Effective date: 20 September 2026
This Policy explains how ASWAY LTD collects, processes, uses, shares, retains and protects data when providing the Voiced website, application and related services, and how you may exercise your rights.
1. Who we are
Voiced is operated by ASWAY LTD, registered in England and Wales under company number 16800650. For personal data whose purposes and means of processing we determine, ASWAY LTD is the responsible company, or “data controller” under data protection law. You may contact us about the use of personal data or your rights as follows.
- Registered address: 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.
- Representative: Ashlyn Ma.
- Contact and consumer complaints: homepage contact form.
- Email: support@voiced.tw.
- UK Information Commissioner's Office (ICO) data-controller registration number: ZC159535.
2. Scope
The voice gateway and registration domain speakbreezily.com are operated by ASWAY LTD and are also covered by this Policy.
This Policy applies to the Voiced website and application, accounts and personalisation, free trials and paid subscriptions, payments, support, feedback and operation of the service. Where a third party independently provides sign-in, payment or another service to you, it may also process data under its own privacy policy; providers processing data on our behalf remain within the disclosures in this Policy.
3. Our data commitments
We do not sell your personal data, provide your data to third parties for advertising, or train AI models on your data. We require service providers processing data on our behalf to follow the same purpose restrictions and not use the data to train their own models or sell it.
When you dictate in cloud mode, the audio, text, settings and context needed for dictation, text processing and personalisation analysis you enable are processed through synchronous zero-retention inference services under Sections 4 and 5. Neither we nor our processors persist their inputs or outputs in the cloud after each request is completed. Local history, personalisation settings and learning results you choose to retain, as well as issue reports you actively submit and account data, are retained for their respective purposes and periods described below.
When you dictate in private local mode, the audio and transcript are processed on your device and are not uploaded. That recording is uploaded only if you actively choose cloud re-recognition for that entry and confirm it, after which it is handled as an ordinary cloud request under this Policy.
“Zero content retention” does not mean that account, payment, usage and security data are not retained, or that the service runs entirely on your device.
4. Data we process
The categories of data we process are described below. The listed items are examples; the actual scope depends on the features you use, the data you provide and what is necessary to operate the service.
4.1 Account and sign-in
To create and manage an account, we process account and contact data you provide or that a sign-in service sends, such as your name, email address, profile picture (if provided), verification status, sign-in method, account identifier, and creation or update time. To maintain sign-in and protect the account, we also process authentication and session data, such as tokens, expiry times, IP addresses, and relevant technical information about the browser or application.
4.2 Subscriptions, payments and support
We process subscription plan, price and currency, billing cycle, payment and subscription identifiers, first successful payment time, applicable discounts, payment status, refunds, payment disputes and entitlement-adjustment records. To handle support and billing, we also retain necessary correspondence, support notes, reasons for decisions and administrative action records.
Complete payment-card data is processed directly by the payment provider; Voiced does not store full card numbers or security codes.
4.3 Device, usage and security
To verify usage, deliver plans, maintain quality and prevent abuse, we process device, service-usage and security data, such as a device identifier or its hash, device name, last-used time, request identifier, source IP, version, processing time, word count, audio and text processing volume, status, error category and necessary billing information.
Free trials record periodic and cumulative usage for the account and pseudonymous device to prevent repeat claims. Some requests retain a hash digest of content to identify replay or duplicate processing. A digest is not the original content, but when it can be linked back to an account it is still managed as linkable data. Device signals do not guarantee a person's identity.
4.4 Content you provide
When you use dictation, text-processing and personalisation features, we process the audio, transcription and processed text, instructions, language preferences and context needed to perform those features. For settings, historical text, corrections and related app information used by personalisation features, see Section 4.6.
Content you submit may include personal data about you or others. Please ensure that you have a lawful basis and the necessary permissions to record, submit and use it.
