EnactVoice · Legal
Privacy Policy
Last updated: 2026-09-13 · Effective: 2026-08-21
1. Who we are
EnactVoice is made by EnactSkill LLC, a Florida limited liability company (“EnactSkill”, “we”, “us”). We are the data controller for the personal data described here. You can reach us at support@enactvoice.com.
2. What this policy covers
This policy covers the EnactVoice iOS app — voice and text conversations with Modal, our AI assistant — and the enactvoice.com website. The EnactSkill web product at enactskill.com has its own policy at enactskill.com/privacy.
3. What we collect
- Account data. Your name, email address, and sign-in identity (Apple, Google, or email). If you sign in with Apple or Google, we receive the name and email your provider shares — never your provider password.
- Phone number. Verified once at account creation through a six-digit code, to keep accounts real and rate-limit abuse. We store the number and its verification timestamp. We do not use it for marketing.
- Voice audio. Your speech streams to our processing pipeline during a conversation. Audio is processed in transit; we do not keep recordings of your voice after processing. See section 4.
- Camera and screen frames. If you turn on the camera or share your screen during a conversation, we take one still frame at the moment you stop speaking, so Modal can see what you are showing it. We do not record video. No image is written to your transcript. See section 4.
- Transcripts. The text of your conversations — what you said and what Modal said — is stored so your history, saved threads, and Modal’s memory work.
- Preferences and memories. Settings you choose, and facts Modal remembers at your direction.
- Usernames and passwords, if you ask Modal to remember one. A password is encrypted at rest in Supabase Vault and never stored in readable form. Modal cannot read one back to you out loud — not in a call, not in a transcript, and not on anyone else’s request. The only way to see it again is on your own device, behind Face ID, Touch ID or your passcode. You choose whether Modal may save these at all, under What Modal may remember, and you can set that kind to Never.
- Files you share. Photos, documents, screenshots. Whatever you hand to Modal. We keep the file, and a short record of it: name, type, size, a one-sentence description, and for a photo the date it was taken and the town or city it was taken in. See section 5.
- Data from accounts you connect. If you connect Google, or let Modal reach the calendar, reminders, contacts, mail, or messages on your iPhone, what it reads there enters the conversation. See section 9.
- Usage and device data. App events, session metadata, approximate device characteristics, and diagnostics through PostHog. No advertising identifiers, no cross-app tracking.
4. How voice conversations are processed
When you talk to Modal, your audio moves through this pipeline:
- Transport. Audio streams over an encrypted WebRTC connection through LiveKit Cloud.
- Transcription. Soniox converts your speech to text in real time.
- Understanding. Anthropic’s Claude models read the transcript and produce Modal’s reply. If Anthropic is unavailable, the same transcript goes to OpenAI through LiveKit Inference, so a conversation does not stop when one provider does. Neither company trains on your conversations.
- Speech. Soniox synthesizes Modal’s reply into audio. Modal’s voice is synthetic — it is not a recording or clone of any real person.
Raw audio exists in this pipeline only for the duration of processing. What persists is the transcript, stored in our database in Frankfurt.
Camera and screen. Both are off until you turn one on. While one is on, we take one still frame at the moment you stop speaking. It travels with that message. If both are on, we use the screen. We do not record video, and we do not take frames between turns. We drop any frame older than two seconds.
A frame goes to the same company that handles the rest of that turn. Which company that is depends on your model setting and on which services are reachable — see section 8.
How long a frame lasts. On our side, a frame is never written to a database, a file, or a log. It stays in the working memory of that one conversation, so Modal can refer back to recent frames. It goes when the conversation ends. Your transcript holds text, never images.
When Anthropic handles the turn, it deletes the frame within 30 days. If its safety systems flag a conversation, it can hold the frame for up to two years. The law can require it to hold data longer. The companies LiveKit routes to hold nothing.
We do not use camera or screen frames to identify anyone. We do not use them to infer emotion or any other characteristic of a person. That applies to anyone else who ends up in the frame, not just you.
5. Files you share
The file goes from your device straight to our storage in Frankfurt. It does not travel through the voice connection. Our server then reads it so Modal can answer questions about it: a document is read in full by Anthropic’s Claude; an image is described by Claude in one sentence.
