Your information
Privacy policy
Effective · Private preview · Ages 18+
This policy explains what My Voice Agents processes, why it does so, who receives information, and how you can manage it.
Your workspace is stored on your device. Live AI sends context to OpenAI. Before enabling Live AI, you choose whether to permit that sharing. Voice calls also send microphone audio directly to OpenAI. Deleting local content does not automatically erase information already processed by a provider.
1. Who we are and scope
Neu Software LLC, a limited liability company registered in Delaware, United States, operates My Voice Agents. “We,” “us” and “our” mean Neu Software LLC. Where applicable data protection law uses that term, we are the controller of personal information processed for the purposes we determine under this policy.
This policy covers our mobile app, myvoiceagents.app, our API at api.myvoiceagents.app, and support communications. For privacy questions or requests, email tash@neu.ie.
The app is a private preview for approved adults. Cloud account registration, cross-device synchronization, purchased subscriptions and real payment collection are not enabled in this preview. A private connection token is an access credential, not a cloud workspace account.
If you enter a different server URL in Settings, that server's operator can receive your connection token, request content and technical information and may use different models or retention rules. This policy describes our service; it does not establish the practices of an independently operated server or website. Check that operator's terms before connecting. A connection test also sends a network request and any entered connection token to the selected server, although it does not send chat or file context.
2. Information and its sources
Information is supplied by you, selected from your device or a file provider, generated by the AI features you use, or produced by devices and networks when they connect. A document, shared agent or conversation you provide can also contain information about another person.
- Agent and workspace information: agent names, roles, instructions, chosen voices and appearance, favorites, onboarding choices, settings, consent status and preview plan or usage counters.
- Conversation and memory information: typed messages, AI responses, call transcripts, manually added or approved memories, and associated dates, message status and call duration. This can include preferences and personal facts you choose to provide.
- Selected files: images, PDFs, text and other supported documents, including names, types, sizes, contents, local references and any personal information or embedded metadata the selected file contains. File preparation can create extracted text and AI summaries.
- Voice and session information: microphone audio during live calls, spoken AI output, transcripts, typed call messages, connection negotiation information and temporary session credentials.
- Connection and operational information: IP addresses processed to connect and limit abuse, request identifiers, timestamps, request methods, routes, response codes, latency, errors and hosting or network diagnostics. Our server also sends OpenAI a derived safety identifier associated with the private access setup; it does not send the original connection token as that identifier.
- Support and privacy requests: your email address, name if provided, correspondence, optional screenshots or diagnostic details, and information reasonably needed to verify and respond to a request.
We do not require a personal name or email address to create a local agent. We do not purchase consumer profiles or import your address book. If you include sensitive or third-party information in content, it can follow the same processing described here; see section 15.
3. Your device and Demo
The app stores agents, messages, saved memories, file references, extracted text and settings in its application storage. It keeps a current workspace and recovery snapshots to handle interrupted saves. Selected files are copied into an app-managed directory so the agent can use them later. Picker copies and exported files can also exist in device cache.
Your private connection token is stored separately using the operating system's secure storage. Ordinary workspace files are not stored in that credential store. Device encryption, backup, restore, sharing and storage settings can affect local copies. We do not provide a server copy of your workspace for recovery.
Demo text conversations use sample behavior without contacting our model API. Demo calls use the device's text-to-speech service to speak sample or typed-conversation replies; they do not start a live microphone connection to OpenAI. The operating system's speech engine and settings determine its own processing, so Demo speech is not a guarantee of fully offline operation.
Content created in Demo remains available in the workspace. If you later enable Live AI for that agent, relevant earlier messages, memories and files can become part of a live request. Opening an external link, sharing a file or testing a server connection is a separate action that can contact another service even while Demo is selected.
4. Live AI, files and voice
Your permission and live messages
Before enabling Live AI, the app shows a disclosure naming OpenAI and asks you to agree. The app checks that permission before model requests and before accessing the microphone for a live call. You can decline and continue using Demo.
For a live chat, the app sends the agent's instructions, a bounded recent conversation, relevant saved memories when enabled, and selected file context to the configured API. Our API sends the necessary content to OpenAI to produce a response and, when memory is enabled, possible memory suggestions. Replies return to the app and are stored with the local conversation.
Attached files
Attaching a file initially creates a local copy. Sending a live message or starting a live call can send its contents, not just its filename. Chat selects a limited set of attached files using the current message’s words and recency; a new voice call selects up to five of the most recently added files; you do not receive a new file-picker prompt each time those files are reused. Text excerpts, images and PDFs may be included. An image or PDF for a voice call can first be sent through OpenAI's text-and-image processing to prepare a summary, which is then included in the voice session. Such summaries can omit details or contain errors.
