How I handle your data.
I am very pleased about your interest in VoiceApp. Data protection is of particularly high priority to me. The use of these Internet pages is generally possible without providing any personal data. However, if a data subject wishes to use special services via my website, processing of personal data may become necessary. If the processing of personal data is required and there is no legal basis for such processing, I generally obtain the consent of the data subject.
The processing of personal data, such as the name, address, email address, or telephone number of a data subject, is always carried out in accordance with the General Data Protection Regulation (GDPR) and in compliance with the applicable country-specific data protection regulations. Through this privacy policy, I inform the public about the nature, scope, and purpose of the personal data I collect, use, and process. Furthermore, data subjects are informed of their rights through this privacy policy.
As the data controller, I have implemented numerous technical and organizational measures to ensure the most complete protection of personal data processed through this website. However, Internet-based data transmissions may have security vulnerabilities, so absolute protection cannot be guaranteed. For this reason, every data subject is free to transmit personal data to me via alternative means, such as by telephone.
This privacy policy is based on the terms used by the European legislator for the adoption of the General Data Protection Regulation (GDPR). It should be easy to read and understand for the public as well as for the people who use VoiceApp. To ensure this, I would like to first explain the terminology used.
In this privacy policy, I use the following terms, among others:
Personal data means any information relating to an identified or identifiable natural person (hereinafter referred to as the „data subject“). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
Data subject is any identified or identifiable natural person whose personal data is processed by the data controller.
Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Restriction of processing is the marking of stored personal data with the aim of limiting their processing in the future.
Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural persons performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
Pseudonymization means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.
Controller or data controller is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
Processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.
Recipient is a natural or legal person, public authority, agency, or another body to which the personal data is disclosed, whether a third party or not. However, public authorities that may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.
Third party is a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data.
Consent of the data subject is any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
The data controller within the meaning of the General Data Protection Regulation (GDPR), other data protection laws applicable in Member States of the European Union, and other provisions related to data protection is:
Dennis HoothThis website collects a series of general data and information each time it is accessed by a data subject or an automated system. This general data and information are stored in server log files. The following may be collected: (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches my website (so-called referrers), (4) the sub-websites accessed via an accessing system on my website, (5) the date and time of access to the website, (6) an Internet Protocol (IP) address, (7) the Internet service provider of the accessing system, and (8) other similar data and information used for security purposes in the event of attacks on my information technology systems.
When using this general data and information, I do not draw any conclusions about the data subject. Rather, this information is needed to (1) deliver the content of my website correctly, (2) optimize the content of my website and its advertising, (3) ensure the long-term functionality of my information technology systems and the technology of my website, and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyberattack. These anonymously collected data and information are therefore statistically evaluated by me to increase data protection and data security and to ensure an optimal level of protection for the personal data I process. The anonymous data of the server log files are stored separately from all personal data provided by a data subject.
The data controller processes and stores personal data of the data subject only for the period necessary to achieve the purpose of storage or as required by the European legislator or other legislators in laws or regulations to which the data controller is subject.
If the storage purpose no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, the personal data is routinely blocked or deleted in accordance with legal requirements.
Every data subject has the right granted by the European legislator to obtain confirmation from the data controller as to whether personal data concerning them is being processed. If a data subject wishes to exercise this right of confirmation, they may contact me as the data controller at any time.
Every data subject has the right granted by the European legislator to obtain from the data controller, at any time and free of charge, information about their personal data stored and a copy of this information. Furthermore, the European legislator has granted the data subject access to the following information:
Furthermore, the data subject has the right to be informed whether personal data has been transferred to a third country or to an international organization. If this is the case, the data subject also has the right to be informed of the appropriate safeguards relating to the transfer.
If a data subject wishes to exercise this right of access, they may contact me as the data controller at any time.
Every data subject has the right granted by the European legislator to obtain from the data controller without undue delay the rectification of inaccurate personal data concerning them. Taking into account the purposes of the processing, the data subject also has the right to have incomplete personal data completed, including by means of providing a supplementary statement.
If a data subject wishes to exercise this right to rectification, they may contact me as the data controller at any time.
Every data subject has the right granted by the European legislator to obtain from the data controller the erasure of personal data concerning them without undue delay, and the data controller is obliged to erase personal data without undue delay where one of the following grounds applies, as long as the processing is not necessary:
If one of the aforementioned reasons applies, and a data subject wishes to request the erasure of personal data stored by Dennis Hooth, they may contact me as the data controller at any time. I will ensure that the erasure request is complied with immediately.
