitly granted share. A participant credential fails closed rather than falling back to a signed-in session in the same browser.
- Meeting bots run as separate machines, one per meeting, which are released and deleted when the meeting ends.
- We do not request deepfake scoring or automatic personal or health information tagging from our speech provider.
- API keys are redacted from our own diagnostic logs.
What we do not have:
We hold no security certifications. We are not SOC 2 audited, not ISO 27001 certified, and not HIPAA compliant. There is no penetration test report. Do not use Voxtiva for protected health information, and do not use it for material that requires a certified processing environment. No system is perfectly secure and we do not claim otherwise.
If something goes wrong. If there is a breach of personal data we will notify the Personal Information Protection Commission of Japan and, where the law requires it, the people affected. Where EEA or UK data is involved we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and tell affected people directly where the risk to them is high.
16. Children
Voxtiva is a business tool. It is not designed for, marketed to, or intended for children. You must be at least 16 to hold a Voxtiva account, or older if the law where you live requires it.
We cannot control who is in a meeting we are asked to join, and a bot in a call has no way of knowing a participant's age. If you believe a child's voice has been recorded and transcribed through Voxtiva, write to privacy@voxtiva.com with enough detail to find the meeting and we will delete the data.
17. Your rights, and how to use them
Whatever your location, you can ask us to:
- Show you the personal data we hold about you, and give you a copy.
- Correct it if it is wrong.
- Delete it.
- Stop using it, or restrict what we do with it.
- Give you a portable copy of data you provided to us.
- Withdraw consent where consent is what we relied on. This does not undo what we did before you withdrew it.
Write to privacy@voxtiva.com. Tell us what you want and give us enough detail to find the data. For a meeting, that means the date and the meeting title or PIN, and the host's name if you know it.
How long we take. We aim to answer within 30 days. If a request is complex we will tell you inside those 30 days and take up to a further 60 days, which is the outer limit the EEA, the UK and California all allow. We do not charge.
Identity checks. We will ask you to prove who you are before we hand over or delete personal data, in proportion to what is being asked for. For a participant with no account we usually need the meeting details above rather than an identity document.
When we have to involve the host. For meeting content we act on the host's instructions. Where a request is about a meeting we will pass it to the host and help them answer it, and we will tell you that we have done so. Where the host cannot or will not act and the law requires deletion, we will act ourselves.
A practical warning about portability. There is no export button in the product today. We fulfil copy and portability requests by hand.
18. Changes to this policy
If we change something that matters, such as adding a provider that receives meeting content, adding a purpose, or changing retention, we will update this page and change the date at the top before the change takes effect. For material changes we will also email account holders. Continuing to use Voxtiva after that means the updated policy applies to you.
We keep the date on this page and on our Terms of Use in step.
Annex A: Japan
This annex applies to personal information handled by Senolytic Lab LLC under the Act on the Protection of Personal Information (個人情報の保護に関する法律, "APPI"). It is written to be read on its own.
A.1 Personal information handler (個人情報取扱事業者)
セノリティックラブ合同会社 (Senolytic Lab LLC)
〒102-0081 東京都千代田区四番町2-4 ブランズ四番町503
代表社員 タイ・バン・デービッド (Thai Van David)
Telephone +81 90 6299 5920
Enquiries and complaints: privacy@voxtiva.com
A.2 Purpose of use (利用目的, APPI Arts. 17 and 21)
We use personal information for the following purposes and no others:
- To provide, operate and maintain the Voxtiva meeting transcription, translation, summary and meeting-question service, including capturing meeting audio, producing transcripts and translations, separating and labelling speakers, producing summaries, action items and highlights, answering questions about a transcript, and producing tone information from provider-supplied emotion labels.
- To create and manage host accounts, sign-in, and user preferences.
- To operate PIN and invitation-based access to a meeting for participants and shared viewers.
- To take payment, manage subscriptions and trials, and keep the accounting and tax records the law requires.
