Privacy Policy

This policy explains what data VoiceWink processes, where it goes, and what rights you have. It is provided in compliance with the EU General Data Protection Regulation (Regulation 2016/679) and Belgian implementing law of 30 July 2018 concerning the protection of natural persons with regard to the processing of personal data.

1. Data controller

Dieter Verlaeckt, trading as DV Studio · Haverlaan 28, 2500 Lier · Belgium

Enterprise number (KBO/BCE): BE 1037.153.197

Contact: support@dvstudio.app

Privacy questions go to the contact address above.

2. What VoiceWink and third parties process — and where

At a glance — what leaves your device. VoiceWink is local-first: by default almost nothing leaves your device, and the app never sends your audio or transcripts to DV Studio. (What you choose to attach to a support email yourself is the one exception — see Section 7.)

Where a third party processes data for its own purposes — such as Lemon Squeezy's checkout and billing as merchant of record, or a cloud provider you enable under your own account and API key — that processing is carried out under the responsibility of that third party, not DV Studio (see Section 3). For the processing this policy attributes to DV Studio — the license-validation calls, opt-in crash reporting, the update check, the speech-model download, support correspondence, and the websites — DV Studio is the controller (see Sections 3, 5, 6 and 7).

The only data that leaves your device is:

Everything not in this list — your recordings, transcripts, settings, dictionary, API keys, reference images, and generated images — stays on your device under %LOCALAPPDATA%/VoiceWink.

VoiceWink runs locally on your Windows device. The categories of data it handles are:

Local data does not leave your device unless you enable a third-party cloud feature at your own risk and under your own responsibility — except for three automatic network calls: license validation to Lemon Squeezy (Section 3 Category A, required to keep your activation valid), the update check to Cloudflare (Section 4, which you can turn off at any time in the app), and the speech-model download from models.voicewink.app, also served by Cloudflare — or, only if that endpoint cannot deliver the file correctly, from Hugging Face (next paragraph; only when a selected model is not yet on your device).

Local speech-model downloads. Local transcription uses locally stored speech-model files. When the model you selected in the app is not yet on your device, VoiceWink downloads the model's files over an encrypted connection from models.voicewink.app, DV Studio's model-download endpoint. Cloudflare hosts those files on its R2 object storage and serves them via its global edge network on DV Studio's behalf (Section 3, Category A — the same processor that operates the update endpoint in Section 4). Each request discloses your IP address, standard HTTP request metadata, and the name of the requested file — never audio, transcripts, or keys. Only if models.voicewink.app cannot deliver the file correctly — it is unreachable, or what it serves fails the integrity check — does VoiceWink automatically retry the download from Hugging Face (huggingface.co), the public repository the files are mirrored from; such a fallback request discloses the same data categories, and Hugging Face processes it under its own privacy policy, for which DV Studio bears no responsibility whatsoever. The downloaded files are stored locally under %LOCALAPPDATA%/VoiceWink/Models and each file's integrity is verified after download.

Special-category data. VoiceWink does not use your voice to identify you — it transcribes speech to text and creates no voiceprint — so it does not process biometric data for the purpose of identification under Article 9 GDPR. We do not intentionally collect special-category data (such as data revealing health, religion, or political opinions). Because you control what you dictate, your audio or transcripts could incidentally contain such content; that content is processed locally on your device, or — if you enable a cloud feature — sent only to the third-party provider you selected under your own account, and DV Studio neither receives nor stores it. The selected third-party provider processes personal data under its own privacy policy for which DV Studio bears no responsibility whatsoever.

Data from third parties. The one third-party source we receive personal data from is Lemon Squeezy: when you buy or activate a key, Lemon Squeezy makes the order and license data available to DV Studio (buyer name, email address, country, order history, and issued license keys — card and payment data stay with Lemon Squeezy and Stripe; see Sections 3 and 5). Beyond that, the only data we hold is what your device sends as described in this policy, or what you send us directly (for example, by email).

3. Third parties involved when you enable cloud features

VoiceWink integrates with three categories of third parties. The category determines who is responsible for the data and what contractual instruments apply.

Category A — third-party providers that interact with VoiceWink

For the four processing operations in this category — license validation, opt-in crash reporting, the update check, and the speech-model download — DV Studio determines the purposes and means and is the controller; the providers process the data to deliver their service to DV Studio. The speech-model download's fallback is the one exception to that provider framing: where that download falls back to Hugging Face because DV Studio's endpoint cannot deliver the file correctly, Hugging Face acts as an independent third party under its own privacy policy — not as a Category A provider — as described in the model-download paragraph in Section 2. Where a provider additionally processes data for its own purposes — most notably Lemon Squeezy as merchant of record for its checkout, billing, tax, and fraud-prevention obligations — it does so under its own privacy policy and its own responsibility. DV Studio does not bear any responsibility with regard to the latter processing activities.

