Privacy Policy
This Privacy Policy explains how Weyvox collects, uses, shares, and protects your personal data, and the rights you have under Regulation (EU) 2016/679 (the GDPR) and the French Data Protection Act (Loi n° 78-17 du 6 janvier 1978, as amended). Weyvox is a communication app for iPhone and Android that includes a personal AI voice agent, calls, real phone numbers, and messaging. This policy covers both the app and the weyvox.com website.
1. Who is responsible for your data
Data controller: Petro Solianyk, operating as an individual entrepreneur (auto-entrepreneur / micro-entreprise) registered in France.
SIREN: 101 887 248
Country / governing law: France (European Union).
Contact for privacy requests: support@weyvox.com
The controller decides why and how your personal data is processed. We have not appointed a Data Protection Officer, as we are not required to under Art. 37 GDPR; the contact above handles all privacy matters.
2. What data we collect
Account & profile
Your phone number (your identity in Weyvox — used to create and sign in to your account; no email address is required), and your profile: first name, last name, date of birth, gender, and an optional profile photo (see “Your profile photo” below for who can see it). Sign-in is confirmed with a one-time SMS code generated and verified by our SMS provider; we do not store the codes — they expire within minutes, and we keep only short-lived anti-abuse counters.
Contacts
Contacts features are optional and rely on the iOS contacts permission — nothing is read until you grant it:
- Contact discovery and "X is now on Weyvox!" notifications — with your permission, the app periodically syncs your address book to our servers: the phone numbers (in international format) and the names as you saved them — no emails, photos, or other contact fields. This is the same model messengers such as Telegram use, and it powers three things: the Weyvox mark shown next to contacts who are registered, opening a chat by number, and a one-time notification when one of your contacts joins Weyvox — shown to you under the name you saved for that person. The reverse is equally true: when you register, users who already have your number in their synced address book are notified that you joined, under the name they saved for you. The synced copy is never shown to other users and is never used for advertising. Deletion: entries you remove from your address book are removed from our servers at the next sync; revoking the contacts permission deletes the entire server copy the next time you open the app's Contacts tab; deleting your account deletes it as well.
- The AI agent's contact book — if you enable the agent's contacts capability, a snapshot of your contacts (names and phone numbers) is uploaded to our servers so the agent can act on requests like "call mum". The snapshot is replaced when your address book changes and is deleted from our servers immediately when you turn the capability off.
Your profile photo
If you set a profile photo, it is shown to people you communicate with — in their chat list, in the chat itself, in their Contacts list when your number is saved in their address book, and on your contact card. That is what makes a profile photo useful: it identifies you to the person on the other side, the same way it does in any messenger.
Viewing only. Other users can see your photo and nothing more. They cannot change it, delete it, or attach it to their own profile: uploading, replacing and deleting a profile photo are restricted to the account that owns it, and our servers reject any attempt to point one account's profile at another account's photo.
Your control. You can change or remove your profile photo at any time in Settings → Personal information. A removed photo stops being served, and deleting your account deletes it as well. A profile photo is entirely optional — without one, other users simply see your initials.
What we do not do. Your photo is not published on any public page, not listed in any directory, not shown to people you have no connection with, and never used for advertising or for training AI models.
Last seen and online status
So that the person you are chatting with can tell whether you are around, the app records when it was last open on your device and whether it is open right now. This is shown in the chat header as “online” or a last seen time, in the same way messengers such as Telegram show it. We keep one such record per account — the latest time only, not a history of your sessions.
Your control. In Settings → Notifications → Privacy → Last seen you choose who may see it: Everyone, My contacts (only people whose number is saved in your own address book), or Nobody. People who are not allowed to see it are shown only an approximate indication (“recently”, “within a week”, “within a month”, “a long time ago”) and never the exact time. This works both ways: if you restrict your own last seen time, you will likewise see only an approximate indication for everybody else. People you have blocked, or who have blocked you, see nothing at all.
The check is performed on our servers, not in the app: when you are not allowed to see someone's exact time, the app is never sent it in the first place.
