Want the short version, no legalese? This page is the full document. If you only want to understand who sees what, the three privacy levels and what encryption protects, read /en/security.

Supplier identification

TECHMED SERVIÇOS MÉDICOS LTDA — CNPJ 46.367.941/0001-69
Rua Prof. RΓ΄mulo Almeida, 52, Ed. Lafayette Velloso β€” Acupe de Brotas β€” Salvador/BA β€” CEP 40290-030 β€” Brasil
Contact: [email protected] Β· zapvoxia.com.br

ZapVox is operated by the legal entity above, responsible for the contractual relationship, billing and support, and the controller of the personal data processed in the Service (Brazilian LGPD, art. 5, VI).

1. Introduction

This Privacy Policy describes how the ZapVox extension ("we", "us", "our") collects, uses, and protects user information ("you"). ZapVox is a browser extension for Chrome/Edge that transcribes, translates, and summarizes audio messages on WhatsApp Web.

Last updated: September 5, 2026

2. Data We Collect

2.1 How each type of data is handled

2.2 Data sent to servers (only when necessary)

DataWhenDestinationPurpose
Audio (base64)Cloud transcriptionSupabase Edge Function β†’ Groq β†’ Google (Gemini) β†’ Cloudflare (Workers AI) β†’ OpenAI, in this order, moving to the next one only when the previous one failsConvert audio to text
Audio (base64)BYOK transcription (your own key)Groq or OpenAI (directly from browser, without passing through us)Convert audio to text
Conversation names (the name saved in your address book and the contact's profile name, as shown in your WhatsApp Web)Along with the audio, on every transcription β€” if the "Conversation names in the transcription" switch is on (it ships on)The same destination as the audio: our Edge Function β†’ transcription provider, or Groq/OpenAI directly under BYOKSpelling hint for the model (Whisper's context field), so the speaker's name comes out spelled as it is in your WhatsApp. They are read at the moment of each transcription, straight from your WhatsApp Web (which is why renaming a contact already counts for the next audio), sent along with the audio and only at that moment, and not recorded on our servers or anywhere else because of this feature β€” the provider processes them with the audio and discards them, under the same retention rules as the audio. The only record of names that exists is the 30-day local cache described in 2.3, which already existed and does not change.
Transcribed textTranslation or summarySupabase Edge Function β†’ Groq/GeminiTranslate or summarize text
JWT tokenAuthenticationSupabase AuthValidate session and plan
EmailLogin/signupSupabase AuthCreate and manage account
Gender and profession (optional, with "prefer not to say")Only if you fill them in under My account β†’ About youSupabase Postgres (RLS)To write to you the right way and, soon, to build a glossary with the terms of your field. You can erase them whenever you want, in the same place.
usage_logs (user_id, action, timestamp)On every cloud transcription/translationSupabase Postgres (RLS)Enforce the plan's daily limits. No audio/text content; counters only.
Reminder text + time (Pro only, opt-in)When a Pro user creates a reminderSupabase Postgres (RLS)Sync reminders across the user's own devices so they fire everywhere. Stored under the authenticated user and readable only by them.
Message schedule text, recipient and timeWhen you create/edit a scheduled message (signed-in user)Supabase Postgres (RLS)Sync across your own devices and let you manage them in the dashboard. Stored under the authenticated user and readable only by you. After the send, the text is removed: only a summary remains (content type, file name, recipient and date).
Anonymous diagnostics (opt-in, off by default)Only if the user enables "Anonymous diagnostics"Supabase Edge FunctionReport technical errors and WhatsApp DOM changes to improve reliability β€” including audio-loading failures (only the technical phase, e.g. "evicted"/"all_phases", plus version and browser). No message content, contact names, phone numbers, or message identifiers.
user_settings.usa_chave_propria (user_id, yes/no, date)When you save or remove your own key (BYOK), and on sign-inSupabase Postgres (RLS)To know how many accounts use their own key, so we can decide whether the feature deserves investment. It is a yes/no: the key never leaves your browser, and we do not record which provider, how many times you used it, or what was transcribed.
active_sessions (user_id, browser identifier, label, timestamp)On sign-in and when using account-based featuresSupabase Postgres (RLS)Maintain one active browser per account (Section 4.1 of the Terms), preventing credential sharing. See section 2.5.
E-mails we send: besides your account notices (payment, security, changes to the Terms), the ZapVox Team sends usage tips in the first days and a monthly bulletin with what changed β€” on the basis of the legitimate interest (LGPD, art. 7, IX) of someone who created an account in knowing what is already theirs. Every one of these e-mails carries a one-click unsubscribe link, by category or for everything, and the switch is also under My account β†’ Team e-mails. Whoever unsubscribes receives nothing beyond what concerns their own account. We never sell or hand your e-mail to anyone.
Note on usage_logs: We record only that an operation happened (to enforce your plan's daily limit), not what was transcribed. No audio, text, contact name or message identifier is persisted on the server. The table is protected by Supabase Row-Level Security β€” you can only read your own records.
Important: The extension does not access your microphoneβ€”it only reads audio already received in WhatsApp Web. Recovery of deleted messages has been discontinued β€” the extension does not store that type of data. With BYOK (your own API key), audio goes directly from your browser to Groq/OpenAI and never passes through our servers.

2.3 Local storage for extension functionality

To provide a smooth experience, ZapVox temporarily stores the following technical data in your own browser (never on our servers):

Full control: You can remove this data anytime by opening ZapVox Settings β†’ "Clear privacy data" within the extension, or by clearing extension data at chrome://extensions.

2.4 Data we do NOT collect

2.5 Browser identifier (one active browser per account)

Context: the extension may be installed on several computers, but the account is active on one at a time β€” activating it on one computer automatically disconnects the previous access; simultaneous use requires the "Additional computer" add-on (see Terms, Section 4.1).

