Privacy Policy
Last updated: August 31, 2026
This Privacy Policy explains how GrumbusVoice (“we”, “us”, “our”) collects, uses, discloses, and protects information about you when you use our software, applications, websites, APIs, and any related services (collectively, the “Service”). It applies to all users of the Service worldwide. By using the Service you consent to the practices described here. If you do not agree, do not use the Service.
1. Scope and definitions
“Personal information” means any information that identifies, relates to, or could reasonably be linked to an identified or identifiable individual. This Policy does not apply to data that is fully aggregated or anonymized such that it cannot be linked back to any individual.
2. What we collect
- Account data: your email address, OAuth provider ID (if you sign in with Google or Apple), a hashed password (if you sign in with email/password), and account preferences (e.g., dictation mode, hotkey).
- Voice audio: while you hold the dictation hotkey, your microphone audio streams to our servers. Audio is forwarded to our speech-recognition provider for transcription. Audio is not retained after the transcription is returned.
- Transcripts: the text resulting from transcription is returned to your device. We do not store the transcript on our servers beyond the request lifecycle, except as needed to enforce abuse limits or as you opt to enable cross-device sync (when offered).
- AI cleanup metadata: when you use Polished or Balanced modes, the raw transcript is sent to an AI language-model provider for cleanup. Only the transcript text is sent; we do not transmit audio, account identifiers, or other personal information beyond what is needed to format the output.
- Usage data: we count the duration of each transcription, mode used, and timestamp so we can enforce your subscription's monthly quota and provide you with usage Insights inside the app.
- Billing data: handled directly by Stripe. We never see, transmit, or store your card number, CVV, or banking details. We store your Stripe customer ID, subscription status, and billing-cycle dates.
- Diagnostic data: when an error or crash occurs, we log the error type, route, request ID, software version, and operating-system version. We do NOT log audio, transcript content, account passwords, or payment data.
- Device identifiers: a device-scoped token used to authenticate the app to our backend, generated locally on first sign-in.
- Website live demo: if you use the “try it” demo on our website, your browser's built-in speech recognition (operated by your browser vendor, e.g. Apple or Google, under their policies) produces a text transcript locally in your browser; only that short text transcript is sent to our servers for cleanup and is not stored after the response is returned. The demo's audio never reaches our servers.
- First-party marketing analytics: on our public marketing pages we record our own funnel events — which page you viewed, which call-to-action you clicked, the answers you selected in the on-site quiz, and which checkout step you reached — against a first-party random identifier stored in the
gv_aidcookie (see Section 14). These events are stored in our own database and are not sent to any third party. If you later create an account, we link the events already recorded against that identifier to your account so we can understand which marketing path led to a sign-up. The quiz answers are your own self-reported estimates (role, what you write, hours at a keyboard, typing speed, backlog, and what you consider an hour of your time to be worth); they are not verified and are used for product and marketing analysis. - Session replay and heatmaps: on our public marketing pages we use Microsoft Clarity, which records a reconstruction of your visit — pages viewed, mouse movement, scrolling, clicks, and page content — plus your approximate location (country/region inferred from IP), browser, operating system, and referring URL, in order to see where visitors get stuck. Text you type into form fields is masked, and passwords are explicitly excluded from recording. Clarity is not loaded inside the signed-in product, and it never receives audio, transcripts, or dictation activity. See Sections 6 and 14.
- Marketing and advertising data: on our public marketing pages we may collect page-view and conversion events (for example CompleteRegistration, InitiateCheckout, Lead, StartTrial, Subscribe), referring campaign parameters (UTM tags and
fbclid), IP address, browser user-agent, Meta click identifiers (_fbp,_fbc), and a hashed email and hashed internal user id, via first-party cookies and — when our advertising measurement is active — the Meta (Facebook) Pixel in your browser and our server-side Conversions API. Email and user id are hashed with SHA-256 on our servers before they are sent on the Conversions API. We do not include raw email in Pixel event parameters. We use this data to measure whether ads led to sign-ups, checkouts, and subscriptions, and to optimize those ads. See Section 14.
3. What we don't collect
- We don't store recorded audio after transcription completes.
- We don't share your transcripts with third parties beyond the AI cleanup provider when you enable polishing modes (and even then only the transcript text is sent, anonymized of account context).
