---
title: "Sub-processors — who can touch your data | VoxisLive"
description: "Every third party involved in running VoxisLive: the two translation engines, our own account server, Polar, Resend."
url: https://voxislive.com/subprocessors
language: "en"
source_html: https://voxislive.com/subprocessors
site: "Voxis — real-time voice translation"
og_image: https://voxislive.com/assets/og.png
generated_by: voxislive-markdown-pipeline
---

[Home](https://voxislive.com/) · / · [Trust center](https://voxislive.com/trust-center) · / · Sub-processors

SUB-PROCESSORS

# Sub-processors

This is the full list of outside parties that can receive data while you use VoxisLive, what each one receives, and why. It is short because most of the work happens on your own machine.

A sub-processor is any company that handles your data on our behalf in order to make the service work. There are three kinds on this list: the **translation engines** that receive your audio while a session is running, the **business plumbing** that keeps an account alive — payment, email, the app stores — and **our own server**, which is on the list because it is where your account lives. Nothing else is involved. If you want the contractual version of this rather than the plain-language one, see the [data processing agreement](https://voxislive.com/dpa); for the wider picture, start at the [trust center](https://voxislive.com/trust-center).

## The list

| Provider | What we use it for | Data category | Processing location | Website |
| --- | --- | --- | --- | --- |
| Google Cloud / AI Studio (Gemini Live) | Live speech translation. The default engine and the catch-all for all 79 target languages. | The session audio while the session is running, plus the translated audio and text that come back. | Google-operated infrastructure; the region is determined by Google for the Live API. | cloud.google.com |
| Alibaba Cloud DashScope (Qwen Realtime) | Live speech translation for the target languages routed to it. | The same as above: session audio in, translated audio and text out. | Alibaba Cloud, in the region the API workspace belongs to. | alibabacloud.com |
| Our own server (PocketBase) | Accounts, licences, minute balance, usage records, problem reports you choose to send. | Email address, hashed password, plan and licence state, minute counts, session metadata, a one-way hash of a device identifier. | A single server we rent and administer ourselves — not a hyperscaler region. | voxislive.com |
| Polar | Payment, invoicing and refunds for purchases made on voxislive.com. Polar is the merchant of record. | Name, email, billing details and card data, all held by Polar. We receive a customer ID and the state of the order, never your card number. | Polar's own infrastructure. | polar.sh |
| Resend | Transactional email: address verification, receipts, account mail and replies to your messages. | Your email address and the content of the mail we send you. | Resend's own infrastructure. | resend.com |
| Microsoft Store / Chrome Web Store | Distribution of the Windows app and of the browser extension, and purchases made inside the Microsoft Store. | Whatever the store records when you install or buy — held under that store's own policy, not ours. | Microsoft / Google infrastructure. | microsoft.com · chrome.google.com |
| Umami (self-hosted) | Page and click counts on the voxislive.com marketing pages. | Aggregate page views and event counts. No account data, no audio, no transcripts. | The same server we administer ourselves; the tracker is served first-party from our own domain. | umami.is |

The last row is on the list for completeness rather than necessity: the analytics software is **self-hosted**, so the page counts never leave our server and no analytics company receives them. We list it anyway, because you cannot tell that from the outside, and a sub-processor list you have to take on faith is worth very little.

## Which engine receives your audio depends on the target language

VoxisLive runs on two cloud engines, and they are not interchangeable per user — they are chosen **per target language**. When a session starts, our server answers with the engine for the language you picked: a set of target languages is routed to Alibaba Cloud's Qwen Realtime model, and Gemini Live covers the rest, including every language Qwen does not voice. You do not choose this in the app, and it can change when a provider's language coverage changes.

That has one consequence worth stating plainly: **you cannot know which of the two providers heard a given session without knowing the target language you chose.** If that matters to your review — for a legal, clinical or procurement reason — there are two ways to make it deterministic:

- **An organisation plan.** A licence on an enterprise plan can be pinned to one engine, so every session on it goes to the same provider regardless of language. Ask us on the [contact page](https://voxislive.com/contact) and we set it on our side.
- **Your own API key (BYOK).** With the one-time BYOK unlock the app talks to the provider your key belongs to, using your own contract with that provider. Your audio then lands under your agreement, not ours. See [pricing](https://voxislive.com/pricing) and [licensing](https://voxislive.com/licensing).