If I have made the personal data public and am obliged as the data controller to erase it pursuant to Article 17(1) GDPR, then, taking into account available technology and the cost of implementation, will take reasonable steps, including technical measures, to inform other data controllers processing the published personal data that the data subject has requested the erasure of all links to, or copies or replications of, such personal data, insofar as processing is not required. I will arrange the necessary measures in individual cases.
Every data subject has the right granted by the European legislator to obtain from the data controller the restriction of processing where one of the following applies:
If one of the aforementioned conditions is met, and a data subject wishes to request the restriction of the processing of personal data stored by Dennis Hooth, they may contact me as the data controller at any time. I will arrange the restriction of the processing.
Every data subject has the right granted by the European legislator to receive the personal data concerning them, which they have provided to a data controller, in a structured, commonly used, and machine-readable format. They also have the right to transmit this data to another data controller without hindrance from the data controller to which the personal data has been provided, where the processing is based on consent pursuant to Article 6(1)(a) GDPR or Article 9(2)(a) GDPR or on a contract pursuant to Article 6(1)(b) GDPR, and the processing is carried out by automated means, provided that the processing is not necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller.
Furthermore, in exercising their right to data portability pursuant to Article 20(1) GDPR, the data subject has the right to have personal data transmitted directly from one data controller to another, where technically feasible and when doing so does not adversely affect the rights and freedoms of others.
To assert the right to data portability, the data subject may contact me at any time.
Every data subject has the right granted by the European legislator to object, on grounds relating to their particular situation, at any time to the processing of personal data concerning them which is based on Article 6(1)(e) or (f) GDPR. This also applies to profiling based on these provisions.
I will no longer process the personal data in the event of an objection, unless I can demonstrate compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or for the establishment, exercise, or defense of legal claims.
If Dennis Hooth processes personal data for direct marketing purposes, the data subject has the right to object at any time to the processing of personal data concerning them for such marketing. This also applies to profiling to the extent that it is related to such direct marketing. If the data subject objects to Dennis Hooth processing for direct marketing purposes, Dennis Hooth will no longer process the personal data for these purposes.
In addition, the data subject has the right, on grounds relating to their particular situation, to object to the processing of personal data concerning them by Dennis Hooth for scientific or historical research purposes or statistical purposes pursuant to Article 89(1) GDPR, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
To exercise the right to object, the data subject may directly contact me directly. The data subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to use their right to object by automated means using technical specifications.
Every individual affected by the processing of personal data has the right, granted by European directives and regulations, not to be subject to a decision based solely on automated processing—including profiling—which produces legal effects concerning them or similarly significantly affects them, provided that the decision (1) is not necessary for entering into or performing a contract between the data subject and the data controller, or (2) is not authorized by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject's rights, freedoms, and legitimate interests, or (3) is not based on the data subject's explicit consent.
If the decision (1) is necessary for entering into or performing a contract between the data subject and the data controller, or (2) is made with the data subject's explicit consent, Dennis Hooth shall implement suitable measures to safeguard the data subject's rights, freedoms, and legitimate interests, including at least the right to obtain human intervention on the part of the controller, to express their point of view, and to contest the decision.
If the data subject wishes to exercise their rights concerning automated decisions, they may contact me as the data controller at any time.
Every individual affected by the processing of personal data has the right, granted by European directives and regulations, to withdraw their consent to the processing of personal data at any time.
If the data subject wishes to exercise their right to withdraw consent, they may contact me as the data controller at any time.
The data controller has integrated Google AdSense on this website. Google AdSense is an online service that enables the placement of advertisements on third-party sites. Google AdSense is based on an algorithm that selects advertisements displayed on third-party sites to match the content of those sites. Google AdSense allows for interest-based targeting of internet users, which is implemented by generating individual user profiles.
The operating company of the Google AdSense component is Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Ireland.
The purpose of the Google AdSense component is the integration of advertisements on my website. Google AdSense places a cookie on the information technology system of the data subject. What cookies are has already been explained above. By setting the cookie, Alphabet Inc. is enabled to analyze the use of my website. Each time one of the individual pages of this website, which is operated by the data controller and on which a Google AdSense component has been integrated, is accessed, the internet browser on the data subject's information technology system is automatically prompted by the respective Google AdSense component to transmit data to Alphabet Inc. for the purpose of online advertising and commission accounting. Within the scope of this technical procedure, Alphabet Inc. gains knowledge of personal data, such as the IP address of the data subject, which serves Alphabet Inc., among other things, to trace the origin of visitors and clicks and subsequently facilitate commission settlements.
