VelvetSpeak

Privacy

VelvetSpeak listens with you during a conversation and helps in the moment. Here is a plain-language overview of what is handled live, what is kept, and what you control. This is a small closed beta, so it's short and specific rather than a legal document.

Last updated: August 22, 2026

What's processed live

Microphone audio, including other people's voices in the conversation, is sent through VelvetSpeak to Deepgram and OpenAI. Those providers transcribe it and help generate the suggestions and debrief you ask VelvetSpeak to produce.

VelvetSpeak uses that content to produce your results and does not sell it. The VelvetSpeak gateway does not intentionally retain raw live audio or conversation text in normal operation.

If you have turned coaching on and accepted the current consent wording, a small amount of the context VelvetSpeak has already saved for you can be sent with a live coaching request as well. It is used to produce that coaching and is not stored on our servers. How much can be included follows the Memory Capture level you picked, and with coaching off nothing is assembled or sent.

Provider retention

Processing providers can keep data under their own service settings and terms even when VelvetSpeak does not save another gateway copy. Every VelvetSpeak request that carries your conversation to OpenAI sends store: false, so OpenAI does not keep a retrievable copy of that request and response. Being precise about what that does and does not mean: it turns off the stored, retrievable object, but it does not by itself switch off OpenAI's separate default abuse-monitoring logs, which can hold customer content for up to 30 days. OpenAI says API data is not used to train its models unless the customer opts in. Anything beyond that flag depends on account-level controls held in the provider's console rather than in VelvetSpeak's code. Read OpenAI's API data controls.

Deepgram's retention behavior depends on the active account configuration and service terms. VelvetSpeak is still verifying the closed-beta configuration and will update this page when that check is complete.

What's stored

  • Local conversation data, according to the Memory Capture level you pick: Minimal, Standard, or Full. Higher levels let the app keep more across sessions. Transcripts, notes, and memory are stored on your device; Minimal keeps almost nothing after a session.
  • Content-free usage metering: counts and durations only (how many sessions, how long, which lens). This keeps the beta within its limits. It never includes what was said.
  • Content-free reliability events, so we can see that something broke without seeing your conversation: a fixed list of event names, the app version, a stable session or account reference, and a fixed failure code. There are no free-text, transcript, prompt, or answer fields on those records.One exception, and it is deliberately narrow: when the app itself crashes or hits an unexpected error, a short technical error message is attached so the failure can actually be diagnosed. It is trimmed to 240 characters, and known secrets, email addresses, and phone numbers are stripped out before it is saved. Only those two crash events can carry it — every other kind of event rejects it outright.
  • A VoiceLock profile, only if you set it up. VoiceLock uses three short samples of your voice to create a server-side recognition profile. The raw enrollment and verification audio is temporary and is not retained by VelvetSpeak. You can delete the profile from Settings → Sound or with Wipe All.

Website and API traffic logs

Like most hosted services, VelvetSpeak's website and API create Apache access logs when they receive a request. A log entry can include the request time and path, HTTP status, IP address, browser or app user-agent, and referrer supplied with the request. These logs help operate the service, investigate failures and abuse, and understand overall traffic. They are not used to build advertising profiles.

Production access logs rotate daily and are retained for roughly 14 days. A restricted hourly GoAccess process creates a separate aggregate covering up to the latest 14 dates with traffic for each of the website and API; traffic GoAccess recognizes as crawlers is excluded from those aggregates. To calculate daily visitor occurrences, its restricted private working database keeps a key made from the traffic date, full client IP address, and a hashed user-agent value. That metric sums each daily visitor count, so the same client can be counted again on another date and in both the website and API reports; it is not a count of people, accounts, or devices. Private keys are recycled after they fall outside the latest 14 active traffic dates; with sparse traffic, that can be longer than 14 calendar days.

Before an aggregate is published to the admin dashboard, IP addresses, hashed and raw user-agent values, referrers, query strings, device versions, and unrecognized request paths are removed. The dashboard shows only totals, dates, broad platform families, response-code families, and an allowlist of common routes. GoAccess limits the platform and route inputs to each source's 500 busiest raw labels before those values are grouped, so the dashboard identifies them as bounded observations rather than exhaustive totals. Website and API active-date ranges can differ and are displayed separately. The dashboard is available only to allowlisted VelvetSpeak admins, is not joined to account records, and does not show individual visitors. Each hourly report replaces the previous report. Because the aggregate is not account-linked, it cannot be deleted by individual account from the dashboard.

Account, access, and feedback records

The beta service also keeps the records needed to operate access and support:

  • Account email, invite or access-request note and status.
  • Plan, quota, and content-free usage counts and durations.
  • Connected device and access-key metadata, status, and lifecycle timestamps. Raw keys are not shown again after their first display.
  • Feedback you submit, including its free-form wording and contact email.

Wipe All does not remove these server-side account and access records or submitted feedback. A final retention schedule and automated account/feedback deletion flow have not yet been implemented for the closed beta.

Your controls

  • Export: download the locally saved app data on this device as JSON. This is not a complete server-account export.
  • Wipe All: delete local memories, sessions, transcripts, cards, reply preferences, tool history, saved Scenes, and VoiceLock profiles. Your account, pairing, and basic settings remain.
  • Revoke your key: turn off access for a device.
  • Memory Capture: change Minimal / Standard / Full at any time; the new level applies going forward.

Questions or requests

If you have a privacy question or need help with local data, server account records, or submitted feedback, email support@velvetspeak.com. Server-record export and deletion workflows are not yet automated or finalized; support can answer questions about the records currently kept.