Messages & media
Personal chats in Weyvox are end-to-end encrypted — section 10 describes exactly how. For storage this means: the text of your messages and every attachment (photos, videos, files, voice messages, albums, captions, locations you choose to share) reach our servers only as encrypted envelopes and encrypted files we cannot decrypt. We store this ciphertext so it can be delivered to the recipient's device and re-downloaded by your own device; the keys that could open it exist only on your and your correspondent's phones.
What our servers do see — because no messenger can deliver messages without it — is delivery metadata: which conversation a message belongs to, who sent it and when, its sequence number and its type (text / attachment / album / voice / call record), reply and forward references (identifiers only — the quoted text itself travels inside the encrypted envelope), emoji reactions, read cursors and unread counters, and, for attachments, the encrypted file's size and a generic content type needed to accept the upload (the real file name, dimensions and caption travel encrypted). Section 10 lists this openly.
Custom chat wallpapers are decoration you pick for your own screen, not messages; they are stored for your account in access-controlled storage, encrypted at rest.
Calls
- Call metadata — for all calls: the parties, direction, date, time, duration and outcome, kept as your call history; for calls to real phone numbers, also the routing and cost data needed to connect and bill the call.
- Call audio — calls are transmitted in real time. We do not keep call audio, with one exception: when AI call notes are enabled (see section 4), the call is recorded solely to produce the note, and the audio is deleted immediately after transcription.
AI call notes (recordings and transcripts)
When you enable AI notes, a recording of the call is transcribed to text and summarised into a short note. Exact lifecycle, verified in our systems:
- the audio exists only for the time needed to transcribe it — for Weyvox-to-Weyvox calls each device uploads its own audio track, and the file is deleted right after our transcription service fetches it (minutes); for operator calls the recording is made by our telephony carrier and used only for transcription;
- the transcript — the verbatim record of what was said — is kept for 24 hours, so that you can ask the agent follow-up questions about the call while it is still fresh, and is then deleted automatically; turning notes off mid-call discards the captured transcript at once;
- the resulting note is ordinary chat content in your account — it stays until you delete it or delete your account.
AI agent data
The instructions you give the agent, its task journals and results, and a per-user agent memory (facts it saves to help you, which you can review and fully clear in the app). Transcripts of phone calls the agent makes for you are kept for 24 hours so you can ask follow-up questions about the call, then deleted automatically; the short call note remains in your chat. Each user's agent data is isolated and used only to provide the agent to that user.
Document templates
If you use PDF templates (Settings > PDF templates), we store what you put in them: the details you issue documents under — name or company name, address, tax or registration number, bank details, email, phone — an optional logo you upload, the per-type defaults (payment terms, signatory, salutation and so on) and any custom field you add. You may enter these yourself, or the agent may write them into a template on your instruction; either way they are yours to edit or clear at any time on that page, and they are deleted with your account. A template is meant to hold your own details, not a third party's — when the agent produces a document for someone else, that party's details belong in the document itself, not in your template.
The documents themselves are not stored by us. A PDF the agent writes for you — and a PDF export of a task report — is generated on your phone and saved nowhere on our servers; we hold no copy of it, and it never counts toward your media storage. What the document was built from (your instructions in the chat and your template) is covered by the sections above.
When the agent is on a call, it also estimates the pitch of the other person's voice in real time, for one narrow purpose: to address them with the correct grammatical gender in languages that require it. The estimate exists only for the duration of the call, is never stored, and is not used for anything else — not for profiling, not for identification, and not for any decision about that person.
Business documents
If you use Business management (Settings > Tools), you can upload the paperwork of your business — contracts, invoices, tax filings, registration papers, supplier and HR files, licences. We store the file itself, the metadata extracted from it (document type, counterparty, number, date, amount, expiry date), a text extract used for search, and any links you make to a customer or an order. These files count towards your storage allowance and are erased when you delete the document or your account.
These documents are NOT end-to-end encrypted — unlike your chats — and we say so plainly on the upload screen, every time. They cannot be: the whole point of the feature is that the AI agent can answer questions about a document, and end-to-end encryption would mean only your device could read it. Those two requirements are mutually exclusive, and we chose readability. Concretely this means: the file is stored encrypted at rest and in transit, but we hold the keys, so our systems and the AI provider processing the document can read its content — whereas with your messages neither we nor anyone else can.
