EnactVoice · Legal

Privacy Policy

Last updated: 2026-09-13 · Effective: 2026-08-21

1. Who we are

EnactVoice is made by EnactSkill LLC, a Florida limited liability company (“EnactSkill”, “we”, “us”). We are the data controller for the personal data described here. You can reach us at support@enactvoice.com.

2. What this policy covers

This policy covers the EnactVoice iOS app — voice and text conversations with Modal, our AI assistant — and the enactvoice.com website. The EnactSkill web product at enactskill.com has its own policy at enactskill.com/privacy.

3. What we collect

4. How voice conversations are processed

When you talk to Modal, your audio moves through this pipeline:

Raw audio exists in this pipeline only for the duration of processing. What persists is the transcript, stored in our database in Frankfurt.

Camera and screen. Both are off until you turn one on. While one is on, we take one still frame at the moment you stop speaking. It travels with that message. If both are on, we use the screen. We do not record video, and we do not take frames between turns. We drop any frame older than two seconds.

A frame goes to the same company that handles the rest of that turn. Which company that is depends on your model setting and on which services are reachable — see section 8.

How long a frame lasts. On our side, a frame is never written to a database, a file, or a log. It stays in the working memory of that one conversation, so Modal can refer back to recent frames. It goes when the conversation ends. Your transcript holds text, never images.

When Anthropic handles the turn, it deletes the frame within 30 days. If its safety systems flag a conversation, it can hold the frame for up to two years. The law can require it to hold data longer. The companies LiveKit routes to hold nothing.

We do not use camera or screen frames to identify anyone. We do not use them to infer emotion or any other characteristic of a person. That applies to anyone else who ends up in the frame, not just you.

5. Files you share

The file goes from your device straight to our storage in Frankfurt. It does not travel through the voice connection. Our server then reads it so Modal can answer questions about it: a document is read in full by Anthropic’s Claude; an image is described by Claude in one sentence.

A photo carries more than its picture. We read what the file itself records: the date it was taken, the camera, and the coordinates. The coordinates become a town or city on our own servers, matched against a lookup table we hold. They go to no one, and we do not store them. The town is what we keep.

We keep that record so Modal can find the file in a later conversation. At the start of each conversation Modal is told about your twelve most recent files, the town included. That is why “the invoice from last week” means something to Modal without you finding it again.

What a file contains becomes part of the conversation you shared it in, and is stored with that conversation’s transcript.

By default, your conversations are not used to train AI models. During onboarding — and any time after, in Settings — you can turn on the Training toggle. With it on, we may use your conversation transcripts to improve EnactVoice, including reviewing calls for quality and accuracy. Turning it off stops future use; it does not recall copies already incorporated into completed work. The toggle covers the text of your conversations. Camera and screen frames are not retained on our side, so they are never part of any training set. The toggle does not change that. Our AI vendors process your conversations to provide the service, under agreements that bar them from training on your data. That bar covers the frames you share, not just the words you say.

7. How we use your data

We do not sell personal data. We do not share it for cross-context behavioral advertising. There is no advertising in EnactVoice.

8. Sub-processors

These vendors process EnactVoice user data on our behalf:

VendorPurposeRegionSafeguards
SupabaseAuthentication, account records, conversation transcripts, preferences, memoriesEU (Frankfurt)Standard Contractual Clauses
LiveKit CloudReal-time voice transport (WebRTC), end-of-turn detection, and hosted model inference (Gemma, for the Light setting)USLiveKit DPA (Standard Contractual Clauses)
AnthropicAI conversation processing (Claude model inference)USAnthropic DPA (Standard Contractual Clauses)
OpenAIBackup AI conversation processing (through LiveKit Inference)USEngaged by LiveKit under its DPA; zero data retention
MicrosoftAlternate host for the OpenAI backup model (Azure, through LiveKit Inference)USEngaged by LiveKit under its DPA; zero data retention
SonioxSpeech-to-text transcription and text-to-speech synthesisUSSoniox DPA
DeepgramBackup speech-to-text (through LiveKit Inference)USEngaged by LiveKit under its DPA; zero data retention
CartesiaBackup text-to-speech (through LiveKit Inference)USEngaged by LiveKit under its DPA; zero data retention
TwilioPhone-number verification codes (Twilio Verify)US, EUTwilio DPA
AppleApp distribution, in-app subscriptions, push notificationsUS, globalApple Developer Program License Agreement
VercelWeb hosting and the API that issues voice-session credentialsUS, global edgeVercel DPA
PostHogProduct analytics and service diagnosticsUSPostHog DPA

Which AI company handles a turn depends on your model setting and on which services are reachable. The Balanced and Deep settings use Anthropic. The Light setting uses a model LiveKit runs on its own infrastructure. If a company becomes unavailable mid-conversation, that turn goes to the backup listed above. The same applies to transcription and speech. LiveKit contracts with every company it routes to on a zero-retention basis: they do not log, store, or train on your conversations.