Voiced does not seek to collect health data or other personal data specially protected by law, does not ask you to provide such data, and does not provide dedicated collection or profiling features for it. Please do not submit such data. If it appears incidentally in ordinary dictation, it is still processed only temporarily to complete that request, under the zero-content-retention arrangement in Section 3, and is not separately analysed, profiled or otherwise used.
We do not use voices to identify a person's biometric identity or use content to build advertising profiles.
4.5 Screen context
“Screen context” must be enabled with your confirmation. You may choose to enable it during setup or later in settings, and may disable it at any time. When enabled, Voiced reads the current window title, focused field and limited excerpts of visible on-screen text during dictation as context for understanding your current input. Those excerpts may contain data about you or others.
We limit context capture using secure-input indicators that the system can recognise and your exclusion settings. Excerpts needed to complete a request are transmitted and processed temporarily under Sections 3 and 5.
Exclusions depend on indicators supplied by the operating system and your settings and cannot recognise every screen that may contain sensitive information. You can disable screen context before processing such content.
4.6 Personalisation settings and learning
Personalisation features process data you provide and settings you enable:
| Feature | Data used and purpose |
|---|---|
| Background, vocabulary and style settings | Background information, specialised vocabulary, common errors, per-app tone and style settings, and custom rewriting instructions you provide, used to choose wording, recognise speech and organise or rewrite text. |
| Smart personalisation | When you enable this feature and retain dictation text history, historical text generated through Voiced in different apps and related app information are used to infer domains and commonly used terms and to create or update personalisation settings. |
| Learn from corrections | When you enable this feature, your manual corrections to dictated text and related recognition-error information are analysed to help determine whether specialised vocabulary and common-error settings should be added or updated. |
To perform these features, necessary settings, historical text, corrections and related app information are transmitted temporarily to us and our contracted AI-processing providers and processed under the zero-content-retention arrangement in Sections 3 and 5.
Local history is retained under Section 6. Personalisation settings and learning results are stored locally under the settings and management features in the application. Voiced does not currently provide cloud storage of this data in your account or cross-device synchronisation.
Custom replacement values are stored and applied locally; only trigger terms needed to complete a request may be transmitted temporarily with that request.
4.7 Performance statistics and diagnostics
We process technical and diagnostic data needed to keep the service secure, troubleshoot it and improve reliability, such as version, latency, processing volume, retries, processing status, performance, error information and necessary cost records. This processing may involve source IP and request metadata listed in Section 4.3. Account-linked records and aggregate statistics that cannot reasonably identify a person are managed separately.
Diagnostic data is managed according to the purposes and legal bases in this Policy and the periods in Section 11. Where consent or an opt-out is legally required for non-essential collection or analysis of device information, we provide the applicable notice and choice.
4.8 Feedback, website and contact
When you actively submit an issue report, we process the original or processed text you choose to send, its description, category, version and submission time. Feedback containing text content is provided only when you choose to enable sharing or actively submit it; it is distinct from technical diagnostics.
We use the content feedback you select to respond, reproduce issues, check errors and verify fixes, and do not use it for model training. Selected content feedback and later quality verification are processed with your consent and retained for the period in Section 11. You may withdraw consent or request deletion as permitted by law.
When you use the contact form, we process your email address, optional name, subject and message to respond, handle complaints or process data-rights requests. When you join a waitlist or request product notifications, we process your email address, interests, language and notification choices. Without separate marketing consent, we send only notices related to what you requested. Website network requests and aggregate statistics are addressed in Section 13.
We use AI tools to help organise support messages and analyse necessary account, payment, error and service-status data, and provide required data to contracted customer-support AI providers. We do not authorise its use for model training. Support data is retained under Section 11.
5. How content is processed and shared
To provide the speech transcription, text organisation or rewriting you request in cloud mode, and the personalisation processing in Section 4.6, necessary audio, text, personalisation settings, related app information and context are encrypted in transit and sent temporarily to our services and contracted speech-recognition, cloud-inference and text-processing providers. Depending on the features you enable, personalisation analysis may separately process retained dictation history or manual corrections. Transmission is limited to what is necessary to perform the relevant feature.
