Transcribe, translate, and summarize WhatsApp Web audio messages with AI
This Privacy Policy describes how the ZapVox extension ("we", "us", "our") collects, uses, and protects user information ("you"). ZapVox is a browser extension for Chrome/Edge that transcribes, translates, and summarizes audio messages on WhatsApp Web.
Last updated: July 18, 2026
Version: 2.0
chrome.alarms. On the Pro plan you can optionally sync them to your account so they also fire on your other devices (see section 2.2).chrome.storage.local for up to 7 days to avoid reprocessing. This data stays exclusively in your browser.chrome.storage.local and never sent to servers.chrome.storage.local (key zapvox_sentiment_cache) for up to 7 days so the sentiment chip survives page reloads without reprocessing. The associated message identifier is the same sanitized hash used by the transcription cache. This data never leaves your browser and is automatically purged after 7 days.| Data | When | Destination | Purpose |
|---|---|---|---|
| Audio (base64) | Cloud transcription (all plans, when local fails) | Supabase Edge Function → Groq | Convert audio to text |
| Audio (base64) | BYOK transcription (your own key) | Groq or OpenAI (directly from browser) | Convert audio to text |
| Transcribed text | Translation or summary | Supabase Edge Function → Groq/Gemini | Translate or summarize text |
| JWT token | Authentication | Supabase Auth | Validate session and plan |
| Login/signup | Supabase Auth | Create and manage account | |
| Reminder text + time (Pro only, opt-in) | When a Pro user creates a reminder | Supabase Postgres (RLS) | Sync reminders across the user's own devices so they fire everywhere. Stored under the authenticated user and readable only by them. |
| Message schedule text, recipient and time | When you create/edit a scheduled message (signed-in user) | Supabase Postgres (RLS) | Sync across your own devices and let you manage them in the dashboard. Stored under the authenticated user and readable only by you. |
| Anonymous diagnostics (opt-in, off by default) | Only if the user enables "Anonymous diagnostics" | Supabase Edge Function | Report technical errors and WhatsApp DOM changes to improve reliability. No message content, contact names, phone numbers, or message identifiers. |
active_sessions (user_id, browser identifier, label, timestamp) | On sign-in and when using account-based features | Supabase Postgres (RLS) | Maintain one active browser per account (Section 4.1 of the Terms), preventing credential sharing. See section 2.5. |
To provide a smooth experience, ZapVox temporarily stores the following technical data in your own browser (never on our servers):
chrome://extensions.
To ensure your account is used by a single person at a time — as set out in Section 4.1 of the Terms of Service — ZapVox needs to tell one browser from another. To that end:
chrome.storage.local. It is accompanied by a generic, human-readable label (e.g., "Chrome · Windows"), derived only from browser type and operating system, so you can recognize on screen which browser is active.If you choose to use your own API keys (Bring Your Own Key — BYOK), they are:
chrome.storage.local| Permission | Why We Need It |
|---|---|
storage | Save settings, transcription cache, and encrypted keys |
unlimitedStorage | Cache Whisper models locally (140 MB to 1.5 GB) to avoid re-download on each use |
notifications | Show notifications when transcription completes |
identity | OAuth authentication for login (Google Sign-In via Supabase) |
alarms | Keep the Service Worker active during long transcriptions and manage daily usage resets |
tabs | Detect WhatsApp Web tabs to send results |
offscreen | Run local Whisper model in an offscreen document (required for Web Workers in MV3) |
host: web.whatsapp.com | Inject content script to add transcription buttons to audio messages |
Under Brazil's Lei Geral de Proteção de Dados (General Data Protection Law), you have the right to:
Under the General Data Protection Regulation (GDPR), you have the right to:
If you are a California resident, you have the right to:
To exercise any of these rights, contact us using the information in Section 12.
chrome://extensions, click "Details" on ZapVox, then "Clear site data". This removes all cached transcriptions, settings, and BYOK keys.
Most of your data is processed locally on your device. However, when cloud processing is used, your data may be transferred to and processed on servers located in the United States (through Supabase and Groq). We implement appropriate safeguards to protect your data during international transfers, including standard contractual clauses and encryption in transit via HTTPS. By using ZapVox, you consent to the transfer of your data to the United States for processing as described in this policy.
| Service | Purpose | Privacy Policy |
|---|---|---|
| Supabase | Authentication, Edge Functions (transcription/translation for Pro plan) | supabase.com/privacy |
| Groq | Cloud transcription, translation, summary (primary provider) + BYOK | groq.com/privacy |
| OpenAI | BYOK transcription (when user provides own key) | openai.com/privacy |
| Google Gemini | Translation and summary fallback (via Edge Function) | policies.google.com/privacy |
| HuggingFace | Download of Whisper ONNX models for local transcription (no user data) | huggingface.co/privacy |
| Stripe | Payment processing (Pro plan) | stripe.com/privacy |
ZapVox is not intended for children under 13 years of age. We do not intentionally collect data from children. If you believe a minor has provided data, please contact us for immediate removal.
ZapVox complies with the Chrome Web Store's Limited Use policy:
We may update this policy periodically. Significant changes will be communicated via notification in the extension or in the changelog. The last updated date will always be visible at the top of this page.
For questions, data requests, or to exercise your rights:
Email: [email protected]
Developer: Diegomaier Nunes Neri
Related documents: Terms of Service