Privacy policy
This Privacy Policy Discusses:
-
How We Collect and Use Personal Data
- Voice Recordings, Transcription, and AI-Assisted Features
-
How We Share Personal Data We Collect
-
Our Data Security and Storage Practices
-
How We Store and Transfer Your Personal Data
-
Your Choices Regarding the Use of Your Personal Data
-
Minors’ Personal Data
-
Privacy Policy Updates
-
How You Can Contact Us
1. How We Collect and Use Personal Data
1.1 We Collect Personal Data When You Use Our Website
-
Upon purchasing products from our website, we collect and utilize your name, phone number, address, and email address to process your order and to keep you informed about notifications, confirmations, updates, product announcements, etc.. We may also use this information to establish an account for you. For residents of the European Economic Area ("EEA"), this data processing is conducted under Article 6.1(b) of the General Data Protection Regulation ("GDPR"), based on the necessity for the performance of a contract. For residents of the People’s Republic of China (“PRC”), this data processing is conducted under Article 13 of the Personal Information Protection Law (“PIPL”), based on the necessity for the performance of a contract.
-
By subscribing to our mailing list or newsletter, your email address is included in our contact database. For EEA residents, this processing is grounded in Article 6.1(a) of the GDPR, predicated on the consent of the data subject.
-
When you communicate with us via email to partake in surveys, seek customer support, or submit information through our website, we may collect your email and other personal data you provide, such as your name, phone number, and address, to address your inquiries and requests, offer customer service, solicit feedback, and maintain communication regarding your use of our Services. For EEA residents, this data processing is based on Article 6.1(a) of the GDPR, relying on the consent of the data subject.
-
In instances where you seek an exchange or refund, we may collect supplementary personal data regarding payment details and the reasons for your request. For EEA residents, such data processing is executed under Article 6.1(b) of the GDPR, necessary for the fulfillment of a contract. For PRC residents, such data processing is executed under Article 13 of the PIPL, necessary for the fulfillment of a contract.
-
As you navigate our website, we may collect data on your browsing activities to enhance the website's performance and design. For EEA residents, this processing is carried out under Article 6.1(d) of the GDPR, justified by the legitimate interests of the controller.
-
Utilization of public comment sections or interactive features on our website may lead to the collection of any information you choose to provide. For EEA residents, this processing is in accordance with Article 6.1(a) of the GDPR, based on the consent of the data subject.
1.2 How We Use Cookies and Similar Technologies
1.3 We Collect Personal Data from Third Parties
1.4 We Aggregate and Anonymize Personal Data
1.5 Public Comment and User Generated Content
1.6 Voice Recordings, Transcription, and AI-Assisted Features
When you use Vocci applications and connected devices (such as a smart ring), we may collect personal data you provide, generate, or make available through the Services, such as voice or other audio recordings, transcripts and related notes or summaries, and other content you submit in connection with AI-assisted features.
How we process voice recordings. Recordings may be stored on your device when captured offline or synced from a paired device. When you upload or sync content, audio is sent to Vocci over encrypted connections and stored in your account cloud storage so you can access, export, or delete it. We do not use your recordings to train shared general-purpose models unless we separately notify you and provide any controls or consent required by applicable law.
How transcription works. If you request transcription (including when auto-transcription is enabled), the general flow is: (1) you upload or sync audio to Vocci; (2) Vocci sends the audio to contracted transcription service providers so they can generate transcript text; and (3) Vocci stores the transcript in your account and makes it available to you in the app. Those providers process audio only to provide transcription on our behalf.
How AI-assisted features use your content. If you use AI-assisted features, relevant portions of your recordings, transcripts, or other content you submit may be sent to our AI providers (Google, OpenAI, and Anthropic, as described in Section 2) to generate summaries, search results, or other responses you request.
For EEA residents, processing necessary to provide these features is conducted under Article 6.1(b) of the GDPR (contract performance). Where optional features require consent under applicable law, we will request consent before activation.
