Privacy Policy
Last updated: June 12, 2026 · Effective: June 12, 2026
In short
We collect the account, business, voice-recording, and customer information you give us to turn your spoken job notes into quotes and invoices. We use trusted processors (Deepgram, Anthropic, Amazon Web Services, Stripe, Twilio) to do this, we do not sell your personal information, and you can access, correct, export, or delete your data at any time by contacting privacy@voiczer.com.
RS NEXT LLC (d/b/a Voiczer) ("Voiczer", "we", "us", or "our") provides a voice-to-document service that converts spoken job descriptions into quotes, invoices, job notes, and related business documents through our mobile applications, websites, and application programming interfaces (collectively, the "Service").
This Privacy Policy explains what personal information we collect, why we collect it, the legal bases on which we rely, how we share it, how long we keep it, the safeguards we apply, and the rights you have. It applies to all users of the Service and to individuals whose information is processed through the Service.
By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, you must not use the Service.
1. Scope and Our Role (Controller vs. Processor)
The Service is offered to businesses and self-employed tradespeople (each, a "Customer" or "you"). We act in two distinct capacities depending on the data involved:
- Controller. For information about your account, the individual users who sign in, billing data, and our own analytics and security logs, we determine the purposes and means of processing and act as a data controller (or "business" under US law).
- Processor. For information you upload or input about your own clients and jobs (for example, the contact details of the homeowners you quote, and the contents of your voice recordings about a job), we act as a data processor (or "service provider") and process that information on your behalf and under your instructions, as further described in our Terms & Conditions and any Data Processing Addendum.
Where we act as processor, you are the controller of that information and are responsible for having a lawful basis to collect it and to share it with us, including obtaining any required consents (see the Terms & Conditions, "Customer Data and Your Responsibilities").
Electronic signatures. When you use the Service to send a contract for electronic signature, the people you ask to sign ("signers") are your End Customers. You are the controller of their information and we act as your processor in capturing the signature and audit trail, except that we act as a controller of the limited security and integrity records we must keep to evidence that a signature occurred (see "Information We Collect" and "Data Retention" below).
2. Defined Terms
- "Personal information" / "personal data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on personal information, such as collection, storage, use, disclosure, or deletion.
- "End Customer" means an individual or business whose details you enter into, or describe within, the Service (for example, the recipient of a quote).
- "Sub-processor" means a third party we engage to process personal information in connection with the Service.
- "Sensitive personal information" has the meaning given under applicable law (for example, the CPRA and the GDPR).
3. Information We Collect
a. Information you provide directly
- Account and identity data: your name, email address, and password (stored only as a salted hash).
- Business profile data: your business name, logo, default tax rate and tax label, currency, preferred language, and the default terms text you choose to print on documents.
- Authentication data: two-factor authentication settings, time-based one-time-password secrets, and one-time recovery codes (stored as hashes).
- Voice recordings: the audio you record or upload describing a job, including any words you speak.
- Content you create: price-book items and aliases, jobs, documents (quotes, invoices, notes, variations), and free-text terms or notes.
- End Customer data you input: the names, email addresses, phone numbers, and service addresses of your clients, and the job details associated with them.
- Support communications: the contents of messages you send us and records of your interactions with our support team.
b. Information generated when you use the Service
- Derived content: transcripts produced from your recordings, transcription confidence scores, and the structured line items, totals, and document drafts our systems generate from your input.
- Document delivery data: the recipients, timestamps, delivery method (email, SMS, or shareable link), and acceptance or signature events recorded against documents you send.
- Electronic signature data: when a contract is signed through the Service, we capture the signer’s typed name, the signature mark (a typed or hand-drawn image), the email address the signing link was sent to, the signer’s IP address and browser user-agent string, the timestamps of viewing, consenting, and signing, the consent disclosure version shown, and a cryptographic hash (digest) of the exact document presented for signing. This forms the audit trail and certificate of completion. An IP address is personal data under the GDPR and Canadian law; we collect it to attribute the signature and protect the integrity of the record.
c. Information collected automatically
- Device and technical data: device type, operating system and version, app version, mobile network information, language and time-zone settings, and unique device or installation identifiers.
- Usage data: features used, pages or screens viewed, actions taken, the dates and times of access, and crash and performance diagnostics.
- Log and connection data: IP address, request metadata, and security events such as sign-in attempts.
