A sub-processor is any company that handles your data on our behalf in order to make the service work. There are three kinds on this list: the translation engines that receive your audio while a session is running, the business plumbing that keeps an account alive — payment, email, the app stores — and our own server, which is on the list because it is where your account lives. Nothing else is involved. If you want the contractual version of this rather than the plain-language one, see the data processing agreement; for the wider picture, start at the trust center.
The list
| Provider | What we use it for | Data category | Processing location | Website |
|---|---|---|---|---|
| Google Cloud / AI Studio (Gemini Live) | Live speech translation. The default engine and the catch-all for all 79 target languages. | The session audio while the session is running, plus the translated audio and text that come back. | Google-operated infrastructure; the region is determined by Google for the Live API. | cloud.google.com |
| Alibaba Cloud DashScope (Qwen Realtime) | Live speech translation for the target languages routed to it. | The same as above: session audio in, translated audio and text out. | Alibaba Cloud, in the region the API workspace belongs to. | alibabacloud.com |
| Our own server (PocketBase) | Accounts, licences, minute balance, usage records, problem reports you choose to send. | Email address, hashed password, plan and licence state, minute counts, session metadata, a one-way hash of a device identifier. | A single server we rent and administer ourselves — not a hyperscaler region. | voxislive.com |
| Polar | Payment, invoicing and refunds for purchases made on voxislive.com. Polar is the merchant of record. | Name, email, billing details and card data, all held by Polar. We receive a customer ID and the state of the order, never your card number. | Polar's own infrastructure. | polar.sh |
| Resend | Transactional email: address verification, receipts, account mail and replies to your messages. | Your email address and the content of the mail we send you. | Resend's own infrastructure. | resend.com |
| Microsoft Store / Chrome Web Store | Distribution of the Windows app and of the browser extension, and purchases made inside the Microsoft Store. | Whatever the store records when you install or buy — held under that store's own policy, not ours. | Microsoft / Google infrastructure. | microsoft.com · chrome.google.com |
| Umami (self-hosted) | Page and click counts on the voxislive.com marketing pages. | Aggregate page views and event counts. No account data, no audio, no transcripts. | The same server we administer ourselves; the tracker is served first-party from our own domain. | umami.is |
The last row is on the list for completeness rather than necessity: the analytics software is self-hosted, so the page counts never leave our server and no analytics company receives them. We list it anyway, because you cannot tell that from the outside, and a sub-processor list you have to take on faith is worth very little.
Which engine receives your audio depends on the target language
VoxisLive runs on two cloud engines, and they are not interchangeable per user — they are chosen per target language. When a session starts, our server answers with the engine for the language you picked: a set of target languages is routed to Alibaba Cloud's Qwen Realtime model, and Gemini Live covers the rest, including every language Qwen does not voice. You do not choose this in the app, and it can change when a provider's language coverage changes.
That has one consequence worth stating plainly: you cannot know which of the two providers heard a given session without knowing the target language you chose. If that matters to your review — for a legal, clinical or procurement reason — there are two ways to make it deterministic:
- An organisation plan. A licence on an enterprise plan can be pinned to one engine, so every session on it goes to the same provider regardless of language. Ask us on the contact page and we set it on our side.
- Your own API key (BYOK). With the one-time BYOK unlock the app talks to the provider your key belongs to, using your own contract with that provider. Your audio then lands under your agreement, not ours. See pricing and licensing.
What each row actually receives
The two translation engines
These are the ones that matter, because they receive speech. Audio is streamed to the engine over an encrypted connection while a session is live, and the translated audio comes back the same way. We do not keep a copy: the stream passes from your machine to the provider, and the translated speech goes to your headphones. Transcripts, when you keep them, are written to a folder on your own disk — not to our server — and you can delete them there. What the providers do with the audio in transit is governed by their own terms; read them, and read our privacy policy for the boundaries we set on our side.
Our own server
Your account, licence, minute balance and usage records are on a server we rent and administer ourselves, running PocketBase — not in a hyperscaler's managed database. That is a deliberate choice and it cuts both ways, so we will say the uncomfortable half too: a single self-administered server is one operator's responsibility, not a platform's, and we hold no certification attesting to how it is run. What we can tell you is what is on it, which is the third row of the table above, and nothing else.
Payment, email and the stores
Purchases made on this site are processed by Polar as the merchant of record, which means Polar — not us — is the seller on your invoice and the party that holds your card data. We receive a customer ID and whether an order was paid or refunded. Purchases made inside the Microsoft Store are Microsoft's transaction under Microsoft's terms, and we see even less. Transactional mail leaves through Resend, which needs your address and the text of the message to deliver it.
What is not on this list
A sub-processor list is useful when the absences are real too, so here are the ones people ask about:
- No advertising or data-broker networks. We do not sell or rent your data, and there is no ad pixel, remarketing tag or enrichment vendor on this site or in the app.
- No meeting bot and no conferencing platform. VoxisLive never joins a call, so Zoom, Teams and Meet are not sub-processors of ours — see meetings for how that works.
- No third-party transcript or recording store. Transcripts and the optional dual-track recording stay on your disk.
- No third-party analytics host, as described above.
- No support desk or CRM with access to your content. Problem reports reach us by mail, scrubbed on your machine before they are sent, and only if you send one.
How this page changes
A sub-processor list is a snapshot, and a snapshot is worth little without a stated update rule. Ours:
- When a provider is added, removed or replaced, this page is updated. It is the canonical list — if another page of ours disagrees with it, this one is right and the other one is stale.
- Customers on an organisation plan are notified of a change to this list at the contact address on the plan.
- Individual accounts should check this page before a review, or write to us and ask; we will answer the same list.
What this page is not
It is not a compliance badge. We hold no ISO 27001, SOC 2 or HIPAA certification, and we are not going to imply one by listing our vendors' certifications as if they were ours. VoxisLive is run by an independent developer, and the thing we can offer in place of an auditor's letter is the mechanism: this list, the data processing agreement, the privacy policy, and a read-only excerpt of the audio-handling code that your security team can read for themselves — see licensing for what that excerpt is and is not.
It is also not a contract. The commitments that bind us are in the terms and the DPA; this page exists so that you can see, in one table, who is involved before you read either of them.