VoiceReelAinos Technology

Privacy Policy

Effective date: September 26, 2026

1. Overview

VoiceReel is a creator tool for short-form video. It lets you browse and play pre-built scripted scenes, schedule simulated ("fake") incoming calls to your own device, apply on-device voice effects to audio you record, and, after you sign in, generate AI scripts and AI voice audio, transform a recording into another voice in the cloud, and create a voice clone from recordings you supply. This Privacy Policy explains what data we collect, why we collect it, who processes it on our behalf, how long we keep it, and the rights you have over it. We designed VoiceReel to collect as little personal data as possible: you can use much of the app without giving us your name or email address.

We are the data controller for the personal data described here. Our servers and primary database are hosted in the European Union (Germany). VoiceReel is provided by Ainos Technology ("Ainos", "we", "us", "our"). Two parts deserve particular attention before you use the paid AI features: Section 6 (voice cloning and cloud voice transformation, which process a recording of a voice) and Section 8 (analytics, advertising, and your consent choices).

2. Accounts and Anonymous Use

You can install and use VoiceReel without signing in. When you first open the app, it generates a random device identifier (a UUID stored securely on your device), and our server creates an anonymous account linked to that identifier. The anonymous account holds no name, email address, or phone number. It lets the app work, lets you earn and spend credits, and helps us prevent abuse. The following features work without signing in:

  • Browsing and playing pre-built scenes
  • Scheduling a simulated incoming call to your own device (caller name, preset avatar, timer)
  • Using the on-device voice changer (effects applied locally on your device)
  • Saving favorites to your device's local storage

You can also create a full account in one of three ways: Sign in with Apple, Sign in with Google, or an email address and password. With Apple or Google, we receive your email address (Apple may give us a private relay address instead), your name if you allow it, a profile picture URL (Google), and the provider's account identifier. With email and password, we store your email address and your password as a salted hash; we never store or log your password in plain text. If you forget your password, or if you delete your account from our website, we email you a one-time code (see Section 9). The AI features (script generation, voice generation, voice cloning, and cloud voice transformation) require you to sign in, because they consume credits that must be tied to a verified identity to prevent abuse.

3. Data We Collect and Why

Data you provide or that is created when you use the app, plus data collected automatically:

  • Device identifier (random UUID) — Created on first launch, to run the app, link your anonymous account, and protect against abuse.
  • Email address, display name, profile picture URL — Only if you create an account (Apple, Google, or email and password), to create and identify your account, restore purchases, and respond to you. You can edit your display name in the app.
  • Authentication provider identifier — The Apple or Google account ID, only if you sign in with Apple or Google, to link your VoiceReel account to that identity. It is never shown to other users or exposed by our API.
  • Password hash — Only for email and password accounts, to authenticate you.
  • AI generation prompts, scripts, and script revisions — When you generate or edit AI content, to produce the content you asked for and keep it in your library. A redacted copy is kept in an internal operational log (see Section 5).
  • Generated voice audio — When you generate AI voice, to deliver the audio you requested and keep it in your library.
  • Voice-clone samples, clone name, and consent record — Only when you create a voice clone. The samples are sent to ElevenLabs and are not stored by us (see Section 6).
  • Cloud voice-transform audio — Only when you run a cloud voice transformation. The clip you submit is sent to ElevenLabs and is not stored by us; the transformed result is stored in your library (see Section 6).
  • Scheduled-call details — On iOS, the caller name, the preset avatar you chose, the time you picked, and your device's call-push token, so our server can deliver the call to your own device (see Section 7).
  • Push notification tokens — If you allow notifications, and on iOS for scheduled calls, to deliver notifications and calls to your own device.
  • Credit balance and credit movement history — To run the credit system, prevent fraud, and provide purchase support.
  • Subscription and purchase metadata — To grant entitlements, support restores and refunds, measure our advertising (Section 8), and meet tax and accounting obligations.
  • Locale, theme, and app settings — To deliver the app in your language and preferences.
  • Support ticket content — Your email address, the category, subject, and message, your app version, and an optional device record (platform, device model, OS version), to respond to your request. Attachments are not accepted.
  • IP address and security audit trail — For security, fraud and abuse prevention. Sensitive operations (for example sign-in, credit changes, purchases, scheduled calls, support tickets) are recorded in a security audit trail with the IP address and a shortened device/app description. The password-reset and web account-deletion forms can be used without signing in, so for each attempt we record an unsalted SHA-256 hash of the email address entered and the IP address, even if that address has no VoiceReel account. We treat these hashes as personal data.
  • Approximate location (country) — Derived from your IP address by PostHog and by the Google AdMob SDK, for analytics and ads. We do not collect precise location.
  • Crash reports, performance data, and diagnostics — Via the Sentry SDK, linked to your VoiceReel user ID so we can investigate problems you report. The Sentry SDK is configured not to attach default personal data, and app-authored fields are scrubbed before sending.
  • Product analytics events — Via the PostHog SDK (EU instance), linked to your VoiceReel user ID, not to your name or email, to understand feature usage and improve the app. Session recording is off. Consent-gated where required (see Section 8).
  • Google Analytics events — Via the Firebase Analytics SDK, a limited set of events (for example app open, sign-up, generation, and purchase) with your VoiceReel user ID, to measure our Google Ads campaigns. Consent-gated (see Section 8).
  • Advertising data — When you watch a rewarded ad: your VoiceReel user ID, a one-time request ID, and ad-interaction data sent to Google AdMob. On Android only, the Google advertising ID may also be used (see Section 8).