- Cookies and similar technologies on our websites (see Section 7).
Biometric authentication: if you enable biometric sign-in (fingerprint or face), the biometric matching is performed entirely on your device by your operating system. We never receive, see, or store your biometric data.
We do not intentionally collect special categories of data or sensitive personal information. Because voice recordings are free-form, please do not record information you do not need for the job (such as health, financial, or government-identifier details about an individual).
4. How We Use Information and Our Legal Bases
We use personal information for the purposes below. For users in the European Economic Area ("EEA"), the United Kingdom, and other jurisdictions that require a legal basis, the applicable GDPR / UK GDPR basis is identified for each purpose.
- To provide the Service — create your account, transcribe recordings, generate documents, and deliver them. Legal basis: performance of a contract (Art. 6(1)(b)).
- To process payments and manage subscriptions and trials. Legal basis: performance of a contract and compliance with legal obligations (Art. 6(1)(b), (c)).
- To secure the Service — authenticate users, operate two-factor authentication, detect and prevent fraud, abuse, and security incidents. Legal basis: legitimate interests and legal obligation (Art. 6(1)(f), (c)).
- To support and communicate with you — respond to requests and send service, security, and transactional notices. Legal basis: performance of a contract and legitimate interests (Art. 6(1)(b), (f)).
- To improve and develop the Service — diagnose errors, analyze aggregated usage, and improve features and accuracy. Legal basis: legitimate interests (Art. 6(1)(f)).
- To comply with law and enforce our terms — meet legal, tax, and accounting obligations and defend legal claims. Legal basis: legal obligation and legitimate interests (Art. 6(1)(c), (f)).
- For marketing communications, where permitted — only with your consent where consent is required, and always with an opt-out. Legal basis: consent or legitimate interests (Art. 6(1)(a), (f)).
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to such processing as described in Section 14.
5. Voice Recordings, Transcription, and Artificial Intelligence
A core function of the Service is converting your speech into structured documents. To do this:
- Your audio recording is uploaded to our cloud storage and sent to our speech-to-text provider, Deepgram, Inc., which returns a text transcript.
- The transcript, together with your price-book items, is sent to our artificial-intelligence provider, Anthropic, PBC, which returns structured line items and a document draft.
We retain the original recording, the transcript, and the raw model output so that you can review, correct, and re-process your documents, and so we can diagnose errors. The accuracy of generated documents depends on the audio and your price book; you remain responsible for reviewing every document before you rely on or send it.
We do not use your recordings, transcripts, or document contents to train our own or third parties’ general-purpose AI models. Our agreements with Deepgram and Anthropic require them to process your data only to provide their services to us and prohibit use of your content to train their models other than as needed to provide the service.
6. Automated Decision-Making and Profiling
The Service uses automated processing (speech recognition and language models) to generate draft documents. These outputs are drafts presented to you for review and do not produce legal or similarly significant effects on any individual without your human review and decision. We do not engage in automated decision-making within the meaning of Article 22 of the GDPR that produces legal or similarly significant effects on individuals, and we do not use your data for credit, employment, insurance, or eligibility scoring.
7. Cookies and Tracking Technologies
Our websites use cookies and similar technologies (such as local storage) to operate the Service, remember your session and preferences, maintain security, and understand usage. We use:
- Strictly necessary cookies and local storage — required to sign you in and keep the Service secure. These cannot be switched off through our controls.
- Functional storage — remembers preferences such as language.
- Analytics technologies — help us understand aggregated usage (see Section 8). Where required by law, these are set only with your consent.
You can control cookies through your browser settings and, where we present a cookie banner or preference center, through those controls. Blocking strictly necessary cookies may prevent the Service from functioning.
Our mobile apps do not use third-party advertising cookies and do not include advertising identifiers for cross-app tracking. We do not engage in cross-context behavioral advertising.
8. Analytics and Third-Party Tracking
We use privacy-respecting product analytics and crash-reporting tools to measure aggregate usage and reliability. These tools process technical and usage data described in Section 3(c). We configure analytics to minimize data and do not use them to build advertising profiles. We do not permit third parties to track you across other websites or apps through our Service for their own advertising purposes.
9. Payment Processing and Financial Data
Subscription payments are processed by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. When you subscribe, your card and payment details are collected and processed directly by Stripe under its own privacy policy; we do not receive or store your full card number. We retain limited billing records such as your Stripe customer identifier, subscription status, trial end date, and invoices, which we use for billing, tax, and accounting purposes.
