Vois
Legal

Privacy Policy

Last updated: September 9, 2026

At Vois, we believe your content is yours, and it should stay that way. This privacy policy explains how we handle data in our desktop application and on our website.

The Short Version

  • Your scripts and audio stay on your device by default. All voice generation happens locally on your machine; files leave only when you choose a connected publishing or sharing destination.
  • No cloud uploads. We don't have servers that process your content.
  • Your connected-service credentials stay with you. Credentials for features you choose to connect are stored locally and never sent to us.
  • Limited network communication. We use the network for setup, verified model-package downloads, updates, license validation, cloned-voice export receipts, and features you choose to connect. The desktop diagnostics setting is on by default for fresh installs; you can turn it off in Settings.

Desktop Application

Local Processing

Vois runs text-to-speech and audio processing on your computer using models stored locally on your device. Vois does not upload your scripts, audio files, projects, or creative work for generation or mastering. If you choose a connected publishing or sharing feature, the files you select may be sent to that destination under its terms.

What We Don't Collect

  • Your scripts or text content
  • Generated audio files
  • Voice samples you provide for cloning
  • Voice state files created during cloning
  • Project files or settings
  • Usage patterns or content analytics beyond the optional diagnostics described below

Voice Cloning Privacy

Voice cloning in Vois is designed with privacy as a core principle:

  • Local processing only. Voice samples you provide for cloning are processed entirely on your device. The audio is never uploaded to our servers or any third party.
  • Voice states stay local. The voice characteristic files (voice states) created during cloning are stored only on your device in encrypted local storage.
  • No biometric voice analysis. We do not analyze or classify voice characteristics. A cryptographic hash (SHA-256) of the reference audio is stored locally for provenance verification only. This hash cannot reconstruct the audio.
  • You control deletion. Delete any cloned voice at any time. Deleting removes both the voice state and any cached reference audio from your device.

For detailed terms on voice cloning usage, consent requirements, and prohibited uses, see our Voice Cloning Terms.

License Validation

To activate Vois, verify that your license remains active, and enforce device limits, the app contacts our license server. This communication includes:

  • Your license key or subscription account identifier
  • A device fingerprint and device name
  • Operating system and app version information
  • The coarse hardware profile described under App Diagnostics, while that setting is enabled

We do not track what text you generate or receive your audio output through license validation.

Export Provenance

Exported audio files contain metadata identifying them as AI-generated by Vois (a unique export identifier, app version, and voice type). This metadata does not contain your personal information, your script text, or any audio content.

When you export audio that uses a cloned voice, the app sends a small provenance receipt to our server containing: the export identifier, your license key, the cloned voice identifier, the audio duration, and a hash of your device fingerprint. No audio, text, or personal information beyond what the license server already has is transmitted. This receipt supports compliance with synthetic media regulations and enables forensic verification if the audio is misused.

Cloned voice generations are also logged locally on your device (timestamps, anonymized hashes, no text or audio). These logs are automatically pruned after 90 days (1 year for exported generations).

AI Model Processing

Vois uses open-source AI models for text-to-speech generation and voice cloning. All model inference runs locally on your device:

  • No training on your data. Your scripts, audio, and voice samples are never used to train or fine-tune AI models. The models ship pre-trained and run in inference-only mode.
  • No model telemetry. The AI models do not phone home, report usage statistics, or transmit any data to model creators or third parties.
  • Model files stored locally. Voice-engine packages are downloaded as needed from cdn.vois.so, checked against the release's verified manifest, and stored on your device. After an app update, Vois automatically re-downloads the current package only for voice engines you previously installed; other packages remain on demand.

For details on the open-source licenses governing these models, see our Terms of Service.

Local Storage

Vois stores data locally on your device, including:

  • Application settings and preferences
  • Project files and scripts (in SQLite database)
  • Generated audio cache
  • Voice model files
  • API keys (encrypted)

This data remains on your computer and is never transmitted to us. You can delete it at any time by uninstalling the application or clearing the application data folder.

Backup Files and Connected Services (Optional)

Vois can create an encrypted backup file that you save wherever you choose. Vois does not upload that backup itself. If you place it in a folder synchronized by Google Drive, Dropbox, OneDrive, iCloud Drive, or another storage provider, that provider's desktop software handles the upload under its terms.

When you choose a connected publishing or sharing feature, Vois sends only the files you select to that destination. The destination provider's privacy policy applies.

Payment Processing

Subscription Billing

Vois uses third-party payment processors to handle subscription billing. When you subscribe, the following information is transmitted to our payment processor:

  • Email address
  • Billing address (optional)
  • Payment method information (credit card, etc.)

Payment data is encrypted and handled directly by our payment processor. We do not store your full credit card details on our servers. For payment processing details, see your payment processor's privacy policy.

