Privacy
Effective 7 August 2026 · Vocket is operated by Esforge
The short version. Vocket records your voice only while you hold the button. It turns what you said into proposed time entries, notes, and tasks, and writes them to your practice-management software only after you confirm each one.
Your recordings and transcripts are never used to train any AI model, ours or anyone else's. The AI providers we use are contractually barred from training on the data we send them.
Audio is deleted once it has been transcribed. You can export everything or delete everything at any time.
What we collect
- Account details: your email address, and the practice settings you enter yourself: default hourly rate, practice areas, timezone, and the names of staff you delegate to.
- Your recordings and their transcripts: the audio you capture by pressing the record button, and the text produced from it.
- What the software proposed, and what you did about it: the structured items generated from a capture, any edits you made, which items you confirmed, and where each one was written.
- A cached copy of your matter list: matter numbers, descriptions, and client names read from your practice-management software, so that saying "the Alvarez case" can be matched to the right matter.
- Access tokens for your practice-management software, held encrypted so Vocket can write on your behalf.
- Operational logs: timing, error codes, and request outcomes. These are filtered by an allow-list: transcripts, matter names, and note text cannot enter our logs.
We do not use advertising trackers, we do not sell data, and we do not build profiles of you or your clients.
What we never collect
- Anyone's voice but yours. There is no call recording, no meeting mode, no ambient or always-on listening, and no wake word. The microphone opens when you press the button and closes when you release it.
- Your screen, keystrokes, calendar, or email. Vocket does not observe how you work.
- Payment card numbers. If and when Vocket charges for a subscription, payment details go directly to our payment processor and never reach our servers.
Why we process it
To provide the service you asked for: transcribing your capture, structuring it into proposed records, matching it to your matters, and writing confirmed items to your practice-management software. We also keep an audit trail of proposals and confirmations, because you may need to show what was created and when.
Where the GDPR applies, our lawful basis is the performance of our contract with you, and our legitimate interest in keeping the service secure and working.
Who else processes it
Vocket runs on infrastructure operated by others. Each is bound by contract to process data only on our instructions, and the AI providers are additionally barred from training on it.
| Provider | What it handles |
|---|---|
| OpenAI | Speech-to-text. Receives your capture audio. Zero-retention, no-training API terms. |
| Anthropic | Structuring the transcript into proposed items. Receives the transcript and your matter list. No-training API terms. |
| Supabase | Database and authentication. Holds your account, captures, transcripts, proposals, audit trail, and encrypted tokens. |
| Railway | Hosting for the Vocket server. |
| Expo | Mobile app delivery and updates. Does not receive capture content. |
| Clio | Your practice-management software. Receives only the items you confirm. Your relationship with Clio is governed by their terms, not ours. |
Data is stored in the United States. If you are outside the US, using Vocket involves transferring your data there.
How long we keep it
- Audio: deleted once transcribed. The only audio that persists is a capture that has not reached our server yet, held on your phone until it does.
- Transcripts, proposals, and the audit trail: kept while your account is open, because they are the record of what was proposed and confirmed.
- Cached matter list: refreshed from your practice-management software and deleted when you disconnect it.
- Access tokens: deleted when you disconnect the integration or close your account.
Security
- Encrypted in transit, and encrypted at rest by our database provider.
- Practice-management access tokens are separately encrypted with AES-256-GCM before they are stored, so they are unreadable even in a database dump.
- Every table is row-secured per user; one account cannot read another's data.
- Application logs are allow-listed, so client content cannot appear in them.
- Nothing is written to your practice-management software without your explicit confirmation. There is no setting that turns this off, because no such setting exists in the code.
No system is perfectly secure. If we ever discover a breach affecting your data, we will tell you what happened, what was exposed, and when.
Your choices
- Export everything: audio you have chosen to keep, transcripts, proposals, confirmations, and the audit log, as a single archive.
- Delete everything: removes every capture, transcript, proposal, and audit record from Vocket. Records already written to your practice-management software remain there, because they are yours and they live in your system, not ours.
- Disconnect the integration at any time, which revokes our access and deletes the stored tokens.
- Depending on where you live, you may also have rights to access, correct, port, or restrict processing of your personal data. Ask and we will action it.
Professional responsibility
Vocket is a tool for capturing your own work product. It does not provide legal advice, does not draft legal documents, and does not perform legal research. Reviewing and confirming what it proposes is your judgment, and remains your responsibility. Nothing on this page is legal advice about your own obligations to your clients or your bar.
Children
Vocket is a professional tool for practising lawyers. It is not directed to anyone under 18, and we do not knowingly collect their data.
Changes
If this policy changes in a way that affects how your data is handled, we will tell account holders by email before the change takes effect, not merely update this page.
Contact
Questions about this policy, or a request to export or delete your data: hello@tryvocket.com.