SpiritWhispers is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our website and services.
Information We Collect
Personal information you provide (such as email address, name, and payment details).
Session and usage data (such as audio recordings, transcripts, and notes).
Technical data (such as IP address, browser type, and device information).
How We Use Your Information
To provide and improve our services.
To communicate with you about your account or updates.
To process payments and manage subscriptions.
To ensure security and prevent fraud.
How We Share Your Information
We do not sell your personal information.
We may share information with trusted service providers (such as payment processors and cloud infrastructure providers) as needed to operate our service.
We may disclose information if required by law or to protect our rights.
Data Storage & Security
We use Supabase to host our database and file storage. Session metadata (e.g., titles, timestamps, notes) is stored in a managed Postgres database, and audio files/transcripts are stored in Supabase Storage (object storage).
Data is transmitted over HTTPS/TLS and stored using industry-standard security controls (including encryption in transit and at rest as provided by our infrastructure providers).
Access to stored data is restricted via authentication and role-based permissions. Shareable client links use signed or tokenized URLs that you control.
AI Processing & Transcription
To generate transcripts, we may securely transmit your audio to third-party AI transcription providers (for example, OpenAI Whisper API or an equivalent service) for the sole purpose of converting speech to text.
We do not permit these providers to use your content for training or marketing. We do not opt in to any provider data-sharing or model-training programs.
Audio is sent over encrypted connections, and we only share the minimum data required to perform the transcription task.
Data Retention
By default, your recordings, transcripts, and notes are retained indefinitely so that you and your clients can revisit them at any time.
You can delete a session (and its associated files) at any time from within the app. When you delete a session, we remove it from active storage; residual copies may remain in system backups and logs for a limited period consistent with standard operational practices.
You can revoke shared links at any time. Once revoked, the link will no longer provide access to the content.
Your Choices
You may access, update, or delete your account information at any time.
You may delete recordings, transcripts, and notes at any time from within the app.
You may opt out of marketing emails by following the unsubscribe link in those emails.
Contact Us
If you have any questions about this Privacy Policy, please contact us at contact@halfinthebox.com.