Privacy Policy
Last updated: September 19, 2026
aloud is built to be private, and to give you a choice about where your data goes. You can run it locally with your own providers, so nothing touches us at all; or you can use aloud cloud, our optional hosted service that connects you to AI and voice providers without us keeping your sessions. This policy explains, plainly, what happens to your data in each case.
The short version
- There are two ways to run aloud. Run it locally / bring-your-own and your content goes only to the providers you choose; aloud receives nothing. Use aloud cloud and your content passes through our service only to reach those providers; we don't retain your session content.
- We don't sell your data; we don't use it for advertising; we don't use your conversations to train AI; and on aloud cloud, we don't retain your conversation data at all.
- aloud cloud needs an account and credits; for that we process the minimum required: sign-in details, your credit balance and usage, and payments handled by our payment processor.
- Wherever your platform allows it, you can run aloud fully on your own, keeping everything on your device.
Two ways to use aloud
- Local / bring-your-own. On supported platforms (such as the desktop app), aloud runs on your device and connects directly to the providers you configure with your own credentials, or fully on-device. There is no aloud cloud in the middle, no account, and we receive nothing, unless you turn on the optional voice commands described below.
- aloud cloud. Our optional hosted service for platforms or situations where running your own isn't practical, such as the web app and the in-beta mobile apps. You sign in, optionally buy credits, and aloud cloud relays your audio and text to third-party AI and voice providers on your behalf, returning the result. We don't store your session content.
What aloud processes, and where it goes
Your voice
Your microphone audio is used to transcribe what you say into text. There are three paths, and the app tells you which one is selected:
- On your device. Where supported (such as Whisper in the desktop app), transcription runs locally and the audio is not sent anywhere.
- Your platform's speech recognizer. The mobile apps default to the recognizer built into your phone, and browsers may offer their own. These are operated by the platform vendor, not by us: depending on the device and its settings, they may process your audio on the device or send it to the vendor's servers (Android's speech recognition, for example, commonly uses Google's). That processing is covered by your platform vendor's privacy policy. We never receive this audio.
- aloud cloud. Your audio is relayed through our service to a speech-to-text provider to transcribe it, then discarded.
We don't record your audio, and we don't store it.
Your words and the AI facilitator
To generate responses, aloud sends your transcribed messages and the conversation so far to a language-model provider:
- Local / on-device providers (e.g. Ollama): your words never leave your device.
- Providers you connect yourself (e.g. Anthropic, OpenAI, OpenRouter, Venice, Groq - with your own API key, or your Claude subscription via the
claudeCLI): your text goes directly to that provider's API under their privacy policy and terms. aloud neither receives nor stores it. - Via aloud cloud: your text is relayed through our service to the language-model provider and is not stored by us.
On aloud cloud, short things you say are also checked by a small classification model, so the app can recognize a spoken command (like "set a timer for ten minutes") or tell whether you're calling the facilitator back from a silence. That check includes what you just said and, during a silence, possibly the few things you said just before it. It's relayed the same way and is not stored by us.
In local or bring-your-own use this check is off by default. You can turn on Voice commands in Settings, which needs a free aloud account. While it's on, what you say in a session is sent through aloud cloud to the same classification model, including with an on-device model like Ollama; your conversation and the facilitator's replies still go only where they went before. We don't store or log it, it costs no credits, and turning the setting off stops it.
Spoken responses
Facilitator responses are turned into speech. Depending on your setup this happens on your device (Piper, or your system's built-in voices), via a cloud voice service you connect, or via aloud cloud, which relays the response text to a text-to-speech provider. We don't store the audio or text.
Saved sessions
aloud can save your session transcripts and a short summary locally on your device so you can revisit them. They stay on your device unless you choose to export or share them. There is no cloud sync, and aloud cloud does not store your transcripts or summaries.
App updates
aloud may check for new versions (a basic network request that does not include your session content).
aloud cloud: accounts, credits, and what we keep
If you use aloud cloud, we process a limited amount of information to run the service. None of it includes the content of your sessions.
- Account. The sign-in details needed to give you an account. You can sign in with Google or Apple (which share a basic identifier such as your email address), or with an email address and password. We use this to identify your account and credit balance, so keep your sign-in secure.
- Email updates (optional). When you create an account you can tick a box to get occasional emails about aloud. It's off unless you turn it on, and you can turn it off any time on the account page. If you opt in, we hold your address for that purpose as well as for your account. We never share or sell it, and opting out or deleting your account removes it from the list.
- Credits and usage. Your credit balance and a metered record of usage (for example, the amount of audio or text processed, and aggregate per-session totals such as how many turns a session ran) so we can charge credits accurately, understand our costs, and prevent abuse. This is operational metering for billing and reliability, not behavioral profiling, and it does not include the content of your sessions.
