Effective date: 1 May 2026 · Policy version: 2026-05-01
Each top-level heading below is a self-contained section. You can replace any single section without breaking the rest of the document. Section IDs are in square brackets [SECTION-ID] for cross-referencing.
is built on trust. We process the minimum amount of personal data necessary, never sell it, never use it for advertising profiling, and give you full control over what we store. This policy explains exactly how we handle your information under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR & Data Protection Act 2018, the EU Artificial Intelligence Act (Regulation (EU) 2024/1689, "AI Act"), the California Consumer Privacy Act / California Privacy Rights Act ("CCPA/CPRA"), the Lithuanian Law on Legal Protection of Personal Data, and applicable e-Privacy rules.
This policy is layered:
If anything in this document is unclear, that is our problem, not yours — email [email protected] and we will explain it in plain language within 48 hours.
The data controller responsible for personal data processed through voxsoma.com and related services is:
Ramūnas Deniušis, sole trader operating under Lithuanian individual activity (individuali veikla).
Note on the registered address. The address above is the legal address used solely for tax, legal notices, and regulatory correspondence. We do not operate a public office. For day-to-day communication please use the email addresses above; we typically reply within 48 hours and always within the statutory 30-day deadline for data-subject rights requests.
No mandatory Data Protection Officer (DPO). As a sole-trader micro-business that does not carry out (a) systematic monitoring of data subjects on a large scale or (b) large-scale processing of special-category data, is not required to appoint a DPO under GDPR Article 37. The privacy contact above performs the equivalent function. You may always escalate any privacy concern to the supervisory authority (see Section 19).
is a digital audio wellness content product. It generates personalised audio tracks combining stereo difference tones, isochronic tones, Schumann-resonance carriers, and (optionally) your own voice recording layered with affirmation text.
is explicitly not:
No automated decision-making with legal or significant effects. We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of GDPR Article 22. The AI we use generates content (affirmation text, audio scripts) — it does not make decisions about you.
Your voice recording stays in your browser — it never reaches our servers. Your affirmation text and chat assistant messages are sent to Anthropic's Claude API for content generation under their commercial Data Processing Agreement, and are not persisted to our application databases. Payments are handled by Stripe. We use Cloudflare for hosting and Resend for transactional emails (with Loops for Elite intake notifications and Brevo for partner outreach — see the sub-processor table). We collect the minimum necessary, never sell your data, never use it for advertising, and give you full GDPR/UK GDPR/CCPA rights. Questions: [email protected].
The following table sets out every category of personal data we process, the purpose, the lawful basis, and the retention period. This table is the canonical reference; all other sections elaborate on it.
| # | Data category | Purpose | Lawful basis (GDPR Art. 6 / 9) | Retention |
|---|---|---|---|---|
| 1 | Voice recordings (your own voice for layering into the audio track) | Local audio mixing inside your browser | Art. 6(1)(b) — contract; not processed as biometric identification data (see Section 6) | Stored only in your browser's IndexedDB; we never receive a copy. Cleared when you clear site data or use the self-service erasure page. |
| 2 | Affirmation / intention text entered into the generator | AI-generated affirmation script | Art. 6(1)(b) — contract | Not persisted to our databases. May exist transiently in edge-infrastructure logs ≤ 24h. Token-count metadata (no identifiers) ≤ 90 days for billing. |
| 3 | Chat assistant messages | AI-powered customer assistance | Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interest in service quality | Not persisted to our databases. May exist transiently in edge-infrastructure logs ≤ 24h. |
| 4 | Email address | Delivery of purchased product, transactional notifications, GDPR-rights identity verification | Art. 6(1)(b) — contract | Until erasure request, or 5 years after last transaction (Lithuanian accounting law obligation, see Section 13). |
| 5 | First name (optional, for personalised email greeting) | Email personalisation | Art. 6(1)(a) — consent (collected only if you provide it) | Same as email. Withdrawable any time. |
| 6 | Country & billing details (collected by Stripe) | Tax calculation (VAT/sales tax), fraud screening, regulatory compliance | Art. 6(1)(c) — legal obligation (tax law); Art. 6(1)(b) — contract | Held by Stripe under its retention policy; we receive only minimal echo (country, last 4 digits of card, transaction ID). 10 years where required by Lithuanian tax law. |
| 7 | Access token | Re-access purchased content without re-paying | Art. 6(1)(b) — contract | Stored in your browser local storage. Deleted when you clear site data. |
| 8 | IP address & request logs | Security, abuse prevention, bot mitigation, fraud screening | Art. 6(1)(f) — legitimate interest | ≤ 30 days at Cloudflare edge; aggregated security telemetry ≤ 12 months. We also run our own abuse counters: a free-use counter keyed to your IP address (≤ 365 days) and short-lived rate-limit counters (1 hour to 48 hours). These store a count, not a browsing history. |