2. How We Share Personal Data We Collect
-
Platform service vendors, such as Shopify Inc., which hosts our website and provides the online e-commerce platform facilitating the sale of our products. Your personal data may be stored and managed through Shopify's data storage systems. For further details, you may review Shopify's Terms of Service or Privacy Policy.
-
Delivery service vendors, with whom we may share your contact information, including address and phone number, to ensure the delivery of products.
-
Email service vendors, including MailChimp, Klaviyo, Shopify Mail, with whom we may share your email address to facilitate the sending of marketing messages, notifications, confirmations, updates, product announcements, and security alerts.
-
Analytics service vendors, utilizing tools like Zalify, which enables Vocci to analyze general usage patterns of our customers, including daily and weekly user metrics.
- AI providers, which process content you submit to deliver AI-assisted features you request, including Google (Google Cloud and Vertex AI, including Gemini), OpenAI, and Anthropic.
- Transcription and other service providers that help us operate the Services, such as providers of hosting, customer support, payment processing, and speech-to-text transcription.
We will only entrust the parties to process your data for achieving the purposes specified in this Policy, and the authorized parties can only access the data to the extent necessary to perform their duties. They have no right to use it for other purposes beyond the scope of the entrust agreement, unless they seek your consent separately. We do not permit service providers to use your personal data for their own commercial or marketing purposes.
Third-party AI data protection. We use commercial or API offerings from Google, OpenAI, and Anthropic. Under their published terms, customer content submitted through those services is generally not used to train their general-purpose models without permission, and is processed to provide the features you request. You may review their policies at Google Cloud, OpenAI, and Anthropic. Vocci does not use your recordings, transcripts, prompts, or related content to train Vocci's own shared general-purpose models unless we separately notify you and provide any controls or consent required by applicable law.
3. Our Data Security and Storage Practices
In case of any personal data security incident, we will, in accordance with requirements set out in laws and regulations, inform you promptly of relevant matters. Meanwhile, we will report the status of the handling of the security incident as required by the regulatory authority.
4. How We Store and Transfer Your Personal Data
Vocci stores and processes personal data in secure cloud infrastructure hosted in accordance with applicable laws.
How long we keep your data.
- Content you save (recordings, transcripts, uploaded files, and related materials): stored in your account until you delete them, ask us to delete them, or close your account. If you do not delete them, they remain available in your account for as long as your account is active.
- Account and profile information: kept for as long as your account is active, and for a limited period afterward where needed for security, support, or legal compliance.
- Data sent to AI or transcription providers to run a feature: retained by those providers only as needed to provide that request and as described in their own policies (see Section 2 for AI providers). This is separate from how long your saved content stays in your Vocci account.
- After you delete content or close your account: we remove it from active systems within a reasonable period (typically within 30 days). Limited residual copies may remain in backups for a short period before being overwritten, unless a longer period is required by law.
In certain situations, we may transfer your personal data to other countries or regions, or allow entities outside of your country or region to access your personal data, in compliance with the law. Any such transfer of your personal data will be conducted in accordance with applicable legal requirements, including appropriate safeguards where required (such as Standard Contractual Clauses or comparable mechanisms).
5. Your Choices Regarding the Use of Your Personal Data
5.1 Your rights under GDPR or Data Protection Act 2018
-
Right to Access. You may request access to the personal data we process about you;
-
Right to Correct and Delete. You may request us to correct, update, shield or delete your personal data in our records;
-
Right to Request a Copy. You may request a copy of the personal data we have processed about you. We can - on your request - send this copy to another party, so you don’t have to send the personal data yourself;
-
Object to processing. You have the right to object to the processing of your personal data and request us to cease processing of it if, for example, this data is being processed for the purpose of direct marketing or where we are relying on a legitimate interest (or those of a third party). In some cases, we may demonstrate that we have compelling legitimate grounds to process your data which override your rights and freedoms.
-
Restrict the processing. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the accuracy of the personal data; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you require us to hold the data even if we no longer need it as you require it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
-
Right to Complain. You may file a complaint against processing your personal data. And you may file a complaint if you are under the impression that we process your data unlawfully;
-
Withdraw Your Consent. You may always withdraw your consent to process your personal data. In that case, we will no longer process your personal data for the purpose for which consent is necessary.
