Privacy, in plain language
Your words deserve clear boundaries.
What happens during a session. What stays afterwards. And the choices that belong to you.
Last updated: September 25, 2026 · Closed beta
01 / Processing
Live help uses cloud services.
Audio and context pass through VelvetSpeak and its processing providers.
02 / Retention
Different data, different homes.
Capture settings govern local conversation data; Plans and optional account features have their own storage rules.
03 / Control
You have choices.
Review capture settings, export local data, request deletion and contact support about account records.
What's processed live
Microphone audio, including other people's voices in the conversation, is sent through VelvetSpeak to Deepgram or OpenAI for transcription. Conversation text and relevant saved context are used to generate suggestions and debriefs. With the updated provider disclosure accepted, Google Gemini can generate Short answers, and Exa can process requested search questions. OpenAI can serve as a backup. These providers process requests under their own service policies.
In app 1.3.2, with consent version 17 accepted: When you request web search, or when VelvetSpeak detects a question about a public fact that may have changed (for example a count, a price, a score or a recent event), that question may be sent to Exa or OpenAI to check the answer.
VelvetSpeak uses that content to produce your results and does not sell it. The VelvetSpeak gateway does not intentionally retain raw live audio or conversation text in normal operation.
In app 1.3.0, About me is a short profile you write yourself. It is kept on your phone and sent with your requests to generate suggestions; VelvetSpeak does not save it on our servers. You can edit or clear it anytime in You › About me.
If you have turned Saved context for coaching on under You › Data & privacy and accepted the current consent wording, a small amount of the context VelvetSpeak has already saved for you can be sent with a coaching request as well — when you ask Coach for guidance, and with an automatic hint when Proactive coaching is also on. It is used to produce that coaching and is not stored on our servers. How much can be included follows the Memory Capture level you picked. With the permission off, no saved-memory context is assembled for coaching; manual Guide me still works with permitted current context. In app versions before 0.8.6 this permission was the Coach switch, and the app carries your choice across.
Provider retention
Processing providers can keep data under their own service settings and terms even when VelvetSpeak does not save another gateway copy. Every VelvetSpeak request that carries your conversation to OpenAI sends store: false, so OpenAI does not keep a retrievable copy of that request and response. Being precise about what that does and does not mean: it turns off the stored, retrievable object, but it does not by itself switch off OpenAI's separate default abuse-monitoring logs, which can hold customer content for up to 30 days. OpenAI says API data is not used to train its models unless the customer opts in. Anything beyond that flag depends on account-level controls held in the provider's console rather than in VelvetSpeak's code. Read OpenAI's API data controls.
Deepgram's retention behavior depends on the active account configuration and service terms. VelvetSpeak is still verifying the closed-beta configuration and will update this page when that check is complete.
What's stored
- Plans and question progress: dashboard-authored notes, lines, key facts, and questions are saved in your account until you delete the Plan, with its last 20 versions. In app 0.8.0, manual corrections and automatic after-session assessments sync answer status, timestamps, and a session reference so the phone and dashboard agree. Progress sync does not contain the conversation or supporting excerpts. Supporting evidence passes through existing debrief processing and is retained only in the saved on-device debrief under your capture choices; it is excluded from Session memory and Coach Profile. In app 0.9.0, the next steps, facts and questions you add to a Plan are saved in your account the same way; the conversation itself still is not. Deleting a Plan removes its questions, progress, added items and sources; the app applies that deletion when it next receives it. Plans and progress are readable text, not end-to-end encrypted, and are never sold.
- Notes and documents you add to a Plan: what is saved is the extracted text, not the file, and it is used to prepare facts, next steps and questions for that Plan. Text, Markdown, SRT, pasted text, DOCX and text PDFs are accepted, up to 4 MB. If reviewed résumé preparation is available for your account and you choose Use this résumé, the reviewed text you approve is saved in your account and sent with your live Interview requests to generate answers. You can withdraw that approval or delete the source or Plan to stop future use. Withdrawal removes the reviewed text; it does not delete the original source text or recall text already sent to a provider or answers already displayed or saved on your device. Deleting a source removes its text. With Suggest next steps on — off unless you turn it on — the end-of-conversation review can also propose next steps and questions; those stay on your device until you add them to a Plan.
- Your lenses and your lens list: personal lenses you create, and the list deciding which lenses your phone and glasses show you, are saved in your account so your phone and dashboard agree. Hiding a lens is a display choice, not a delete. The official lenses are the product's and cannot be edited, copied or exported.
