E:Voice public policy
Privacy Policy
Effective August 9, 2026. This policy describes how E:MERGENCE LLC handles information used by the E:Voice Android app and by the E:Voice account service. Questions or privacy requests can be sent to evoice@emergencerising.com.
E:Voice Android app
E:Voice is local-first. Most data stays in app-private storage on your device. Data leaves your device only for a feature you turned on, to a destination you chose. E:Voice contains no advertising or third-party analytics. It does not silently upload crash details: a crash report is sent only after you review the report surface and affirmatively choose Send to developer.
- Microphone and voice: speech recognition runs on your device by default using a bundled offline model. If you select a cloud speech provider instead, recorded audio is sent to that provider using credentials you supplied. Spoken replies are produced by the voice provider you select; a cloud voice provider receives the reply text.
- Camera and photos: photos you capture or attach are stored in app-private storage. They are sent to the AI provider or paired runtime you chose for that conversation when you attach them to a message.
- Contacts: E:Voice does not request the Android Contacts permission and cannot read your address book. When you use Android's contact picker to share one contact, that contact's name, organization, phone numbers, and email addresses become message content and a vCard attachment sent to the provider or runtime you chose.
- Messages, documents, and projects: content needed for a request is sent to the model provider you configured (for example OpenAI, Anthropic, Google Gemini, OpenRouter, or an endpoint you enter) or to a runtime you own and paired. Provider accounts, keys, terms, availability, and charges are separate from E:Voice.
- Optional memory, search, and web features: when enabled, queries or memory content go to the provider you configured for that feature.
- Backup export: a backup archive you create yourself contains conversations, the AERIS Node graph, and media, and excludes stored credentials. You choose whether to save it to your device or send it through the Android share sheet to a destination you pick. The archive is not encrypted, so store it somewhere you trust.
- Paired runtimes and AERIS OS continuity: pairing is opt-in and uses a host you supply. When paired and signed in, E:Voice can sync conversations, messages, agents, documents, projects, profile facts, avatar references (not image bytes), and redacted receipts with your own desktop. Sync content goes between your signed-in devices or paired runtime. On Direct, Stable, and Play distributions, a device with Google Play services can register for a metadata-only Firebase wake so it does not need constant polling. The E:MERGENCE account service receives only an opaque request ID, source-device ID, reason, and timestamp in that doorbell; it does not receive the message, conversation, agent, memory, or project content. Devices without Google Play services use the app's non-Firebase fallback.
- Provider API keys and key sharing: keys are held in encrypted storage backed by the Android Keystore. When you share a key with a paired agent, it is sealed end to end for that recipient; the relay carries only ciphertext, and a share is single-use and short-lived.
- Identifiers: E:Voice uses no advertising identifier and reads no hardware identifiers such as IMEI, serial number, or Android ID. Phone-state access is used only to read whether a call is ringing or active so voice mode can pause. Random, install-scoped identifiers are used for pairing and message routing.
- Reports and diagnostics: diagnostics stay on the device unless you submit a report. AI response reports, product feedback, and crash reports are sent only when you affirmatively submit them. A crash report contains only a client report ID, occurrence time, app version and version code, exception type, short summary, capture type, repeat count, and an optional note. E:Voice does not submit breadcrumbs, a raw stack trace, conversation or message content, agent content, or AERIS memory/context in this report.
- Network protection: connections to provider and E:MERGENCE services use HTTPS. A connection to a runtime or desktop you own may use plain HTTP when it stays inside your own private network (for example a Tailscale/WireGuard tailnet) or on device loopback, where that network provides the encryption.
E:Voice is not directed to children under 13.
Information the account service handles
- Account and profile information: email address, username, display name, profile settings, and optional profile or community content you submit.
- Authentication and service records: password hashes, session and token hashes, API or bridge credential metadata, access grants, entitlements, and subscription status.
- Push registration and continuity metadata: an encrypted Firebase Cloud Messaging registration token, an install-scoped device ID, platform/distribution/app version metadata, and metadata-only doorbell receipts and delivery-attempt records. Doorbells contain no message, conversation, agent, memory, or project content.
- Activity and technical information: download, access, security, and audit events; device or session identifiers; IP address; and user-agent information.
- Content sent to this service: feedback, posts, comments, uploaded media, agent configuration, and other material you choose to store through account-service features.