- We don't sell, rent, or trade personal information to data brokers.
- We don't use advertising, analytics, or session-replay tracking inside the app itself. The Meta Pixel, Microsoft Clarity, and our own funnel analytics run on our public marketing website only (Section 14) — they are not loaded on the signed-in product pages, and they never see your dictation activity, audio, or transcripts.
- We don't collect biometric identifiers, geolocation data, or contacts.
4. How we use information
We use the information we collect to: (a) provide, maintain, and improve the Service; (b) authenticate you and prevent unauthorized access; (c) process payments and enforce subscription limits; (d) send you transactional and account-related communications; (e) detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms of Service; (f) comply with legal obligations; (g) generate aggregated, de-identified statistics about Service performance and usage; and (h) measure advertising performance and optimize Meta ads using the Pixel and Conversions API described in this Policy.
5. Legal bases for processing (EU/UK/EEA users)
If you are in the EU, UK, or EEA, our legal bases for processing your personal information are: (i) contract performance — to deliver the Service you have subscribed to; (ii) legitimate interests — to operate, improve, and secure the Service; (iii) legal obligation — to comply with applicable law; and (iv) consent — for any processing for which we ask your consent (which you may withdraw at any time).
6. Service providers (subprocessors)
We use the following providers to operate the Service. Each is bound by their own privacy policy and (where applicable) by data-processing agreements with us. The list may change over time; the version current at the time you read this page is authoritative.
- Deepgram (US) — speech-to-text transcription provider. Receives audio during dictation; does not retain audio after transcription per our agreement and their stated policy.
- OpenAI / Anthropic (US) — AI language-model providers used for transcript cleanup in Polished and Balanced modes. Receives transcript text only; subject to provider data-handling commitments (no training on input by default).
- Stripe (US) — payment processing. Subject to Stripe's privacy policy.
- Resend (US) — transactional email delivery. Receives only the recipient email address and message contents.
- Sentry (US) — error and crash reporting. Receives error metadata; does not receive audio, transcripts, passwords, or payment data.
- Vercel (US) — application hosting and edge networking.
- Neon (US) — managed Postgres database.
- Cloudflare (US) — domain DNS and email routing.
- Meta Platforms, Inc. (US) — advertising measurement on our marketing website only (Meta Pixel and Conversions API), when active: page-view and conversion events (CompleteRegistration, InitiateCheckout, Lead, StartTrial, Subscribe), hashed email, hashed user id, IP address, user-agent, and click IDs (
_fbp,_fbc). Never audio, transcripts, or in-app activity. See Section 14 for your choices. - Microsoft Corporation (US) — Microsoft Clarity session replay and heatmaps on our public marketing website only. Receives a reconstruction of your visit on those pages (page content, clicks, scrolling, mouse movement), IP-derived approximate location, browser and device metadata, and referring URL. Form-field text is masked and passwords are excluded. Never audio, transcripts, in-app activity, or payment details. Microsoft may use this data as described in its own privacy statement. See Section 14 for your choices.
- Apple App Store / TestFlight (US) — for iOS app distribution and testing (where applicable).
- GitHub (US) — for software releases and update distribution.
We may add or replace subprocessors from time to time as needed to operate the Service. Material changes will be reflected in this list.
7. International data transfers
GrumbusVoice is operated from Canada and our subprocessors are primarily in the United States. If you access the Service from outside Canada or the United States — including from the European Union, United Kingdom, EEA, or any other jurisdiction — you acknowledge and consent to the transfer of your personal information to and processing in Canada, the United States, and other jurisdictions where we or our subprocessors operate, which may have data-protection laws different from those of your country. Where required, we rely on Standard Contractual Clauses or other approved transfer mechanisms.
8. Data security
We implement reasonable administrative, technical, and physical safeguards designed to protect personal information from loss, unauthorized access, disclosure, alteration, or destruction. These include encryption in transit (HTTPS/TLS), encryption at rest where supported by our infrastructure providers, access controls, and routine review of security practices. No method of transmission or storage is 100% secure, and we cannot and do not guarantee the absolute security of any information. You acknowledge that the Service is provided over the public internet and that you bear responsibility for the security of your own devices, account credentials, and network. To the maximum extent permitted by law, we disclaim all liability for any unauthorized access to or disclosure of your personal information that occurs despite our reasonable security measures. In the event of a breach affecting your personal information, we will notify you and, where required, the applicable regulator without undue delay in accordance with applicable law.