- To send service email, including the post-meeting summary email and meeting-share invitations.
- To respond to enquiries, requests and complaints.
- To keep the service secure, to prevent and investigate unauthorised access and misuse, and to diagnose and fix faults, including through capture-quality telemetry and error reports.
- To measure product usage in aggregate so we can improve the product.
- To send information about the pilot to people who joined the waitlist, with their consent.
- To comply with law and to respond to lawful requests from public authorities.
We will not use personal information beyond these purposes without telling you first.
A.3 Provision to third parties (第三者提供, APPI Art. 27)
We do not sell personal information and we do not provide it to third parties for their own purposes, other than as follows:
- Providers acting for us (委託). The companies in section 11 process personal information on our behalf under contract, within the scope necessary to achieve the purposes above. This is entrustment under APPI Art. 27(5)(i) and not third-party provision.
- The meeting platform. On the Zoom native path, meeting audio reaches us from Zoom under permissions the host granted from their own Zoom account.
- Legal requirement. Where the law requires it or permits it without consent, including responding to a court, a public authority, or an urgent threat to life or property.
- Business transfer. If the business is transferred, in which case the data moves with it for the same purposes.
A.4 Provision to third parties in foreign countries (外国にある第三者への提供, APPI Art. 28)
Almost all of our processing happens outside Japan. APPI Art. 28 requires us to name the foreign countries involved, to describe those countries' personal information protection systems, and to describe the measures the recipient takes. Here is the position.
Countries. Personal information, including meeting audio, transcripts, translations, summaries, emotion labels, account details and billing details, is transferred to and processed in the United States of America. Every provider named in section 11 is a company established in the United States, and we have not configured a regional deployment with any of them, so the United States is the country to name for all of them. Fly.io runs the meeting bot machine in its lax region, Los Angeles. PostHog receives analytics at its United States cloud.
We have not obtained written confirmation of the specific data location from every provider, and we do not claim to know how any of them sub-processes internally. If a provider tells us its processing happens somewhere else, we will name that country here instead.
The system in the United States. The United States has no single comprehensive federal data protection law equivalent to the APPI. Protection comes from sector-specific federal laws, from state laws such as the California Consumer Privacy Act, and from the enforcement of companies' own privacy commitments by the Federal Trade Commission. There is no independent national data protection supervisory authority of the kind Japan has. United States public authorities can compel the production of data held by companies subject to their jurisdiction, in circumstances and by procedures that differ from Japanese law. The United States is not a country designated as having an equivalent standard under APPI Art. 28(1).
The measures the recipients take. We rely on each provider's published data processing terms and on the security measures each of them publishes. We have not completed our own record of contract terms with every provider that impose measures equivalent to those required of a personal information handler under the APPI, and we have not completed the record of the periodic check the Act contemplates. We are telling you that rather than asserting a safeguard we cannot evidence.
Information about the measures a specific recipient takes is available on request from privacy@voxtiva.com.
A.5 Retained personal data (保有個人データ) disclosures, APPI Art. 32
- The handler's name and address, and the name of its representative: given in section A.1.
- The purposes of use of all retained personal data: given in section A.2.
- Procedures for requests for disclosure, correction, addition, deletion, cessation of use, cessation of provision to third parties, and disclosure of third-party provision records: write to privacy@voxtiva.com. Tell us what you are asking for and give us enough detail to find the data. We will tell you what we need in order to verify your identity, and we will respond within 30 days, or tell you inside that period if a complex request needs longer. We do not charge a fee.
- Where to complain: privacy@voxtiva.com. This is the complaints contact required by Art. 32(1)(iv), and it is the same mailbox as the privacy contact. You may also complain to the Personal Information Protection Commission (個人情報保護委員会), the supervisory authority in Japan.
- Security control measures (安全管理措置): summarised in section 14. This includes measures taken in light of the external environment (外的環境の把握): because our data is held outside Japan, principally in the United States, we take account of that country's personal information protection environment, described in section A.4, when we assess whether our security measures are adequate.