Ordinary cloud request content is processed under the synchronous zero-retention arrangement in Section 3. Content that incidentally includes sensitive information is handled under Section 4.4. Private local mode dictation is not transmitted under this Section unless you actively choose cloud re-recognition for that entry.
Feedback you actively submit, account data and local data are managed under their respective sections. Provider categories and purposes are in Section 9; actual provider names and processing regions are provided on the information page referenced in Section 10.
6. Data on your device
Local history may include transcribed text, processed results, related application information and diagnostic data. Whether local history and audio are retained, the retention period and deletion method depend on your choices during initial setup or later settings. You can adjust the settings or actively delete data using options in the application.
Local data is affected by the security settings of your device and operating system. Voiced does not separately encrypt all local history. You are responsible for device security and backups. Deleting your cloud account does not mean that copies on your device or in backups you created are also deleted.
7. Purposes and legal bases
We process data to provide accounts, dictation, text processing and the personalisation settings you ask us to apply; analyse dictation history or corrections to create or update personalisation settings when you enable smart personalisation or learning from corrections; provide free trials and paid entitlements; handle payments, refunds and support; process content feedback at your choice; maintain reliability, verify usage and prevent abuse; comply with tax and other legal obligations; handle disputes and lawful requests; and send product news at your choice.
Where the UK GDPR or EU GDPR applies:
| Processing purpose | Primary basis |
|---|---|
| Accounts, core features, background, vocabulary and style settings you ask us to apply, subscriptions and general support | Performance of a contract with you or steps at your request before entering into a contract |
| Necessary security, fraud and abuse prevention, reliability analysis and usage management | Legitimate interests in maintaining a secure and reliable service, balanced against necessity and impact on you; contract also applies where necessary to deliver a plan |
| Statutory tax, accounting and regulatory requirements | Legal obligation |
| Establishing, exercising or defending legal claims | Applicable legitimate interests or legal obligation |
| Optional smart personalisation, learning from corrections, screen context, content feedback and later quality verification, and product marketing messages | Your consent, which may be withdrawn at any time |
These bases apply according to the actual data, data subject and processing circumstances; specially protected data also requires the applicable processing condition. Withdrawing consent does not affect lawful processing before withdrawal and does not disable core features that do not rely on that optional data. You may object to processing based on legitimate interests under Section 14.
8. Consequences of not providing data
You may choose not to provide data, but without necessary sign-in information you cannot use account features; without audio or text the related processing cannot be completed; and without information required for payment you cannot subscribe. Smart personalisation, learning from corrections, screen context, text feedback, marketing messages and non-essential personalisation data are optional. Not enabling or providing them does not affect core features that do not need them. History needed for smart personalisation is handled under Section 4.6.
9. Recipients of data
We provide data only to the following categories of recipients where they need it:
| Recipient category | Purpose and scope of data |
|---|---|
| Speech-recognition, cloud-inference and text-processing providers | Temporary processing of audio, text, settings and context needed for enabled features, dictation history, corrections and related app information needed for personalisation analysis, and necessary technical metadata; processed synchronously with zero retention under Sections 3 and 5 |
| Hosting, database, security and website-operation providers | Transmission and storage of account and operational data, and provision of the website, forms, security and aggregate analytics |
| Payment and identity-verification providers | Information needed for sign-in, payments, invoices, subscriptions and payment security |
| Communications, support, customer-support AI and operational-notification providers | Necessary contact information, correspondence, actively submitted feedback, and account, payment, error and service-status data needed to provide support; ordinary dictation content is not automatically provided for this reason |
| Professional advisers and authorities legally entitled to receive data | Data necessary for tax, accounting, disputes, audits or lawful requests |
Contracted providers process data within agreed purposes under applicable service agreements, data-processing terms and our instructions. Where payment or sign-in services process data for their own legal obligations and independent services, they are also responsible under their own policies.