We do not access your contacts, call logs, SMS or text messages, photos, or your real phone number. VoiceReel does not place real phone calls or send real messages: a simulated call only ever rings your own device. During a scene call the app reads only the loudness level of the microphone to detect when you have finished speaking; that audio is not recorded, stored, or sent anywhere. We do not sell your personal data (see Section 12).

4. On-Device Data

Some data stays on your device: your favorites and recently played scenes, saved caller presets, voice-changer recordings and their history, downloaded scene audio, and app settings. On-device voice-changer recordings are processed locally and are not uploaded, unless you choose a cloud voice transformation (Section 6). When you first sign in, the app sends your favorites and recent plays to our server so they can be moved onto your account; our server records only how many there were, not which scenes. Signing out erases favorites, caller presets, and voice-changer recordings from the device, and deleting your account clears the app's local data on the device you delete from.

Uninstalling the app removes its local data from the device. Copies of app data in your own device backups (for example Android automatic backup or an iCloud backup), and content you have already shared or exported to other apps, are outside our control.

5. AI-Generated Content

When you generate an AI script, your prompt text and the scene details you enter are sent to OpenAI to produce the script. When you generate AI voice, the script text is sent to ElevenLabs to synthesize the audio. To help improve the quality of AI generation, we participate in OpenAI's data-sharing program: your generation prompts and the resulting scripts may be used by OpenAI to develop and improve their models. Because of this, please do not include personal, sensitive, or confidential information in your generation prompts; the prompts are meant to describe a fictional scene for a short video, not to carry personal data. VoiceReel does not run its own content-screening step on your prompts; OpenAI and ElevenLabs apply their own safety systems and may decline some requests. You remain responsible for what you create under our Terms of Service.

We also keep an internal log of AI requests and responses, which we use to operate, debug, and improve the service and to prevent abuse. Before an entry is stored we redact personal identifiers (such as email addresses, phone numbers, and card-like numbers); voice-clone audio is never written to it. The log is held in a store separate from our main database and is never sent to our analytics providers. It has no fixed expiry: we remove older entries manually, and we delete your entries when you delete your account.

6. Voice Cloning and Cloud Voice Transformation

These two optional features process a recording of a human voice, which some laws treat as biometric or sensitive data. Please read this section before using them.

  • What voice cloning collects — The audio samples you record or import, a name for the clone, and your consent record. The samples are streamed to ElevenLabs, which creates the voice clone (a voice model) on its infrastructure and returns an identifier. We do not store your samples: they are held in memory only long enough to check and upload them. We keep the clone's name, language, the ElevenLabs identifier, and your consent record.
  • Purpose — Only to let you generate speech in the cloned voice inside VoiceReel. We do not use voice clones to identify you, to infer anything about you, or for advertising.
  • Consent — Before a clone is created, you must confirm either that the voice is your own or that you have permission from the person whose voice it is. Our server rejects a clone request without this confirmation and records which statement you chose, the version of the consent text you saw, and a server timestamp, linked to your account and the clone. Our legal basis is your explicit consent. Please do not clone anyone's voice without their permission. If you believe a clone was made from your voice without consent, contact [email protected].
  • Retention and deletion — The voice clone stays at ElevenLabs until you delete it in the app or delete your account. Deleting it removes it from your library and instructs ElevenLabs to delete it; if that request fails, our server retries until ElevenLabs confirms the deletion, and your account is not finally purged until that is confirmed. The consent record is kept as evidence that consent was given.
  • Cloud voice transformation — When you use speech-to-speech or background-noise isolation, the clip you record or import is sent to ElevenLabs for processing. We do not store the source clip: it is held in memory, sent to ElevenLabs, and then discarded. Only the transformed result is stored in your library, until you delete it or your account.

The free voice changer applies its effects on your device and does not upload your audio. Your device asks for microphone permission once; the permission covers the on-device voice changer, voice cloning, cloud voice transformation, and turn detection during scene calls, and only voice cloning and cloud voice transformation send audio off your device.