To ensure your account is used by a single person at a time β€” as set out in Section 4.1 of the Terms of Service β€” ZapVox needs to tell one browser from another. To that end:

3. API Keys (BYOK)

If you choose to use your own API keys (Bring Your Own Key β€” BYOK), they are:

4. Security

5. Browser Permissions

PermissionWhy We Need It
storageSave settings, transcription cache, and encrypted keys
notificationsShow notifications when transcription completes
identityOAuth authentication for login (Google or Microsoft, via Supabase)
alarmsKeep the Service Worker active during long transcriptions and manage daily usage resets
tabsDetect WhatsApp Web tabs to send results
host: web.whatsapp.comInject content script to add transcription buttons to audio messages

6. Your Rights

ZapVox is operated from Brazil and the processing of your personal data is governed by Brazil's Lei Geral de ProteΓ§Γ£o de Dados (LGPD, Law No. 13,709/2018). Under it you have the right to:

We answer requests of this kind from anyone, wherever you live β€” we do not require you to be in Brazil to ask for access, correction or deletion of your data.

To exercise any of these rights, contact us using the information in Section 12 β€” or, for deletion, use the dashboard button.

How dashboard deletion works (v3.13.3+): once you confirm by typing the safety word, deletion is immediate and final: we erase your account, name, e-mail, usage history, glossary, reminders, schedules and connected-computer records. If there is an active subscription it is ended at the same moment and no new charge is made β€” if ending it at Stripe fails, the account is not deleted and you see a notice to try again. The refund policy (Terms, Β§10.1) is applied first, automatically. What remains: only the payment records tax law requires us to keep (LGPD, art. 16, I), unlinked from you (account identifier and e-mail removed). Nothing that lives only on your computer passes through our servers β€” for that, see below.
How to clear local privacy data: Open ZapVox Extension β†’ Settings β†’ click "Clear privacy data". This removes diagnostic logs and contact name cache without affecting your settings or account.
How to clear all extension data: Go to chrome://extensions, click "Details" on ZapVox, then "Clear site data". This removes all cached transcriptions, settings, and BYOK keys.

7. International Data Transfers

Some data (settings, cached transcripts, reminders) stays in your browser, but audio transcription and other AI features rely on cloud processing, so your data may be transferred to and processed on servers located in the United States (through Supabase and Groq). We implement appropriate safeguards to protect your data during international transfers, including standard contractual clauses and encryption in transit via HTTPS. By using ZapVox, you consent to the transfer of your data to the United States for processing as described in this policy (LGPD, art. 33).

8. Third Parties and Subprocessors

ServicePurposePrivacy Policy
SupabaseAuthentication, Edge Functions (transcription/translation for Pro plan)supabase.com/privacy
GroqCloud transcription, translation, summary (primary provider) + BYOKgroq.com/privacy
OpenAIBYOK transcription (when user provides own key)openai.com/privacy
Google GeminiTranslation and summary fallback (via Edge Function)policies.google.com/privacy
StripePayment processing (Pro plan)stripe.com/privacy

9. Data Retention

10. Minors

ZapVox is not intended for children under 13 years of age. We do not intentionally collect data from children. If you believe a minor has provided data, please contact us for immediate removal.

11. Chrome Web Store Limited Use Disclosure

ZapVox complies with the Chrome Web Store's Limited Use policy:

11-A. Distribution through extension stores (Chrome, Edge and Firefox)

ZapVox is distributed through the Chrome Web Store (Google), Microsoft Edge Add-ons and Firefox Add-ons (Mozilla). To publish and update the extension we send those stores the program package. Mozilla additionally requires the extension's source code, because the package is minified β€” this is a mandatory condition to publish there, applied to every extension in that situation, and the material is used only by Mozilla's review team, under confidentiality.

What the stores NEVER receive, under any circumstance:

What we send is the program, not your data. Source code describes how the extension works; it does not β€” and could not β€” contain any user's information. This section does not change any commitment in Sections 7 and 11: data transfers remain limited to the subprocessors listed there.

12. Changes to This Policy

We may update this policy periodically. Significant changes will be communicated via notification in the extension or in the changelog. The last updated date will always be visible at the top of this page.

13. Contact

For questions, data requests, or to exercise your rights:

Email: [email protected]

Developer: Diegomaier Nunes Neri

Related documents: Terms of Service

In-app feature notices

To suggest features you haven't used yet (and avoid repeating ones you already use), the extension looks only at which features you have already used β€” a signal that already exists in your account. These notices collect no new data and never use the content of your messages or audios. You can turn them off in Settings → What's new.

AI providers (transcription)

Audio sent for cloud transcription is processed by one of these subprocessors, always in this order, moving to the next one only when the previous one fails: Groq β†’ Google (Gemini) β†’ Cloudflare (Workers AI) β†’ OpenAI. They process the audio to produce the text and do not store it for that purpose. In BYOK mode, processing happens directly at your own key's provider (Groq or OpenAI), without passing through us.

Two transparency corrections made on 16/08/2026, so that this page describes what the code actually does:

Google (Gemini) receives the audio when it is reached in the cascade β€” not only the already-transcribed text. See the table in section 2.2.

Cookies, Analytics and subprocessors

Cookies and audience measurement

On the website pages (zapvoxia.com.br) we use Google Analytics 4 to measure audience in aggregate (pages visited, traffic source, device). GA4 anonymizes the IP address by default and stores first-party cookies in your browser. We do not use advertising or remarketing cookies, and we do not sell data.

Subprocessors

To operate the Service we rely on the following providers, each processing only the minimum necessary:

Some of these providers are based abroad; international transfers comply with the LGPD (arts. 33 et seq.) and are limited to what is necessary to provide the Service.