A.6 Anonymously and pseudonymously processed information
We do not create, use or provide anonymously processed information (匿名加工情報) or pseudonymously processed information (仮名加工情報).
A.7 Breach reporting (APPI Art. 26)
If a breach of personal data occurs that is reportable under Art. 26 we will report it to the Personal Information Protection Commission and notify the people affected, within the periods the Commission's rules require.
Annex B: European Economic Area and United Kingdom
This annex applies if you are in the EEA or the UK. It is written to be read on its own. Where it says GDPR it means Regulation (EU) 2016/679, and, for the UK, the UK GDPR and the Data Protection Act 2018.
B.1 Who is the controller
- For meeting content (audio, transcripts, translations, summaries, panel questions and answers, participant names, emotion labels and the recording), the host decides whether the meeting is recorded, which meeting, who sees the result and when it is deleted. We act on the host's instructions and we do not use meeting content for our own purposes. The intended allocation is therefore host as controller, Voxtiva as processor under Art. 28.
- For everything else (host account data, billing, security and diagnostic data, analytics, waitlist), we are the controller.
Read this together with section 6.1: the processor allocation depends on a written data processing agreement, we do not yet publish one, and we will not pretend one is in place when it is not.
B.2 Information under Articles 13 and 14
- Identity and contact details of the controller: section 1.
- Data protection officer: we have not appointed one.
- Purposes and legal bases: section 8.
- Legitimate interests relied on: providing a feature the host enabled (tone), keeping the service secure, diagnosing faults, and product analytics. We have weighed each against the rights of the people affected. You can object to any of them under Art. 21.
- Recipients: section 11.
- Transfers outside the EEA and UK: section B.3.
- Retention: section 13. The honest answer for meeting content is that we keep it until the host deletes it or closes the account.
- Your rights: section 17 and section B.4.
- Source of the data, where it did not come from you (Art. 14): if you are a participant, we obtained your voice from the meeting itself, and your name from the meeting platform's participant list or from what you typed into the Voxtiva panel. We did not obtain it from a public source or a data broker.
- Whether providing data is a statutory or contractual requirement: for a host, providing a name and email is necessary to have an account. For a participant, nothing is required of you; the recording is initiated by the host.
B.3 International transfers
We are established in Japan. Japan has an adequacy decision from the European Commission for transfers from the EEA to Japanese business operators, and a UK adequacy decision for transfers from the UK. That covers the transfer to us.
It does not cover onward transfers to our providers in the United States. For those we rely on each provider's standard data processing terms, which is what section 11 records. We have not completed our own record of the specific Article 46 safeguard that applies to each of them. We will not assert a mechanism we cannot evidence. Ask privacy@voxtiva.com and we will tell you the current status for a specific provider.
B.4 Your rights
You have the rights in section 17, and in addition:
- Restriction of processing while a dispute about accuracy or legitimate interests is resolved (Art. 18).
- Objection to processing based on our legitimate interests (Art. 21). If you object we stop unless we can show compelling legitimate grounds that override your rights.
- Not to be subject to a decision based solely on automated processing producing legal or similarly significant effects (Art. 22). We make no such decisions. The emotion labels, the summaries and the assistant's answers are shown to people; they do not make decisions and they are not used by us to make decisions about anyone.
- To complain to a supervisory authority in the EEA country where you live, where you work, or where you think something went wrong. In the UK that is the Information Commissioner's Office (ico.org.uk). We would rather you told us first, at privacy@voxtiva.com, but you do not have to.
B.5 No Article 27 representative
We have not designated a representative in the Union under Article 27 GDPR, and we have not designated a UK representative. We are telling you this rather than leaving a gap where a name should be.
What that means for you in practice: there is no local office you can walk into or write to in your own country. You must contact us in Japan, at privacy@voxtiva.com, and we will answer. It does not reduce your rights, and it does not reduce our obligations. It also does not stop you complaining to your own supervisory authority, which you can do directly.