- AI response reports: a category, reason, redacted response excerpt, limited app and agent references, and an opaque receipt when a signed-in user reports an AI response.
- Crash reports: the exact fields shown before submission: client report ID, occurrence time, app version and version code, exception type, short summary, capture type, repeat count, and optional user note. The server redacts secrets, email addresses, device paths, IP addresses, and URLs before storage. Only the administrative owner can review and disposition this queue.
E:Voice may also keep app-local or connected-agent data under the controls of the app or the connected runtime. This account-service policy does not imply that every E:Voice conversation is uploaded to this service.
How we use information
We use this information to authenticate accounts, provide downloads and entitlements, connect authorized agent runtimes, process subscriptions, operate requested community or feedback features, prevent abuse, diagnose failures, support users, and maintain service integrity.
Service providers
We use service providers only where needed to operate a feature. Current account-service integrations include Stripe for subscription billing, Resend for transactional email, Cloudflare Turnstile for abuse prevention, Firebase Cloud Messaging for metadata-only device wake notifications, and hosting or network infrastructure providers. Firebase receives the registered push token and doorbell metadata needed to route that wake notification; it does not receive E:Voice message, agent, project, or memory content in the doorbell. Those providers process information under their own terms and retention obligations. Model, speech, memory, and search providers you configure in the app are your own accounts with those companies and process your content under their terms.
Storage, security, and retention by category
Passwords and supported authentication credentials are stored as one-way hashes rather than readable secrets. We use access controls and operational safeguards appropriate to the service. No system can promise absolute security.
- App data on your device: kept until you delete it in the app, clear the app's storage, or uninstall E:Voice. Deleting your account does not erase data held only on your device.
- Account, profile, and user content: kept while the account or content remains active, then deleted when the user removes it or a verified account deletion completes.
- Sessions, keys, and bridge credentials: kept while needed for authentication or connection, then revoked or deleted when they expire, are replaced, or account deletion starts.
- Push registrations: kept while the registered device remains active, then replaced or marked inactive when the app refreshes or unregisters the token, Firebase reports the exact token as unregistered, or account deletion completes.
- Continuity doorbells and dispatch attempts: kept for up to 7 days by default, then deleted together. Account deletion deletes the account-linked doorbells and their dispatch records.
- Draft and owned uploads: kept while an upload or profile edit is pending or published, then removed when discarded, replaced, or account deletion completes. Failed cleanup keeps deletion retryable and is not reported as complete.
- Security and service records: kept while needed to investigate abuse, protect accounts, operate support, or meet applicable obligations. Account-linked service records controlled by this service are removed when deletion completes. A minimal operational event may remain only after account identifiers, profile details, and observed account IP addresses are removed; aggregate or otherwise non-account-linked records may also remain.
- AI response reports: kept for up to 365 days by default for safety, privacy, abuse, and quality review. Startup maintenance enforces expiration, with the same cleanup also run by report and moderation traffic. Account deletion removes the reporter link while the server-redacted report and moderation audit remain only until their existing expiration date.
- Crash reports: kept for up to 90 days by default for owner support and failure triage. Account deletion removes the reporter link, while the already-redacted report and its owner audit trail remain only until that report's existing expiration date. Expiration deletes both the report and its audit trail.
- Billing records: Stripe may retain payment, dispute, fraud-prevention, and legal records under Stripe's own obligations even after the E:Voice account is deleted.
- Deletion receipt: after completion, this service keeps an opaque status receipt and credential hash with timestamps. It does not retain the deleted user ID, email, stable account fingerprint, request IP, or profile content.
Your controls
You can review or change available account details through account settings. You can also request permanent account deletion without contacting support, either from Settings inside the E:Voice app or from the public page below. A deletion request revokes account credentials immediately, then completes required subscription and owned-upload cleanup before reporting success. Data stored only on your device is removed by deleting it in the app or uninstalling E:Voice.
Open account deletion information
The service's administrative owner account cannot use automated self-deletion because deleting it would disable account-service administration. The owner must use evoice@emergencerising.com for a separately verified removal or ownership-transfer process. This exception does not apply to ordinary E:Voice user accounts.
Policy updates
We may update this policy as E:Voice and its services change. Material changes should be reflected here and in the app's release-specific Data Safety disclosures.
Comments
Open a post image to comment.