A photo carries more than its picture. We read what the file itself records: the date it was taken, the camera, and the coordinates. The coordinates become a town or city on our own servers, matched against a lookup table we hold. They go to no one, and we do not store them. The town is what we keep.
We keep that record so Modal can find the file in a later conversation. At the start of each conversation Modal is told about your twelve most recent files, the town included. That is why “the invoice from last week” means something to Modal without you finding it again.
What a file contains becomes part of the conversation you shared it in, and is stored with that conversation’s transcript.
6. Training consent
By default, your conversations are not used to train AI models. During onboarding — and any time after, in Settings — you can turn on the Training toggle. With it on, we may use your conversation transcripts to improve EnactVoice, including reviewing calls for quality and accuracy. Turning it off stops future use; it does not recall copies already incorporated into completed work. The toggle covers the text of your conversations. Camera and screen frames are not retained on our side, so they are never part of any training set. The toggle does not change that. Our AI vendors process your conversations to provide the service, under agreements that bar them from training on your data. That bar covers the frames you share, not just the words you say.
7. How we use your data
- To run the service: conversations, history, memory, voice processing, and camera or screen frames when you turn one on.
- To secure it: phone verification, abuse prevention, rate limiting.
- To operate it: diagnostics, performance measurement, support.
- To bill it: subscription state through Apple. We never see your card number.
- To improve it — only with your Training consent, per section 6.
We do not sell personal data. We do not share it for cross-context behavioral advertising. There is no advertising in EnactVoice.
8. Sub-processors
These vendors process EnactVoice user data on our behalf:
| Vendor | Purpose | Region | Safeguards |
|---|---|---|---|
| Supabase | Authentication, account records, conversation transcripts, preferences, memories | EU (Frankfurt) | Standard Contractual Clauses |
| LiveKit Cloud | Real-time voice transport (WebRTC), end-of-turn detection, and hosted model inference (Gemma, for the Light setting) | US | LiveKit DPA (Standard Contractual Clauses) |
| Anthropic | AI conversation processing (Claude model inference) | US | Anthropic DPA (Standard Contractual Clauses) |
| OpenAI | Backup AI conversation processing (through LiveKit Inference) | US | Engaged by LiveKit under its DPA; zero data retention |
| Microsoft | Alternate host for the OpenAI backup model (Azure, through LiveKit Inference) | US | Engaged by LiveKit under its DPA; zero data retention |
| Soniox | Speech-to-text transcription and text-to-speech synthesis | US | Soniox DPA |
| Deepgram | Backup speech-to-text (through LiveKit Inference) | US | Engaged by LiveKit under its DPA; zero data retention |
| Cartesia | Backup text-to-speech (through LiveKit Inference) | US | Engaged by LiveKit under its DPA; zero data retention |
| Twilio | Phone-number verification codes (Twilio Verify) | US, EU | Twilio DPA |
| Apple | App distribution, in-app subscriptions, push notifications | US, global | Apple Developer Program License Agreement |
| Vercel | Web hosting and the API that issues voice-session credentials | US, global edge | Vercel DPA |
| PostHog | Product analytics and service diagnostics | US | PostHog DPA |
Which AI company handles a turn depends on your model setting and on which services are reachable. The Balanced and Deep settings use Anthropic. The Light setting uses a model LiveKit runs on its own infrastructure. If a company becomes unavailable mid-conversation, that turn goes to the backup listed above. The same applies to transcription and speech. LiveKit contracts with every company it routes to on a zero-retention basis: they do not log, store, or train on your conversations.
Accounts you connect are not on this list. The difference matters. These vendors process your data on our behalf, under our instructions. A connected account is a service you already use, answering on your authority. Google decides how it handles your mail and your files, and we cannot instruct it. We ask; your permission is what makes the answer possible.
What a connector returns, and what a file contains, enters the conversation. From there it reaches whichever company handles that turn, from the table above.
9. Connected accounts
Connectors are off until you turn them on, and they work only while a conversation is open. Nothing reads your accounts in the background.
Apple. Calendar, reminders, contacts, mail, and messages are granted by iOS and held by iOS. Only you can withdraw them, in your iPhone’s Settings. The permission stays on your phone; the data does not. What Modal reads there enters the conversation and reaches the same companies that handle the rest of it. Mail and Messages open a draft on your screen for you to send. Neither can send anything by itself.