-
Requesting channels. Please email us at support@vocci.ai to submit your data request.
5.2 California Privacy Rights
-
No Sale of Personal Data. If Vocci ever chooses to sell personal data, you would have the right to opt out of the sale of your personal data.
-
Right to Disclosure. California Consumers have the right to request that we disclose certain data about our collection and use of your personal data over the past 12 months.
-
Right to Access. You have the right to request that we provide you with access to specific pieces of personal data we have collected about you over the past 12 months (also called a "data portability request").
-
Right to Deletion. You have the right to request that we delete any of your personal data that we collected from you and retained, with certain exceptions.
-
Right to Correct. You have the right to request us to correct inaccurate personal data if and when you learn that we maintain inaccurate personal data about you.
-
Right Against Discrimination. You have the right not to be discriminated against for exercising any of the rights described in this section. We will not discriminate against you for exercising your right.
-
Right to Limit the Use of Sensitive Personal data. Some of personal data we collect and use in accordance with purposes described in this Privacy Policy might fall into the scope of sensitive personal data as defined by CPRA. The use of such sensitive personal data will be limited to that use that is necessary for us to provide Services to you or perform our duties as required by CCPA and CPRA. If we may use your sensitive personal data for any other purpose, we will inform you and you have the right to limit the use of your sensitive personal data. Upon your request, we will not use your sensitive personal data for the proposed additional purpose.
-
Submit a Consumer Privacy Request. To exercise any of the above rights, please submit a verifiable consumer privacy request to Vocci by email at support@vocci.ai.
-
Verification. We cannot respond to your request or provide you with personal data unless we can verify your identity and your authority to make the request and confirm that the personal data relates to you.
-
Authorized Agent. You may make a verifiable consumer request on behalf of your minor child. Otherwise, only you, or a person you have designated in writing as your authorized agent or who is registered with the California Secretary of State to act on your behalf, or to whom you have provided power of attorney pursuant to California Probate Code sections 4000 to 4465 ("Authorized Agent") may make a verifiable consumer request related to your personal data.
-
Vocci’s Response. We endeavor to respond to a verifiable consumer request within 45 days of receipt. If we require more time, we will notify you in writing of the reason and extension period. We will deliver our written response by mail or electronically, at your option. Any disclosures we provide will only cover the 12-month period preceding receipt of the verifiable consumer request. If we cannot comply with part or all of your request, we will explain the reasons in our response. We do not charge a fee to process or respond to your verifiable consumer privacy request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
-
Other California Privacy Rights. California Civil Code sections 1798.83-1798.84 (the Shine the Light Act) entitles California residents to request disclosure regarding personal data sharing with affiliates and/or third parties for marketing purposes. If you are a California resident and you would like to request a copy of this notice, please contact us at support@vocci.ai with the subject line "Request for California Privacy Data."
5.3 Nevada Privacy Rights
5.4 Your Rights under PIPL
You can access and manage your information by the following methods, and we will respond to your request in accordance with the laws and regulations:
You have the right to access, correct, update or transfer your personal data, and obtain a copy of your personal infrmation. You may reach us via the contact information provided in Section 8 and we will respond within the time limit prescribed by law.
In addition to the personal data necessary for using the Services, you may contact us to change the scope of your consent. When you withdraw your consent, we will no longer process the corresponding personal data. However, your decision to withdraw your consent will not affect the processing of personal data which has been carried out based on your authorization.
We will guarantee your rights to delete your personal data and only retain your personal data for a limited period required by the laws and regulations. Under any of the following circumstances, you may contact us to delete your personal data:
- when our processing of personal data violates laws and regulations or our agreements with you;
- when you have withdrawn your consent to our processing of your personal data;
- when the purpose of processing your personal data has been achieved, cannot be achieved, or the processing is no longer necessary (e.g., when you no longer use our Services);
- when we no longer provide you with any Services, or the retention period has expired;
- Other circumstances as stipulated by laws and regulations.
When you exercise the above rights, we may require you to verify your identity in order to protect your account and personal data security.