- Lenses you publish: publishing submits a lens's recipe and example outputs for review. Once approved, they are visible to every VelvetSpeak member under a display name you choose, and anyone can copy them. Your Plans, notes, People, lines, conversations and account details are never included. You can unpublish at any time; copies others already made stay theirs and keep working. Deleting your account withdraws your listings and removes the recipe text from them.
- Lenses you upvote: you can upvote shared lenses on Explore. Your upvotes are saved in your account so they stay in place on every device you sign in on; other members see only the count, never who voted; deleting your account removes your upvotes. What is stored is which lens you voted for, that it was you, and when — there is no comment, rating or reason column, and nothing resolves a lens back to the members who voted for it.
- Local conversation data, according to the Memory Capture level you pick: Minimal, Standard, or Full. Higher levels let the app keep more across sessions. Transcripts, notes, and memory are stored on your device; Minimal keeps almost nothing after a session. Optional Session memory sync, described below, saves a separate summary in your account.
- Session memory sync, if you turn it on: a summary of new sessions can be saved in your account, including the recap, outcome, commitments, key moments, lesson and captured items. Audio, transcripts and Plan-question evidence are excluded. Older sessions are not backfilled. These summaries are readable text, not end-to-end encrypted; we keep the newest 100 for at most 12 months. Turning sync off requests deletion of the server copies. If deletion cannot be confirmed, the app reports that and retries. This setting is separate from Plan progress sync.
- Content-free usage metering: counts and durations only (how many sessions, how long, which lens). This keeps the beta within its limits. It never includes what was said.
- Content-free reliability events, so we can see that something broke without seeing your conversation: a fixed list of event names, the app version, a stable session or account reference, and a fixed failure code. There are no free-text, transcript, prompt, or answer fields on those records.One exception, and it is deliberately narrow: when the app itself crashes or hits an unexpected error, a short technical error message is attached so the failure can actually be diagnosed. It is trimmed to 240 characters, and known secrets, email addresses, and phone numbers are stripped out before it is saved. Only those two crash events can carry it — every other kind of event rejects it outright.
- Legacy voice profiles. Earlier versions offered optional VoiceLock enrollment to create a server-side recognition profile. The current Beta has no VoiceLock setup or profile-deletion control. If you enrolled in an earlier version, contact support to confirm whether a profile remains and request its deletion; Wipe All is not confirmation that a legacy server profile was removed.
Website and API traffic logs
Like most hosted services, VelvetSpeak's website and API create Apache access logs when they receive a request. A log entry can include the request time and path, HTTP status, IP address, browser or app user-agent, and referrer supplied with the request. These logs help operate the service, investigate failures and abuse, and understand overall traffic. They are not used to build advertising profiles.
Production access logs rotate daily and are retained for roughly 14 days. A restricted hourly GoAccess process creates a separate aggregate covering up to the latest 14 dates with traffic for each of the website and API; traffic GoAccess recognizes as crawlers is excluded from those aggregates. To calculate daily visitor occurrences, its restricted private working database keeps a key made from the traffic date, full client IP address, and a hashed user-agent value. That metric sums each daily visitor count, so the same client can be counted again on another date and in both the website and API reports; it is not a count of people, accounts, or devices. Private keys are recycled after they fall outside the latest 14 active traffic dates; with sparse traffic, that can be longer than 14 calendar days.
Before an aggregate is published to the admin dashboard, IP addresses, hashed and raw user-agent values, referrers, query strings, device versions, and unrecognized request paths are removed. The dashboard shows only totals, dates, broad platform families, response-code families, and an allowlist of common routes. GoAccess limits the platform and route inputs to each source's 500 busiest raw labels before those values are grouped, so the dashboard identifies them as bounded observations rather than exhaustive totals. Website and API active-date ranges can differ and are displayed separately. The dashboard is available only to allowlisted VelvetSpeak admins, is not joined to account records, and does not show individual visitors. Each hourly report replaces the previous report. Because the aggregate is not account-linked, it cannot be deleted by individual account from the dashboard.
Account, access, and feedback records
If you choose Google or Microsoft sign-in, that provider authenticates you and shares your email and basic account identity with Supabase, our account service. Provider metadata can include your name and profile picture. VelvetSpeak does not receive your Google or Microsoft password or request access to your mailbox, contacts, or files.
The beta service also keeps the records needed to operate access and support:
- Account email, invite or access-request note and status.