Two consequences you should know before you upload anything sensitive. First, a document is read once when you upload it — sent to our AI provider to extract the text and metadata — and again only if you ask the agent a question its extract cannot answer. Files of 8 MB or more are uploaded to the AI provider’s file storage to be read; we delete them from there automatically within 24 hours, and an hourly clean-up enforces this. Second, you can exclude any single document from the agent entirely: the switch “Do not let the agent read this” on the document’s page erases its text extract and search index, so the document stays stored and visible to you while the agent cannot find or read it. This is a per-document choice, not an all-or-nothing one.
Voice providers are not involved here: business documents never enter the call pipeline.
Keypad tones on agent calls (DTMF)
When the agent navigates a phone menu for you ("press 1 for bookings"), it sends keypad tones (DTMF) on the call. The digits it presses can be sensitive — a booking reference, an account number, a code you dictated. They are handled accordingly: each sequence is transmitted to our telephony carrier over an encrypted connection solely to press the keys on that call, is not stored anywhere after the key presses are delivered, and our technical logs record only that keys were pressed and how many — never which ones.
Agent voice and voice cloning
You choose the voice your agent speaks with on calls: a ready-made voice, or a clone of your own voice. If you clone your voice, you record a short sample in the app; it is used to build a voice model — held by our text-to-speech provider as our processor — so the agent can speak in a voice modelled on yours. It is your own voice only (you cannot clone anyone else's), used solely for your own agent, is not shared with other users, and you can delete it at any time in Settings, which removes the voice model. We rely on your explicit consent for this (Art. 6(1)(a) GDPR, and Art. 9(2)(a) to the extent a voice model is treated as biometric data); you give it by recording and enabling the clone, and withdraw it by deleting the clone.
Location
If you allow location and the agent's location capability is on, your approximate coordinates are sent with a request when the agent needs nearby results ("find a pharmacy near me"). Location is used per request and not stored on our servers.
Identity documents for phone numbers (KYC)
Some real phone numbers can only be registered with identity information, because telecom regulations and our carrier require it. In that case, during the purchase you upload the requested documents (for example an identity document or proof of address) and form details (such as name, date of birth, address). We use them for one purpose only — submitting your number registration to the carrier — and keep them only as long as the application needs them:
- while your application is in progress, documents are stored encrypted at rest in a private storage bucket, separate from ordinary chat media;
- once the number is activated, the documents, the form details and the application record are automatically and permanently erased within 24 hours;
- a document you replace or remove during the application is purged from storage within about 3 hours;
- if the application is cancelled or expires, the same automatic clean-up removes its data; deleting your account removes it as well.
Billing & usage
Your prepaid balance, top-up transactions (processed by the App Store — we never receive or store card details), and usage records (per-day, per-operation charges: calls, agent usage, notes, storage) needed to charge your balance and show your history.
Technical & device data
Push-notification tokens, a device/app identifier, IP address, and short-lived technical logs generated when the app talks to our servers — used to deliver calls and notifications, keep the service secure, and diagnose problems. Weyvox uses no third-party advertising, analytics, or tracking SDKs in the app.
Reports of abusive content
Because personal chats are end-to-end encrypted, our servers cannot open a reported conversation — so the evidence comes from the reporter's device. When you report a message, your app decrypts, on your phone, the reported message (its text and its attachments) and a short window of surrounding messages for context, and transmits them to moderation together with the reason you selected and your optional comment. The report screen tells you this before you send. We receive nothing else from the conversation, and we cannot pull anything more from our servers — they hold only ciphertext. The submitted snapshot is kept even if the author later deletes the message — otherwise a report would lose its subject exactly when it matters. Reporting an account (rather than a specific message) sends no conversation content at all.
The evidence may contain another person's messages. That is lawful because you are a participant in that conversation and you decide what to send us, but we state it explicitly here: by reporting a message you are transmitting to us content authored by someone else, decrypted by your own device for that purpose. Reports and their evidence are accessible solely to our moderation systems and to the publisher; they are never shared with the person you reported, and the person you report is never told who reported them. If you are reported, you are told which rule was broken — not by whom. And because device-submitted material could in principle be fabricated, an indefinite block in an end-to-end-encrypted case is never applied automatically — only a human moderator can confirm it (see section 8).