10. How We Share Information and Categories of Recipients
We do not sell your personal information and we do not share it for cross-context behavioral advertising. We disclose personal information only as follows:
a. Sub-processors and service providers
We share information with vetted providers who process it on our behalf:
- Amazon Web Services, Inc. (AWS) — cloud hosting, database, file storage of recordings and documents, and transactional email delivery (Amazon SES). Region: United States.
- Deepgram, Inc. — speech-to-text transcription of your recordings.
- Anthropic, PBC — language-model generation of document drafts from transcripts.
- Stripe, Inc. — payment processing and subscription billing.
- Twilio Inc. — SMS delivery of quotes and invoices when you choose to send by text message.
- Product analytics, crash-reporting, and infrastructure providers that support the operation of the Service.
b. Document recipients
When you send a quote, invoice, or note, we transmit it to the recipient(s) you designate (your End Customer) by the method you choose — email, SMS, or a shareable hosted link protected by an unguessable token.
SMS/text messages. When you choose to send a document by SMS, we send a one-time, transactional text message, through our messaging provider Twilio Inc., to the mobile number you provide for that recipient; the message contains a short introduction and a link to the document or signing page. These messages are transactional and relate to a specific document requested from you (the sender) — we do not send marketing or promotional text messages through the Service. Recipients can reply STOP at any time to opt out of further messages, or HELP for assistance; message and data rates may apply. Mobile phone numbers and any SMS consent are used solely to deliver the document you send and are never sold, or shared with third parties or affiliates for their own marketing purposes.
c. Legal, safety, and corporate transactions
- To comply with applicable law, regulation, legal process, or enforceable governmental request.
- To enforce our Terms, protect the rights, property, or safety of Voiczer, our users, or the public, and to detect or prevent fraud or security issues.
- In connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case we will require the recipient to honor this Privacy Policy or notify you of any material change.
We require all sub-processors to protect personal information under written agreements consistent with this Policy and applicable law.
11. International Data Transfers
We are based in, and primarily store data in, the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States and other countries that may have different data-protection laws than your own.
Where we transfer personal data out of the EEA, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum), and, where applicable, transfers to recipients certified under the EU-US Data Privacy Framework or covered by an adequacy decision. You may request a copy of the relevant safeguard by contacting privacy@voiczer.com.
12. Data Retention
We keep personal information only for as long as necessary for the purposes described in this Policy:
- Account, business profile, and content (recordings, transcripts, documents, customers, price book): for the life of your account and then deleted or anonymized within 90 days after account closure, unless a longer period is required by law.
- Voice recordings and transcripts: retained while your account is active so you can review and re-process documents; you may delete individual recordings at any time, and they are removed from active systems within 30 days of deletion.
- Billing and tax records: retained for up to seven (7) years to meet financial, tax, and accounting obligations.
- Security and access logs: typically retained for up to 12 months.
- Signed contracts and signing audit trails: a fully executed contract, its certificate of completion, and the associated audit events are retained as a business and legal record. Because a signed contract is also a record of the other parties to it, we may retain it after your account closes for as long as needed to make it available to those parties and to comply with law; it is held in tamper-evident, restricted-access storage.
- Backups: residual copies in encrypted backups are overwritten on our standard backup rotation, generally within 90 days.
When we act as processor for End Customer data, we retain it according to your instructions and delete or return it on termination as set out in our Terms / Data Processing Addendum.
13. Data Security
We implement technical and organizational measures designed to protect personal information, including:
- Encryption of data in transit (TLS) and at rest for stored files and databases.
- Hashing of passwords (Argon2) and of two-factor recovery codes; optional two-factor authentication.
- Access controls, least-privilege principles, and segregation of customer data by account.
- Signed, time-limited URLs for file uploads and downloads, and unguessable tokens for hosted document links.
- Network controls, monitoring, logging, and regular review of our providers’ security posture.
No method of transmission or storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for keeping your credentials confidential and for the security of the devices you use.
14. Data Breach Notification
We maintain procedures to detect, investigate, and respond to personal-data breaches. Where a breach is likely to result in a risk to the rights and freedoms of affected individuals, we will notify the competent supervisory authority without undue delay and, where required, within 72 hours of becoming aware of it, and we will notify affected individuals and, where we act as processor, the relevant controller without undue delay, in accordance with applicable law (including the GDPR and US state breach-notification statutes).
