Last updated: August 3, 2026
Input content
VoiceFlow does not write recordings, transcripts, or AI-refined text to its server database. Content exists only while being transmitted and processed for speech recognition and text refinement. Desktop history is stored locally on the user's computer and can be deleted by the user.
Encrypted transport
VoiceFlow Mic audio travels from phone to PC over a local-network TLS connection protected by a pairing code and certificate fingerprint binding. PC traffic to speech recognition and text refinement services uses WSS or HTTPS.
Account and device data
Sign-in processes your username and password. The server stores only an Argon2 password hash, never the plaintext password. The account center displays device name, platform, last-used time, plan status, and Pro selection, and records essential security audit events.
Sessions and security
Web sessions use Secure, HttpOnly, SameSite=Strict cookies valid for up to seven days. Origin checks and CSRF tokens protect changes. Essential network metadata such as IP address may be processed for rate limiting, troubleshooting, and abuse prevention, never advertising profiles.
Trial abuse prevention
To enforce one 30-day Pro trial per device, an irreversible device identifier and first-Pro record remain after a device is deleted from an account. This record is used only for entitlement decisions and duplicate-trial prevention.
Local preferences and inactive features
Language and currency preferences stay in browser local storage. The website has no analytics, advertising cookies, payments, or active support submission. The account center does not collect recordings.
Your controls
You can delete bound devices, change your password, and revoke all sessions from the account center. This policy will be updated before payments or support submissions add new purposes, retention periods, or user rights.