B.6 AI transparency: the emotion recognition feature
Under Article 50 of Regulation (EU) 2024/1689 (the AI Act), people exposed to an emotion recognition system must be informed that they are exposed to it.
You are being informed. When Voxtiva is capturing a meeting, an emotion recognition system is running on the voices of everyone in that meeting. For each finished utterance our speech provider returns a label describing the emotion it infers from the sound of the voice. We store that label with the speaker identifier, the time and the language, and we display it to the host and to participants as "Tone" in the side rail, live and afterwards.
This inference is made from acoustic features of speech. It is not a measurement of what anyone actually feels, and it can be wrong. Accents, illness, tiredness, a bad microphone, background noise and cultural differences in speech all affect it. Do not treat a tone reading as a fact about a person.
If you do not want this running, the host can ask us to disable it for their account at privacy@voxtiva.com, and any participant can ask the host to switch it off before the meeting.
We also inform you, as Art. 50 requires for AI-generated content, that the translations, the summaries, the action items, the highlights and the assistant's answers are generated by AI models and are not written or checked by a person.
Annex C: United States
This annex applies if you are in the United States. It is written to be read on its own.
C.1 California: categories of personal information (CCPA/CPRA)
In the 12 months before the date at the top of this page we collect, or would collect if you used the service, the following categories under Cal. Civ. Code § 1798.140(v).
| Category | What we collect | Source | Why | Disclosed to |
|---|---|---|---|---|
| Identifiers | Name, email address, account identifiers, meeting identifiers, IP address in server logs | You, your meeting platform's participant list, our sign-in provider | To run accounts and meetings | Convex, WorkOS, Vercel, Stripe, Resend, PostHog, Sentry |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name and email tied to a paid subscription | You and Stripe | Billing | Stripe, Convex |
| Commercial information | Plan, subscription and trial state, meetings created, usage against plan limits | Our own systems | Billing and enforcement of plan limits | Stripe, Convex, PostHog |
| Internet or network activity | Pages viewed in the product for a fixed set of events, error reports, performance samples | Your browser | Product measurement and fault diagnosis | PostHog, Sentry |
| Audio and electronic information | The recorded audio of a meeting, the transcript, the translation, and the emotion label inferred from each utterance | The meeting itself | To provide transcription, translation and summaries | Modulate.ai, DeepInfra, Convex, Fly.io |
| Professional or employment information | Whatever people happen to say about their jobs during a meeting, which we do not seek but do record | The meeting itself | Incidental to transcription | Modulate.ai, DeepInfra, Convex |
| Inferences | The emotion label; the summary, action items and highlights drawn from what was said | Derived by AI models from the audio and transcript | Product features | DeepInfra, Convex |
We keep each category for the periods in section 13. For meeting content, that means until the host deletes it or closes the account.
C.2 Sale and sharing
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA as amended by the CPRA. We have not done so in the preceding 12 months. We do not sell or share the personal information of minors under 16.
Because we do not sell or share, there is no "Do Not Sell or Share My Personal Information" link on our site. If that changes we will add one before it changes.
C.3 Sensitive personal information
Meeting audio is audio information, and depending on what is said a meeting can easily contain sensitive personal information: health details, union membership, immigration status, sexual orientation, racial or ethnic origin, or the contents of communications.
We use and disclose sensitive personal information only to provide the service you or the host asked for, that is to transcribe, translate, summarise and answer questions about the meeting, and for security and fault diagnosis. We do not use it to infer characteristics about a consumer, other than the emotion label described in section 5.6, which is inferred from the sound of the voice and shown to the meeting's own participants. You may still ask us to limit our use of sensitive personal information by writing to privacy@voxtiva.com.
On voiceprints. Speaker separation groups the voices inside a single meeting so the transcript can say who spoke. We do not build a voiceprint that identifies a person across meetings, and we hold no voiceprint database.
