VoxSpace Privacy Policy
Last updated: July 28, 2026
VoxSpace is the iOS client for the self-hosted VoxSpace
server. The architecture is deliberately simple about privacy: your audio and
derived content go to the server instance you choose — run by
you or your organization — not to any third-party cloud operated by the app
developer.
1. What the app collects
- Account metadata — your user id, email address, display
name, and workspace, returned by your server at sign-in to present your
account. Linked to you, used only for app functionality.
- Device name — sent to your server once during device
binding to label the device. Linked to your device, used only for app
functionality.
- Device key material — a P-256 public key and its
thumbprint used for request signing (DPoP). The private key never leaves the
device and is stored in the iOS Keychain, this-device-only.
- Audio data — microphone recordings you make and audio or
video files you import, uploaded to the server instance you selected.
- Derived content — transcripts and AI summaries produced
by your server from that media.
- Limited client telemetry — compact operational events
(for example upload failures and recovery statistics) used to keep the app
reliable, sent only to your server.
2. What the app does not do
- No third-party analytics or advertising SDKs.
- No tracking, no ad targeting, no sale or sharing of your data with third parties.
- The camera is used on-device only for scanning enrollment QR codes; no frames are collected or transmitted.
- No data is sent to any server other than the VoxSpace instance you enroll with.
3. How data is protected
- All traffic uses TLS; requests are signed with short-lived ES256 proofs. The app stores no cookies and keeps no caches.
- On-device data is protected by iOS Data Protection; signing keys are Keychain-resident and never exported.
- Local recordings, imports, and snapshots live in the app's protected storage and are excluded from backups.
4. Retention and deletion
Content uploaded to your server is retained according to that server's
policies, which your administrator controls. In the app you can delete
recordings and sessions, and deletion removes both the local copy and the
server copy through the same interface. Client telemetry is retained only in
memory and in short batches pending upload.
5. Background features
Live Activities, background uploads, and share-extension imports are
processed locally on your device. If push notifications are enabled in a
future release, they are delivered by Apple Push Notification service with no
message content shared beyond what is required for delivery.
6. International transfer
Because VoxSpace is self-hosted, where your data goes depends entirely on
where your server instance runs. The app itself transfers nothing to any
other jurisdiction.
7. Children
The app is not directed at children and does not knowingly collect data
from children.
8. Changes and contact
This policy may be updated with the app; material changes are noted in the
release notes. Questions: contact your server administrator or the project at
the support link on our App Store page.
VoxSpace 隐私政策
最后更新:2026 年 7 月 28 日
VoxSpace 是自托管 VoxSpace 服务器的 iOS 客户端。它在隐私上的架构原则非常简单:你的音频与衍生内容只发往你自己选择的服务器实例(由你或你的组织运行),而不是任何由应用开发者运营的第三方云。
1. 应用收集什么
- 账户元数据——登录时由你的服务器返回的用户 ID、邮箱、显示名与工作区,仅用于呈现你的账户,与你关联,仅用于应用功能。
- 设备名称——设备绑定时发送一次,用于在服务器上标识该设备,与设备关联,仅用于应用功能。
- 设备密钥材料——用于请求签名(DPoP)的 P-256 公钥及其指纹。私钥永不离开设备,存放于 iOS 钥匙串且仅限本机。
- 音频数据——你录制的麦克风音频,以及你导入的音视频文件,会上传到你选择的服务器实例。
- 衍生内容——由你的服务器基于这些媒体生成的转写与 AI 总结。
- 有限的客户端遥测——用于保障应用可靠性的简明运行事件(例如上传失败与恢复统计),仅发送到你的服务器。
2. 应用不做什么
- 不含任何第三方分析或广告 SDK。
- 不追踪、不做广告定向、不出售或与第三方共享你的数据。
- 相机仅在本机用于扫描绑定二维码;不收集、不传输任何画面。
- 不向你绑定实例以外的任何服务器发送数据。
3. 数据如何被保护
- 全部流量使用 TLS;请求使用短生命周期 ES256 证明签名。应用不保存 Cookie、不保留缓存。
- 设备端数据受 iOS 数据保护;签名密钥驻留钥匙串且永不导出。
- 本地录音、导入与快照保存在受保护存储中,且不参与备份。
4. 保留与删除
上传内容按你的服务器策略保留,由服务器管理员控制。你可以在应用内删除录音与会话,删除会同时移除本地副本与服务器副本。客户端遥测仅短暂保存在内存与待发批次中。
5. 后台功能
灵动岛(Live Activities)、后台上传与分享扩展导入均在本机处理。若未来启用推送通知,将通过 Apple 推送服务投递,除投递所需内容外不共享任何信息。
6. 跨境传输
由于 VoxSpace 是自托管的,数据去往何处完全取决于你的服务器实例部署在哪里。应用本身不向任何其他法域传输数据。
7. 儿童
本应用不面向儿童,亦不有意收集儿童数据。
8. 变更与联系
本政策可能随应用更新,重大变更会在发布说明中注明。如有疑问,请联系你的服务器管理员,或通过 App Store 页面上的支持链接联系项目。