botTalk

Privacy & data

Privacy Policy – botTalk

Last Updated: August 27, 2026

Effective Date: August 27, 2026

Controller: Giovanni Gutierrez, operating botTalk from Utah, United States

Privacy Contact: support@bot-talk.app

This Privacy Policy explains how Giovanni Gutierrez, operating botTalk from Utah, United States ("botTalk," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal information when you use the botTalk mobile application, websites (including api.bot-talk.app), and related services (collectively, the "Service"). This Privacy Policy is a notice describing our practices; it is not a request for blanket consent to every form of processing described below.

Please review this Privacy Policy before using the Service. If you do not want botTalk to process information necessary to provide the Service, do not create an account or use the applicable feature.

01

Information We Collect

A. Account and information you provide

  • Email address, username, and authentication information. Passwords are protected using one-way hashing on our backend.
  • Support requests and other communications you send us.
  • Optional voice-enrollment information described in Section 6.
  • Subscription or transaction status supplied by Google Play if Google Play billing is enabled. botTalk does not receive or store your full payment-card number. Google Play billing is not enabled as of this Policy's Effective Date; this Policy will be updated before botTalk begins processing Google Play purchase information.

B. Audio, transcripts, and AI requests

Microphone capture begins only when you start a feature that needs it and remains visibly disclosed by Android while background microphone capture is active. The app analyzes short audio frames on your device for voice activity and, if you enabled enrolled-speaker filtering, whether speech matches your enrolled voice profile. Audio that is not selected by this process is not intentionally uploaded for transcription.

Selected speech is encoded as a WAV audio segment and uploaded over HTTPS to botTalk's authenticated backend. The backend holds the segment only while processing the request and forwards it through OpenRouter to the selected speech-recognition provider. The resulting transcript, relevant instructions, and limited recent context are then sent through the same backend and AI gateway to generate the requested suggestion.

botTalk's backend does not create a server-side conversation-history archive from WAV audio, transcripts, prompts, or AI responses. It retains only the limited usage, allowance, accounting, security, and operational records described below. Completed transcript-and-suggestion history is encrypted and stored in the app's private storage on your device. It is not synchronized to your botTalk account or backed up by botTalk.

C. Technical and usage information

We process a pseudonymous installation credential, account identifier, request time and type, selected provider and model, audio duration or token counts, cost and allowance information, active-session information, and limited error, security, and fraud-prevention records. IP addresses may be used temporarily for rate limiting and may appear in limited infrastructure or proxy logs, but ordinary application request logs exclude IP addresses, headers, query strings, authentication information, request bodies, and identifying error details.

The Service does not request precise location. An IP address processed temporarily by network infrastructure may indicate an approximate region. We do not currently include an advertising network or third-party behavioral analytics SDK, and we do not use personal information for cross-context behavioral advertising.

02

Sources of Information

We receive information directly from you, automatically from the app and its backend when you use the Service, from Google Play if billing is enabled, and from service providers involved in authentication, email delivery, hosting, security, transcription, or AI generation. During optional voice enrollment, the speech-recognition service configured on your Android device may process enrollment audio to verify the words you read. Whether that processing occurs on your device or through a network service depends on your device and its settings.

03

How We Use Information

  • Provide voice-activity detection, optional enrolled-speaker filtering, transcription, and AI-generated suggestions requested by you.
  • Create, authenticate, secure, and manage accounts, sessions, and subscriptions.
  • Enforce usage limits and account for provider costs.
  • Operate, secure, troubleshoot, and improve the reliability of the Service without creating a server-side archive of conversation content.
  • Respond to support requests and communicate administrative or security information about the Service.
  • Prevent, investigate, and respond to fraud, abuse, security threats, and violations of our Terms.
  • Comply with legal obligations and establish, exercise, or defend legal claims.

We do not use conversation content or voice profiles for advertising, and we do not sell personal information.