The data subject may, as stated above, prevent the setting of cookies through my website at any time by means of a corresponding adjustment of the internet browser used and thus permanently object to the setting of cookies. Such an adjustment to the internet browser used would also prevent Alphabet Inc. from setting a cookie on the data subject's information technology system. In addition, cookies already set by Alphabet Inc. may be deleted at any time via the internet browser or other software programs.
Google AdSense also uses so-called tracking pixels. A tracking pixel is a miniature graphic embedded in web pages to enable log file recording and log file analysis, which allows for statistical evaluation. Based on the embedded tracking pixel, Alphabet Inc. can determine whether and when a website was opened by a data subject and which links were clicked by the data subject. Tracking pixels are used, among other things, to analyze the flow of visitors to a website.
Through Google AdSense, personal data and information, including the IP address, which is necessary for the collection and billing of displayed advertisements, is transmitted to Alphabet Inc. in the United States of America. This personal data is stored and processed in the United States of America. Alphabet Inc. may share this personal data collected through the technical procedure with third parties.
Google AdSense is explained in more detail at this link: https://www.google.de/intl/de/adsense/start/.
The data controller has integrated the Google Analytics component (with anonymization function) on this website. Google Analytics is a web analytics service. Web analytics is the collection, gathering, and analysis of data about the behavior of visitors to websites. A web analytics service collects, among other things, data about the website from which a data subject has accessed another website (so-called referrers), which subpages of the website were accessed, or how often and for how long a subpage was viewed. Web analytics is mainly used to optimize a website and to carry out a cost-benefit analysis of internet advertising.
The operating company of the Google Analytics component is Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Ireland.
The data controller uses the addition "_gat._anonymizeIp" for web analytics via Google Analytics. By means of this addition, the IP address of the data subject's internet connection is truncated and anonymized by Google if access to my website is from a member state of the European Union or another contracting state to the Agreement on the European Economic Area.
The purpose of the Google Analytics component is to analyze visitor traffic on my website. Google uses the collected data and information, among other things, to evaluate the use of my website, to compile online reports for me showing the activities on my website, and to provide other services related to the use of my website.
Google Analytics places a cookie on the data subject's information technology system. What cookies are has already been explained above. By setting the cookie, Google is enabled to analyze the use of my website. Each time one of the individual pages of this website, which is operated by the data controller and on which a Google Analytics component has been integrated, is accessed, the internet browser on the data subject's information technology system is automatically prompted by the respective Google Analytics component to transmit data to Google for the purpose of online analysis. Within the scope of this technical procedure, Google gains knowledge of personal data, such as the IP address of the data subject, which serves Google, among other things, to trace the origin of visitors and clicks and subsequently facilitate commission settlements.
By means of the cookie, personal information, such as the access time, the location from which access was made, and the frequency of visits to my website by the data subject, is stored. Each time my website is visited, this personal data, including the IP address of the internet connection used by the data subject, is transmitted to Google in the United States of America. This personal data is stored by Google in the United States of America. Google may share this personal data collected through the technical procedure with third parties.
The data subject may, as stated above, prevent the setting of cookies through my website at any time by means of a corresponding adjustment of the internet browser used and thus permanently object to the setting of cookies. Such an adjustment to the internet browser used would also prevent Google from setting a cookie on the data subject's information technology system. In addition, cookies already set by Google Analytics may be deleted at any time via the internet browser or other software programs.
Furthermore, the data subject has the option to object to and prevent the collection of data generated by Google Analytics related to the use of this website and the processing of this data by Google. To do so, the data subject must download and install a browser add-on from the link https://tools.google.com/dlpage/gaoptout. This browser add-on informs Google Analytics via JavaScript that no data and information about website visits may be transmitted to Google Analytics. The installation of the browser add-on is considered an objection by Google. If the data subject's information technology system is later deleted, formatted, or reinstalled, the data subject must reinstall the browser add-on to disable Google Analytics. If the browser add-on is uninstalled or deactivated by the data subject or another person within their control, the browser add-on may be reinstalled or reactivated.
Further information and the applicable data protection provisions of Google may be retrieved under https://www.google.de/intl/de/policies/privacy/ and under http://www.google.com/analytics/terms/de.html. Google Analytics is explained in more detail at this link: https://www.google.com/intl/de_de/analytics/.