Accounts you connect are not on this list. The difference matters. These vendors process your data on our behalf, under our instructions. A connected account is a service you already use, answering on your authority. Google decides how it handles your mail and your files, and we cannot instruct it. We ask; your permission is what makes the answer possible.

What a connector returns, and what a file contains, enters the conversation. From there it reaches whichever company handles that turn, from the table above.

9. Connected accounts

Connectors are off until you turn them on, and they work only while a conversation is open. Nothing reads your accounts in the background.

Apple. Calendar, reminders, contacts, mail, and messages are granted by iOS and held by iOS. Only you can withdraw them, in your iPhone’s Settings. The permission stays on your phone; the data does not. What Modal reads there enters the conversation and reaches the same companies that handle the rest of it. Mail and Messages open a draft on your screen for you to send. Neither can send anything by itself.

Google. One permission wearing many faces. Google issues a single credential covering everything you have agreed to, and offers no way to hand back part of it. Three things are worth knowing before you connect. Connecting Gmail grants a permission that can send mail as you, because Google offers no draft-only permission. Modal’s tools never send. Connecting Drive, Docs, Sheets, or Slides grants access to the files this app makes for you. The rest of your Drive is closed to it. Google gives no create-only permission, so the same grant can delete a file the app made — never one you made. No tool in the app deletes a file. The permission is what you grant, so the permission is what we disclose.

The third is about Google’s screen, not ours. Its consent sheet says the Docs, Sheets, and Slides permissions can delete all your documents. They cannot delete one. The one that can delete is the Drive permission beside them, and it reaches only files the app made. The app says each of these on the connector’s row before you tap.

If you connected Docs, Sheets, or Slides before this version took effect, your grant still includes read access to your whole Drive. Disconnecting Google and reconnecting replaces it with the narrower grant.

Switching a connector off takes that access away from Modal. Disconnecting Google takes all of it away. Neither shrinks the permission. It lives in your Google account, and you withdraw it there, at myaccount.google.com/permissions. Deleting your EnactVoice account withdraws it for you.

We hold the credential Google issued under it. Connecting gives Google nothing new about you. Every action Modal takes on a connected account is recorded, so you can ask what it did.

EnactVoice’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

10. Where data lives and moves

Stored data — your account, transcripts, preferences, memories — lives in Supabase’s Frankfurt region (EU). Real-time processing is different: voice transport, transcription, and AI inference run on US infrastructure while a conversation is live. Files you share are stored in Frankfurt and read by our processing server in the US. Data from a connected account is read in the US. Camera and screen frames travel the same path. For transfers out of the EEA and UK we rely on Standard Contractual Clauses with each vendor.

11. Data retention

12. Deleting your account

In the app: Settings → Profile → Delete account. This removes your account, transcripts, memories, preferences, phone record, connector permissions, and the records of files you shared, from our live systems at the time of the request. Backup copies age out per section 11. Subscription management and refunds for App Store purchases remain with Apple.

Two of those go beyond our own records. The files you shared are removed from our storage, not merely unlisted. Any account you connected is withdrawn at the provider first, so EnactVoice stops being listed in your Google account rather than keeping a key to it.

Both happen before anything else is deleted, and if either fails the deletion stops and your account is still there. That is deliberate. An account that still exists can be deleted again; a permission stranded behind a deleted account can never be withdrawn by anyone. So if Google cannot be reached, deletion is refused.

Deleting one file in the Library removes both the file and its record.

13. Your rights

Depending on where you live (GDPR, UK GDPR, CCPA/CPRA), you can request access to your data, a copy of it, correction, deletion, restriction of processing, or object to processing. Write to support@enactvoice.com and we respond within 30 days. We do not discriminate against you for exercising these rights. You can also complain to your local supervisory authority.

14. Age requirement

EnactVoice is for adults. You must be at least 18 to create an account, and we do not knowingly collect personal data from anyone under 18. If we learn we hold data on someone under 18, we delete it.

15. You are talking to an AI

Modal is an AI assistant, not a person. Its voice is synthesized. Its answers can be wrong, and nothing it says is professional advice. We say this in the app, and it belongs in the privacy policy too: the party processing what you say in a conversation is software.

16. Changes to this policy

When we make material changes we update the date above and give notice in the app or by email at least 30 days before the change takes effect, where required.

17. Contact

EnactSkill LLC · Ponte Vedra, FL, USA · support@enactvoice.com

Modal is in rest state.