04

How We Disclose Information

We do not sell personal information. We disclose information only as described below:

  • AI processing. OpenRouter and the selected downstream provider receive selected WAV audio when required for transcription. They also receive transcripts, instructions, and limited recent context needed to generate a response. The selected provider or model is displayed through the Service. Provider practices may vary.
  • OpenRouter privacy controls. botTalk configures its OpenRouter requests to deny routing to providers that collect request data for model training or related data-collection purposes. This setting is different from Zero Data Retention. Unless a request is routed to a provider endpoint with a Zero Data Retention policy, a downstream provider may retain request information under its published policy.
  • Device speech recognition. During optional enrollment, the speech-recognition service configured on your Android device may receive enrollment audio to verify the words you read.
  • Operations. Hosting, network, security, support, and email providers process limited information as needed to operate the Service on botTalk's behalf.
  • Payments. If enabled, Google Play processes purchases and provides subscription or transaction status. Google's handling is governed by its own policies.
  • Legal and safety. We may disclose information when reasonably necessary to comply with applicable law or legal process; enforce our agreements; investigate fraud, abuse, or security incidents; or protect botTalk, users, or others.
  • Business transfers. Information may be transferred as part of a merger, financing, reorganization, acquisition, bankruptcy, or sale of assets, subject to applicable law and the protections described in this Policy.

You are responsible for obtaining any legally required consent from another person before intentionally using the Service to capture or process that person's voice or conversation.

05

Optional Voice Enrollment and Biometric Information

Voice enrollment is optional. You may select "Continue without speech enrollment" and still use the Service's main functions. If you enroll, botTalk creates a numeric voice profile used to determine whether detected speech likely matches the enrolled speaker for the optional speaker-filter feature.

The encrypted local copy is stored in app-private storage. An account-linked encrypted copy is stored on botTalk's backend so the profile can be restored for the same account. botTalk does not use the profile to verify a government-issued or civil identity, for advertising, or to train an AI model. Depending on applicable law, the profile may constitute biometric or sensitive personal information, including biometric data used for speaker recognition.

Where processing requires consent, enrollment occurs only after you make the separate choice to enroll. Refusing enrollment does not prevent access to the Service's main functions. You may withdraw consent and stop future use of the profile at any time by deleting the voice profile through the app's privacy or voice settings, or by contacting support@bot-talk.app. Deleting the voice profile disables enrolled-speaker filtering and deletes the account-linked backend profile and local profile, subject to the backup expiration period in Section 7. Withdrawal does not affect processing that was lawful before withdrawal.

Re-enrollment replaces the existing profile. Permanently deleting your account also deletes the account-linked backend profile and instructs the app to delete the local profile.

06

Data Retention

botTalk keeps personal information only for the periods stated below or for the shortest longer period required by applicable law. Automated retention jobs run hourly using bounded deletion batches.

WAV audio, transcripts, prompts, and AI responses. botTalk's backend holds this content only while completing the provider request and does not retain it afterward as server-side conversation history. OpenRouter and downstream providers control their own processing and retention, subject to the privacy controls and provider policies described in Section 5.

On-device conversation history. Encrypted history remains in the app's private storage until you clear it, permanently delete the account through the app, clear app storage, or uninstall the app.

Password reset and verification. Password-reset codes and verification records are deleted within 24 hours after expiration. Password-reset delivery and abuse-prevention records are deleted within 7 days.

Sessions and installation credentials. Active credentials are retained while necessary to authenticate an authorized account or installation. Expired or revoked application sessions are deleted within 30 days after expiration or revocation.

Request reservations and usage records. Abandoned reservations are safely reclaimed after they can no longer represent a live request. Completed request reservations and daily usage or allowance records are ordinarily deleted within 30 days.

Accounting and Premium records. Minimal account-linked accounting records and Premium allowance-period records are deleted within 395 days.

Logs. Ordinary application request logging is disabled. Application request logs exclude request bodies, authentication information, IP addresses, headers, query strings, and identifying error details. IP addresses used for rate limiting are ordinarily held only in memory for the applicable rate-limit window. Infrastructure and proxy logs are retained for no longer than 30 days, and container logs are subject to capped rotation.

Security and fraud records. These records are ordinarily deleted or irreversibly de-identified within 30 days. A hold may preserve only records tied to a specific account, device, or request when reasonably necessary to investigate an active incident. Each hold is reviewed at least every 30 days and ends no later than one year after it begins, unless a separate legal preservation obligation requires otherwise.

Support communications. These are ordinarily deleted within 12 months after the support matter is closed.

Account information and voice profiles. Account information and the server-side voice profile are retained for the lifetime of the account and deleted when the account or voice profile, as applicable, is permanently deleted.

Backups. Backups containing deleted account or voice-profile information expire within 30 days. Deleted information may remain in encrypted backups until expiration but is not restored into active service except when necessary for disaster recovery; if restored, the applicable deletion is re-applied.

