Who this policy covers
Two different people use AmphiVox, and the difference matters:
| Term | Who they are |
|---|---|
| Creator | Someone with an account who builds a form and shares it. |
| Respondent | Someone who answers a form by speaking. Respondents do not need an account and usually have none. |
For answers submitted through a form, the Creator decides what is asked and why. They are responsible for that data. We only process it on their behalf, to run the form and deliver the responses where they have chosen. In data-protection terms the Creator is the controller and AmphiVox is the processor.
If you answered someone’s form and want your answers corrected or deleted, contact the person or organisation whose form you filled in — they hold that data. If you cannot reach them, write to us at contactus@amphivox.com and we will help where we can.
For a Creator’s own account details, we are the controller and this policy governs directly.
What we collect
From Creators
| What | Why we have it |
|---|---|
| Name and email address | From your Google sign-in, to identify your account. |
| Your forms | The questions and settings you create. |
| Connected account credentials | If you connect Google Sheets, Google Drive or Microsoft Excel, we store access tokens so responses can be delivered there. These are encrypted. |
| Usage records | Session counts, durations and processing costs per form, so you can see your usage. |
From Respondents
| What | Why we have it |
|---|---|
| Your speech | Captured while a voice session is running, to work out your answers, and — only if you choose to dictate one — while you record a short feedback note. See section 3. |
| Your answers | Whatever the Creator’s form asks for. This may include your name, email, phone number, address or uploaded files. |
| Session technical data | Connection identifiers and timings, so a session can run and be debugged. |
Voice data
This is the part most people want to know about, so it is stated plainly.
- Your microphone is used in two places, and only after your browser asks your permission: while a voice session is running, and if you choose to dictate a note on the optional feedback card shown after a session. You can refuse, or stop at any time.
- Recordings of your voice are not saved. Audio is streamed to a speech-recognition provider, converted to text, and discarded. It is never written to a file or database.
- Dictating feedback. The feedback card that can appear after a session lets you speak a short note instead of typing it, up to 30 seconds. If you use it, the recording is sent to our speech-recognition provider once, converted to text, and discarded — the audio is never stored. Only the resulting text is kept, and only if you choose to send it. Typing is always available instead, and dictation is never started without you pressing the microphone button.
- The text of what you said is sent to an AI model so it can work out which answer belongs in which field.
- While the session runs, your answers are held in memory only. When the session ends they are discarded. Only what you actually submit is stored.
- Diagnostic logs. To debug faults, our servers write operational logs that can include the text of a conversation and the answers collected during it. These logs are automatically deleted after 7 days and are not used for any other purpose.
Why we process it
| Purpose | Basis |
|---|---|
| Running a voice session and filling in a form | Necessary to provide the service you asked for |
| Using your microphone | Your permission, given in the browser and withdrawable at any time |
| Delivering responses to the Creator | On the Creator’s instructions, as their processor |
| Keeping you signed in | Necessary to provide the service |
| Debugging faults and preventing abuse | Our legitimate interest in a working, non-abused service |
We do not use this data for advertising, profiling, or automated decisions that produce legal or similarly significant effects about anyone.
Google user data
If you connect a Google account, we request only the following access. Each permission exists for one specific feature.
| Permission | What it is used for |
|---|---|
| Google Drive & Sheets | Covers both file-upload storage and Google Sheets delivery. For each, AmphiVox works only inside the one Drive folder or the one spreadsheet you set for that form — one it creates for you, or an existing one you select with Google’s file picker. |
| Email address | Shows which Google account is connected, so you can confirm you linked the right one. |
Limited Use. AmphiVox’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically: we do not transfer Google user data to third parties except as needed to provide or improve the features you have enabled, to comply with applicable law, or as part of a merger or acquisition. We do not use Google user data for advertising, and we do not allow humans to read it except with your explicit permission, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymised.
If you connect Microsoft Excel instead, the permission Microsoft grants covers your files generally rather than a single workbook. We only ever use it to create and write to the one workbook set as a form’s destination.
You can disconnect at any time from within AmphiVox, or revoke access directly at your Google account permissions page.
How long we keep data
| Data | Kept for |
|---|---|
| Voice recordings | Not kept — discarded as the session runs |
| A dictated feedback note (the audio) | Not kept — transcribed once, then discarded |
| Answers collected during a session | Held in memory only; discarded when the session ends |
| Diagnostic logs (may contain conversation text) | 7 days, then deleted automatically |
| Submitted responses stored in AmphiVox | Until the Creator deletes the form they belong to. We do not currently impose an automatic time limit. |
| Creator account details | Until the account is deleted |
| Connected account credentials | Until you disconnect the integration or delete the form |
| Device identifier record (see section 10) | 30 days on our servers; the related cookie lasts 1 year |
Responses delivered to a Creator’s own Google Sheet, Excel workbook or Drive folder are held in their account, under their control and their retention choices — not ours.