App Diagnostics (Optional, On by Default)

The desktop app can send redacted diagnostics, controlled by a single setting: Settings → Send crash reports and diagnostics. It is on by default for fresh installs; you can turn it off in Settings. Turning it off closes the diagnostic clients, stops new reports, deletes queued reports from app storage, and stops the native crash helper.

When enabled, we receive two things:

  • Crash and error reports. Redacted stack traces, including sanitized native crash stacks, error classifications, voice-engine category, execution method, model quality profile, text length, optional numeric generation seed, and timing. A short trail of sanitized breadcrumbs records the run-up to a failure: an operation category such as generation, licensing, or audio, and a fixed event label for that step, for example generation started, completed, cancelled, timed out, or failed, alongside an error class and coarse counts and durations. Descriptive breadcrumb text is replaced on your device before sending, and the native crash helper receives only these same sanitized fields, not a separate raw copy. Breadcrumbs record that an operation happened, never what you wrote, generated, or named. Native crash dumps are processed locally into module basenames, numeric instruction addresses, debug identifiers, and unwound frames, then deleted without being uploaded.
  • A coarse hardware profile. Operating system and major version, CPU architecture, a physical CPU core count when available, a memory range (not an exact figure), and which graphics acceleration backend appears usable. Detection can be inconclusive, and an unknown result is recorded as unknown rather than guessed. From those signals the app derives whether your machine is expected to run Omni acceptably, which informs product and plan recommendations. While this setting is on, the same capability profile is also attached to license validation requests, which carry your license key and device fingerprint. The profile itself contains no direct identifiers, but in that context it can be associated with your license.

The diagnostics payload never includes your name, email, serial numbers, MAC addresses, hostname, username, absolute file paths, license keys, raw error messages, script or transcript text, voice or speaker names, reference audio, generated audio, PCM, or audio samples. These exclusions describe the diagnostics report itself, not the license validation request described above, which is identified by design. Structured error fields are scrubbed on your device before transmission, binary crash dumps never leave your device, and the local Vois log file is never uploaded. The hardware profile is deliberately coarse: it describes what your machine can do, not what you made with it.

If a report cannot be delivered right away, it is held locally until it can be sent. The native diagnostics queue is bounded: at most 100 reports, kept no longer than seven days, and reports rejected with a non-retryable response are deleted rather than retried. Reports raised in the app window are queued in local browser storage until delivery; turning diagnostics off deletes that queue too. Once a report reaches Sentry, how long it is stored is governed by our Sentry service configuration.

Separately, our license service uses Sentry for redacted server-side error reporting. This is not controlled by the desktop diagnostics setting because it runs on our server. Its final scrubber removes request bodies, headers, cookies, route parameters, user data, error messages, and absolute paths before transmission; reports may retain a request method, fixed endpoint name, allowlisted operation or error category, and a short random request identifier.

Website

Analytics

We use Google Analytics on our marketing website (vois.so) to understand how visitors find and use our site. This includes:

  • Pages visited and time spent
  • Referral sources
  • General geographic region (country/city level)
  • Device type and browser

This data is anonymized and used in aggregate to improve our website. You can opt out of Google Analytics by using a browser extension or enabling "Do Not Track."

Newsletter

If you sign up for our newsletter, we collect your email address and send emails through Resend (resend.com). We use this to share product updates, voice production tips, and workflow guides. You can unsubscribe at any time using the link in any email we send.

Cookies

Our website uses minimal cookies for essential functionality and analytics. These cookies do not track you across other websites. We do not use cookies for advertising or retargeting.

Data Security

We take security seriously. Our license server uses HTTPS encryption for all communications. API keys stored locally in the desktop app are encrypted. We do not store your scripts, project files, voice samples, or generated audio on our servers.

Third-Party Services

We work with the following service providers:

  • Cloudflare – Website hosting and license server infrastructure
  • Google Analytics – Website analytics
  • Resend – Email newsletter service
  • Sentry – Two separate uses. Desktop crash and error reporting, sent only while the diagnostics setting is on, and license-service operational error reporting, which runs on our server under redaction and is not controlled by that setting

Each of these services has their own privacy policy governing how they handle data.

Your Rights

You have the right to:

  • Access your data – Request a copy of any personal data we hold about you
  • Delete your data – Request deletion of your personal data from our systems
  • Opt out – Unsubscribe from marketing emails at any time
  • Control production data – Scripts, projects, voice samples, and generated audio are stored locally and remain under your control

Children's Privacy

Vois is not intended for children under 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us to have it removed.

Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes by posting a notice on our website or within the application. Continued use of Vois after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions about this privacy policy or how we handle your data, contact us at support@vois.so.