| 8a | Safety-review records — created only when a chat message triggers one of our safety filters | Enforcing our content rules; responding appropriately where a message suggests someone may be at risk | Art. 6(1)(f) — legitimate interest | ≤ 30 days, then automatically deleted. Holds an excerpt of the flagged message, an excerpt of the assistant's reply, and the IP address. This is the only case in which we retain message content — ordinary affirmation text and chat messages are not persisted (see rows 2 and 3). |
| 8b | Waitlist email (if you join the Overnight Session waitlist) | Telling you when that product launches | Art. 6(1)(a) — consent | ≤ 730 days, or until you ask us to remove you. We store the email address and a signup timestamp only. |
| 8c | Elite / Complete-bundle intake — your name, email, and the free-text you write about what you want and what to avoid | Producing the bespoke track you ordered, handling revisions, and evidencing what was ordered if a payment is disputed | Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interest for dispute evidence | ≤ 365 days, then automatically deleted. The track itself is produced within 5–7 days; the record is kept beyond that only for revision requests and because card-scheme chargeback windows run to roughly 120 days. |
| 9 | Cookie consent record (choice + policy version + timestamp) | Compliance evidence under e-Privacy Directive and GDPR Art. 7(1) | Art. 6(1)(c) — legal obligation | Stored in your browser. Mirrored server-side ≤ 13 months solely as audit evidence. |
| 10 | Affiliate referral ID & sale event (only if you arrived through an affiliate link and consented to non-essential cookies) | Affiliate commission calculation | Art. 6(1)(a) — consent (cookie consent) | ≤ 24 months from last referral activity. |
| 11 | Age-confirmation flag (boolean) | Age-gate compliance | Art. 6(1)(c) — legal obligation; Art. 8 GDPR (children's data) | Until erasure. |
No special-category (Art. 9) data is processed. See Section 6 for our position on voice data.
No criminal-conviction data (Art. 10) is processed.
When you record your voice on , the audio is captured by the Web Audio API running entirely inside your browser, stored locally in IndexedDB, and used solely to layer your own voice into the audio track that you then download. The audio data is never transmitted to our servers. We do not have, and cannot obtain, a copy.
GDPR defines biometric data as data resulting from "specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person" (Art. 4(14)). Article 9 special-category status applies only when the data is processed for the purpose of uniquely identifying a natural person.
:
The voice data is therefore raw audio used as a passthrough mixing input — it is not processed for the purpose of unique identification, and Art. 9 does not apply. This position is consistent with EDPB Guidelines 3/2019 and the European Data Protection Board's clarifications on biometric data.
The EU AI Act (Reg. 2024/1689) prohibits real-time remote biometric identification in publicly accessible spaces (Art. 5) and classifies biometric categorisation and emotion recognition systems as high-risk or limited-risk depending on context (Annex III; Art. 50). performs none of these activities. Voice is used solely as a creative input by the user themselves on their own device.
You can clear all locally stored voice recordings at any time by:
We have no record of when you do this because we never had the data.
does not operate user accounts, passwords, or login systems. To enable users to restore their library on a new device, we use a 6-word Recovery Card generated deterministically at purchase time and shown on the success page. The user is responsible for saving the 6 words (we recommend their password manager or a screenshot).
On a new device, the user enters the 6 words and we restore their library entitlements. This is the only way library state crosses devices. We do not sync, push, or back up your library to our servers — only entitlement records (which products you purchased) are stored, keyed by a one-way hash of your Recovery Card. Your voice recordings, your affirmations, and your baked audio files never leave your device. If you lose the Recovery Card, your Stripe purchase receipt is the legal fallback — contact [email protected] with the receipt and we will manually verify and restore.
The Recovery Card hash is processed under GDPR Art. 6(1)(b) (performance of a contract — delivery of the lifetime access you purchased). We retain the hash for the lifetime of your purchase. To erase the hash and forfeit your future restore ability, contact us — but note this also makes future device transfers impossible.
Two features use the Anthropic Claude API:
In compliance with EU AI Act Article 50, we expressly inform you:
This disclosure is also surfaced inside the chat assistant interface itself.
The AI provider is Anthropic, PBC (a Public Benefit Corporation incorporated in Delaware, USA), acting as our data processor under GDPR Article 28. The processing is governed by Anthropic's Commercial Terms of Service and Anthropic's Commercial Data Processing Addendum (DPA), which form part of our contract with Anthropic for API access.
We use Anthropic's Claude API under Commercial Terms. This is materially different from Anthropic's consumer products (Claude Free / Pro / Max). Specifically:
claude-haiku-4-5 (or a successor model in the same family if Anthropic deprecates the version).To avoid unnecessary processing of sensitive data, please do not include in your inputs: full names of third parties, government identifiers, payment-card numbers, medical history, or other special-category data. The affirmation generator and chat assistant do not need this information to function. We do not block such inputs technically, but we filter and minimise them in line with GDPR Art. 5(1)(c) (data minimisation).