Live calls and transcripts
Our API prepares the session context and obtains a short-lived OpenAI session credential. Microphone audio then travels from the device directly to OpenAI over the realtime connection, rather than through our API server. OpenAI also receives connection metadata and messages you type during the call, and returns audio and text. Muting stops the microphone track from sending new speech; ending the call closes the app's connection.
The app processes transcripts during a call even if Save call transcripts is off. That setting controls whether call text is added to your persistent local chat history, including messages typed during the call. It does not disable OpenAI's processing, transcription or applicable retention. A local call-ended entry, date and duration can still be saved.
If agent memory is enabled, the app can send a temporary transcript through our API to OpenAI when a call ends to propose memories, including when transcript saving is off. The app and our API do not intentionally create a permanent raw-audio recording. This does not mean OpenAI retains no audio or other content under its own controls.
5. Memory and personalization
Memory consists of entries you add yourself or explicitly approve. A model suggestion is not a saved memory until you select the save action. The app lets you view, edit and delete entries. Our model instructions and filtering try to keep suggestions grounded in your own words and avoid sensitive information; these measures cannot guarantee that every suggestion is accurate or appropriate.
With memory enabled, saved entries help tailor future responses and may be sent with relevant context. Turning memory off stops inclusion of saved memory entries in future requests and stops new memory suggestions. It does not delete those entries or remove the same facts from instructions, past messages, files or a session that has already received them.
The AI may summarize or draw inferences from content to answer you, and those inferences may be wrong. We do not use this personalization to decide eligibility for employment, credit, housing, insurance or other opportunities with legal or similarly significant effects. The preview does not offer voiceprint authentication or identity matching; the voice feature is used for conversation and transcription.
7. Website, cookies and advertising
Cloudflare serves our website and its assets and provides DNS. Website delivery and security involve technical information such as IP addresses, requested URLs, browser or connection information, timestamps and error or traffic metadata. Cloudflare may make operational traffic information available to us through its service. Its network-error reporting can receive browser reports about failed connections.
Our current website code has no submission form, advertising tags or separately configured product-analytics service. It does not set advertising or analytics cookies or use browser storage for those purposes. The interactive examples stay in the page and do not send your example text to an AI model. Browsers can cache assets, and hosting or security services can use technical mechanisms needed to provide their service; this policy does not promise that every browser or provider is cookie-free.
We do not use advertising SDKs in the app. We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising. Browser signals such as Global Privacy Control do not change these current practices because those activities are not performed. Legacy “Do Not Track” signals likewise do not change the operation of this preview.
8. Recipients and other disclosures
OpenAI
OpenAI receives the content and technical information needed for live AI, including the request context, live voice and transcripts described above. It processes that information to deliver the models and operate and protect its services. Our text, memory-extraction and file-summary requests use store: false.
OpenAI states that API content is not used to train its models by default unless the API customer opts in. Its default abuse-monitoring retention is up to 30 days and can include content; legal or safety exceptions can extend this. Some prompt caching can retain encrypted representations for up to 24 hours, and flagged image or file inputs can be retained for safety review. store: false does not remove all provider retention, and we do not represent this preview as having Zero Data Retention. See OpenAI's API data controls.
Infrastructure providers
Hetzner hosts our API infrastructure. The API receives live request content to perform the requested work; it does not maintain server-side conversation history or a user file library in the current private profile. Network and infrastructure providers necessarily handle traffic and operational information. See Hetzner's privacy information.
Cloudflare delivers our website and DNS, as described above. The API hostname currently uses DNS-only routing: its HTTPS traffic goes directly to our API host, not through Cloudflare's reverse proxy. That distinction does not describe OpenAI's own provider infrastructure. See Cloudflare's privacy policy.
Device services, support and other recipients
Your operating system, chosen speech engine, file provider, backup service, browser, sharing applications and any distribution platform can process information when you use their features. Opening external links is governed by the destination service's practices. These parties do not receive your full workspace from us simply because you install the app.
If you contact us, our email service and people handling the request process the details you send. We may involve a relevant service provider to investigate an issue, using the information needed for that investigation. Avoid sending access tokens, model API keys, government identifiers, private documents or a complete workspace when a brief description will do.
Where reasonably necessary and legally permitted, information may be disclosed to professional advisers or appropriate authorities to comply with binding law or valid legal process, protect rights, investigate abuse, or address security incidents. If the service is involved in a business transfer, information under our control may be disclosed to advisers and an appropriate successor, subject to applicable notice and privacy obligations. This does not authorize unrelated advertising use.
Purchases
Store purchases and RevenueCat are not connected in the current preview. Preview plan choices and usage displays are local app state, not payment transactions. We do not currently collect payment-card details or transmit purchase records to RevenueCat for this preview.