15. Your Privacy Rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you and obtain a copy.
- Rectify inaccurate or incomplete information.
- Erase your information ("right to be forgotten") in certain circumstances.
- Restrict or object to certain processing, including processing based on legitimate interests and direct marketing.
- Data portability — receive your information in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller.
- Withdraw consent at any time where processing is based on consent, without affecting prior processing.
- Lodge a complaint with a supervisory authority (see Section 19).
To exercise these rights, contact privacy@voiczer.com. We will respond within the timeframe required by applicable law (generally one month under the GDPR; 45 days under US state laws, extendable as permitted). We will verify your identity before acting and will not discriminate against you for exercising your rights. If you are an End Customer and your data was provided by one of our business Customers, we will refer your request to that Customer (the controller) and assist them in responding.
16. EEA and UK Rights (GDPR / UK GDPR)
If you are in the EEA or the United Kingdom, the rights in Section 15 apply to you under the GDPR and UK GDPR. The controller is RS NEXT LLC (d/b/a Voiczer). You may contact our privacy team at privacy@voiczer.com. You also have the right to lodge a complaint with your local data-protection authority, or with the UK Information Commissioner’s Office (ICO), if you believe our processing infringes the law.
17. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the rights to know, access, correct, and delete your personal information, to data portability, and to limit the use of sensitive personal information.
- Categories collected: identifiers (name, email, IP, device IDs); commercial information (subscription and billing records); audio/electronic information (voice recordings); internet/network activity (usage and log data); and professional/business information.
- Sources, purposes, and recipients are described in Sections 3, 4, and 10.
- No sale or sharing: in the preceding 12 months we have not sold your personal information and have not shared it for cross-context behavioral advertising, and we do not knowingly do so. We therefore do not offer a "Do Not Sell or Share My Personal Information" sale opt-out, but you may still exercise the rights below.
- Sensitive personal information: we do not use or disclose sensitive personal information for purposes beyond those permitted under the CPRA, so the right to limit does not change our practices.
To exercise your California rights, contact privacy@voiczer.com. You may use an authorized agent. We will not discriminate against you for exercising your rights. California "Shine the Light" requests regarding disclosures for third-party direct marketing may also be sent to that address; we do not disclose personal information to third parties for their own direct marketing.
18. Other US State Privacy Rights
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. We do not sell personal data or use it for targeted advertising or for profiling that produces legal or similarly significant effects. To exercise your rights, contact privacy@voiczer.com. If we decline a request, you may appeal by replying to our response; if your appeal is denied you may contact your state attorney general.
19. Children’s Privacy
The Service is a business tool intended for users aged 18 and over. It is not directed to children, and we do not knowingly collect personal information from anyone under 16, and specifically not from children under 13 in the meaning of the U.S. Children’s Online Privacy Protection Act (COPPA). If we learn that we have collected personal information from a child under the applicable age without appropriate consent, we will delete it promptly. If you believe a child has provided us with personal information, contact privacy@voiczer.com.
20. Do Not Track
Some browsers transmit "Do Not Track" (DNT) signals. Because there is no common industry standard for DNT, our websites do not respond to DNT signals. We do not track you across third-party websites for advertising regardless of any DNT setting. Where required by law, we honor recognized opt-out preference signals such as Global Privacy Control (GPC) as a valid request to opt out of sale/sharing.
21. Third-Party Links and Services
The Service may link to third-party websites or services (for example, your payment provider or external links you include in documents). We are not responsible for the privacy practices of those third parties, and this Policy does not apply to them. Review their privacy policies before providing information.
22. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and, where required, notify you by email or in-app notice before the change takes effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
23. Contact Us
For privacy questions or to exercise your rights, contact:
- RS NEXT LLC (d/b/a Voiczer)
- Privacy: privacy@voiczer.com
- General/legal: legal@voiczer.com
- Address: RS NEXT LLC, c/o Northwest Registered Agent Service, Inc., 2501 Chatham Rd Ste N, Springfield, IL 62704-4188, USA
EEA/UK users: if you require an EU or UK representative under Article 27 of the GDPR, contact us at the address above and we will provide current representative details where one is appointed.
This document is provided for transparency and does not constitute legal advice. © 2026 RS NEXT LLC (d/b/a Voiczer). All rights reserved.