Verbose Privacy Policy
This Privacy Policy explains what personal data Verbose (the "Service", operated by the operator of Verbose, "the Operator", "we", "us") collects, how we use it, and the choices you have. It applies to the hosted Verbose service and the Verbose desktop application when used in hosted mode.
1. What Verbose does with your text
Verbose reads text aloud. When you use the hosted Service, the text you choose to have spoken or rewritten (typically text you copy to your clipboard) is sent over an encrypted connection (TLS) to our servers and passed to third-party AI service providers acting as our processors, which perform the text rewriting and speech synthesis. This processing is transient: the text is processed to produce your rewritten text or audio and is not stored in our database. We store a count of characters processed (for usage metering and billing), not the text itself.
Be thoughtful about what you copy and speak: the Service processes whatever text you give it. Do not submit text containing other people's personal data unless you are entitled to process it.
2. Data we collect
| Category | Data | Source | Why |
|---|---|---|---|
| Account | Google account subject identifier, email address, basic profile (the
Google openid email profile scopes) |
Google sign-in | Create and identify your account; contact you about your account |
| Device sessions | Device identifier, device label you or your system provide, hashed session token, token expiry, revocation status | Your device during sign-in | Keep you signed in per device; let you or us revoke a device |
| Billing | Stripe customer identifier; billing event records (event type, a cryptographic hash of the event payload) | Stripe | Manage your subscription. Your payment card is collected and processed by Stripe; we never receive or store full card numbers. |
| Usage metering | Plan, billing period, characters of text processed (counted server-side as units), plan features, trial/grace timestamps | Generated by the Service | Meter included usage, enforce plan limits, billing |
| Content (transient) | Text you submit for rewriting or speech; the resulting rewritten text and audio | You | Provide the Service; processed transiently, not stored in our database (see Section 1) |
| Support | Anything you send us when you contact support | You | Answer you |
Stored on your device (not on our servers): your session token, cached account/plan/usage display state, and your local app preferences (playback speed, queue settings, window state). Deleting the app's local data or signing out removes the session material from the device.
We do not collect your Google password (Google sign-in never shares it with us). We do not sell personal data, and we do not use your content to train AI models.
3. Who processes your data
We use these categories of processors and service providers:
- Google — sign-in (OAuth). Google's own privacy policy governs your Google account.
- Stripe — subscription billing and payment card processing.
- DigitalOcean — cloud hosting; our application and managed Postgres database run on DigitalOcean infrastructure.
- Third-party AI service providers acting as our processors — perform text rewriting and speech synthesis on the text you submit, on our instructions, solely to provide the Service.
We share personal data with these providers only as needed to run the Service, and with authorities where the law requires it.
4. Legal bases (GDPR)
Where the GDPR or similar law applies, we process personal data on these bases:
- Contract — account, device sessions, content processing, usage metering, billing: needed to provide the Service you signed up for.
- Legitimate interests — securing the Service, preventing abuse and fraud, enforcing usage limits.
- Legal obligation — tax and accounting records tied to billing.
- Consent — where we ask for it explicitly; you can withdraw it at any time.
5. Retention
| Data | Proposed retention (not yet final) |
|---|---|
| Account record | Until you delete your account |
| Device sessions | Until expiry or revocation; post-revocation period to be decided |
| Usage metering | To be decided (billing/tax justification, e.g. current period + N years) |
| Billing events | To be decided (tax/accounting requirement) |
| Submitted text and audio | Not stored (transient processing); log retention to be confirmed, Section 1 |
6. Your rights
Depending on where you live (including under the GDPR and the CCPA/CPRA), you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to not be discriminated against for exercising these rights.
- Access / export / correction / deletion: contact us at [email protected]. We will verify the request against your signed-in account.
- CCPA note: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use personal information for cross-context behavioral advertising.
- Complaints: you may lodge a complaint with your data protection authority.
7. Security
All hosted API traffic uses HTTPS/TLS. Device session tokens are stored only as cryptographic hashes on our servers. Upstream AI provider credentials are held only on our servers, never on your device. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you and the relevant authorities as required by law.
8. International transfers
Your data is processed where our hosting and processors operate.
9. Children
The Service is not directed to children and we do not knowingly collect personal data from children.
10. Changes
We may update this policy. For material changes we will give reasonable advance notice (for example by email or in-app notice) before they take effect.