9. Purposes and legal bases
We use the information described above to provide the functions you request, maintain the workspace, deliver live AI with your permission, authenticate private access, keep the service reliable and secure, respond to support and privacy requests, and meet legal obligations. We do not use your conversations to build an advertising profile.
Where EEA or UK data protection law applies, the legal bases for our processing are:
- Your consent: optional Live AI sharing of conversation, file and memory context and microphone audio with OpenAI. You can decline or withdraw through the controls below without losing Demo. Withdrawal does not undo processing that was lawful before it.
- Providing the service you request: processing needed to perform our agreement with you for local agent creation, workspace storage, editing and exports.
- Legitimate interests: technical information needed to deliver the website, authenticate and protect private access, prevent abuse, diagnose faults, and respond to support. The interests are operating a secure, usable service and assisting its users, subject to applicable balancing requirements.
- Legal obligations: information needed to comply with applicable binding law, valid legal process and data-protection requests.
You are not required by law to submit content to the app. Live features need the relevant content, network connection, permission and access credential to work; a voice call also needs microphone permission. A support or privacy request may need enough information for us to understand it and, where necessary, verify the requester. These bases do not mean that any sensitive information is suitable for the preview.
10. Retention and deletion
Your workspace and files
Local information remains until you remove it, reset the workspace or clear the app's device data. You can delete memories, remove files, delete agents or select Settings → Reset this device. A previous recovery snapshot may still contain removed text until a later save overwrites it or a full reset clears the snapshots.
Reset clears managed workspace snapshots, imported agent files and the saved connection token. It cannot erase files you exported, another application's copies, recipient copies, operating-system backups or data already sent to a provider. Picker and export cache files may remain until cache or app data is cleared. Uninstalling and reinstalling can interact with device backup and secure-storage behavior; use the in-app reset before uninstalling when you want to clear managed data. Device or storage failures can prevent a deletion from completing.
Server processing and operational logs
Our private API handles request bodies, attached content, prepared summaries and replies while fulfilling a request, without intentionally persisting them as a conversation database. Request and response buffering to disk is disabled at its reverse proxy. Temporary in-memory processing is not a secure-erasure guarantee.
Routine API application logs contain request identifiers, methods, recognized route names, response status, duration and sanitized failure information. They are configured to exclude content, authorization credentials and query strings. Routine API access logs contain timestamp, method, status and duration, excluding full URLs and client IP addresses. IP addresses are still processed for connections and in-memory request limits. Rare critical web-server errors can produce additional connection or request diagnostics.
API web-server logs rotate daily when nonempty, retaining 14 rotated files plus the active log. Empty files are not rotated, so this is not a guaranteed 14-day maximum age. Container logs rotate across three files of up to 10 MB each; their maximum age depends on volume and is not time-limited by that setting.
Providers, support and legal records
OpenAI retention is described in section 8. Cloudflare, Hetzner, device services and other recipients apply their relevant operational, security and legal retention practices. We do not promise one common retention period across them.
We keep support and rights-request correspondence for as long as reasonably needed to resolve the request, handle related follow-up, document our response, address disputes or satisfy applicable legal obligations. The criteria include the issue's status, sensitivity, continuing security needs and any applicable recordkeeping requirement. Information retained for a legal obligation or dispute is limited to that purpose.
Deleting a local conversation does not automatically submit a deletion request to OpenAI or other recipients. Contact us about information under our control or requests involving our providers. We will explain applicable exceptions and what we can identify; we cannot search or restore your local-only workspace from our server.
11. Your controls
- Stop Live AI sharing: choose Demo in Settings and save. This withdraws the app's Live AI permission and ends an active call without requesting new memories. Requests already sent may complete or remain in provider records.
- Control the microphone: mute or end a call, or change microphone permission in device settings. Denying the microphone prevents live voice calls; it does not prevent text chat.
- Control memory: view, edit, delete or disable an agent's saved memory. The same information can remain in instructions, files or chat history. Edit the instructions or remove the file as needed; deleting the agent or resetting the workspace clears its managed conversation history.
- Control transcripts: use Save call transcripts to choose whether call text is stored in local chat. Turn off agent memory as well if you do not want a call-end transcript sent for memory suggestions.
- Control file context: choose only files you want an agent to use and remove attachments before later live requests. Adjust photo or document access through the operating system where available.
- Copy or clear local data: use transcript, agent and file exports or the local deletion and reset controls. Exported agent definitions do not include the full workspace.
Changes to stored content cannot retract data already supplied to a live session. End that session before changing context you want excluded from the next one. Contact us if you cannot use a control or need an accessible way to make a request.
12. Security
The hosted website and API use HTTPS. Live audio uses an encrypted realtime transport. Private model endpoints require a connection token, model API credentials remain on the server, and request limits and sanitized logging reduce unnecessary exposure. The app stores its connection token in operating-system secure storage.
