Privacy Policy
Effective date: . Document version 1.9.1.
Controller: SHCH Studio LTD, company number 17107327, registered in England and Wales. Controller correspondence may be posted to the registered office: 14 Summit Way, London, England, N14 7NL. This launch is an individual-user service. Organisation-controlled personal-data processing is not offered without separately agreed controller/processor roles and data-processing terms.
This Policy covers Verba for macOS and iOS, the keyboard extension, appverba.com, accounts, cloud processing, sync, feedback, and diagnostics.
1. Privacy Summary
- Local content stays on the device for that operation; cloud content leaves the device.
- Verba does not use launch advertising or product-analytics SDKs, sell personal information or User Content, or use it for targeted advertising.
- Diagnostics are off by default and locally time-limited when enabled.
- Verba does not create voiceprints or use recordings to identify or authenticate people.
- Verba makes no solely automated decision about a user with legal or similarly significant effects at launch.
2. Local and Cloud Processing
Local
On supported devices, local rewriting and transcription use models stored on the device. Selected text, audio, transcript, and output are not sent to Verba's cloud AI provider for that local operation. Local files and preferences remain under device and operating-system controls. Non-content requests may still occur for authentication, security, updates, metadata and model downloads.
Cloud
When a user explicitly chooses a cloud feature, Verba sends the information required for that request to its Cloudflare backend and, where needed, xAI. Gemini and Groq are not active production routes. On iOS, the keyboard has no microphone access and sends only text explicitly targeted with a cloud action. The containing app owns foreground recording and can upload audio; only a result, not audio, enters the one-hour keyboard handoff.
3. Information, Purposes, Bases, and Retention
| Information and purpose | UK lawful basis | Retention |
|---|---|---|
| Account email, Clerk/internal IDs, session/app/device metadata and auth events—to create accounts, provide cloud access and prevent takeover. | Contract; legitimate security interests. | Access tokens normally 15 minutes; refresh credentials 30 days. Account records while open. Deletion scrubs active identity, with limited security tombstones/revocation records retained while needed. |
| 18+ confirmation, accepted Terms version, acknowledged Privacy Policy version, server time, platform and app version—to record and enforce the adult-only account boundary, evidence the contract and record that notice links were provided. | Contract; compliance and legal-claim interests. | While the account is open and up to six years after closure where reasonably needed for legal claims. On new sign-up, Clerk also receives the legal-accepted signal and may retain its own timestamp until provider-level deletion. |
| Cloud text input/output—to perform a selected rewrite, Fix, Translate, polish or style request. | Contract. | Default Verba text route does not persist content in D1 after response; content-free usage/audit remains. xAI non-ZDR terms allow up to 30 days plus limited legal/security/safety/abuse exceptions. No ZDR claim. |
| Cloud voice audio, size/duration, transcript, polish, recognition hints, job/provider/error state—to transcribe, deliver and troubleshoot. | Contract; reliability and abuse-prevention interests. | Verba attempts to delete raw audio from Cloudflare R2 as soon as the job completes or fails. Hourly cleanup makes unclaimed uploads deletion-eligible after one hour and final-job audio after 24 hours; failed deletes remain tracked for retry. Verba automatically clears D1 transcript, polish, recognition hints and terminal error content after 24 hours, while retaining a content-free lifecycle row. Separately, xAI may retain received audio/transcript User Content for up to 30 days under its non-ZDR terms. |
| Personal dictionary/supported settings sync. | Contract, initiated by user. | Until overwritten or account deletion. Disabling future sync does not by itself remove the existing server copy. |
| Authenticated style-profile API record: name, tone, preferred terms, custom instructions, default marker and revision. | Contract, initiated by the account holder. | Until overwritten, account deletion or a verified earlier deletion request. The launch UI can load an existing record but has no self-service create or delete controls. |
| Optional Cloud Voice History metadata, excluding audio/transcript/output. | Contract, initiated by user. | User selects 7, 30, 90, or 365 days. Expired rows are removed by hourly cleanup, normally within one hour after expiry; separate deletion is available. |
| Bounded local diagnostics—to inspect/export troubleshooting. | Consent. | Off by default; one hour, or expressly selected enhanced 24 hours. Disabling clears the rolling log; exports stay local unless shared. |