## What each row actually receives

### The two translation engines

These are the ones that matter, because they receive speech. Audio is streamed to the engine over an encrypted connection while a session is live, and the translated audio comes back the same way. We do not keep a copy: the stream passes from your machine to the provider, and the translated speech goes to your headphones. Transcripts, when you keep them, are written to a folder on your own disk — not to our server — and you can delete them there. What the providers do with the audio in transit is governed by their own terms; read them, and read our [privacy policy](https://voxislive.com/privacy) for the boundaries we set on our side.

### Our own server

Your account, licence, minute balance and usage records are on a server we rent and administer ourselves, running PocketBase — **not in a hyperscaler's managed database**. That is a deliberate choice and it cuts both ways, so we will say the uncomfortable half too: a single self-administered server is one operator's responsibility, not a platform's, and we hold no certification attesting to how it is run. What we can tell you is what is on it, which is the third row of the table above, and nothing else.

### Payment, email and the stores

Purchases made on this site are processed by **Polar as the merchant of record**, which means Polar — not us — is the seller on your invoice and the party that holds your card data. We receive a customer ID and whether an order was paid or refunded. Purchases made inside the Microsoft Store are Microsoft's transaction under Microsoft's terms, and we see even less. Transactional mail leaves through Resend, which needs your address and the text of the message to deliver it.

## What is not on this list

A sub-processor list is useful when the absences are real too, so here are the ones people ask about:

- **No advertising or data-broker networks.** We do not sell or rent your data, and there is no ad pixel, remarketing tag or enrichment vendor on this site or in the app.
- **No meeting bot and no conferencing platform.** VoxisLive never joins a call, so Zoom, Teams and Meet are not sub-processors of ours — see [meetings](https://voxislive.com/use-cases/meetings) for how that works.
- **No third-party transcript or recording store.** Transcripts and the optional dual-track recording stay on your disk.
- **No third-party analytics host**, as described above.
- **No support desk or CRM with access to your content.** Problem reports reach us by mail, scrubbed on your machine before they are sent, and only if you send one.

## How this page changes

A sub-processor list is a snapshot, and a snapshot is worth little without a stated update rule. Ours:

1. When a provider is added, removed or replaced, **this page is updated**. It is the canonical list — if another page of ours disagrees with it, this one is right and the other one is stale.
2. **Customers on an organisation plan are notified** of a change to this list at the contact address on the plan.
3. Individual accounts should check this page before a review, or write to us and ask; we will answer the same list.

## What this page is not

It is not a compliance badge. **We hold no ISO 27001, SOC 2 or HIPAA certification**, and we are not going to imply one by listing our vendors' certifications as if they were ours. VoxisLive is run by an independent developer, and the thing we can offer in place of an auditor's letter is the mechanism: this list, the [data processing agreement](https://voxislive.com/dpa), the [privacy policy](https://voxislive.com/privacy), and a read-only excerpt of the audio-handling code that your security team can read for themselves — see [licensing](https://voxislive.com/licensing) for what that excerpt is and is not.

It is also not a contract. The commitments that bind us are in the [terms](https://voxislive.com/terms) and the [DPA](https://voxislive.com/dpa); this page exists so that you can see, in one table, who is involved before you read either of them.

FAQ

## Common questions

### Does my audio go to Google or to Alibaba Cloud?

It depends on the target language you pick. A set of target languages is routed to Alibaba Cloud's Qwen Realtime model; Gemini Live covers the rest of the 79. The routing is decided by our server when the session starts, not in the app. If you need every session to go to one named provider, an organisation plan can be pinned to a single engine, or you can use your own API key under the BYOK unlock.

### Do you store my audio or my transcripts?

No. Audio is streamed to the translation engine while the session is live and is not retained by us. Transcripts are written to a folder on your own machine, where you can read, export or delete them. The exception is one you trigger yourself: if you send a problem report and tick the box to include the transcript, that copy reaches our server with the report.