7. Scheduled Calls and Push Notifications

A simulated call rings only your own device. On Android, a scheduled call is set as a local alarm on your device, and the call details stay on the device. On iOS, a scheduled call is normally delivered by our server: when you schedule it, the app sends us the caller name, the preset avatar you chose, the time, and your device's call-push token, and at the chosen time our server sends a push through the Apple Push Notification service (APNs) so the call can ring even when the app is closed. If server delivery is not available, the iOS app falls back to a local notification on the device.

Other push notifications are delivered through Firebase Cloud Messaging (Google) and APNs, using your device's push token. Cancelling a scheduled call cancels the server delivery. Deleting your account cancels any pending scheduled call and clears your push tokens.

8. Analytics, Advertising, and Your Consent Choices

We use two analytics services: PostHog (EU instance) for product analytics, and Firebase Analytics (Google Analytics 4) for a limited set of events used to measure whether our Google Ads campaigns work, including purchase events (amount, currency, and transaction ID, never card or bank details). We do not send your email address, prompts, scripts, or audio to these services. Rewarded video ads are served by Google AdMob. When you choose to watch one, the app attaches your VoiceReel user ID and a one-time request ID so Google can confirm to our server that you watched the ad before we grant credits.

  • EEA, UK, and Switzerland — Analytics and advertising collection is off by default when the app starts. Google's User Messaging Platform (UMP) shows a consent form, and we apply your choices through Google Consent Mode. If you decline, or your choice cannot be determined, analytics stays off and AdMob serves only non-personalized (or limited) ads. You can change your choices at any time in Settings → Privacy choices.
  • Other regions — Analytics is on by default, and you can turn it off in Settings with the "Share anonymous usage data" switch. Ads may be personalized by Google according to its policies.
  • Advertising identifiers — On iOS, VoiceReel does not request App Tracking Transparency permission, does not access the advertising identifier (IDFA), and does not track you across other companies' apps or websites. On Android, Google Analytics and AdMob may use the Google advertising ID, subject to your consent where required; you can reset or delete it, or opt out of ads personalization, in your device settings.

9. Transactional Email

We send a small number of transactional emails: the one-time code to reset a forgotten password, and the one-time code to delete an account from our website. These emails are sent through Brevo, which receives your email address and the message content (including the code). Codes are 8 digits, expire after 10 minutes, allow a limited number of attempts, and are rate-limited per address. We do not send marketing email.

10. Sub-Processors

We use the third-party service providers below to operate VoiceReel. Each receives only the data needed for its specific function. We maintain Data Processing Agreements with our sub-processors as required by GDPR Article 28:

  • OpenAI — AI script generation. Receives your prompt text, the scene details you enter, and the generated script; under OpenAI's data-sharing program, which we have enabled to improve generation quality, this content may also be used by OpenAI to develop and improve their models.
  • ElevenLabs — AI voice synthesis, voice cloning, and cloud voice transformation. Receives the text to be spoken and returns the audio; receives your voice-clone samples and stores the resulting voice clone; receives the clip you submit for transformation and returns the result.
  • RevenueCat — Subscription and in-app purchase management. Receives purchase information and your VoiceReel user ID.
  • Google AdMob and User Messaging Platform — Rewarded video ads, reward verification, and consent collection. Receives your VoiceReel user ID and a one-time request ID when you watch an ad, ad-interaction and device data, approximate location derived from IP address, and, on Android, the advertising ID.
  • Firebase Analytics / Google Analytics (Google) — Google Ads campaign measurement. Receives a limited set of usage and purchase events with your VoiceReel user ID and a Firebase installation ID, and, on Android, the advertising ID. Consent-gated (Section 8).
  • Firebase Cloud Messaging (Google) and Apple Push Notification service — Push notifications and delivery of scheduled calls on iOS. Receive your device push token and the notification content.
  • Brevo — Transactional email. Receives your email address and the one-time code email.
  • Sentry — Crash and error reporting. Receives stack traces, performance data, and device state, linked to your VoiceReel user ID.
  • PostHog — Product analytics (EU instance). Receives usage events linked to your VoiceReel user ID, and derives your country from your IP address.
  • Apple and Google sign-in — If you choose them, Apple and Google authenticate you and share your account identifier, email address, and (if you allow it) name with us.
  • Hetzner — Data hosting (servers and database). Hosts all server-side data, in the European Union (Germany).
  • Cloudflare — Content delivery, DNS, web application firewall, and backup storage. Receives network request metadata including IP addresses, and stores our encrypted backups.