- Payments. If you buy credits with a card, payment is handled by our payment processor, Stripe, and we don't receive or store your full card details. If you instead choose to pay on-chain with a stablecoin, that transaction is by its nature recorded on a public blockchain; we receive only what's needed to credit your account.
- Abuse prevention. When you create an account, we record the IP address you signed up from, used only to catch abusive signup patterns (like farming free credits). It's deleted automatically after 90 days, and right away if you delete your account.
- Operational logs. We may keep minimal, short-lived technical logs (for diagnostics, security, and abuse prevention) that do not contain your session content.
- Error records. When a call we relay fails or is refused, we keep a short record of it - what went wrong (an error code or reason, the provider and model involved, token or byte counts), never anything you said or the AI replied. It's how we notice problems the app handles quietly. These records sit with your account record and are anonymized when you delete your account, like the credit ledger.
We don't retain the content of your sessions on aloud cloud. None of it. Your audio, your words, and the AI's responses pass through only to reach the providers that fulfill them; nothing is stored on our side afterward.
Your own API keys
On some platforms you can supply your own provider API keys instead of using credits. Those keys are stored only on your device, and never on our servers. On the web app this is off by default; it applies only if you manually turn on bring-your-own-key. Your sessions then call each provider directly from the app, so your key and your words don't pass through aloud cloud at all. There are two exceptions. If you turn on Voice commands (see "Your words and the AI facilitator" above), what you say is checked through aloud cloud; your key is never part of that. The other is looking up a provider's list of available models, which is relayed through our server with your key; it's used transiently, in memory, and we neither store nor log it.
What we don't do
- No advertising or ad networks.
- No selling or sharing of your personal data.
- No using your conversations to train AI models, and no retaining them on aloud cloud, at all.
- No third-party analytics or behavioral tracking. (aloud cloud meters credit usage only as needed to run the service.)
- No accounts at all in local mode; accounts exist only for aloud cloud.
Third-party services
Whenever your content is processed by an AI or voice provider, whether you connect it yourself or aloud cloud relays to it, that provider handles your data under its own privacy policy and terms. Please review the policy of whichever provider applies; aloud is not responsible for how third parties handle data sent to them.
When you use aloud cloud, we aim to be transparent about which providers we rely on. We currently use Anthropic, Google, OpenAI, and Novita (via OpenRouter) for language models. The Kimi model is an open model from Moonshot AI, but it runs on Novita's US infrastructure (with Groq, also US, as a fallback host); your sessions are not sent to Moonshot. We also use OpenAI for speech-to-text and Microsoft Azure AI Speech, Google Cloud Text-to-Speech, and OpenAI for voice. We use TypeSafe (US-hosted) for the classification model that recognizes spoken commands and reads silence cues. Payments are handled by Stripe (and, for on-chain stablecoin payments, settled directly on a public blockchain). We'll keep this list current as our providers change.
Behind the service itself: aloud cloud runs on Fly.io in the United States, and our account database (sign-in details, credits, and usage metering, never your session content) is backed up to Cloudflare R2. Both handle data for us as infrastructure providers under data processing agreements.
Your control
- Run aloud locally (where your platform allows) to keep everything on your device.
- Choose on-device providers for maximum privacy if your hardware is capable.
- Your credentials and settings live on your device in local mode. Clear them anytime.
- Delete saved sessions from your device whenever you like.
- For aloud cloud, delete your account anytime from the app's account screen, or email us at the address below. Details: aloud.rest/delete-account.
Where your data lives, and for how long
aloud cloud is operated from the United States, so if you use it from somewhere else (including the EU or UK), your account information, and the session content we relay, are processed in the US. The providers we relay to may process data in other regions under their own terms.
- Session content: never stored, so there is nothing to retain.
- Account and credit records: kept while your account exists. When you delete your account, we remove your sign-in identities and scrub the record of your email address and IP; what remains is an anonymous credit ledger we keep for accounting.
- Signup IP address: deleted after 90 days at most.
- Backups: the account database backup is continuously replaced; data scrubbed from the live database ages out of it within about a day.
Your rights
You can see, correct, export, or delete the account data we hold, and object to or restrict our use of it. Deleting your account from the app removes it immediately; for anything else, email us and we'll sort it out. If you're in the EU, UK, or another region with a data protection law, these are the rights that law gives you, and you can also complain to your local data protection authority. Where a legal basis is required, ours are: performing our contract with you (accounts, credits, relaying your sessions) and our legitimate interest in keeping the service secure and preventing abuse.
Children's privacy
aloud is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect information from them.
Changes to this policy
We may update this policy from time to time; the "last updated" date above will change. Significant changes will be reflected here.
Contact
Questions about privacy, or want your account data deleted? Email lexkrusz@gmail.com.