Legal

Privacy Policy

Last updated August 12, 2026

This covers two groups. Customers, the teams who install Voicebox. And their end users, the people who type into the widget. For anything an end user submits, the customer is the controller and Voicebox is the processor acting on their instructions.

01Who we are

Arc Labs LLC operates Voicebox, a feedback widget and analysis service, and is the data controller for customer accounts. Write to us at support@usevoicebox.dev.

02What we collect

Account information. Signing in with Google gives us your name, email address, and profile image. We never receive your password. We also store the OAuth tokens Google issues and a session token, which is what keeps you signed in.

Organization and project settings. Names, timezone, widget appearance, and your domain allowlist.

Feedback submissions. The message text, the type and rating chosen, an optional email address the submitter typed, and context captured at the moment of submission: the page URL, the referring page, the browser user-agent, and the language setting.

Identify traits. Whatever a customer chooses to pass through Voicebox("identify", …), typically a user id, plan, or company. Customers are told not to put sensitive categories of data in here.

Invitations. If someone invites you to their team, we store the email address they entered until the invitation is accepted, revoked, or expires.

Technical information. The submitter's IP address, recorded against submissions solely to enforce rate limits and detect abuse, and deleted automatically after seven days.

03Why we're allowed to (legal bases)

Where the UK or EU GDPR applies, we rely on:

  • Contract, to give a customer the service they signed up for: their account, their projects, their dashboard.
  • Legitimate interests, to keep the service running and safe: rate limiting, abuse detection, and security logging. We think this is a low-impact and expected use.
  • Legal obligation, where we must keep records.

For end-user feedback, the legal basis is the customer's to establish, not ours. We process it only on their instructions.

04What is, and isn't, sent to the AI model

This is the section worth reading carefully, because it's the one people assume the worst about.

Sent: the feedback message text, the type the person selected, and the rating they gave. For grouping, we send the one-sentence summaries the model itself wrote, plus the existing theme names so it can reuse them.

Never sent: the email address the submitter typed, any identify traits the customer passed, the IP address, the page URL, or anything about the customer's account.

That isn't only a promise. The function that scores a submission accepts three fields and no others, so there is no path through which the rest could travel, and the grouping step replaces record ids with line numbers before anything leaves.

Our model provider is DeepSeek, a company based in Hangzhou, China. Feedback text is therefore transferred outside the UK, the EEA, and the United States, to a country without a UK or EU adequacy decision. Where that transfer is restricted, we rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, and customers should assess that transfer as part of their own compliance. We do not permit the provider to use content for training, and we send no direct identifiers with it.

Any customer can switch AI analysis off, under Settings, without leaving the product. Nothing is sent to the model while it is off. Feedback is still collected, stored, and displayed; it simply arrives without sentiment or themes.

05How we use information

  • To run the service: collect, store, display, and analyze feedback.
  • To score sentiment and cluster feedback into themes.
  • To send product email, weekly digests and account notices.
  • To enforce plan limits and rate limits, and to prevent abuse.
  • To bill customers on paid plans.

We do not sell or share personal information, as those terms are defined under California law, and we have not done so in the preceding twelve months. We do not use the contents of anyone's feedback to train models, and we run no advertising.

06Cookies

Voicebox sets four cookies, all of them strictly necessary, and no others. There is no analytics, no advertising pixel, no session recorder, and no third-party script anywhere on this site or in the dashboard. That is why you have never seen a cookie banner here: there is nothing to consent to.

  • authjs.session-token, keeps you signed in.
  • authjs.csrf-token, blocks cross-site request forgery.
  • authjs.callback-url, returns you to the right page after signing in.
  • authjs.pkce.code_verifier, secures the Google sign-in exchange. Expires in fifteen minutes.

The dashboard also remembers which project you were last looking at, in your browser's local storage. It never leaves your device.

The widget sets nothing at all. No cookie, no local storage, no identifier of any kind on the sites where it's installed. Installing Voicebox does not create a cookie-consent obligation for our customers.

07Who else sees it

We use these subprocessors:

  • Vercel, application hosting, United States.
  • Neon, PostgreSQL database hosting, United States.
  • Google, sign-in for customer accounts, United States.
  • DeepSeek, the language model behind analysis, China.
  • Resend, transactional and digest email, United States.
  • Stripe, subscription billing, United States. Used only once paid plans are enabled on your account.

We'll give customers at least 30 days' notice by email before adding or replacing a subprocessor, so there is time to object.

Webhooks. Customers can configure Voicebox to forward each new submission to an endpoint of their choosing. Where they do, the submission, including any email address and identify traits, is sent to that destination. We don't control it, and the customer is responsible for what happens there.

We also disclose information where the law requires it, and to a buyer if the business is ever sold, in which case this policy travels with it.

08If you submitted feedback through a widget

The business whose site you were on controls that record. The fastest way to have it corrected or deleted is to ask them directly. You can also write to support@usevoicebox.dev and we'll pass the request on and help them action it.

The widget sets no cookies, stores nothing on your device, and does not follow you between sites. It records the page you submitted from and the page that referred you there, and nothing else about your browsing.

09Retention

Feedback and themes are retained for as long as the customer's account exists, their value is that they accumulate. Cancelling a paid plan deletes nothing; the account moves to the free tier and the history stays accessible and exportable.

Two things expire on their own: submitter IP addresses are deleted after seven days, and invitations are removed once accepted, revoked, or expired.

Deleting an organization removes it, its projects, its feedback, its themes, and the accounts of anyone who was only a member there. That happens immediately, from Settings, and cannot be undone. Backups roll off within 30 days.

10Your rights

Depending on where you live you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and not to be discriminated against for asking.

Two of those are buttons rather than requests. Export everything and Delete this organization are both under Settings, on every plan, and neither requires talking to us. For anything else, write to support@usevoicebox.dev and we'll respond within 30 days.

If you're in the UK or EEA and think we've got this wrong, you can complain to your data protection authority, in the UK the Information Commissioner's Office. We'd rather you told us first so we can fix it.

11Security

Data is encrypted in transit. API keys are stored only as hashes and shown to you exactly once. Card details, when paid plans are enabled, are handled entirely by Stripe and never reach our servers. No system is perfectly secure and we won't pretend otherwise.

If a breach affects your data, we'll notify affected customers without undue delay and within 72 hours of becoming aware, with what we know, what we're doing, and what you should do.

12Children

Voicebox is a business tool, is not directed at children under 13, and we do not knowingly collect their information. Customers agree not to install the widget on services directed at children. If you believe a child has submitted feedback through Voicebox, tell us and we'll remove it.

13Changes

We'll email account holders before making material changes and update the date at the top of this page.