Privacy policy
This policy explains what SAWANT CORE LLP processes when you use Sawoice, what remains on your device, which providers receive cloud content, and how to exercise your rights.
Legal and grievance identity
Operator of Sawoice at sawoice.com. Public legal, privacy, grievance, and customer-care contact is email-only.
SAWANT CORE LLP operates Sawoice and is the controller of the account, product-operation, support, and Sawoice API data described here. The website identity is sawoice.com. Privacy, grievance, support, and customer-care requests may be sent to support@sawoice.com.
Local transcription runs on the device. Sawoice does not receive local microphone audio, local transcript history, dictionary entries, local settings, or the passive three-second voice-activation buffer merely because those features are used.
Local history is optional. When enabled, it is plaintext inside the user-protected application-data directory. Device credentials are stored using the operating system credential facility where supported. Local settings, history, dictionaries, downloaded models, and device-held provider data remain subject to the device owner's controls and backups.
We process the minimum account, authentication, entitlement, device-linking, support, and security data needed to provide the service. This can include name, verified email address, account and session identifiers, age attestation, legal-document acceptances, linked-device metadata, settings selected for sync, plan and entitlement state, and stable security events.
We do not ask for a date of birth. Sawoice is restricted to people aged 18 or older, and records only an age attestation.
When you explicitly choose Cloud Boost or Cloud TTS, the desktop or mobile client sends the requested audio or text through the Sawoice API to the selected provider. Sawoice relays the content for that request and does not retain cloud audio, realtime frames, prompts, or transcript bodies after the response completes by default.
Before a cloud request, Sawoice presents provider-specific notice and records an acknowledgement that you requested cloud processing after seeing that notice. This record is not described as privacy consent and does not replace any legal permission needed to record another person.
Providers have different retention, training, residency, and account-control terms. The current configured mode and last policy-review date appear on the Cloud Processing and Subprocessors pages. An unverified setting is shown as unknown.
A cloud transcript body is not stored by Sawoice by default. If a user explicitly saves a mobile transcript as a note, that note is stored as user content until the user hard-deletes it or closes the account.
When mobile privacy mode is enabled, automatic transcript-to-note persistence is refused. A manually authored or explicitly saved note remains permitted. Deleted mobile notes are hard-deleted rather than archived.
We retain identifiable cloud request metadata and API write-event records for 13 months for quota calculation, cost reconciliation, service reliability, fraud prevention, and security. These records may include user and device references, provider, model, route, timestamps, duration, latency, stable outcome code, credit usage, and calculated cost.
They do not include audio, transcript text, prompts, tokens, provider response bodies, raw error messages, or full request bodies. After account deletion, eligible usage is converted to anonymous provider/model/month financial aggregates.
Polar Software, Inc. is the buyer-facing Merchant of Record and reseller for live purchases. Polar handles checkout, payment, transaction taxes, invoices, receipts, disputes, chargebacks, and its hosted customer portal. SAWANT CORE LLP remains responsible for the Sawoice licence, product operation, support, privacy, delivery, and entitlement enforcement.
Polar uses payment infrastructure including Stripe. Sawoice stores normalized customer, subscription, order, refund, amount, currency, tax, period, status, and event identifiers needed to reconcile entitlements. Sawoice does not store card details, billing addresses, tax IDs, or full Polar webhook bodies.
Cloud-processing acknowledgement records notice and the user's request. It is not the legal basis for every related processing activity.
Sawoice and its providers may process account, billing, email, support, and requested cloud content outside the user's country. The provider and subprocessor register names known companies and links to their Privacy Policies and Terms where available. Production hosting and database locations are recorded only after the production vendors are confirmed.
Where required, SAWANT CORE LLP will use approved transfer mechanisms such as EU Standard Contractual Clauses and the UK Addendum or IDTA, together with transfer assessments and supplementary measures. Publishing this policy does not itself prove those agreements have been executed.
Account deletion requires fresh authentication and an emailed confirmation. Any active recurring billing must first be canceled or revoked so an inaccessible account cannot continue to be charged. Sessions and device credentials are revoked, user content is hard-deleted through cascades, and only restricted legally required records remain.
The closure record contains an HMAC identity reference, account-created and closure dates, closure reason, accepted legal version identifiers, and purge date. It contains no raw user ID, email, name, device, audio, transcript, note, or raw usage row.
Subject to applicable law, users may request access, correction, deletion, portability, restriction, objection, consent withdrawal, sale/targeted-ad opt-out, appeal, grievance handling, or a general privacy inquiry. Sawoice voluntarily offers these request categories globally even where a statutory threshold may not apply.
Requests can be submitted through the Privacy Request page or from an authenticated account. We may verify identity, narrow an overbroad request, or retain information required by law. The internal response target is 30 days, with jurisdiction-specific extensions recorded and explained. A denied or limited request can be appealed.
The website uses only essential authentication and security cookies or equivalent storage required to sign in, maintain a session, prevent abuse, and protect account workflows. No analytics, advertising, session replay, or non-essential tracking is currently used, so no non-essential cookie banner is presented.
If that posture changes, the compliance contract, policy, and consent controls must be reviewed before deployment.
Sawoice uses access controls, encryption in transit, dedicated encryption/HMAC keys for privacy cases, content-free structured security events, bounded retention jobs, and credential revocation. No system is perfectly secure.
Security incidents are assessed under applicable notification duties, including CERT-In, GDPR/UK GDPR, Polar, and the EU Cyber Resilience Act schedule. Details that would increase exploitation risk are not published in an active incident.
Sawoice is not offered to anyone under 18. If we learn that an underage person created an account, we will suspend processing needed to preserve security and arrange deletion subject to legal obligations.
Material changes receive appropriate notice and a new policy version. The version accepted or acknowledged by an account is retained as evidence. Questions, requests, appeals, and grievances can be sent to support@sawoice.com or submitted through the Privacy Request page.
Mandatory rights and local regulator complaint routes remain available. Nothing in this policy limits a non-waivable consumer or privacy right.