9. Children's privacy
The Service is not directed to and is not intended for use by children. You must be at least 13 years old (or the minimum age in your jurisdiction at which you can consent to online services without parental consent — 16 in much of the EU) to use the Service. We do not knowingly collect personal information from children under that age. If we become aware that we have inadvertently collected personal information from a child without verified parental consent, we will delete it promptly. If you believe a child has provided us personal information, contact privacy@grumbus.app.
10. Your rights
Depending on your jurisdiction, you may have some or all of the following rights regarding your personal information:
- Access: request a copy of the personal information we hold about you.
- Portability / export: receive your data in a structured, commonly used, machine-readable format.
- Correction: ask us to correct inaccurate or incomplete information.
- Deletion / erasure: ask us to delete your account and personal information, subject to legal retention requirements.
- Restriction / objection: ask us to restrict or stop certain processing activities.
- Withdraw consent: where processing is based on consent, withdraw it at any time (without affecting prior lawful processing).
- Complain: lodge a complaint with your local data-protection authority. EU residents may complain to their national supervisory authority. Canadian residents may complain to the Office of the Privacy Commissioner of Canada.
To exercise any of these rights, email privacy@grumbus.app from the email address associated with your account, or use the in-app account management at grumbus.app/account. We will respond within 30 days (or any shorter period required by law). We may need to verify your identity before fulfilling certain requests.
11. California residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act, collectively the “CCPA”) gives you specific rights:
- Right to know the categories and specific pieces of personal information we collect, use, and disclose.
- Right to delete personal information we have collected from you, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing of personal information. We do not sell personal information. When our advertising measurement is active, disclosures to Meta from our marketing website may constitute “sharing” for cross-context behavioral advertising under the CCPA. You can opt out at any time: we honor the Global Privacy Control (GPC) browser signal automatically (no advertising, analytics, or session-replay trackers load at all for GPC browsers), or email privacy@grumbus.app.
- Right to limit use of sensitive personal information. We do not use sensitive personal information for purposes other than those permitted under the CCPA.
- Right to non-discrimination for exercising your CCPA rights.
The categories of personal information we collect are: identifiers (email, account ID), commercial information (subscription status, payment history), audio/electronic information (during transcription only, not retained), internet activity (limited diagnostic data, our own marketing-funnel events and quiz answers, session-replay data from our marketing pages, and — when advertising measurement is active — the advertising/attribution identifiers described in Section 2), and inferences derived from usage. We retain each category for the periods described in Section 13. To exercise your CCPA rights or designate an authorized agent to do so on your behalf, contact privacy@grumbus.app.
12. Canadian residents (PIPEDA and provincial laws)
If you are a Canadian resident, the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and any applicable provincial privacy laws (including New Brunswick's Personal Health Information Privacy and Access Act, where applicable) govern our handling of your personal information. You have the right to access, correct, and challenge our use of your personal information, and to escalate complaints to the Office of the Privacy Commissioner of Canada or your provincial commissioner. We are located in New Brunswick, Canada.
13. Data retention
- Account data: kept while your account is active and for up to 90 days after you delete your account, after which it is permanently removed (subject to legal-retention obligations such as tax record requirements).
- Voice audio: not retained after transcription completes (typically a few seconds).
- Transcripts: not retained on our servers beyond the request lifecycle, unless you have enabled an optional sync feature in which case they are retained encrypted until you delete them.
- Usage minutes / billing records: retained for at least 24 months for billing reconciliation, tax, and audit purposes.
- Diagnostic logs: retained for up to 90 days, then aggregated or deleted.
- First-party marketing analytics: the
gv_aidcookie is stored for 12 months. The funnel events recorded against it are retained for up to 24 months, after which they are deleted or aggregated. Events linked to an account are deleted with the account under the account-data rule above. - Session replay: Microsoft Clarity recordings are retained by Microsoft according to its own retention schedule (currently 30 days for recordings, with heatmap and aggregate data kept longer). We do not keep a separate copy.
