The short version
Recording and transcription happen on your own computer. We only store what you choose to sync to the cloud. There are no analytics, no trackers and no marketing cookies, just one functional session cookie. Voice profiles are used only with your explicit consent. AI features are off by default and run on an API key you provide yourself. To access or delete your data, email hello@lavox.app.
This policy explains what personal data the Lavox service processes, why, and what rights you have. It covers the Lavox Hub desktop application for macOS and the web dashboard at app.lavox.cloud. The Chrome extension has its own, narrower policy at /privacy-extension.
1. Who is responsible for your data
The data controller for the Lavox service is:
TÁTRA"99"Szolgáltató Kft. ("Tátra 99"), a limited liability company registered in Hungary
Registered office: Frankel Leó út 27. földszint 5., 1027 Budapest, Hungary
Company registration number: 01-09-688426
Tax number: 12481699-2-41
Contact for privacy matters: hello@lavox.app
2. What we collect, why, and on what legal basis
Account data
Your name, email address, and either a password or a Google sign-in link. Passwords are stored
only as a scrypt hash, never in plain text. If you sign in with Google, we receive your Google
account identifier and email address instead of storing a password.
Purpose: creating and securing your account.
Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)).
Meeting data
Audio recordings, optional video (webcam), transcripts, and meeting metadata (title, time,
duration). All of this is created locally on your device; it reaches our
servers only if you enable cloud sync (auto-save), in which case the finished recording and
transcript are uploaded to your account and shown in the web dashboard.
Purpose: storing and displaying your meetings across your devices.
Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)).
Calendar data (only if you connect a calendar)
If you choose to connect your Google Calendar, we process event titles, times, and attendee
names, and use them to name meetings and to help identify who is speaking. We never touch your
calendar unless you connect it, and you can disconnect it at any time.
Purpose: naming meetings and supporting speaker identification.
Legal basis: your consent, given when you connect the calendar
(GDPR Art. 6(1)(a)); you may withdraw it at any time by disconnecting.
3. Voice profiles: special category data
To recognise who is speaking in your meetings, you can record a short voice enrollment sample for a person. From that sample we derive a numeric voice embedding (a "voice profile") stored with your account. Because a voice profile characterises a person's voice, we treat it as biometric-type data, a special category of personal data under Article 9 GDPR.
- We process voice profiles only with explicit consent (GDPR Art. 9(2)(a)), given when the sample is recorded.
- Voice profiles are used for exactly one thing: labelling speakers in your own meetings. They are never used for any other purpose and never shared with anyone.
- You can withdraw consent and delete voice profiles at any time by emailing hello@lavox.app. Withdrawal does not affect the lawfulness of processing that happened before it.
4. Where processing happens: your device first
Recording and transcription run entirely on your own computer; the Lavox Hub app transcribes audio locally using an on-device speech model. Nothing leaves your device unless you enable cloud sync. If cloud sync is off, we hold nothing about your meetings at all.
The same applies to the memory feature: the structured memory built from your recordings and dictation (including its search index and embeddings) is stored in a local database on your device and is computed there. Its MCP interface serves AI tools running on your machine; we never receive, store or process the contents of your memory. If you connect a cloud AI tool to it yourself, that transfer happens under the terms of the tool you chose.
5. AI features and your own API key
AI features (meeting summaries and an AI-assisted step of speaker identification) are switched off by default. If you enable them, they run using an API key you provide yourself (for example an OpenRouter key). When these features run, excerpts of your transcripts are sent to the AI provider you chose; that processing is governed by the provider's own terms and privacy policy, and we do not control it. Choose your provider accordingly.
6. Where your data is stored, and who helps us store it
We use a small number of infrastructure providers (processors):
| Provider | What they handle | When |
|---|---|---|
| netcup GmbH (Germany, EU) | Database: accounts, transcripts, meeting metadata, voice-profile embeddings | Always, once you have an account with cloud sync |
| Cloudflare Inc. (R2 object storage) | Media files: audio and video recordings you sync | Only if you enable cloud sync |
| Vercel Inc. | Hosting of the web dashboard (app.lavox.cloud) and this website | Always, when you use the web dashboard |
| Google LLC | Sign-in with Google (OAuth); calendar data | Only if you sign in with Google or connect your calendar |
| AI providers you connect yourself (e.g. via OpenRouter) | Transcript excerpts, for summaries and speaker identification | Only if you enable AI features with your own API key |
Where a provider processes data outside the European Economic Area, the transfer relies on the safeguards of GDPR Chapter V, such as the EU–U.S. Data Privacy Framework or the European Commission's Standard Contractual Clauses.
Backups and retention
- We keep your data for as long as your account exists.
- Backups are made daily and rotated after 7 days, stored on the same server as the database.
- When you delete data or your account, it is removed from live systems, and expires from backups within 7 days through the normal rotation.
7. Cookies
The web dashboard sets one functional session cookie (NextAuth) that keeps you signed in. That is all. There are no analytics, no trackers, no marketing or advertising cookies, and no fingerprinting, on the dashboard or on this website.
8. Your rights and how to use them
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectify inaccurate data;
- erase your data ("right to be forgotten");
- receive your data in a portable format;
- restrict or object to certain processing, and withdraw any consent at any time.
How to exercise them: email us at hello@lavox.app. There is no self-service deletion in the product yet, so requests are currently fulfilled manually; we respond and complete requests within 30 days.
9. Complaints
If you believe we process your data unlawfully, you can lodge a complaint with the Hungarian supervisory authority: the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) (naih.hu), or with the supervisory authority of the EU member state where you live or work. We would appreciate the chance to address your concern first at hello@lavox.app.
10. Children
The service is intended for people aged 16 or older. We do not knowingly process the data of children under 16. If you believe a child under 16 has created an account, contact us and we will delete it.
11. Changes to this policy
When we change this policy, we will post the new version here and update the date at the top. If a change is material, we will also notify you by email or through the service before it takes effect.
See also our Terms of Service.