Privacy Policy

Effective July 24, 2026

Voco is a voice-first calorie and macro tracker for iPhone (App Store bundle fit.voco.app). This policy explains what Voco collects, why, where it lives, and the control you have over it. It is written to be read: plain language, short sections, no claims the code cannot back up.

Who we are

Voco is built and operated by Saketh Thippireddy, an individual doing business as Voco, based in Texas, United States ("Voco," "we," "us"). For privacy purposes, that individual is the data controller of the personal data described here. Questions go to hello@voco.fit (see Contact).

Some of the data Voco handles relates to your body and diet, so we also publish a dedicated Consumer Health Data Privacy Policy. It covers the same practices described here, in the format some state health-privacy laws require.

What we collect

We collect what the app needs to work, and that is it:

We do not collect your contacts, photos, location, or any advertising identifier. There are no ad SDKs in the app, and we do not track you across other apps or websites.

Voice recordings

This is the part people care about most, so here is exactly what happens.

When you log a meal by voice, the app sends that short clip to our server, which passes it to a speech-to-text service and gets back a transcript. The transcript is then interpreted by an AI model into foods and estimated macros, and you confirm the result before it is saved.

Voco does not store your audio. There is no code path that writes the recording to any database, file store, or bucket; the server processes the clip in memory and moves on. What Voco keeps is the text transcript and the nutrition numbers you confirm. The transcript stays attached to your food log until the log or your account is deleted, so you and Voco can both see what was actually said.

The speech and language work is done by specialized US-based speech-to-text and AI providers acting as our service providers under data-processing agreements: one transcribes your audio (with an automatic backup if it is unavailable), and an AI model interprets the transcript into foods and macros. These providers state that data sent through their APIs is not used to train their models by default, and they may retain API inputs briefly (on the order of 30 days) for abuse monitoring under their own policies. We are honest about the boundary: "not stored" is our guarantee about Voco's systems; what happens inside a provider's short processing window is governed by their terms.

We do not create voiceprints, we do not use your voice to identify you, and Voco has no speaker-recognition features. Microphone access is used only while you are recording a log, and if you deny it, you can type instead; the app still works.

How we use your data

We do not sell your personal data. We do not share it for advertising. We do not use your health-related data for marketing or data mining. If a Global Privacy Control signal ever applies to you, there is nothing it needs to switch off, because there is no sale or ad-sharing to opt out of. Voco is not a healthcare provider and is not covered by HIPAA; we protect your data because it is the right way to build this, not because a hospital rulebook applies.

Where your data lives & security

Your profile, logs, and subscription state live in a PostgreSQL database hosted by Supabase in the United States (AWS us-east-2). Access is enforced at the database level by row-level security: every query runs as you, and the rules prevent one account from reading another's rows. The privileged server key that could bypass those rules never exists on your device; it lives only in our server functions and is used for narrow jobs like deleting your account.

On your phone, your login session is kept in the iOS keychain (via expo-secure-store), not general app storage. All traffic between the app, our servers, and our vendors is encrypted in transit.

No system is perfectly secure. Our approach is to collect little and lock down access, so a breach would have less to expose.

Third-party processors

A small set of vendors runs parts of the service on our behalf. Each receives only what its job needs:

These providers process data under their service terms and data-processing agreements. We do not let any of them use your data for their own advertising.

Analytics & crash reporting

We measure how the app is used so we can improve it, and we built the pipeline to be content-free by design:

Data retention & deletion

We keep your data for as long as your account exists, so your history and streak are there when you come back. Deleting a single log hides it immediately and permanently from your account; the row is retained internally until your account is deleted. Anonymous accounts that never sign up are purged automatically after 30 days.

You can delete your account from inside the app: Settings, then Delete Account. This deletes your login and, through database cascade rules, everything tied to it: profile, food logs and their transcripts, workout logs, weight logs, streaks, weekly summaries, food memory, and usage counters. It cannot be undone.

Three honest footnotes on deletion:

Data export: email us and we will send you a portable copy of your data.

Your rights

We extend these to every user, wherever you live:

If you are in the EU or UK, these map to your GDPR rights, and you also have the right to complain to your local supervisory authority (in the UK, the ICO). Voco is operated from the United States and your data is processed there. When our vendors move data internationally they rely on recognized safeguards such as EU standard contractual clauses or Data Privacy Framework certification. Voco's AI produces informational estimates that you review and can edit before saving; it makes no automated decisions with legal or similarly significant effects about you.

If you are in California or another US state with a privacy law, the practical answers are above: we do not sell or share your personal information, and access, deletion, correction, and portability are yours to use. We extend these voluntarily to everyone rather than gating them by state. Washington and Nevada residents: see the Consumer Health Data Privacy Policy.

To exercise anything the app does not already let you do directly, email hello@voco.fit. We do not discriminate against anyone for exercising a privacy right.

Children

Voco is not directed at children under 13 and is not intended for them. You must be at least 13 to use it, and onboarding asks your age as part of building your plan. We do not knowingly collect personal data from children under 13; if you believe a child under 13 has an account, email us and we will delete it.

Changes

If we change this policy, we will update the effective date at the top and post the new version at this address. For material changes we will make a reasonable effort to notify you in the app. Continuing to use Voco after a change means you accept the revised policy.

Contact

Questions, requests, or privacy concerns: hello@voco.fit. We aim to respond to privacy requests promptly, and within any deadline the law where you live sets.