Payments themselves are processed by Apple (App Store) and Google (Google Play). We never receive or store your full payment card details; Apple and Google handle billing and provide us only with the purchase metadata needed to grant your entitlements. In the current version all AI voice audio is produced by ElevenLabs; if we add another voice provider that would receive your data, we will update this policy first.

11. Data Retention and Deletion

We keep personal data only as long as needed for the purpose it was collected, then delete or anonymize it:

  • Account and user-generated content — Scripts, generated audio, transformed audio, and scheduled calls are kept until you delete them or your account, then removed within 30 days of account deletion.
  • Voice-clone samples and voice-transform source clips — Not stored by us.
  • Voice clones at ElevenLabs — Until you delete the clone or your account; deletion is retried until ElevenLabs confirms it (Section 6).
  • Voice-clone consent record — For the life of the clone, and afterwards in our security audit trail as evidence that consent was given.
  • Internal AI request log — No fixed period; older entries are removed manually, and your entries are deleted when you delete your account (Section 5).
  • Push tokens — Until you turn off notifications or delete your account.
  • Security audit trail, including the email-hash records of password-reset and web-deletion attempts — Kept only as long as needed to detect and investigate abuse and fraud. We review it periodically and remove entries that are no longer needed, and we remove entries on request where the law requires it. It is not removed by the account-deletion purge. If you want records about your email address removed, email [email protected].
  • One-time email codes — 10 minutes, then invalid.
  • Credit movement records — For the life of the account; retained in anonymized form for audit integrity after account deletion.
  • Purchase events — Up to 7 years, to meet tax and accounting obligations.
  • Support tickets — As long as needed to handle your request and any follow-up, and deleted with your account.

You can delete your account at any time from Settings → Delete Account in the app, or, if you cannot sign in, at ainostec.com/voicereel/delete-account by confirming an emailed code. Deletion immediately signs you out and invalidates your authentication tokens, removes identifying details (email, name, avatar, sign-in identifiers) from your account record, hides your content, cancels scheduled calls, clears push tokens, and instructs ElevenLabs to delete your voice clones. Within 30 days a scheduled process permanently deletes your account data, scripts, generations, and associated audio files (GDPR Article 17, "right to erasure"). Some records are retained after deletion only where the law requires it (for example, purchase and tax records), in anonymized form for ledger-integrity audits, or in the security audit trail as described above.

12. Your Privacy Rights

If you are in the EEA or UK, under GDPR you have the right to access the personal data we hold about you, rectify inaccurate data, erase your data ("right to be forgotten") via account deletion, port your data, object to or restrict certain processing, withdraw consent where processing is based on consent (including your analytics and advertising choices in Settings, and your voice-clone consent by deleting the clone), and lodge a complaint with your local data protection authority. There is no self-service export button yet; to get a copy of your data, email [email protected] and we will send it within the period the law allows. To exercise any of these rights, use the in-app controls or email [email protected].

If you are a California resident (CCPA/CPRA), you have the right to know what personal information we collect, to request its deletion or correction, and to not be discriminated against for exercising these rights. We do not sell your personal information. Rewarded ads are served by Google AdMob, which may use device and ad-interaction data to personalize ads as described in Section 8; you can make a "Do Not Sell or Share My Personal Information" request at [email protected]. A voice clone may be sensitive personal information; we use it only to provide the clone you asked for. We will respond to all requests within the timeframes required by applicable law, and we may need to verify that a request comes from you.

13. Children's Privacy

VoiceReel is not directed to children. You must be at least 13 years old (or the minimum age of digital consent in your jurisdiction, if higher) to use the app. We do not knowingly collect personal data from children under that age, and the voice-cloning feature must not be used with a child's voice. If you believe a child under that age has provided us with personal data, contact [email protected] and we will delete it.

14. Data Security

We protect your data with measures including: encryption in transit (HTTPS/TLS) for all API traffic; encrypted backups; strict access controls and isolation of administrative interfaces; rate limiting and replay protection on sensitive operations; an encrypted local database on your device; and redaction of sensitive fields from our logs (we do not log email addresses, passwords, one-time codes, payment data, authentication tokens, or raw audio; our internal AI request log has personal identifiers redacted as described in Section 5). No method of transmission or storage is perfectly secure, but we work to protect your data using industry-standard practices.

15. International Data Transfers

Our servers and primary data store are located in the European Union (Germany). Some sub-processors listed in Section 10 process data outside your country, including in the United States; this includes ElevenLabs, OpenAI, Google, Apple, RevenueCat, and Sentry. Where required, such transfers are governed by appropriate safeguards (for example, Standard Contractual Clauses or an adequacy decision).

16. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you in the app. Continued use of VoiceReel after an update means you accept the revised policy.

17. Contact

Questions about this policy or your data:

Ainos Technology
Email: [email protected]
Web: ainostec.com/voicereel