Automatic license-validation egress. To enforce per-license activation limits, VoiceWink contacts Lemon Squeezy automatically in three situations, independent of the cloud-feature toggles in Categories B and C:

The instance name is a random device label, not your hostname or any other personal identifier, so these calls do not transmit information that identifies you personally beyond the license key itself. The license key and instance identifier leave your device only via these license-validation calls and are held by Lemon Squeezy under its merchant-of-record retention policy. Legal basis: performance of a contract (Article 6(1)(b) GDPR) — without these calls the paid license cannot be enforced. For the processing Lemon Squeezy performs for its own purposes as merchant of record — its checkout, billing, tax, fraud-prevention, and retention obligations — DV Studio does not bear any responsibility; that processing is governed by Lemon Squeezy's own privacy policy.

International transfers (Category A). Some Category A providers process personal data outside the European Economic Area (EEA), mainly in the United States. Those transfers are protected by European Commission–approved safeguards: certification under the EU–US Data Privacy Framework (DPF) where the provider holds it, and in any event the Commission's Standard Contractual Clauses (SCCs) incorporated in the provider's data-processing terms. Sentry ingests and stores crash reports in its EU (Frankfurt) region; to the extent Sentry, as a US-headquartered provider, accesses that data from outside the EEA, the same safeguards apply. You can request a copy of, or details about, the safeguards applying to a specific provider by writing to the contact in Section 1.

Category B — Bring-your-own-key (BYOK) cloud providers you select per session

These providers are reachable from VoiceWink only if you supply your own API key and you choose which provider to use for a given feature. DV Studio chose the integration list and the request shape, but every actual data transfer happens under your account at the provider you have chosen, governed by your own terms with that provider. DV Studio bears no responsibility whatsoever.

When you use a category-B feature, the audio or text needed for that feature is sent over an encrypted connection from your device directly to the provider you selected. Your API key for that provider is transmitted with the request — to that provider only, to authenticate it — and is never sent to DV Studio. Each provider operates under its own privacy policy for which DV Studio bears no responsibility whatsoever. Most operate outside the EU (United States); transfers are governed by your terms with the provider, including any standard contractual clauses or equivalent safeguards.

Dictionary and trigger words. Where the provider supports it, VoiceWink also sends the words from your custom Dictionary, and your prompt trigger words, with each transcription request so that the provider recognizes them more reliably. This applies to Deepgram, ElevenLabs and OpenAI (the latter only on models that accept the field), each behind its own toggle on the Models page. These words are your own content and often proper names; they go only to the provider you selected, under the same BYOK framing as the audio itself, and never to DV Studio.

Category C — User-supplied endpoints

VoiceWink supports configuring a custom OpenAI-compatible base URL — for example a self-hosted Ollama server, a private gateway, or any other endpoint that speaks the OpenAI Chat Completions API. When you point VoiceWink at such an endpoint, DV Studio has neither a relationship with the operator of that endpoint nor knowledge of where the data ultimately lands. The endpoint is fully under your control and your responsibility.

If you do not enable any cloud feature

No audio, text, or transcribed content leaves your device — with three automatic exceptions: the license-validation egress to third-party Lemon Squeezy in Section 3 Category A (cannot be disabled while a paid license is active; required for the license to remain valid), the update-check egress in Section 4 (which you can turn off at any time in the app), and the speech-model download described in Section 2 (which happens only when a local model you selected is missing). None of the three ever carries audio, text, or transcribed content.

4. Automatic update check

VoiceWink contacts updates.voicewink.app to check whether a newer version of the Software is available. By default this check fires shortly after the application starts and then repeats approximately every 24 hours while the application is running. When the automatic-installation setting is on (the default), an update found by the check may be downloaded and installed automatically; the download reveals the same data categories as the check itself (IP address, User-Agent, channel, version — nothing new). You can turn off automatic update checking and automatic update installation at any time in the app.

4.1 What is sent

Each update check is a single HTTPS GET to https://updates.voicewink.app/<channel>/releases.<channel>.json. The request carries:

No transcribed text, audio, API keys, license keys, or local identifiers other than the four items above are sent.

4.2 Who receives it

The endpoint is served by Cloudflare from a Cloudflare R2 bucket controlled by DV Studio. Cloudflare's default request logs (which may include source IP, timestamp, request path, and basic HTTP metadata) are governed by Cloudflare's privacy policy and retained per Cloudflare's defaults. DV Studio does not independently log update requests for analytics purposes; the manifest is a static object served by R2.