Website visitors (weyvox.com)
- The site sets no advertising or analytics cookies and uses no trackers.
- The on-site demo assistant answers questions about Weyvox. It has no access to any user account or data. Messages you type are processed by our AI provider to generate the reply and are not stored by us afterwards; your IP address is kept for 3 hours solely for rate limiting, then deleted automatically.
- Our hosting/CDN provider processes standard connection data (such as IP addresses) to serve and protect the site.
Support
If you contact us, we keep your message and contact details for as long as needed to resolve your request.
3. Why we use your data and our legal bases
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Providing the service | Account, profile, messages & media, call metadata, agent data, balance & usage | Contract — Art. 6(1)(b) |
| Registering a real phone number | KYC documents and form details | Contract — Art. 6(1)(b); compliance with carrier/regulatory identification requirements — Art. 6(1)(c) |
| AI call notes (recording & transcription) | Call audio, transcript | Consent — Art. 6(1)(a): you switch notes on, and can turn them off at any time |
| Contact discovery & "joined Weyvox" notifications | Synced address book (numbers + names as saved) | Consent — Art. 6(1)(a): you grant the iOS contacts permission, and revoking it deletes the server copy. Matching numbers against new registrations (including numbers of people not yet on Weyvox) — legitimate interests, Art. 6(1)(f), limited to numbers and names with no other contact fields |
| Agent contact book, location for the agent | Contacts snapshot; per-request location | Consent — Art. 6(1)(a), withdrawable at any time in settings |
| Showing your last seen / online status to people you chat with | Time the app was last open on your device; whether it is open now | Contract — Art. 6(1)(b): it is part of the messaging experience. You control who sees it, and can restrict it to your contacts or switch it off entirely in settings |
| Agent voice cloning (your own voice) | Voice sample and the derived voice model | Consent — Art. 6(1)(a), and Art. 9(2)(a) where treated as biometric; withdrawn by deleting the clone |
| Billing, accounting and tax records | Top-up and charge records | Legal obligation — Art. 6(1)(c) (French commercial and tax law) |
| Security, anti-fraud, anti-abuse, service reliability | Technical data, logs, rate-limit counters | Legitimate interests — Art. 6(1)(f) |
| Answering support requests | Your messages and contact details | Legitimate interests — Art. 6(1)(f) |
Where we rely on legitimate interests, we have balanced them against your rights; you may object at any time (see section 9).
4. Call recording and AI notes — your responsibility
5. Who we share data with
We do not sell your personal data and we do not share it with advertisers. To run Weyvox we rely on a small number of service providers ("processors") acting on our documented instructions under Art. 28 GDPR contracts. They fall into the following categories:
- App store and payment platform — app distribution, in-app purchases, push notifications.
- Telephony carrier — real phone numbers, routing of calls to and from regular phones, and — where regulations require — receiving the KYC information you provide to register a number (the carrier processes it under its own regulatory obligations).
- Cloud hosting, database and storage providers — running our servers and storing account data and the encrypted envelopes and encrypted media files of your chats (which neither we nor they can decrypt).
- AI processing providers — speech-to-text, text-to-speech, and the language models that power the agent, the notes, and the website demo assistant. They process this content as processors, solely to provide the feature to us.
- A mapping/location provider — only when the agent needs place information for a task.
- An email provider — for messages you send to our support address.
We may also disclose data where required by law, or to protect our rights, our users, or the public. A current list of the specific sub-processors is available on request at support@weyvox.com.
6. International data transfers
Some providers process data outside the European Economic Area (notably in the United States). Where that happens, we rely on safeguards recognised by Chapter V GDPR — an adequacy decision (such as the EU–US Data Privacy Framework, where the provider is certified) and/or the European Commission's Standard Contractual Clauses, with supplementary measures where appropriate. You can request more information about these safeguards at the contact address above.
