Privacy Policy
Last updated: April 16, 2026
Vaak is operated by Chirotpal Das, an individual developer based in Bengaluru, Karnataka, India, under the brand name SarthiAI. This Privacy Policy explains what information we collect, why we collect it, and how we handle it when you use the Vaak desktop app or the vaak.sarthiai.com website.
In this policy, "we," "us," and "our" refer to Chirotpal Das. "You" refers to the person using Vaak.
The short version
- Your voice is never recorded, uploaded, or stored by us. Transcription happens entirely on your Mac.
- We collect only what is necessary to run your account: email, subscription status, and usage minutes (for free tier limits).
- Payments go through Dodo Payments. We never see your card details.
- We do not sell your data. We do not use your data to train AI models.
- You can delete your account at any time, which removes all of your data from our systems.
1. Information we collect
Account information. When you sign up, we store your email address and, if you sign in via Google, your name and profile picture URL. This is handled by Supabase Auth.
Subscription information. We store your subscription status (trial, active, cancelled, expired), plan (monthly, yearly, lifetime), billing period end date, and a subscription ID from our payment processor.
Usage data. For free tier accounts only, we store the total number of transcription minutes used in the current month, so we can enforce the free-tier limit (60 minutes per month by default).
Technical information. Standard server logs (IP address, browser type, timestamps) are kept for security and debugging. We use an IP address one time at page load to detect your country, for regional pricing. We do not store this IP alongside your account.
What we do not collect. We do not record, transmit, or store any audio from your microphone. We do not store transcribed text. We do not track which applications you dictate into. The Vaak app does not send telemetry.
2. How we use information
- Authenticate you into your account.
- Process payments and manage your subscription.
- Enforce free tier usage limits.
- Send essential account emails (payment receipts, subscription status changes, password resets).
- Respond to your support requests.
- Detect and prevent fraud or abuse.
We do not use your data for advertising, profiling, or training AI models.
3. Third parties we rely on
We keep this list short and only use providers necessary to operate Vaak:
- Supabase: authentication, database, and backend functions. Hosted on their cloud infrastructure.
- Dodo Payments: subscription billing and payment processing. Your card data is handled directly by Dodo; we never see or store it.
- Google OAuth: optional sign-in provider. Only used if you choose to sign in with Google.
- Railway: hosts our website.
- MaxMind GeoLite2: local database used to detect country from IP for regional pricing. No data leaves our server.
Each of these providers has their own privacy policy. We do not share your data with them beyond what is necessary to provide the service.
4. Data retention
We keep your account data for as long as your account exists. If you delete your account, we remove all of your account data from our database within 30 days. Payment records required by law (tax, accounting) are retained by our payment processor per their retention policies.
5. Your rights
You have the right to:
- Access: request a copy of the data we hold about you.
- Correct: update your email or other account details.
- Delete: delete your account and all associated data, at any time, from your account page.
- Export: request a machine-readable export of your data.
- Withdraw consent: you can stop using Vaak at any time.
To exercise any of these rights, email support@sarthiai.com.
6. Cookies
The Vaak website uses a small number of essential cookies, set by Supabase, to keep you signed in. We do not use advertising or tracking cookies. We do not use analytics cookies.
7. Security
We use industry standard measures to protect your data: HTTPS everywhere, JWT-based session tokens with short expiry, server-side row-level security for database access, HMAC signature verification for webhooks, and no storage of payment card details. No system is perfectly secure, but we take this seriously.
8. Children
Vaak is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has provided us with information, please contact us and we will delete it.
9. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email and update the "Last updated" date at the top. Continued use of Vaak after changes means you accept the updated policy.
10. Contact
Questions, requests, or concerns? Email us:
Data controller: Chirotpal Das
Bengaluru, Karnataka, India
Operating Vaak under the brand SarthiAI.