- Advertising attribution cookies:
gv_attris stored for 30 days. Meta's_fbpand_fbccookies are set by Meta's Pixel script and follow Meta's cookie lifetime. Server-side conversion events are sent to Meta at the time of the event and are then subject to Meta's retention. - Backups: may persist for up to 30 days after deletion from primary storage; we do not restore deleted user data from backups except in the event of catastrophic data loss.
14. Cookies and tracking
Our website uses:
- Strictly necessary cookies for authentication, session management, and basic security (e.g., CSRF protection). These cannot be disabled.
- A first-party attribution cookie (
gv_attr, 30 days) on marketing pages that remembers which campaign brought you here (UTM parameters andfbclid) from the first visit that carried them. An existinggv_attrcookie is not overwritten by a later visit. We use it to keep ad-click context across pages, to stamp checkout metadata so later subscription events can be attributed, and to append those parameters onto a Mac download link emailed from a phone. _fbp(Meta): browser identifier set by the Meta Pixel so Meta can match browser events to ads. Sent to Meta on the Pixel and on the Conversions API. Lifetime is controlled by Meta's script._fbc(Meta): click identifier set by the Meta Pixel when you arrive from a Meta ad (or synthesized server-side from a storedfbclidif the Pixel has not set the cookie yet). Sent raw to Meta. Lifetime is controlled by Meta's script.- A first-party analytics cookie (
gv_aid, 12 months) on marketing pages: a random identifier, generated in your browser, that lets us count one visitor once across the pages of our own funnel and see where people drop out. It contains no personal information and is never sent to a third party. We also keep a per-tab identifier in your browser'ssessionStorage(gv_sid), which is discarded when you close the tab. - Meta (Facebook) Pixel, when our advertising measurement is active, on public marketing pages only: it sets Meta's cookies and reports page views and conversion events (for example, starting a trial) to Meta to measure ad performance and build advertising audiences. It is never present inside the signed-in app, and it never receives audio, transcripts, or dictation activity.
- Microsoft Clarity, when configured, on public marketing pages only: session-replay and heatmap analytics. Its script sets first-party cookies (
_clck, roughly 12 months, and_clsk, roughly 1 day) to tie the pages of one visit together, and Microsoft may set its own cookies on theclarity.msdomain. It records how you move through the marketing pages so we can see where the experience breaks. Text entered into form fields is masked and password fields are excluded from recording. It is not loaded on the signed-in product pages or in our admin tools, and it never receives audio, transcripts, or dictation activity. Card details are entered on Stripe's own checkout pages, which Clarity cannot see.
Your choices: we honor the Global Privacy Control (GPC) signal — if your browser sends GPC, no advertising pixel and no session-replay script loads, and no attribution or analytics cookie is set, automatically. You can also block or clear cookies in your browser; the Service works without any of them. Blocking _fbp, _fbc, gv_attr, gv_aid, or Clarity's cookies may make our measurement less accurate; it does not stop you from using the Service. Microsoft also offers its own opt-out for Clarity. To request that we stop sending account-linked conversion events to Meta, or that we delete the funnel events associated with your account, email privacy@grumbus.app. For legacy Do-Not-Track signals (which lack an industry-consensus meaning), GPC is the signal we honor.
15. Aggregated and de-identified data
We may create aggregated or de-identified data (e.g., total dictations across all users in a given period) that does not identify any individual. We may use, disclose, and retain such data without restriction for any lawful purpose, including to improve the Service and to publish industry statistics.
16. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. The “Last updated” date at the top of this Policy indicates when it was last revised. Material changes will be communicated via email to your account address or via in-app notice at least 14 days before they take effect. Your continued use of the Service after the effective date constitutes acceptance.
17. Limitations
To the maximum extent permitted by applicable law, the privacy practices described in this Policy do not give rise to any contractual right of action against GrumbusVoice beyond the rights expressly granted by applicable privacy law. Any claim arising out of or relating to this Privacy Policy or our handling of your personal information shall be subject to the dispute resolution and limitation of liability provisions of our Terms of Service, including the binding arbitration clause and the cap on liability.
18. Contact and complaints
For privacy questions, requests to exercise your rights, or to file a complaint with us first (which we encourage before contacting a regulator):
Email: privacy@grumbus.app
Mailing address: GrumbusVoice, Fredericton, New Brunswick, Canada
We will acknowledge your inquiry within 30 days. If we are unable to resolve your complaint to your satisfaction, you may escalate to your local data-protection authority.