### Who is the seller on my invoice?

For a purchase made on voxislive.com, Polar is the merchant of record — Polar is the seller of record on the invoice and holds the card data; we receive a customer ID and the order state. For a purchase made inside the Microsoft Store, Microsoft is the seller under Microsoft's own terms.

### Do you use analytics or advertising trackers?

The marketing pages count page views and clicks with self-hosted Umami, served from our own domain, so those counts never reach an analytics company. There is no ad network, remarketing tag or data-broker integration. The desktop app reports minute counts and session outcome data to our own server to run your quota — not to any analytics vendor.

### Are you ISO 27001, SOC 2 or HIPAA certified?

No. We hold no security or privacy certification, and we would rather say so than let a vendor's badge be mistaken for ours. What we publish instead is this list, the DPA, the privacy policy and a read-only excerpt of the audio-handling code, so the claims can be checked rather than trusted.

### Will you tell me when this list changes?

This page is updated when a provider is added, removed or replaced, and it is the canonical version — if another page of ours disagrees, this one is current. Customers on an organisation plan are notified at the plan's contact address. Everyone else can check this page or write to us and ask.


## Structured data (JSON-LD)

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://voxislive.com/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Trust center",
          "item": "https://voxislive.com/trust-center"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Sub-processors",
          "item": "https://voxislive.com/subprocessors"
        }
      ]
    },
    {
      "@type": "WebPage",
      "name": "Sub-processors — who can touch your data | VoxisLive",
      "url": "https://voxislive.com/subprocessors",
      "description": "Every third party involved in running VoxisLive: the two translation engines, our own account server, Polar, Resend.",
      "inLanguage": "en",
      "isPartOf": {
        "@type": "WebSite",
        "name": "VoxisLive",
        "url": "https://voxislive.com/"
      },
      "publisher": {
        "@type": "Organization",
        "name": "VoxisLive",
        "url": "https://voxislive.com/"
      }
    },
    {
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Does my audio go to Google or to Alibaba Cloud?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "It depends on the target language you pick. A set of target languages is routed to Alibaba Cloud's Qwen Realtime model; Gemini Live covers the rest of the 79. The routing is decided by our server when the session starts, not in the app. If you need every session to go to one named provider, an organisation plan can be pinned to a single engine, or you can use your own API key under the BYOK unlock."
          }
        },
        {
          "@type": "Question",
          "name": "Do you store my audio or my transcripts?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. Audio is streamed to the translation engine while the session is live and is not retained by us. Transcripts are written to a folder on your own machine, where you can read, export or delete them. The exception is one you trigger yourself: if you send a problem report and tick the box to include the transcript, that copy reaches our server with the report."
          }
        },
        {
          "@type": "Question",
          "name": "Who is the seller on my invoice?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "For a purchase made on voxislive.com, Polar is the merchant of record — Polar is the seller of record on the invoice and holds the card data; we receive a customer ID and the order state. For a purchase made inside the Microsoft Store, Microsoft is the seller under Microsoft's own terms."
          }
        },
        {
          "@type": "Question",
          "name": "Do you use analytics or advertising trackers?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The marketing pages count page views and clicks with self-hosted Umami, served from our own domain, so those counts never reach an analytics company. There is no ad network, remarketing tag or data-broker integration. The desktop app reports minute counts and session outcome data to our own server to run your quota — not to any analytics vendor."
          }
        },
        {
          "@type": "Question",
          "name": "Are you ISO 27001, SOC 2 or HIPAA certified?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. We hold no security or privacy certification, and we would rather say so than let a vendor's badge be mistaken for ours. What we publish instead is this list, the DPA, the privacy policy and a read-only excerpt of the audio-handling code, so the claims can be checked rather than trusted."
          }
        },
        {
          "@type": "Question",
          "name": "Will you tell me when this list changes?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "This page is updated when a provider is added, removed or replaced, and it is the canonical version — if another page of ours disagrees, this one is current. Customers on an organisation plan are notified at the plan's contact address. Everyone else can check this page or write to us and ask."
          }
        }
      ]
    }
  ]
}
```