Payment processing is performed exclusively by Stripe, Inc. (USA) and its EU sub-entities (Stripe Payments Europe Ltd., Ireland). Stripe is PCI-DSS Level 1 certified.
We never see, store, or transmit your full card number, CVC, or expiry date. The card data flows from your browser directly to Stripe over an encrypted connection (TLS 1.2+), and we receive only:
Legal basis: GDPR Art. 6(1)(b) (contract) and Art. 6(1)(c) (legal obligation — tax & accounting law).
Retention: Stripe retains transaction data per its own retention policy. We retain transaction-linked records for 10 years as required by Lithuanian accounting law (Buhalterinės apskaitos įstatymas, Art. 19) and EU VAT rules (Council Directive 2006/112/EC).
For Stripe's own privacy practices and lawful basis for transfers, see Stripe's Privacy Policy and Stripe's Data Processing Agreement.
These are every third party that receives personal data in the course of running this service, what they receive, and why. This list is derived from the code that actually runs, not from an intended architecture.
| Sub-processor | What it receives | Purpose | Location |
|---|---|---|---|
| Cloudflare, Inc. | IP address, request metadata, and all data stored in Workers KV and R2 | Hosting, CDN, bot mitigation, application storage, audio delivery | USA (company); the R2 audio bucket is provisioned in the Eastern Europe (EEUR) region |
| Stripe, Inc. / Stripe Payments Europe Ltd. | Payment details, billing country, email | Payment processing, tax calculation, fraud screening | USA / Ireland |
| Anthropic PBC | Affirmation / intention text and chat assistant messages | Generating affirmation scripts and answering product questions | USA |
| Resend | Your email address and the message content | Transactional email — purchase confirmation, recovery and support mail | USA |
| Loops | Email address and event metadata | Notification and follow-up mail for Elite intake submissions | USA |
| Brevo (Sendinblue) | Recipient business email address | Partner outreach only, sent from [email protected]. Deliberately isolated from the transactional pipeline; it never touches customer purchase or recovery mail. | France (EU) |
Correction to an earlier version of this policy. The summary above previously named Loops as the provider of transactional email. That was inaccurate: transactional mail is sent through Resend, and Loops is used for Elite intake notifications. Both are now listed separately with their real roles.
International transfers. Cloudflare, Stripe, Anthropic, Resend and Loops are established in the United States, so using this service involves transferring personal data outside the EEA. Each of these providers offers a Data Processing Agreement incorporating the European Commission's Standard Contractual Clauses (Decision 2021/914) as its transfer mechanism. Brevo processes within the EU.
What we do not do. We do not sell personal data, we do not share it with advertising networks, and we do not use it to train any AI model. No sub-processor beyond those named above receives personal data. If that ever changes, this table changes first.
If you would like a copy of the transfer safeguards for any specific provider, email [email protected].
uses only strictly necessary functional storage by default. We do not use advertising cookies, cross-site tracking pixels, or third-party analytics that follow you across the web. Specifically:
| Technology | Purpose | Type | Lifetime |
|---|---|---|---|
voxsoma_consent (localStorage) | Records your cookie-consent choice, policy version, timestamp | Strictly necessary (compliance evidence) | 13 months |
voxsoma_token (localStorage) | Lets you re-access purchased content | Strictly necessary | Until cleared by you |
Cloudflare __cf_bm / Turnstile | Bot mitigation, abuse prevention | Strictly necessary (security) | Session / 30 minutes |
Stripe __stripe_mid / __stripe_sid | Fraud prevention during checkout | Strictly necessary (security) | 1 year / 30 minutes |
| Rewardful affiliate cookie | Affiliate commission attribution | Non-essential — only set after explicit consent | 60 days |
Consent mechanism. Before any non-essential cookie (currently only the Rewardful affiliate cookie) is set, we present a consent banner that complies with GDPR Article 7 (informed consent), ePrivacy Directive Article 5(3) (storage consent), and the EAA 2025 accessibility requirements. The banner allows you to Accept, Reject, or close (which is treated as rejection). Your choice is stored in voxsoma_consent with a 13-month TTL. You can withdraw consent at any time via Cookie Settings or by clearing your browser storage.
You have the right to: (a) access the personal data we hold about you; (b) request rectification of inaccurate data; (c) request erasure (the "right to be forgotten"); (d) restrict processing; (e) data portability; (f) object to processing; (g) lodge a complaint with your local supervisory authority (in Lithuania: State Data Protection Inspectorate). California residents have additional rights under CCPA — see our CCPA Opt-Out page.
To exercise any of these rights, contact [email protected]. We respond within 30 days as required by law.
Privacy questions or requests: [email protected]. We may update this policy from time to time; the version date at the top of this page reflects the most recent revision. Material changes will be announced on the homepage and via email to active subscribers where applicable.