The API and AI provider must be able to process the content sent to them. This is not end-to-end encryption that prevents those services from accessing it. Ordinary local workspace files rely on device and application-storage protections; the app does not put them all in its secure credential store. No network, device or service can be guaranteed completely secure.
Protect your device and access token, review the server URL before connecting, and avoid sharing credentials in messages or support requests. If you suspect unauthorized access or a security incident, contact tash@neu.ie with a brief description. We will handle any applicable notification obligations under the law that applies.
13. International processing
Neu Software LLC is registered in the United States. Our infrastructure and AI providers operate internationally, and information can be processed in the United States and other countries outside your own. Those countries may have different privacy laws.
The location of an API server does not determine where all OpenAI, Cloudflare, support or device-provider processing occurs. The preview does not promise that information stays in a particular country or region. For information about relevant processing locations, the transfer arrangements applicable to your information, or access to any applicable transfer safeguards, contact us using the details below.
14. Privacy rights and requests
How to contact us
Email tash@neu.ie and describe the information and action involved. You can use the subject “Privacy request,” but no special wording is required. Include your country or state if useful for identifying applicable rights. Do not send a password, connection token or complete identity document with an initial request.
Rights vary with applicable law and our role. We may need proportionate verification before disclosing, changing or deleting information. We will request only what is reasonably needed and use verification information for that process. We will explain any refusal, limitation or permitted extension and respond within the period required by applicable law. Requests are normally free, subject to exceptions permitted by that law.
We cannot remotely access a local workspace that has not been sent to us. We can guide you through local controls and address information we or our providers can identify. Please do not send additional private content solely to establish that a local file exists.
EEA and United Kingdom
Where applicable, you may request access to personal data, correction, erasure, restriction and a portable copy. You may withdraw consent at any time. These rights have conditions and exceptions; for example, erasure can be limited by a legal obligation to retain a record.
Your right to object: you may object to processing based on legitimate interests for reasons relating to your circumstances. We will assess the objection as required by applicable law. You may object to direct marketing at any time; we do not currently use your data for that purpose.
You may complain to a competent data protection authority, including where you live or work or where an alleged infringement occurred. See the EEA supervisory-authority directory and the UK Information Commissioner's Office. Contacting us first is welcome but does not remove your complaint rights.
United States state privacy laws
Where a state law applies, rights may include confirming processing; accessing categories or specific pieces of personal information; correcting inaccuracies; deleting information; obtaining a portable copy; and learning about sources, purposes and categories of recipients. Some states also provide access to a list of specific third-party recipients or categories of such recipients.
Applicable laws may provide rights to opt out of sale, sharing for cross-context behavioral advertising, targeted advertising or profiling used for legal or similarly significant decisions, and to limit certain uses of sensitive information. We do not carry out those sale, advertising or significant-decision profiling activities. We use sensitive information supplied in content for the requested function and applicable operational or legal purposes, not advertising. You may still contact us to exercise any right that applies.
We will not unlawfully discriminate or retaliate against you for exercising privacy rights. A feature may nevertheless be unavailable where the information or permission you choose not to provide is necessary for that feature.
Authorized agents and appeals
Where applicable, an authorized agent can submit a request for you. We may ask for evidence of authority and verify your identity directly where the law permits, without imposing requirements on opt-out requests that the law prohibits.
If we decline a request and an appeal right applies, reply to our decision or email tash@neu.ie with “Privacy appeal,” identifying the decision and why you want it reviewed. We will review the appeal and provide a written explanation within the applicable deadline. If an appeal is denied, you can contact your state attorney general or other regulator, and we will provide the complaint information required by law. General information is available from the California Attorney General and in the Delaware Personal Data Privacy Act.
15. Children and sensitive information
The private preview is intended for people aged 18 and over. It is not directed to children, and we do not knowingly invite children to provide personal information. If you believe a child has provided information to us, contact tash@neu.ie so we can investigate and take appropriate steps, including deletion where required.
Do not use the preview to submit passwords, financial account credentials, government identifiers, medical records or other highly sensitive information. It is not designed as a confidential clinical record system. Sensitive information can also include racial or ethnic origin, religious beliefs, sexuality, genetic information and other categories protected by local law.
If you place that information in a message, memory, document or image, it may be processed as part of your chosen live request. A warning or automated filter cannot guarantee its removal before processing. General Live AI permission should not be treated as permission from another person or as authorization to process every category of protected data. Only provide information about others when you have the necessary permission or other lawful authority.
16. Updates and contact
We may update this policy to reflect changes to our practices, technology or legal obligations. We will revise the effective date and provide additional notice or seek new permission when required for a material change. The app's sharing disclosures and privacy controls apply alongside this policy.
Neu Software LLC
Registered in Delaware, United States.
Privacy and support: tash@neu.ie
More help: Support