Retention-run records. botTalk may retain aggregate records showing that a retention job ran. These records do not contain customer identifiers.

07

Your Rights and Choices

Depending on where you live, applicable law may give you rights concerning personal information. You may submit a request to support@bot-talk.app. We may request information reasonably necessary to verify your identity or authority. Where required, we will respond without undue delay and ordinarily within one month. Rights may be subject to exceptions under applicable law.

  • Access: request confirmation of whether we process your personal information and receive a copy of personal information within the scope of the applicable right.
  • Correction: request correction of inaccurate or incomplete personal information.
  • Erasure or deletion: request deletion where the applicable legal conditions are met. This is sometimes called the right to erasure or right to be forgotten.
  • Restriction: request that certain processing be restricted in circumstances provided by law.
  • Data portability: where applicable, receive personal information you provided to us in a structured, commonly used, machine-readable format and request transmission to another controller where technically feasible.
  • Objection: object to processing based on legitimate interests in circumstances provided by law. botTalk does not use personal information for direct marketing or behavioral advertising.
  • Withdraw consent: withdraw consent at any time for processing based on consent, including optional voice-profile processing, without affecting the lawfulness of earlier processing.
  • Complaint: lodge a complaint with an applicable privacy or data-protection regulator.

Requests may be submitted by email. When portability applies, botTalk will provide eligible server-held data electronically. Conversation history is stored locally on your device and is not available from botTalk's servers. The app may be used to view, clear, or export locally stored history where an export feature is available.

Uninstalling botTalk or clearing app storage permanently deletes local history and the local voice profile. Reinstalling or signing in again cannot restore local history. Uninstalling alone does not delete the online account or backend voice profile.

08

International Processing and Transfers

botTalk is operated from the United States. Information may be processed in the United States and in other countries where OpenRouter, selected downstream AI providers, or operational service providers process information. Those countries may have data-protection laws different from the laws where you live.Where an applicable data-transfer law requires safeguards for a transfer made by botTalk, botTalk will use the verified mechanism identified in this section and will provide information about the applicable safeguard upon request. Provider privacy and retention information for OpenRouter-routed requests is available at:

OpenRouter provider logging and retention directory

09

Children’s Privacy

The Service is not directed to children under 13. Where local law sets a higher age for a child to consent to relevant data processing, the applicable higher age applies. If you are under 18, you represent that you have permission from a parent or guardian where required. We do not knowingly collect personal information from a child in violation of applicable law. If we learn that we have done so, we will delete the information as required.

10

Security

We use reasonable technical and organizational safeguards appropriate to the nature of the information and the risks presented. Network requests use encrypted transport. Local conversation records and the local voice profile are encrypted in app-private storage. Server-side voice profiles are encrypted. Access is limited according to operational need. Retention jobs use bounded, transactional deletion batches, and retention holds are limited and periodically reviewed.

No security measure can guarantee absolute security, and third-party providers remain responsible for their own systems. If a personal-data breach requires notice under applicable law, botTalk will notify the appropriate authority and affected individuals as required.

11

Account and Local-Data Deletion

Clearing history deletes the local conversation history but does not delete the online account. Uninstalling or clearing app storage deletes local data but does not, by itself, delete the online account or server-side voice profile.

You may permanently delete your account through the app or permanently delete your voice profile under Settings → Audio & voice. Deletion removes the encrypted copies and disables speaker filtering. Re-enrollment replaces any existing profile. Successful account deletion via "Delete Account" removes the account profile and account-linked voice profile from active systems controlled by botTalk and instructs the app to delete that account's local history. Limited information may remain temporarily in encrypted backups or be retained where applicable law permits or requires it, subject to Section 7.

12

Changes to This Privacy Policy

The Last Updated date identifies when this text was most recently revised. The Effective Date identifies when this version begins governing the processing described in it; it is the same for the version of the Policy and does not depend on when a particular user downloaded the app or created an account.

We may revise this Policy as the Service or applicable law changes. For new users, the then-current version applies when they begin using the Service. For existing users, material changes will take effect on the stated Effective Date after advance notice through the app or email when required or practicable. If a change requires new consent, botTalk will request that consent instead of treating continued use as consent.

13

Contact Us

Controller: Giovanni Gutierrez, operating botTalk from Utah, United States

Email: support@bot-talk.app

Use this address for privacy questions, access or portability requests, correction requests, deletion requests, objections, restriction requests, or withdrawal of consent.