VelvetSpeak

Privacy

VelvetSpeak listens with you during a conversation and helps in the moment. Here is a plain-language overview of what is handled live, what is kept, and what you control. This is a small closed beta, so it's short and specific rather than a legal document.

Last updated: August 5, 2026

What's processed live

Microphone audio, including other people's voices in the conversation, is sent through VelvetSpeak to Deepgram and OpenAI. Those providers transcribe it and help generate the suggestions and debrief you ask VelvetSpeak to produce.

VelvetSpeak uses that content to produce your results and does not sell it. The VelvetSpeak gateway does not intentionally retain raw live audio or conversation text in normal operation.

Provider retention

Processing providers can keep data under their own service settings and terms even when VelvetSpeak does not save another gateway copy. VelvetSpeak currently uses OpenAI Responses without requesting zero application-state retention. OpenAI says API data is not used to train its models unless the customer opts in, while application state and abuse-monitoring logs may be retained for up to 30 days by default. Read OpenAI's API data controls.

Deepgram's retention behavior depends on the active account configuration and service terms. VelvetSpeak is still verifying the closed-beta configuration and will update this page when that check is complete.

What's stored

  • Local conversation data, according to the Memory Capture level you pick: Minimal, Standard, or Full. Higher levels let the app keep more across sessions. Transcripts, notes, and memory are stored on your device; Minimal keeps almost nothing after a session.
  • Content-free usage metering: counts and durations only (how many sessions, how long, which lens). This keeps the beta within its limits. It never includes what was said.
  • Optional session memory sync: when you turn this on, VelvetSpeak stores distilled session summaries for future context, never audio or transcripts. The server text is readable rather than end-to-end encrypted. It keeps at most the newest 100 sessions and nothing older than 12 months; turning sync off deletes the server copy.

Website and API traffic logs

Like most hosted services, VelvetSpeak's website and API create Apache access logs when they receive a request. A log entry can include the request time and path, HTTP status, IP address, browser or app user-agent, and referrer supplied with the request. These logs help operate the service, investigate failures and abuse, and understand overall traffic. They are not used to build advertising profiles.

Production access logs rotate daily and are retained for roughly 14 days. A restricted hourly GoAccess process creates a separate aggregate covering up to the latest 14 dates with traffic for each of the website and API; traffic GoAccess recognizes as crawlers is excluded from those aggregates. To calculate daily visitor occurrences, its restricted private working database keeps a key made from the traffic date, full client IP address, and a hashed user-agent value. That metric sums each daily visitor count, so the same client can be counted again on another date and in both the website and API reports; it is not a count of people, accounts, or devices. Private keys are recycled after they fall outside the latest 14 active traffic dates; with sparse traffic, that can be longer than 14 calendar days.

Before an aggregate is published to the admin dashboard, IP addresses, hashed and raw user-agent values, referrers, query strings, device versions, and unrecognized request paths are removed. The dashboard shows only totals, dates, broad platform families, response-code families, and an allowlist of common routes. GoAccess limits the platform and route inputs to each source's 500 busiest raw labels before those values are grouped, so the dashboard identifies them as bounded observations rather than exhaustive totals. Website and API active-date ranges can differ and are displayed separately. The traffic portion of the dashboard is available only to allowlisted VelvetSpeak admins, is not joined to account records, and does not show individual visitors. Each hourly report replaces the previous report. Because the aggregate is not account-linked, it cannot be deleted by individual account from the dashboard.

Product-use aggregates

The admin dashboard separately calculates a rolling 30-day product-use view from content-free account and live-session records. It uses account IDs, UTC start dates, and the server-attributed session source long enough to count unique eligible testers and distinguish one-day activity from return activity on two or more dates. The signed-in admin, administrator/member profiles, automated runs, admin QA, and sessions without a verified real-user source are excluded.

The rendered view contains aggregate counts and daily totals, not account IDs, emails, audio, transcripts, prompts, or responses. This account-backed product-use view is kept separate from the GoAccess request data above; website requests are never presented as people.

Account, access, and feedback records

The beta service also keeps the records needed to operate access and support:

  • Account email, invite or access-request note and status.
  • Plan, quota, and content-free usage counts and durations.
  • Connected device and access-key metadata, status, and lifecycle timestamps. Raw keys are not shown again after their first display.
  • Feedback you submit, including its free-form wording and contact email.
  • If you subscribe to News, your normalized email address, confirmation timestamps, and a one-time confirmation-token hash. Google Workspace sends the confirmation and update emails from support@velvetspeak.com through the Gmail API over HTTPS; Supabase remains the delivery-list source of truth. No update is sent until you confirm, and every update includes visible and one-click unsubscribe controls that remove the local News subscription record. A temporary per-recipient outbox supports retries and is deleted after a completed post send. Unconfirmed requests expire after 24 hours and their local rows are deleted by a daily cleanup within the following eight days. To limit public-form abuse, the server briefly uses the request IP to derive a secret-keyed in-memory rate-limit value; neither the IP nor that value is written to the subscription database.

Wipe All does not remove these server-side account and access records, submitted feedback, or a separately confirmed News subscription. News subscriptions are removed locally when you use an email or dashboard unsubscribe control; you can also ask support to remove one. A final retention schedule and automated account/feedback deletion flow have not yet been implemented for the closed beta.

Your controls

  • Export: download the locally saved app data on this device as JSON. This is not a complete server-account export.
  • Wipe All: delete wearer knowledge on this device and synced session summaries on the server. Your account, subscription, pairing, basic settings, and local Beta key remain; disconnect or revoke the key separately.
  • Revoke your key: turn off access for a device.
  • Memory Capture: change Minimal / Standard / Full at any time; the new level applies going forward.
  • News updates: use the unsubscribe link in any update, or the News updates control in your dashboard, to stop delivery and remove the local subscription record.

Questions or requests

If you have a privacy question or need help with local data, server account records, or submitted feedback, email support@velvetspeak.com. Server-record export and deletion workflows are not yet automated or finalized; support can answer questions about the records currently kept.