| Feedback message and reviewed attachment—to process the submission, diagnose, secure, and handle complaints. | Requested steps/contract; attachment consent; legitimate security/complaint interests. | While open and then only for follow-up, security/abuse, or legal claims. There is no automatic fixed-period feedback purge; verified deletion triggers manual review. Non-personal ideas or genuinely de-identified learnings may be kept to improve Verba. |
| Usage, content-free audit, hashed rate-limit keys, webhooks and request/security data—to enforce limits and protect reliability. | Legitimate security, fraud-prevention and legal-claim interests. | Rate windows expire with enforcement. Audit/security records normally reviewed after 12 months; longer only for an active incident, dispute, fraud investigation or legal requirement. |
| Legacy licence/billing/tax/fraud records from a separate transaction. | Contract; legal obligation; fraud/legal-claim interests. | Normally the statutory period of six years, longer only for audit, dispute or legal claim. The free account launch starts no paid plan or automatic conversion. |
| Website/API IP, time, URL, user agent, response/security data—to deliver and protect the service. | Legitimate reliable-delivery/security interests. | Cloudflare operational retention and incident criteria. No non-essential Verba analytics or advertising cookies. |
An email/auth credential is required for an account. Cloud content is optional; withholding it only prevents the selected cloud operation. Local features remain available where supported.
4. Sensitive Content
Speech audio is personal information, but Verba does not derive voiceprints. Text/audio can reveal special-category or criminal-offence information. Cloud features are not designed for deliberate submission of that information or another person's confidential data. Do not submit it unless all required authority and lawful grounds exist and Verba has expressly confirmed support; use local processing where available. A future intentional route requires a separate Article 9 mechanism.
5. Sync, iCloud, Models, and Device Storage
- Verba Cloud sync is opt-in and currently stores personal dictionary and supported mobile settings; legacy envelopes may hold older style/profile fields until overwritten/deleted.
- A separate authenticated style-profile API record can contain a name, tone, preferred terms and custom instructions. The launch UI can load an existing record but has no self-service create/delete controls.
- Private iCloud/CloudKit sync is user-enabled in the user's private Apple database. Current Mac exports contain personal dictionary terms; legacy snapshots may hold older fields.
- Local encrypted voice history is off by default and Keychain-backed when enabled.
- Direct model downloads disclose normal network/request data to the model host, but not selected text, audio, transcript, or output.
6. Diagnostics, Cookies, and Communications
Verba does not automatically upload its diagnostic bundle. Users review and export a ZIP and choose whether to send it. The schema excludes selected text/audio/transcripts/outputs/prompts, emails, local paths, keys and tokens.
At launch, appverba.com has no Verba advertising pixels, product analytics or non-essential cookies. Cloudflare and Apple may use necessary storage/request processing under their terms. Future non-essential storage, analytics or marketing requires advance information and choice. Authentication/service messages are not marketing; Verba sends no marketing email at launch.
7. Recipients and International Transfers
Main recipients are Cloudflare for hosting/security, Clerk for authentication, xAI for selected cloud requests, Apple for platform/TestFlight/App Store/iCloud services, and Hugging Face or another named model host for direct downloads. Some act as processors; platform/direct-download services may be independent controllers. Lemon Squeezy and billing adapters are not active for the free account launch.
Providers may process in the United States and other countries they list. Where UK adequacy does not apply, SHCH Studio LTD relies on provider agreement transfer terms such as the UK Addendum to EU SCCs, with the required data-protection test and supplementary measures. The approved production configuration records the actual account, entity, route and retention mode. Requests for a copy of applicable safeguards may be posted to the registered office; no ZDR or certification claim is made.
8. Account Export and Deletion
Verba provides self-service account-data export in the Mac app and self-service account-deletion initiation in the Mac and iOS Account settings. Export and deletion remain available to an authenticated account whose legal-document version is stale, so accepting new Terms is not required for those routes. The export includes the persisted account legal-acceptance record but is not every security/provider record: it omits some session, feedback, webhook, provider and tombstone tables and limits audit history. A broader access request remains available.