Provider additions, replacements and processing regions are described under Section 10. In a merger, acquisition or business transfer, we provide data only as necessary, require applicable protections to continue, and give notice as required by law.
10. Cross-border processing and provider updates
ASWAY LTD is a UK company. To provide the service, data may be processed by us and our contracted providers in countries or regions outside your location. Principal providers, service purposes, categories of data received, and processing countries or regions are listed on the Sub-processors and processing regions page, which supplements this Policy.
We may add or replace providers for service, security, quality and operational needs. Where the data uses and protection commitments in this Policy do not change, we provide current information by updating that page. We give notice under Section 19 for material changes to data use or protection and obtain consent where required by law.
Where cross-border transfer safeguards are required by law, we use the applicable adequacy decision, International Data Transfer Agreement (IDTA), Standard Contractual Clauses (SCCs) and necessary UK Addendum, or other lawful safeguards, based on the actual transfer. You may contact us under Section 1 to ask about the safeguards and obtain copies where the law permits. Copies may be redacted as permitted by law to protect others' data or confidential information.
11. Retention and deletion
Data is retained for the periods below and deleted or anonymised when the period expires or the purpose no longer requires it. Where genuinely necessary to comply with a specific legal obligation, resolve an outstanding dispute or address a particular security incident, only directly relevant records are retained longer for the necessary period. This does not permit routine additional retention of ordinary dictation content.
| Data category | Retention method or period |
|---|---|
| Inputs, outputs and necessary context for dictation, text processing and personalisation-analysis requests | Synchronous zero-content-retention processing under Sections 3 and 5; not persisted in the cloud after each request is completed. Local and actively submitted data are addressed below |
| Local history and audio | According to Section 6 and your settings |
| Local personalisation settings and learning results | Retained according to Section 4.6 and the settings and management features in the application |
| Account data | For the life of the account; related data is removed from production systems when the account is deleted, while records required by law are handled under the relevant items in this section |
| Sign-in and security records containing IP addresses | Generally up to 90 days; sessions also become invalid on sign-out, expiry or account deletion |
| Short-term account-linked performance records | Generally 30 days |
| Technical reliability, request-processing and diagnostic records | Generally up to 180 days |
| Daily account usage and plan-management records | Generally up to 730 days; the minimum cumulative and period data needed to enforce free-trial limits are retained for the life of the account |
| Pseudonymous marker preventing repeat free-trial claims after account deletion | 24 months from the most recent claim or use of a free trial; the period restarts only when a free trial is claimed or used again |
| Actively submitted text feedback | Working and archived copies of original text, processed results and related content for up to 180 days from submission, deleted sooner when no longer needed; long-term test cases use data that cannot reasonably identify a person |
| General support and contact | 24 months after the case is closed; feedback content containing original text or processed results remains subject to the 180-day limit above; necessary billing or dispute records follow the applicable obligation or dispute period |
| AI customer-support working copies | Our copies are deleted within 90 days after the case is closed, and within the same period we request deletion by the provider; provider copies are cleared under applicable data-processing terms and deletion mechanisms. Copies containing text feedback remain subject to the 180-day limit above |
| Launch waitlist | Deleted 90 days after the formal launch notice is sent; you may ask to withdraw or delete it sooner |
| Separately consented product and marketing notifications | Until you unsubscribe or consent is no longer valid; only the necessary suppression record is retained to prevent further messages. The waitlist does not automatically become a marketing subscription |
| Invoices and statutory accounting records | Usually six years after the end of the relevant accounting year; extended as required by law or for an unresolved investigation, filing or similar matter |
| Aggregate statistics that cannot reasonably identify a person | May be retained long-term for reliability, quality and capacity trends; not used to contact a person or make individual account decisions |
Residual backup copies are used only for necessary recovery, cleared through backup rotation and not used ordinarily. Backup copies of text feedback remain subject to the 180-day limit above.