- Plan, quota, and content-free usage counts and durations.
- Connected device and access-key metadata, status, and lifecycle timestamps, for VelvetSpeak and VelvetLingo. Raw keys are not shown again after their first display.
- Feedback you submit, including its free-form wording and contact email.
To keep our own testing out of product numbers, we may mark an account as internal, test or duplicate. Only VelvetSpeak admins can see this label, and it does not change what the account can do.
After you accept consent version 16 (app 1.3.0), VelvetSpeak saves account-linked, content-free measurements of how you use suggestions, recaps and memory suggestions, your feedback, and delivery timing. Under consent version 15 they cover suggestion use, feedback, and delivery timing only. These can record which answer pages were opened and when the glasses acknowledged a display write; they do not establish that you read or spoke a suggestion. Measurements contain no conversation or suggestion text and remain until account deletion or operator cleanup, with no automatic expiry.
Separately, you can choose to include the exact suggestion and conversation excerpt shown in a support report preview. Only the report's separate, initially unchecked attachment box sends those excerpts to VelvetSpeak support for review. This is an exception to device-only conversation storage, not automatic collection or automatic model training. Report excerpts remain until account deletion or operator cleanup; local Wipe All does not delete them.
In app 1.3.0, with consent version 16 accepted, you can also choose to attach, to a support report, the exact request behind one suggestion — the recent conversation text, the Plan or Scene and settings it used, and what VelvetSpeak showed — so we can replay that moment and fix it. That attachment is a separate box, off by default, shown in full before you send it, kept with your report until account deletion or operator cleanup, and never used automatically for model training.
Wipe All does not remove these server-side account and access records or submitted feedback. During the closed beta, account deletion is an admin-assisted support process, not a self-service control. The reset permanently removes the sign-in identity, beta access, profile, app keys, quotas, connected-device metadata, saved Plans and Coach data, account-linked telemetry, support threads, submitted feedback, and prior beta-request and invite standing. Email addresses in operational sign-in and approval delivery events are anonymized. Content-free reset and audit records retain the former internal account ID, a one-way digest of the former email (not the raw address), and cleanup counts; other account-detached operational totals may also remain.
A newsletter subscription is a separate consent record. Account deletion does not cancel it or remove its email-addressed delivery history. Ask support to handle newsletter records separately if that is also what you want.
VelvetLingo
VelvetLingo is a second app for Even Realities glasses that uses your VelvetSpeak account. Your VelvetSpeak beta access includes VelvetLingo.
While you choose to listen, sound from the glasses microphone is sent through the VelvetLingo service to Deepgram for transcription and to OpenAI for translation and reply ideas. These providers process requests under their own service policies. VelvetLingo saves no transcripts, recordings or conversation history on our servers.
VelvetLingo uses the same account allowance as VelvetSpeak. Each meaning or set of reply choices counts as a suggestion, and listening time counts toward the same minute safeguards. Our VelvetLingo usage records are content-free counts and durations, labelled with the app they came from.
Each app connects with its own key or short code: VelvetSpeak at velvetspeak.com/connect, and VelvetLingo at velvetspeak.com/connect/velvetlingo. "Remove from this phone" clears a saved key from that phone only. To stop a key working, use "Turn off access" on your account's Apps & devices page.
For VelvetLingo keys we also keep when a key was first connected and last used, an optional device name you type, and a history of when codes and keys were created, used or turned off. We also record:
- when a VelvetLingo request was refused or refunded, or a live listening stream stopped early, for example because the shared allowance was used up;
- the number of language-model tokens and the model used for each response;
- the VelvetLingo app version.
None of these records contain what was said.
Your controls
- Export: download the locally saved app data on this device as JSON. This is not a complete server-account export.
- Wipe All: delete local memories, sessions, transcripts, cards, reply preferences, tool history, and phone-created Plans. Website Plans, your account, pairing, and basic settings remain.
- Revoke your key: turn off access for a device.
- Memory Capture: change Minimal / Standard / Full at any time; the new level applies going forward.
Questions or requests
If you have a privacy question or need help with local data, server account records, or submitted feedback, email support@velvetspeak.com. Server-record export is not yet a self-service workflow. Support can answer questions about the records currently kept and can arrange the admin-assisted account reset described above.
The conversation starts with clarity.
Read the beta disclosure for the responsibilities and limitations of using VelvetSpeak with other people.
Read the disclosure