Google. One permission wearing many faces. Google issues a single credential covering everything you have agreed to, and offers no way to hand back part of it. Three things are worth knowing before you connect. Connecting Gmail grants a permission that can send mail as you, because Google offers no draft-only permission. Modal’s tools never send. Connecting Drive, Docs, Sheets, or Slides grants access to the files this app makes for you. The rest of your Drive is closed to it. Google gives no create-only permission, so the same grant can delete a file the app made — never one you made. No tool in the app deletes a file. The permission is what you grant, so the permission is what we disclose.
The third is about Google’s screen, not ours. Its consent sheet says the Docs, Sheets, and Slides permissions can delete all your documents. They cannot delete one. The one that can delete is the Drive permission beside them, and it reaches only files the app made. The app says each of these on the connector’s row before you tap.
If you connected Docs, Sheets, or Slides before this version took effect, your grant still includes read access to your whole Drive. Disconnecting Google and reconnecting replaces it with the narrower grant.
Switching a connector off takes that access away from Modal. Disconnecting Google takes all of it away. Neither shrinks the permission. It lives in your Google account, and you withdraw it there, at myaccount.google.com/permissions. Deleting your EnactVoice account withdraws it for you.
We hold the credential Google issued under it. Connecting gives Google nothing new about you. Every action Modal takes on a connected account is recorded, so you can ask what it did.
EnactVoice’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
10. Where data lives and moves
Stored data — your account, transcripts, preferences, memories — lives in Supabase’s Frankfurt region (EU). Real-time processing is different: voice transport, transcription, and AI inference run on US infrastructure while a conversation is live. Files you share are stored in Frankfurt and read by our processing server in the US. Data from a connected account is read in the US. Camera and screen frames travel the same path. For transfers out of the EEA and UK we rely on Standard Contractual Clauses with each vendor.
11. Data retention
- Voice audio: not retained after processing.
- Camera and screen frames: not retained by us; held only until the conversation ends. Vendor retention in section 4.
- Transcripts, preferences, memories: kept while your account exists, or until you delete them in the app. Encrypted details are the exception.
- Encrypted details: kept for 12 months, then deleted. You can delete one sooner in the app.
- Files you share and their records: kept until you delete them. There is no automatic expiry.
- Connector permissions: kept until you disconnect.
- The record of what Modal did on a connected account: kept while your account exists.
- Phone number and verification record: kept while your account exists.
- Analytics events: up to 12 months.
- Billing records: held by Apple and in our accounting records for 7 years, as tax law requires.
- Backups: deleted data ages out of encrypted backups within 90 days.
12. Deleting your account
In the app: Settings → Profile → Delete account. This removes your account, transcripts, memories, preferences, phone record, connector permissions, and the records of files you shared, from our live systems at the time of the request. Backup copies age out per section 11. Subscription management and refunds for App Store purchases remain with Apple.
Two of those go beyond our own records. The files you shared are removed from our storage, not merely unlisted. Any account you connected is withdrawn at the provider first, so EnactVoice stops being listed in your Google account rather than keeping a key to it.
Both happen before anything else is deleted, and if either fails the deletion stops and your account is still there. That is deliberate. An account that still exists can be deleted again; a permission stranded behind a deleted account can never be withdrawn by anyone. So if Google cannot be reached, deletion is refused.
Deleting one file in the Library removes both the file and its record.
13. Your rights
Depending on where you live (GDPR, UK GDPR, CCPA/CPRA), you can request access to your data, a copy of it, correction, deletion, restriction of processing, or object to processing. Write to support@enactvoice.com and we respond within 30 days. We do not discriminate against you for exercising these rights. You can also complain to your local supervisory authority.
14. Age requirement
EnactVoice is for adults. You must be at least 18 to create an account, and we do not knowingly collect personal data from anyone under 18. If we learn we hold data on someone under 18, we delete it.
15. You are talking to an AI
Modal is an AI assistant, not a person. Its voice is synthesized. Its answers can be wrong, and nothing it says is professional advice. We say this in the app, and it belongs in the privacy policy too: the party processing what you say in a conversation is software.
16. Changes to this policy
When we make material changes we update the date above and give notice in the app or by email at least 30 days before the change takes effect, where required.
17. Contact
EnactSkill LLC · Ponte Vedra, FL, USA · support@enactvoice.com