Verbose
Draft — pending legal review, not yet in force This document is a working draft prepared for human/legal review. It has not been published as final, has no effective date, and creates no rights or obligations until it is reviewed, approved, and published at verbose.sh.

Verbose Privacy Policy

Effective date: to be set on publication.

This Privacy Policy explains what personal data Verbose (the "Service", operated by the operator of Verbose, "the Operator", "we", "us") collects, how we use it, and the choices you have. It applies to the hosted Verbose service and the Verbose desktop application when used in hosted mode.

Data controller: to be named on publication, with a contact address.

1. What Verbose does with your text

Verbose reads text aloud. When you use the hosted Service, the text you choose to have spoken or rewritten (typically text you copy to your clipboard) is sent over an encrypted connection (TLS) to our servers and passed to third-party AI service providers acting as our processors, which perform the text rewriting and speech synthesis. This processing is transient: the text is processed to produce your rewritten text or audio and is not stored in our database. We store a count of characters processed (for usage metering and billing), not the text itself.

Be thoughtful about what you copy and speak: the Service processes whatever text you give it. Do not submit text containing other people's personal data unless you are entitled to process it.

2. Data we collect

CategoryDataSourceWhy
Account Google account subject identifier, email address, basic profile (the Google openid email profile scopes) Google sign-in Create and identify your account; contact you about your account
Device sessions Device identifier, device label you or your system provide, hashed session token, token expiry, revocation status Your device during sign-in Keep you signed in per device; let you or us revoke a device
Billing Stripe customer identifier; billing event records (event type, a cryptographic hash of the event payload) Stripe Manage your subscription. Your payment card is collected and processed by Stripe; we never receive or store full card numbers.
Usage metering Plan, billing period, characters of text processed (counted server-side as units), plan features, trial/grace timestamps Generated by the Service Meter included usage, enforce plan limits, billing
Content (transient) Text you submit for rewriting or speech; the resulting rewritten text and audio You Provide the Service; processed transiently, not stored in our database (see Section 1)
Support Anything you send us when you contact support You Answer you

Stored on your device (not on our servers): your session token, cached account/plan/usage display state, and your local app preferences (playback speed, queue settings, window state). Deleting the app's local data or signing out removes the session material from the device.

We do not collect your Google password (Google sign-in never shares it with us). We do not sell personal data, and we do not use your content to train AI models.

3. Who processes your data

We use these categories of processors and service providers:

We share personal data with these providers only as needed to run the Service, and with authorities where the law requires it.

4. Legal bases (GDPR)

Where the GDPR or similar law applies, we process personal data on these bases:

5. Retention

Retention periods below are proposals pending decision and implementation; they will be finalized before publication.

DataProposed retention (not yet final)
Account recordUntil you delete your account
Device sessionsUntil expiry or revocation; post-revocation period to be decided
Usage meteringTo be decided (billing/tax justification, e.g. current period + N years)
Billing eventsTo be decided (tax/accounting requirement)
Submitted text and audioNot stored (transient processing); log retention to be confirmed, Section 1

6. Your rights

Depending on where you live (including under the GDPR and the CCPA/CPRA), you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to not be discriminated against for exercising these rights.

7. Security

All hosted API traffic uses HTTPS/TLS. Device session tokens are stored only as cryptographic hashes on our servers. Upstream AI provider credentials are held only on our servers, never on your device. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you and the relevant authorities as required by law.

8. International transfers

Your data is processed where our hosting and processors operate.

9. Children

The Service is not directed to children and we do not knowingly collect personal data from children.

10. Changes

We may update this policy. For material changes we will give reasonable advance notice (for example by email or in-app notice) before they take effect.

11. Contact

[email protected]