Article 6(1)(a) of the GDPR serves as the legal basis for processing operations in which I obtain consent for a specific processing purpose. If the processing of personal data is necessary for the performance of a contract to which the data subject is a party, such as processing required for the delivery of goods or the provision of another service or consideration, the processing is based on Article 6(1)(b) of the GDPR. The same applies to processing operations necessary for carrying out pre-contractual measures, such as in cases of inquiries about my products or services. If I am subject to a legal obligation requiring the processing of personal data, such as for the fulfillment of tax obligations, the processing is based on Article 6(1)(c) of the GDPR. In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or another natural person. In such cases, the processing would be based on Article 6(1)(d) of the GDPR. Finally, processing operations could be based on Article 6(1)(f) of the GDPR. This legal basis covers processing not covered by any of the aforementioned legal grounds if the processing is necessary for the purposes of the legitimate interests pursued by me or a third party, provided that such interests are not overridden by the interests, fundamental rights, and freedoms of the data subject. Such processing operations are particularly permissible because they have been specifically mentioned by the European legislator. In this regard, it was considered that a legitimate interest could be assumed if the data subject is a client of the controller (Recital 47, Sentence 2 of the GDPR).
If the processing of personal data is based on Article 6(1)(f) of the GDPR, my legitimate interest is the operation and continued development of VoiceApp.
The criterion for the duration of the storage of personal data is the respective statutory retention period. After the expiration of this period, the corresponding data is routinely deleted, provided it is no longer necessary for the fulfillment or initiation of a contract.
I inform you that the provision of personal data is partly required by law (e.g., tax regulations) or may result from contractual provisions (e.g., information about the contractual partner). Sometimes it may be necessary for the conclusion of a contract that a data subject provides me with personal data, which must subsequently be processed by me. For example, the data subject is obliged to provide me with personal data when I enter into a contract with them. Failure to provide the personal data would mean that the contract with the data subject could not be concluded. Before providing personal data, the data subject may contact me at any time. I will clarify to the data subject on a case-by-case basis whether the provision of personal data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the personal data, and what the consequences of not providing the personal data would be.
I do not use automated decision-making or profiling.
The Discover section of this website displays public VoiceApp users and groups (the 10 most recent of each). The displayed data is retrieved from the VoiceApp API. It exclusively consists of data that users have actively made public themselves.
The following data is displayed:
Profile pictures are temporarily cached on the web server to reduce API requests (max. 1 hour). Public metadata (nickname, subject) is cached for max. 5 minutes. After this period, the data is automatically discarded.
The VooMe section of this website displays public VooMes from the VoiceApp API (up to 10 most recent). The displayed data consists exclusively of content that users have actively published publicly.
The following data is displayed:
Cover images are temporarily cached on the web server to reduce API requests (max. 1 hour). Feed metadata is cached for max. 5 minutes. Audio files are not cached and are streamed directly.
This privacy policy is based on a template by DGD Deutsche Gesellschaft für Datenschutz GmbH and has been adapted and extended for VoiceApp.
Status: June 21, 2026
VoiceApp has been developed to store only the data necessary to fulfill the app’s functionality.
One reason for this is data protection, and since I finance the project with private funds,
I aim to minimize server costs as much as possible.
No data is sold to third parties!
VoiceApp is based in Germany and is subject to German laws and regulations.
By using the app, users agree to the collection, processing, and use of data in accordance with the following description.
VoiceApp requires data to enable the transmission of messages and files to other users. The processed data is exclusively handled on the server infrastructure in Germany (Frankfurt).
This information is transmitted during the login process and is used solely for technical analysis, improving app compatibility, and troubleshooting.
The data will not be shared with third parties.
All communication with other users and groups is SSL-encrypted.
Messages are not stored permanently on the server. If a message cannot be delivered because the recipient is offline, it is held until delivery. Once delivery is confirmed, a daily cleanup process deletes it from the server completely no later than 7 days afterwards, including any associated media files. Messages that can never be delivered are deleted after 90 days. When an account is deleted, all messages still held for that user are removed immediately.
ContactsWith the user's consent, the contacts from the smartphone address book can be checked to see if a particular contact is already registered with VoiceApp.
Users can set their profile and groups to public. Public profiles are visible to other app users as well as visitors of the VoiceApp website in the Discover section.
The following data is visible:
Visibility can be set back to private for users and groups at any time in the profile and group settings in the app.