When you disconnect Google Sheets or Google Drive, or delete your account, we actively revoke that connection with Google, not just delete our own record of it — so the permission you granted no longer works, rather than sitting unused. Microsoft does not offer an equivalent way for us to revoke a single connection, so an Excel connection is deleted from our records but the permission itself is only fully removed if you also remove it from your Microsoft account.
We keep an internal record of session counts and processing costs per form for our own accounting, even after the account or form is deleted. It contains no answers, no names, and no other personal content — only usage totals.
Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to the processing of your personal data, to withdraw consent, and to receive a copy of your data. You can also complain to your local data protection authority.
To exercise any of these, write to contactus@amphivox.com. We may need to verify who you are before acting. We aim to respond within 30 days.
Creators can delete an individual form at any time from within the product, which also deletes the responses, connected credentials and widget keys belonging to it. You can also delete your entire account yourself, at any time, from your Profile page — this immediately and permanently deletes your account, every form you own, and everything listed under section 7. If you can’t access your account, email us at the address above and we will action it for you.
If you were a Respondent, see section 1 — the Creator of the form controls your answers, so please contact them first.
Security
Measures currently in place:
- All traffic to the service is encrypted in transit using HTTPS.
- Submitted responses are encrypted before they are stored, using authenticated symmetric encryption (Fernet, AES-128-CBC with HMAC).
- Credentials for connected Google and Microsoft accounts are encrypted before storage.
- Sign-in tokens are held in HTTP-only cookies, which scripts on a page cannot read.
- Voice sessions run in isolated processes with a hard duration limit.
No system is perfectly secure and we cannot guarantee absolute security. If you find a vulnerability, please report it to contactus@amphivox.com.
Artificial intelligence
When you use a voice form, you are talking to an AI system, not a person. It listens to your answers, decides which field each answer belongs to, and asks follow-up questions.
Speech recognition and AI interpretation make mistakes. You can review every answer on screen before submitting, and correct anything that was misheard. Nothing is submitted until you choose to submit it.
The AI does not make decisions about you that have legal or similarly significant effects. It only fills in a form.
Is what I say used to train AI models?
No. AmphiVox does not train, fine-tune or improve any AI model using your speech, your answers, or anything else you send us. We do not build AI models at all. The providers we pass data to are committed to the same under the terms that apply to our account:
| Provider | What their terms give you |
|---|---|
| Google — Gemini, the AI that runs the conversation and reads any form image a Creator uploads | We use it on a billed account, which makes it a paid service under Google’s terms. Google does not use what we send, or what it sends back, to improve its products or train its models. It keeps a copy for a limited period — up to 55 days — solely to detect abuse and policy violations. |
| Google Cloud — speech recognition and speech synthesis | Audio and transcripts are not logged at all by default. The optional programme that would let Google use them to improve the service is opt-in, and we have not enabled it. Google’s cloud terms separately commit it not to train AI models on customer data without permission. |
| Sarvam AI — speech recognition and synthesis for Indian languages, and transcription of a dictated feedback note | Training on customer content is off by default and requires explicit opt-in consent. We have not opted in. |
Those are the providers’ own commitments, checked on 3 September 2026. We do not control their terms and they can change them. If a change affects what happens to your data, we will update this policy.
The short-lived copies described above are held by those providers for security purposes, under their own policies. They are separate from the diagnostic logs on our own servers described in section 3, which we delete after 7 days.
Voice and biometric data
We do not create voiceprints and we do not identify anyone by their voice. Your speech is used for one purpose only: converting what you said into text so it can be placed in the right field.
We do not use voice to authenticate or verify identity, we do not attempt to detect emotion, and we do not categorise people by voice characteristics.
Children
AmphiVox is not intended for anyone under 18, and we do not knowingly collect their data. If you believe a child has provided data to us, contact contactus@amphivox.com and we will delete it.
Creators are responsible for not directing forms at children without a proper legal basis and any parental consent their local law requires.
Changes and how to contact us
We may update this policy. The “last updated” date at the top always reflects the current version. If we make a significant change we will make that clear on this page.
For any privacy question, request or complaint, email contactus@amphivox.com.
See also our Terms of Service.