Deletion revokes Verba sessions, marks the user deleted, deletes style/sync/cloud-history, scrubs voice content, durably retries R2 and linked Clerk-user deletion, and removes/scrubs active identity. A pending_cleanup response means provider or R2 work remains queued; completion is not claimed until both finish, and a best-effort current-session revoke is not a substitute for provider-user deletion. Limited hashed tombstones and records needed for security, licence continuity, accounting, fraud, disputes and law remain. If an active legacy subscription row exists, automated closure pauses to avoid leaving a provider agreement unmanaged; cancel the legacy subscription through its provider before retrying deletion. Statutory rights requests may still be posted to the registered office.
9. Rights and Objection
Depending on the basis, users may request access/copy, correction, erasure, restriction, portability, withdraw consent, and complain. Rights are not absolute; identity may be verified. We normally respond without undue delay and within one month, with a lawful extension explained.
Send a rights request by post to SHCH Studio LTD at 14 Summit Way, London, England, N14 7NL. There is normally no fee.
Right to object: where we rely on legitimate interests, a user may object. We stop unless compelling grounds override the user's interests/rights/freedoms or legal claims require processing. Direct marketing can always be objected to; Verba conducts none at launch.
10. Data-Protection Complaints
Write to the registered office with “Data protection complaint” clearly marked on the correspondence. We acknowledge within 30 days, investigate without undue delay, provide updates, and communicate the outcome.
Users may also complain to the Information Commissioner's Office: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF; 0303 123 1113; ico.org.uk/make-a-complaint.
11. Children, Security, and Changes
Accounts are for people 18 or over and Verba is not directed to children. Native sign-in captures an 18+ self-attestation, accepted Terms version and acknowledged Privacy Policy version. Production session exchange requires the same evidence and fails closed while enforcement or the approved document configuration is unavailable. If a child supplied information, write to the registered office. Verba uses encrypted transport, Keychain storage, hashed/HMAC credentials and deletion fences, short-lived credentials, scoped access, redacted diagnostics, rate limits and audit controls. No system is completely secure; suspected breaches are assessed and notified where required.
We review this Policy when features, providers, law, or retention change. Material changes receive a new date and reasonable notice. We do not use information for a materially incompatible new purpose without notice and a lawful basis.
Service Provider and Subprocessor Register
Active processors
| Provider | Purpose and information | Transfer/retention |
|---|---|---|
| Cloudflare | Website/Worker, D1, R2 audio, Queues, DNS/CDN and security; hosted account, User Content, voice, sync/history, feedback, usage/audit and request data. | Global network including US. Cloudflare DPA includes UK transfer provisions. Verba periods above apply to controlled content; infrastructure/log terms also apply. |
| Clerk | Email-code auth, email/profile, subject/session identifiers, auth events, revocation and the new-sign-up legal-accepted signal/timestamp. | US and listed subprocessors; Clerk DPA/SCC mechanisms. In-app Verba account deletion durably requests linked Clerk-user deletion; broader verified rights requests use the in-app account-data route or registered-office correspondence. |
| xAI | Selected cloud text, transcription and polish; request content/metadata needed for that operation. | US/locations listed by xAI; xAI DPA. Non-ZDR User Content up to 30 days with narrow exceptions; terms state no foundation-model training. |
User-selected platforms and other recipients
| Provider | Status and exposure |
|---|---|
| Apple | Platform, App Store/TestFlight, optional private iCloud and user-controlled Apple diagnostics under Apple terms. |
| Hugging Face | Direct model downloads expose IP, user agent and model URL, not User Content. |
Standby or not active
Lemon Squeezy, Gemini, Groq, Sentry, Paddle, RevenueCat, and a Verba-owned transactional email provider are not active routes for the free launch. Each requires an advance role/DPA/transfer/retention review plus Terms/Policy/register update before activation.
Provider changes
Before routing personal information to a new/materially changed provider, Verba confirms the production route, role, contract/DPA, retention, security and transfer mechanism; updates this page; tests diagnostics/config; and normally gives 30 days' notice of a disadvantageous change unless urgent legal/security/safety reasons prevent it.