VooMe is a social audio feature built into VoiceApp. Users can record short audio posts, add a title and cover image, and publish them publicly to a global feed or share them privately in chats. Public VooMes are visible to all app users as well as visitors of the VoiceApp website.
Data stored for each VooMePublic VooMes are temporarily cached on the VoiceApp website to reduce server load: feed data is cached for up to 5 minutes, preview images for up to 1 hour. Audio files are not cached and are streamed directly from the server.
DeletionUsers can delete their VooMes at any time within the app. Upon deletion, the VooMe data is removed from the server. Cached versions on the website are automatically cleared once the cache period expires.
ReportsIf a VooMe is reported via the in-app reporting function, the report data (including the reported VooMe and the reason for the report) is processed exclusively for the purpose of reviewing and moderating the content.
VoiceApp does not share data with third parties. However, some functionalities may require the use of external data sources, frameworks, or operating system functions that process data and are subject to their own privacy policies.
Crash ReportsTo ensure that VoiceApp continues to function correctly, anonymized crash reports are required.
After an app crash, information such as the app’s state at the time of the crash, stack trace, device manufacturer and operating system, and the last log messages are transmitted to Google and stored for analysis. The error report is deleted after the bug is fixed. These reports do not contain any personal data.
Hosting and processorsThe VoiceApp servers run in a Kubernetes cluster operated by DigitalOcean, LLC in its Frankfurt am Main data centre. The database is a managed MySQL service provided by Aiven Ltd. (Finland), likewise running on infrastructure in Frankfurt am Main. Accounts, messages and media files sent in chats are therefore processed in Germany. Both providers are bound by data processing agreements pursuant to Art. 28 GDPR.
Beyond that, the Google services named in this policy are used (Firebase Storage, Firebase Cloud Messaging for push notifications, Crashlytics for crash reports, and AdMob or AdSense for advertising). No other third parties receive data.
Storage of published VooMes (Google Firebase Storage)When a user publishes a VooMe to the public feed, its audio file and cover image are stored in and served from Google Firebase Storage (Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Ireland). The storage location is the US-CENTRAL1 region, which means the files are held in a data centre in the USA. The transfer is based on the EU Standard Contractual Clauses; Google LLC is also certified under the EU-US Data Privacy Framework. The legal basis is Art. 6(1)(b) GDPR (performance of the user agreement). Deleting the VooMe or the account removes the files.
VooMes that are not published are never transferred there and remain local on the device. A VooMe sent inside a chat is delivered like any other media file through the servers in Frankfurt am Main.
VoiceApp uses Google AdMob to display advertisements. Whether these ads are personalized depends on your consent.
Personalized Advertising
If you explicitly consent in the consent dialog (Google UMP – User Messaging Platform),
you may be shown personalized advertisements.
These are based on your user behavior, interests, and other information
that Google processes in accordance with your consent.
Non-personalized Advertising
If you do not grant consent or reject it, VoiceApp displays exclusively
non-personalized advertisements. These are not based on your individual user behavior,
but only on general factors such as the app content or your approximate location
(e.g., country or city).
To provide advertising, VoiceApp uses the Google Mobile Ads SDK. The processing of personal data is carried out exclusively in accordance with your selection in the consent dialog and in compliance with the General Data Protection Regulation (GDPR) as well as the ePrivacy Directive (ePR).
For more information on data processing by Google AdMob, please refer to Google's privacy policy: Google Privacy Policy .
Users have the right to access their stored personal data at any time.
The account and all associated data can be deleted via the app (Profile -> Settings -> Delete account).
VoiceApp does not knowingly collect personal information from children. If I become aware that a child has provided me with personal data, I will delete it promptly. Parents or guardians who believe their child has provided me with personal data may contact me at privacy@voiceapp.me.
VoiceApp does not sell personal information. California residents have the same rights as described above, including the right to know what personal data I collect, the right to deletion, and the right to opt out of the sale of personal information (which does not apply, as I do not sell data). For requests, please contact privacy@voiceapp.me.
The data controller within the meaning of the General Data Protection Regulation is:
Dennis HoothNo data protection officer has been appointed: VoiceApp is operated by a single individual, and the conditions requiring an appointment under Art. 37 GDPR or § 38 BDSG are not met.
For any questions about data protection you can reach me at privacy@voiceapp.me
VoiceApp reserves the right to update this privacy policy from time to time to comply with legal requirements or to implement new functionalities in the privacy policy. The current privacy policy is linked within the app (Profile → Settings → Help → Privacy Policy).