7. How long we keep your data
We keep personal data no longer than needed for each purpose. The concrete periods, as implemented in our systems:
| Data | Retention |
|---|---|
| Account, profile, messages and media (held as end-to-end-encrypted ciphertext — see section 10), call history, AI notes, agent memory | Life of your account; erased when you delete your account (numbers are released with the carrier; media storage is wiped) |
| Media that no chat participant keeps any more | Physically erased by a nightly clean-up |
| Call audio recorded for an AI note | Deleted immediately after transcription (minutes) |
| Call transcripts and note drafts | 24 hours, then deleted automatically; discarded at once if you turn notes off |
| Transcripts of agent-made calls (follow-up context) | 24 hours |
| Business documents (file, extracted metadata and text extract) | Life of your account, or until you delete the document; a copy held by the AI provider for reading large files is deleted within 24 hours |
| Server-side backup of your agent chat history (restore on a new or lost phone) | Life of your account; deleted when you delete your account |
| Synced address book for contact discovery (numbers + names) | While you use contact sync; entries removed from your address book are deleted at the next sync; revoking the contacts permission deletes the whole server copy at the next visit to the Contacts tab; deleted with your account |
| PDF templates (issuer details, logo, per-type defaults) | Kept until you change or clear them on the PDF templates page; deleted with your account. Documents generated from them are never stored by us |
| Agent voice clone (voice sample and model) | Kept while you keep the clone enabled; deleted when you remove it in Settings or delete your account |
| KYC documents and form details for a number purchase | Only while the application is in progress; erased automatically within 24 hours after activation (replaced/removed uploads — within ~3 hours; cancelled applications are cleaned up the same way) |
| Reports of abusive content and the evidence submitted from the reporter's device | 90 days after the case is closed. Cases involving illegal content (child sexual abuse material, terrorism, human trafficking) are kept longer as evidence and for any reporting obligation to the authorities |
| End-to-end encryption keys of your chats | Never stored by us — they exist only on your phone (see section 10) |
| Moderation record of an account (confirmed violations, warnings, blocks) | Life of the account. Counters and the sanction ladder reset automatically after 12 months without a new confirmed violation |
| Last seen / online status | A single latest value per account, overwritten every time the app is opened or closed — no session history is kept; deleted with your account |
| Per-operation usage records | 90 days, then the whole day's records are deleted |
| Top-up and billing records | Statutory accounting periods under French law (up to 10 years) |
| Sign-in SMS codes | Not stored by us; expire within minutes at the provider |
| Website demo-chat IP (rate limiting) | 3 hours |
| Technical logs | Short rotation windows used for operations and security |
Deletion covers your device as well. When you delete your account in the app, the app erases not only the server copy of your data but also what it kept on your phone: the local encrypted message databases together with their encryption key, the end-to-end encryption identity keys of your chats, and cached or temporary media files (including decrypted previews the app had prepared for display). Security credentials the app stores in the iOS Keychain are marked this-device-only, so they are never copied to your other devices through iCloud keychain sync — the only way they ever move is the device-to-device QR transfer described in section 10.
Residual copies may persist briefly in backups before being overwritten in the normal backup cycle.
8. Automated processing and the AI agent
The AI agent acts only on your instructions and within the capabilities you have switched on. For any concern about an action performed by the agent, you can always reach a human at the contact address above.
Content moderation is the one place where we do decide about you automatically. When someone reports a message or an account, the report is triaged by an AI system, and for clear-cut cases the resulting sanction — a warning or a temporary block — is applied without a person in the loop. Because a block restricts your access to a paid service, we treat this as automated decision-making under Art. 22 GDPR and rely on the ground that it is necessary for the performance of our contract with you (Art. 22(2)(a)) and for the safety of other users. The safeguards are deliberate and are described in full in the Community Rules:
- the heavier the consequence, the higher the confidence the system must have before acting on its own;
- anything uncertain, contested, or severe is escalated to a human for decision;
- for reports on end-to-end-encrypted messages, the system judges only the material submitted from the reporter's device, and an indefinite block is never applied automatically in such cases — only a human can confirm it;
- an account is never deleted automatically — automation can block, only a person can delete;
- you are told which rule was found to be broken and what sanction applies, and you have the right to obtain human intervention, express your point of view and contest the decision by writing to support@weyvox.com. A decision found to be wrong is reversed and the counters corrected.