One thing we cannot tell you. Whether Modulate.ai derives a speaker embedding of its own inside its service, and what it does with one if it does, is not visible from our code. We have asked and we do not have a written answer yet, so we cannot rule it out. It bears on the sensitive personal information analysis in this section and on the Illinois position in section C.6, and we would rather tell you we do not know than let you assume we do.
C.4 Your California rights
You may ask us to:
- Know what personal information we collect, use, disclose and (if ever) sell or share, both in categories and in the specific pieces we hold about you.
- Delete the personal information we hold about you.
- Correct inaccurate personal information.
- Limit our use and disclosure of sensitive personal information.
- Opt out of sale or sharing. Not applicable today; we do neither.
Write to privacy@voxtiva.com. We will confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days if we tell you why. We will not discriminate against you for exercising any of these rights. An authorised agent may act for you if they give us written proof and you confirm it directly.
If you are a participant with no account, we can still act on your request. Give us the meeting date and the meeting title or PIN so we can find the right meeting.
C.5 Other state privacy laws, and "Shine the Light"
If you live in a state with a comprehensive consumer privacy law (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana), you have broadly the rights in section C.4: access, deletion, correction, portability, and opt-out of targeted advertising, sale and certain profiling. We do no targeted advertising, no sale, and no profiling that produces legal or similarly significant effects. Use the same address, privacy@voxtiva.com. Where your state gives you a right to appeal a refusal, say so in your message and we will treat it as an appeal and respond in writing.
California "Shine the Light" (Cal. Civ. Code § 1798.83). We do not disclose personal information to third parties for those third parties' own direct marketing purposes. If you want that confirmed in writing, ask at privacy@voxtiva.com.
C.6 Recording law: read this before you record a meeting in the United States
Voxtiva records conversations. In the United States that is regulated, and the rules differ by state. If you are a host, this is your responsibility, not ours.
Federal law and most states allow a call to be recorded with the consent of one party. A significant number of states require all parties to consent. Among them:
- California (Cal. Penal Code § 632). Confidential communications require the consent of all parties. Criminal penalties, plus a private right of action.
- Illinois (720 ILCS 5/14-2). Eavesdropping on a private conversation without the consent of all parties is a criminal offence.
- Washington (RCW 9.73.030). All parties must consent to the recording of a private communication. Criminal and civil exposure.
- Pennsylvania (18 Pa. C.S. § 5703). All-party consent for the interception of an oral or electronic communication.
- Florida (Fla. Stat. § 934.03). All-party consent, criminal penalties.
If any participant is in one of these states, or you cannot tell where everyone is, get everyone to agree out loud before you start, and let the recording capture that agreement. A bot in the participant list and a line in the chat are notice; in an all-party state they are not by themselves consent.
Illinois BIPA (740 ILCS 14). Illinois treats a "voiceprint" as a biometric identifier and requires written notice and written consent before one is collected, with a private right of action and statutory damages per violation. As stated in section C.3, we do not build a voiceprint that identifies people across meetings and we hold no voiceprint database. If any provider in our chain derives a voiceprint from meeting audio, BIPA is engaged for any Illinois participant. As section C.3 says, we cannot yet rule that out for our speech provider. If you record meetings with participants in Illinois, take advice before you do.
Nothing in this section is legal advice to you. It is a warning that this product does something the law in several states regulates closely.
Contact
セノリティックラブ合同会社 (Senolytic Lab LLC)
Branz Yonbancho 503, 2-4 Yonbancho, Chiyoda-ku, Tokyo 102-0081, Japan
〒102-0081 東京都千代田区四番町2-4 ブランズ四番町503
代表社員 タイ・バン・デービッド (Thai Van David)
+81 90 6299 5920
Privacy, data subject requests and complaints: privacy@voxtiva.com Everything else: hello@voxtiva.com
We have no representative in the European Union or the United Kingdom. Contact us in Japan.