4.3 Legal basis

Update checking relies on Article 6(1)(b) and (f) GDPR — performance of the contract, because the updates it finds are included with your activation key (see the EULA, section 12.2), and legitimate interests, balancing your interest in receiving security and bug-fix updates against the minimal data collected. The data minimization is structural: no app-level analytics, no separately-retained logs, and the user-facing automatic-update-check setting is honored before the network call is made.

4.4 Your control

The app provides a setting that turns automatic update checking off; when it is off, the automatic check never fires. That choice is offered during first-run setup, and both automatic update checking and automatic update installation can be turned off at any time. A manual check remains available and works as a one-shot request — using it is itself a deliberate, user-initiated request for that single check.

5. Website visitors

This section covers visits to the product website at voicewink.app and to the publisher website at dvstudio.app. Both are served on the same hosting described below; dvstudio.app is a small publisher page that links to voicewink.app rather than redirecting to it. The rest of this policy describes the VoiceWink application itself.

6. Legal bases

We rely on the following legal bases under Article 6 GDPR:

You can withdraw consent at any time by turning the relevant feature off in the app.

We do not sell or share your personal information, and we do not use it for advertising or behavioral profiling.

7. Retention

Local data (transcripts, settings, history) remains on your device until you delete it. Uninstalling the Software leaves your local data in place by default. You can remove it at any time with the data-management controls inside the app (see section 9), or by deleting the %LOCALAPPDATA%/VoiceWink folder.

The local items with their own shorter lifetimes are: a recording kept after a failed transcription, or after VoiceWink detected no speech in it (both removed when you retry, start a new recording, or close the app, with a 7-day sweep as backstop); recordings kept by the keep-recordings debugging option, unsent problem-report bundles, and prompt-trace logs (all swept after 7 days); and reference-image copies (kept while any History entry references them, then erased with the last of those entries). The memory-only capture buffer described in Section 2 is never written to disk at all.

Cloud-provider retention follows each provider's policy. Most providers offer zero-retention or short-retention modes; we encourage you to review the privacy policy of each provider you enable.

Lemon Squeezy and Stripe retain billing records as required by financial-services law.

Sentry retains crash reports for up to 90 days by default.

Cloudflare's logs for the update and speech-model endpoints follow Cloudflare's standard retention; DV Studio does not separately retain update-check or model-download records. A fallback model-download request to Hugging Face is governed by Hugging Face's own privacy policy (Section 2).

Support correspondence. Email exchanged with support@dvstudio.app (including any logs, screenshots, or diagnostic bundles you choose to attach) is retained for 90 days by default after the conversation has closed, and longer only where the exchange relates to an open support ticket, a billing dispute, a security incident, or a legal/regulatory inquiry that requires us to keep the record. We will delete or anonymize support correspondence on request via the rights process in section 9.

A report you build with "Report a problem" is prepared locally and attached to an email you send from your own mail client — the app never transmits it. By default the report is redacted: API keys and license keys are removed, and prompt content appears only as summaries with the text replaced by its length. The dialog additionally offers, each behind its own checkbox and advisory, raw prompt logs (your dictated text and AI prompts and results verbatim, including any Dictionary words) and your audio recordings. Both are your own content, included only by your explicit choice for that one report. Standard application logs can also contain provider response content.

8. How we protect your data

We apply technical and organizational measures appropriate to the risk (Article 32 GDPR):

9. Your rights

Under Articles 15 to 22 GDPR you may:

You can exercise local-data rights directly inside the app: its settings include data-management controls that let you export your data (a portable copy of your settings, history, vocabulary, and word replacements), delete your history, or delete all app data. For anything the in-app controls do not cover — including data held by DV Studio, such as support correspondence — contact us at support@dvstudio.app and we will action your request. We aim to respond within one month, as required by Article 12 GDPR; if a request is particularly complex we may extend this and will tell you why.

We do not carry out automated decision-making that produces legal or similarly significant effects concerning you (Article 22 GDPR). The fraud-prevention measures attached to license activation are rule-based limits on activation counts, not automated profiling.

You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données):

Address: Drukpersstraat 35, 1000 Brussels

Email: contact(at)apd-gba.be

Telephone number: +32 (0)2 274 48 00

www.gegevensbeschermingsautoriteit.be

10. Changes to this policy

When this policy changes you will be asked to review and accept the new version before continuing to use the Software. Past acceptances are recorded as content hashes locally so the in-app gate can detect when an update needs your attention.