AI transparency. Because the agent speaks with other people on your behalf, it always identifies itself as an AI assistant at the start of every call — on outbound calls, on auto-answered incoming calls, and when it takes over a live call — in line with Article 50 of the EU AI Act (Regulation (EU) 2024/1689), which requires that people are informed they are interacting with an AI system at the latest at the first interaction. This is a built-in rule you cannot switch off. The agent speaks in an AI-generated voice; if you have chosen to clone your own voice, this same spoken disclosure ensures the other party is never misled into thinking a human is speaking, and the clone is only ever your own voice, never an impersonation of someone else.
9. Your rights
Under the GDPR you have the right to: access your data; rectify inaccurate data; erase your data ("right to be forgotten"); restrict or object to certain processing (including any processing based on legitimate interests); data portability; and to withdraw consent at any time (e.g. switch off AI notes, the agent's contacts or location) without affecting prior processing. You can delete your account and its data directly in the app at any time (Settings → Account → Delete account).
Under Art. 85 of the French Data Protection Act, you also have the right to give directives about what happens to your data after your death; you can send them to the contact address.
To exercise any right, contact support@weyvox.com — we respond within one month, as the GDPR requires; we may ask you to verify your identity from the phone number on the account. You also have the right to lodge a complaint with the French supervisory authority, the CNIL (Commission Nationale de l'Informatique et des Libertés), 3 place de Fontenoy, 75007 Paris — www.cnil.fr.
If you are not a Weyvox user
Your number can reach our systems without you ever installing Weyvox — because someone who has you in their phone book synced their contacts, or because our AI agent placed a call to you on a user's instruction. You do not need an account, and you do not need to write to us, to put a stop to that.
Go to weyvox.com/optout/ and block your number. You confirm the number by SMS, and the block takes effect immediately: the number can no longer register a Weyvox account, calls to and from it through Weyvox are refused, it is removed from every synced address book on our servers and is rejected from future syncs, and it neither triggers nor receives "contact joined" notifications. The whole process is automatic — no document, no waiting, no review.
The block is not permanent by force: you can lift it yourself on the same page, confirming the number by SMS again. This matters because phone numbers get reassigned — whoever holds the number later must not be locked out by a decision they never made.
One order applies: if the number currently has a Weyvox account, delete the account in the app first (Settings → Account → Delete account), then block the number.
10. Security and encryption
We use technical and organisational measures appropriate to the risk (Art. 32 GDPR): encryption in transit, private storage buckets for sensitive files (including KYC documents), per-user data isolation enforced at the API and database level, access controls and least-privilege keys, and the automatic deletion schedules described above — the most sensitive data (call audio, transcripts, identity documents) is designed to exist for the shortest possible time. No system is perfectly secure, but if a breach occurs we will notify the CNIL and, where required, you, in line with Arts. 33–34 GDPR.
End-to-end encryption of personal chats
Personal conversations in Weyvox are end-to-end encrypted: message texts, photos, videos, files, voice messages, albums, captions and shared locations. Encryption and decryption happen on the participants' phones; our servers relay and store only ciphertext they cannot read.
How it works, concretely. Each device generates an identity key pair (Curve25519) inside the phone's secure Keychain; the private half never leaves the device and is never sent to us. For every conversation, the two devices independently derive the same conversation key from their key pairs (X25519 key agreement with HKDF-SHA256) — there is no key server, no key distribution and no key escrow. Messages are sealed with ChaCha20-Poly1305 authenticated encryption and cryptographically bound to the exact message and conversation they belong to, so a ciphertext cannot be moved or replayed into another chat. Every media file is additionally encrypted with its own random 256-bit key, generated for that one file and travelling only inside the encrypted message envelope; forwarding a file never exposes the key of the conversation it came from. All of this runs on Apple's own cryptography (CryptoKit) on your device. We do not have, and cannot obtain, the keys to your conversations — which also means we could not hand your message content to anyone else: a lawful-order request can reach only the ciphertext and the metadata described below.
