EFFECTIVE JULY 14, 2026
Privacy policy
Spoke is designed around a simple boundary: your recordings and transcription stay on your device.
What Spoke stores locally
Voice recordings, transcripts, note text, titles, tasks, tags, playback data, local search data, transcription models, and local AI-usage diagnostics are stored on your Android device. Uninstalling the app or deleting local data can remove them. Spoke does not upload audio.
Optional account and sync
If you explicitly sign in and choose to move a workspace into your account, Spoke uses Firebase Authentication and Cloud Firestore to sync note text, transcript text, titles, task-related note data, timestamps, language settings, deletion markers, and other note metadata. Audio, embeddings, provider usage, and hidden server fields are not accepted by sync.
Cloud AI in version 1.0.1
OpenAI and Anthropic features are unavailable. Ask, Create, semantic recall, and generated observations are locked previews. Tapping these previews does not send note text to an AI provider.
Required service and security metadata
Spoke uses Firebase App Check, Installations, Remote Config, Authentication, Firestore, and callable Functions. These services may receive an app-installation identifier, integrity token, IP-derived country code, language and time-zone settings, app and operating-system version, device model, network type, and ordinary request metadata. We use this information to protect the backend from abuse, authenticate requests, maintain compatibility, and deliver app configuration. It is not used to send note text or audio to an advertising or cloud-AI provider.
Optional analytics and crash reports
Firebase Analytics and Firebase Crashlytics default off. After your first successful note, Spoke offers separate opt-ins. If enabled, analytics may record content-free events and technical attributes such as model setup, capture completion, feature entry point, counts, durations, app version, and device class. Crash reports may include stack traces and technical diagnostics. We never intentionally include note text, titles, transcripts, search terms, email addresses, or audio in analytics parameters.
Website analytics
This website does not load Microsoft Clarity until you choose “Allow analytics.” If allowed, Clarity can collect clicks, scrolling, mouse movement, page layout, performance and diagnostic events, referrer, device/browser details, approximate country, and masked page content to provide heatmaps and reconstructed session recordings. Advertising storage remains denied. The website never contains or sends your Spoke notes, transcripts, search terms, email, or audio to Clarity. Microsoft controls Clarity data retention under its published retention policy. You can change your choice at any time.
Model downloads and network data
The private transcription model is downloaded from the model host selected in the app build. The host can receive ordinary connection data such as IP address and user agent. The model is checksum-verified and used locally.
Retention, deletion, and security
Synced data remains until you delete it or your account. In-app account deletion requires recent reauthentication and deletes account-owned server records. Local notes and audio remain unless you separately delete them. You can also use the external deletion process. We use authentication, App Check, owner-scoped database rules, schema validation, and transport encryption.
Contact
For privacy questions, email hi@studiokunj.com. Studio Kunj operates Spoke.