Privacy Policy
Last updated: 30 August 2026
This policy explains what Voxonow Yazılım ("Voxonow", "we") collects when you use the product, what happens to it, and what you can ask us to do about it. It applies to the Voxonow web app and API, and serves as our disclosure notice under Turkish data protection law (KVKK aydınlatma metni). Voxonow Yazılım is the data controller (veri sorumlusu).
It is written to match what the software actually does. Where a practice is a choice we made rather than a technical necessity, it says so.
What we collect
- Account information — your name, email address and a password hash, or a Google account identifier if you sign in with Google.
- Workspace content — messages, channel and thread structure, and files you upload.
- Voice session metadata— who joined a call, when, for how long, and how many seconds each participant's microphone was live. There is no recording feature: nobody can press record, and no call is kept as audio. On most calls the audio is relayed in real time and never written to disk.
- Call transcripts— the words spoken on a call, stored as text with the name of whoever said each line. The audio itself is still never kept; what is saved is the text your own browser produces from it. Transcription happens on your device, using the speech recogniser your operating system already ships, and only ever on your own microphone — so it works in Chrome and Safari and not in Firefox, and a call may have no transcript at all. Saved transcripts are readable by the members of the workspace the call happened in, are searchable across that workspace, and are deleted when the call or the workspace is deleted — and, where the operator of this deployment has set a retention window for them, automatically once that window passes. If the workspace has AI features switched on, transcripts are sent to that workspace's chosen AI provider to produce the call summary — see the section on AI features below.
- Activity records — read positions, reactions, bookmarks, and an audit log of administrative actions such as removing a member or deleting a workspace.
- Technical data — browser and device information and timestamps, for debugging and abuse prevention. Rate limiting uses your IP address in short-lived memory; we do not store IP addresses in our database.
AI features, and what they send
Voxonow can answer questions from your workspace's own conversations, summarise a call, catch you up on what you missed, and translate a message. These features work by sending text to an AI provider — message bodies, and, when summarising a call, the transcript of what was said on it.
They are off unless your workspace admin turns them on. Voxonow does not hold or pay for an AI key: an admin adds their own key for Anthropic, OpenAI or Google, and usage is billed to that account. Until they do, no message ever reaches an AI provider.
Once a key is configured, and only then:
- Message bodies, author display names, channel names and timestamps are sent to the provider your admin chose, for that request only. We do not send them anywhere else, and we do not use your content to train anything of our own.
- The messages sent are the ones the person using the feature could already read. That includes their own direct messages — so a colleague using "Catch me up" may send a DM you wrote to them to the provider.
- Any channel can be excluded, including a DM. An excluded channel's messages are never sent to any AI feature, while staying fully readable and searchable in the product as normal.
- Anyone in a workspace can see whether AI is enabled there and which provider it uses.
These providers process the data under their own API terms, which is a relationship between your workspace and them. If that matters to your organisation, the honest answer is to review those terms — or to leave the AI features off, which costs you nothing else in the product.
Who else processes your data
Besides our own servers, these providers handle data on our behalf or at your request:
- LiveKit — relays voice and screen-share streams in real time. Nothing is recorded.
- Anthropic, OpenAI or Google — only if your admin configured an AI key, as described above.
- Resend — sends invitation, verification, password reset and missed-message emails. Notification emails deliberately say who wrote to you and where, never what they said.
- Google— if you sign in with Google, or connect Google Drive or Calendar yourself. Drive files are referenced, never copied to us. Sending a calendar invitation passes the attendees' email addresses to Google, as any calendar invitation does.
- GitHub — if your workspace links a repository, and for our own encrypted database backups.
- Object storage — where uploaded files are kept, if configured; otherwise they stay on our own disk.
- Sentry — error reports. Message bodies, search terms, request bodies and email addresses are stripped before an error leaves our server.
- Push services (Apple, Google, Mozilla) — if you enable notifications. The payload names the sender and channel, never the message text.
One thing worth knowing: when a link is pasted into any channel, our server fetches that page once to build a preview. The site at the other end sees a request from us — never from you, so your IP address is not disclosed — but it does learn that its link was shared.
Most of these are outside Turkey, so using Voxonow involves transferring data abroad (KVKK m.9). Some are outside the EU/EEA.
How long we keep it
Workspace content is kept for as long as your workspace exists, unless this deployment sets a retention period — in which case older messages, audit records and diagnostic data are deleted permanently on a schedule.
Deleting a message deletes what it said. The text is emptied from our database and its search index, any cached translation is removed, and attached files are deleted from storage. An empty placeholder remains so replies underneath it do not break for other people.
Deleting your account removes your profile, email address, sessions and personal settings. Messages you posted to shared channels remain, attributed to a deleted user, because removing them would tear holes in conversations belonging to other people. If you need those removed as well, ask us and we will discuss what is possible.
Backups are encrypted and kept for up to 60 days, so deleted data can persist in them for that period before ageing out.
How it is protected
Traffic is encrypted in transit. Passwords are hashed, and every credential we hold on your behalf — AI keys, integration tokens — is encrypted at rest. Database backups are encrypted before they leave the server.
Message content itself is stored unencrypted in our database, which is what allows search to work. It is not end-to-end encrypted, and we can technically read it — though nothing in the product is built to, and our own platform administrators have no way to read message content through the application.
Your rights
Under KVKK m.11 and, where it applies, the GDPR, you can ask us whether we hold data about you, ask for a copy, ask for it to be corrected or deleted, and object to how it is used.
Two of those you can exercise yourself, right now, without asking anyone: Settings → Account → Download my data gives you everything this account holds as a file, and the same screen deletes your account. The download deliberately excludes messages other people wrote, including inside your direct messages, because those are their words rather than yours.
For anything else, email privacy@voxonow.com. We aim to respond within 30 days, which is the deadline KVKK sets. If you are not satisfied, you may complain to the Turkish data protection authority (KVKK Kurumu) or, in the EU/EEA, your local supervisory authority.
Changes to this policy
If this changes materially we will update the date at the top and, where it affects you, tell you directly.
Contact
Voxonow Yazılım — data controller (veri sorumlusu).
privacy@voxonow.com