6. Minors’ Personal Data
7. Privacy Policy Updates
8. How You Can Contact Us
Cookie Policy
-
I. What is a cookie
-
II. Cookies on our Website
-
III. How we use cookies
-
IV. How to control and delete cookies
-
V. Changes to this Policy
-
VI. How to contact us
I. What is a cookie?
II. Cookies on our Website
III. How we use cookies
3.1 CATEGORY 1: STRICTLY NECESSARY COOKIES (SUCH COOKIES ARE EXEMPT FROM CONSENT)
3.1.1 First-party cookies
| Cookie Title/ Name of provider | Purpose | Persistence | Management of Cookie | Available External Information |
| __pf_session | Preserves users states across page requests. | 1 day | HTTP Cookie | |
| __pf_user | Preserves users states across page requests. | 2 years | HTTP Cookie | |
| _secure_session_id | Necessary for the shopping cart functionality on the website. | 1 day | HTTP Cookie | |
| _shopify_d | The cookie is necessary for the secure checkout and payment function on the website. This function is provided by shopify.com. | Session | HTTP Cookie | |
| cart_currency | The cookie is necessary for the secure checkout and payment function on the website. This function is provided by shopify.com. | 13 days | HTTP Cookie | |
| cookietest | This cookie is used to determine if the visitor has accepted the cookie consent box. | Session | HTTP Cookie | |
| pf-analytic-checked | Determines whether the user has accepted the cookie consent box. | Persistent | HTML Local Storage | |
| secure_customer_sig | This cookie is used to store customer credentials securely when processing a purchase on the website - the cookie is essential in making a secure online transaction. | 1 year | HTTP Cookie | |
| shopify_pay_redirect | The cookie is necessary for the secure checkout and payment function on the website. This function is provided by shopify.com. | 1 day | HTTP Cookie |
3.1.2 Third-party cookies
| Cookie Title/ Name of provider | Purpose | Persistence | Management of Cookie | Available External Information |
| _pay_session | This cookie is used in conjunction with the payment window - The cookie is necessary for making secure transactions on the website. | Session | HTTP Cookie | shop.app |
| CONSENT [x2] | Used to detect if the visitor has accepted the marketing category in the cookie banner. This cookie is necessary for GDPR-compliance of the website. | 2 years | HTTP Cookie | Google: https://policies.google.com/privacy |
3.2 CATEGORY 2: FUNCTIONALITY COOKIES (SUCH COOKIES ARE SUBJECT TO YOUR CONSENT)
3.2.1 First-party cookies
| Cookie Title/ Name of provider | Purpose | Persistence | Management of Cookie | Available External Information |
| localization | Holds the users timezone | 13 days | HTTP Cookie |
3.3 CATEGORY 3: PERFORMANCE COOKIES (SUCH COOKIES ARE SUBJECT TO YOUR CONSENT)
3.3.1 First-party cookies
| Cookie Title/ Name of provider | Purpose | Persistence | Management of Cookie | Available External Information |
| _ga | Registers a unique ID that is used to generate statistical data on how the visitor uses the website. | 2 years | HTTP Cookie | |
| _gat | Used by Google Analytics to throttle request rate | 1 day | HTTP Cookie | |
| _gid | Registers a unique ID that is used to generate statistical data on how the visitor uses the website. | 1 day | HTTP Cookie | |
| checkout | Used in connection with checkout. | 4w | ||
| checkout_token | Used in connection with checkout. | 1y | ||
| dynamic_checkout_shown_on_cart | Used in connection with checkout. | 30min | ||
| hide_shopify_pay_for_checkout | Used in connection with checkout. | session | ||
| tracked_start_checkout | This cookie determines how the user accessed the Website. This information is used to determine from which traffic source the user was lead to the Website. | 1 year | ||
| outbrain_cid_fetch | This cookie determines how the user accessed the Website. This information is used to determine from which traffic source the user was lead to the Website. | Only during the Website visiting session |
3.3.2 Third-party cookies
| Cookie Title/ Name of provider | Purpose | Persistence | Management of Cookie | Available External Information |
| datr | Provide fraud prevention. | 2y | Facebook: https://cookiedatabase.org/service/facebook/ | |
| wd | Deliver an optimal experience for your device's screen | 1 week | Facebook: https://cookiedatabase.org/service/facebook/ | |