Usage, security and billing data that can be linked back to an account is not treated as anonymous statistics merely because names are removed, it is encrypted or identifiers are replaced. We do not re-identify data that can no longer reasonably identify a person in order to answer an individual request.
12. Automated restrictions and review
We use payment status, plan terms, usage and security signals to manage entitlements and prevent abuse. An anomalous signal may first trigger request refusal, rate limiting or temporary suspension; it does not mean that a breach has been confirmed.
If you believe a restriction is mistaken, you may object under Section 1. Where the law requires an explanation, human intervention, review or other safeguard for an automated decision, we provide the applicable safeguard.
13. Cookies and website technologies
We use cookies or equivalent technologies needed to maintain sign-in, payments, security and preferences. Aggregate website analytics do not use persistent identifiers to build cross-site advertising profiles, and we do not use advertising pixels to track your dictation content.
Website resources, fonts or embedded services may cause their providers to receive an IP address, browser information, time and resource name. If we introduce non-essential tracking technology that legally requires consent, we obtain consent before enabling it and provide a choice.
14. Your personal-data rights
Under applicable law, you may ask about, access or obtain a copy of your data; request correction, completion, cessation of collection, processing or use, deletion, restriction of processing or data portability; withdraw consent or object to particular processing; challenge qualifying automated decisions; and complain to a supervisory authority.
Submit a request through the methods in Section 1. We may request information necessary to verify your identity. We do not charge where the law requires requests to be free. Where the law permits a necessary fee or refusal of a manifestly unfounded or excessive request, we act under those rules and explain the reason.
Where Taiwan's Personal Data Protection Act applies, we decide a request for inquiry, access or a copy within 15 days of receipt, and a request for correction, cessation or deletion within 30 days. We may extend those periods as permitted by law and give written notice of the reason. Where the UK GDPR or EU GDPR applies, we generally respond within one month, subject to lawful extensions or suspension of time.
These rights remain subject to lawful limits including the rights of others, legal obligations and necessary legal claims.
15. Account deletion
You may request account deletion using the homepage contact form or support@voiced.tw. We process the request after necessary identity verification. Deletion covers account data and related records we retain; statutory accounting records, necessary dispute records and the marker preventing repeat claims under Section 11 are retained for their limited purposes and periods.
When deleting the account, we also stop renewal of the linked subscription and explain when that takes effect. For actively submitted feedback that has already been separated from the account, you may provide a date or necessary clues to help locate it. Local personalisation settings, learning results, history and backups you created are handled under Sections 4.6 and 6.
16. Security
We use measures proportionate to risk, including encryption in transit, storage protection, access restrictions, key management, minimum necessary logging and retention clean-up. Authorised personnel access data only as needed for their work and for limited purposes. No network or storage system can guarantee absolute security.
If a personal-data incident requires notification by law, we notify the supervisory authority and affected people under applicable law and explain the likely impact and response measures.
17. Age
The service is available only to users who meet the age eligibility in Section 2 of the Terms of Service. If we discover an ineligible account, we may restrict or terminate the service and handle related data as required by law.
18. Contact and complaints
If you have questions, a rights request or a complaint about personal-data processing, contact ASWAY LTD through the form, support@voiced.tw or address in Section 1. We handle it under applicable law.
You may also complain to the UK ICO or another personal-data protection authority with jurisdiction.
19. Policy updates and language
The effective date of this version appears on this page. We give advance notice through an appropriate channel such as the website, application or email of changes that materially affect rights or data use, and obtain consent where required by law. Provider and processing-region information is maintained under Section 10.
This Policy is written in Traditional Chinese. Other-language versions are provided for reference; if there is any ambiguity, the Traditional Chinese version prevails.