What stays visible to us — deliberately, and listed openly. A messenger cannot route, order, deliver and bill messages without some metadata. Our servers see: which conversation a message belongs to and its ordering numbers; who sent it and when (and when it was edited); the message type (text / attachment / album / voice / call record); reply and forward references as identifiers (the quoted text itself is encrypted); emoji reactions; read cursors, unread counters and online status; and, for attachments, the size of the encrypted file and a generic content type (the real file name, dimensions and caption are encrypted). This metadata is protected in transit (TLS) and at rest, isolated per user by row-level policies enforced in the database itself, and media ciphertext is reachable only through short-lived signed links, never a public URL. The app contains no advertising or analytics SDKs.
What is not end-to-end encrypted — stated honestly:
- SMS and calls to regular phone numbers pass through the public telephone network, which by its nature cannot be end-to-end encrypted. The app marks such conversations accordingly.
- The Weyvox system chat and the moderation chat are written by our servers — encrypting them "end-to-end" against ourselves would be meaningless.
- Your chat with the AI agent lives on your phone with a server-side backup (see below) — it is not part of the end-to-end-encrypted personal chats, because the agent's replies are produced on our side.
- An AI call note, when you enable it, lifts end-to-end protection for that one call: the call audio is transcribed and summarised on our side to produce the note (with the lifecycle in section 2), and the resulting note is delivered to your chat.
- App-to-app voice and video calls are encrypted end-to-end in transit (WebRTC); nothing of their content is stored unless you enable an AI note.
One phone, key transfer by QR code — and what happens if you lose the phone
A Weyvox account is active on exactly one phone at a time, and your encryption keys exist only on that phone. When you change phones, the app moves the keys directly between the two devices with a two-QR-code handshake (Settings → Account → Move to a new device): the new phone displays a code, the old phone scans it and displays a sealed reply, encrypted to the new phone with fresh one-time keys. The keys never touch our servers — not even in encrypted form. After a successful transfer, the old phone is signed out automatically. Signing in on a new phone with an existing account always shows this transfer guide first.
The honest consequence: if your phone is lost, broken or erased before you transferred the keys, your encrypted chat history is permanently unreadable — for everyone. Not for us, not for you on a new phone, not for any authority: no copy of the key exists anywhere except on that phone. The keys are deliberately marked this-device-only, excluded from iCloud Keychain sync and from device backups, and there is no backdoor, no recovery procedure and no support request that can restore them. Your account itself survives — you sign in on the new phone with your number and keep your balance, your purchased phone number, your agent's memory and its chat history (restored from its backup); new conversations simply start with fresh keys, and your contacts see a "key changed" notice in the chat. We would rather state this trade-off plainly than quietly hold a key copy that would defeat the encryption.
The AI agent and your encrypted chats
End-to-end encryption changes what the agent's chat access means: it is device access, not server access. When you open the agent inside a personal conversation (a per-feature toggle, off by default), your own phone decrypts the recent messages you see — and, when your question concerns them, the specific attachments — and hands them to the agent together with your request. The agent sees exactly what your device chose to send for that request, nothing more; our servers still cannot read the conversation on their own, and there is no server-side path by which the agent could "look something up" in your chats. The agent is also barred from copying another person's messages into its long-term memory. The same applies on calls: the agent no longer receives any digest of your correspondence with the person you are talking to.
Your conversations with the AI agent
Your chat history with the Weyvox agent lives on your phone, in a local database on the device — that is what the app reads and displays. We also hold a server-side copy for one purpose only: so that you can restore your history when you change your phone or lose it. That copy exists as a backup, not as a working store: it is never shown to other users, never used to train any model, and it is deleted when you delete your account. To generate each reply, the message is transmitted to the AI provider whose model produces the answer and is processed there as our processor under a data-processing agreement (Art. 28 GDPR); we do not retain it there. What we do keep, deliberately and visibly to you, is the agent's long-term memory (facts you asked it to remember or that it learned while helping you — you can review and erase them at any time), the background tasks it is running, and transcripts of calls it made, kept for 24 hours so you can ask follow-up questions about a call.
11. Children
Weyvox is not intended for children. In line with our Terms of Use, you must be at least 18 years old to use Weyvox; your date of birth is collected at registration and registrations below this age are refused. We do not knowingly collect data from anyone under 18; if you believe a minor has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will change the "Last updated" date above and, for significant changes, notify you in the app or by other appropriate means before they take effect.
13. Contact
For any privacy question or request: support@weyvox.com.