| dpr | Deliver an optimal experience for your device's screen | 1 week | Facebook: https://cookiedatabase.org/service/facebook/ | |
| presence | Support your use of Messenger chat windows. | session | Facebook: https://cookiedatabase.org/service/facebook/ | |
| locale | Store language settings. | 7 days | Facebook: https://cookiedatabase.org/service/facebook/ |
3.4 Category 4: Marketing Cookies (such cookies are subject to your consent)
3.4.1 First-party cookies
| Cookie Title/ Name of provider | Purpose | Persistence | Management of Cookie | Available External Information |
| _fbp | Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers. | 3 months | HTTP Cookie | |
| _gcl_au | Used by Google AdSense for experimenting with advertisement efficiency across websites using their services. | 3 months | HTTP Cookie | |
| _landing_page | Stores visitors' navigation by registering landing pages - This allows the website to present relevant products and/or measure their advertisement efficiency on other websites. | 13 days | HTTP Cookie | |
| _orig_referrer | This cookie is used to collect information on a visitor. This information will become an ID string with information on a specific visitor – ID information strings can be used to target groups with similar preferences, or can be used by third-party domains or ad-exchanges. | 13 days | HTTP Cookie | |
| _s | Collects data on user behaviour and interaction in order to optimize the website and make advertisement on the website more relevant. | 1 day | HTTP Cookie | |
| _shopify_s | Collects data on user behaviour and interaction in order to optimize the website and make advertisement on the website more relevant. | 1 day | HTTP Cookie | |
| _shopify_sa_p | Collects data on visitors' behaviour and interaction - This is used to make advertisement on the website more relevant. The cookie also allows the website to detect any referrals from other websites. | 1 day | HTTP Cookie | |
| _shopify_sa_t | Collects data on visitors' behaviour and interaction - This is used to make advertisement on the website more relevant. The cookie also allows the website to detect any referrals from other websites. | 1 day | HTTP Cookie | |
| _shopify_y | Collects data on user behaviour and interaction in order to optimize the website and make advertisement on the website more relevant. | 1 year | HTTP Cookie | |
| _y | Collects data on user behaviour and interaction in order to optimize the website and make advertisement on the website more relevant. | 1 year | HTTP Cookie | |
| _uetsid | Collects data on visitor behaviour from multiple websites, in order to present more relevant advertisement - This also allows the website to limit the number of times that they are shown the same advertisement. | 1 day | HTML Local Storage | |
| _uetvid | Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences. | 1 year | HTML Local Storage |
Third-party cookies
| Cookie Title/ Name of provider | Purpose | Persistence | Management of Cookie | Available External Information |
| fr | Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers. | 3 months | HTTP Cookie | Facebook: https://cookiedatabase.org/service/facebook/ |
| IDE | Used by Google DoubleClick to register and report the website user's actions after viewing or clicking one of the advertiser's ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user. | 1 year | HTTP Cookie | Google: https://policies.google.com/privacy |
| test_cookie | Used to check if the user's browser supports cookies. | 1 day | HTTP Cookie | Google: https://policies.google.com/privacy |
| xs | Store a unique session ID. | 3 months | Facebook: https://cookiedatabase.org/service/facebook/ | |
| c_user | store a unique user ID. | 30 days | Facebook: https://cookiedatabase.org/service/facebook/ | |
| sb | store browser details. | 2 years | Facebook: https://cookiedatabase.org/service/facebook/ | |
| 1P_JAR | Provide ad delivery or retargeting | 1 month | Google: https://policies.google.com/privacy | |
| NID | Provide ad delivery or retargeting, store user preferences. | Google: https://policies.google.com/privacy | ||
| DV | Provide ad delivery or retargeting. | Google: https://policies.google.com/privacy |
IV. How to control and delete cookies
V. Changes to this Policy
VI. How to contact us