Velvet Voice — Privacy Policy
Last updated 1 September 2026
Velvet Voice is a voice-first social app. You are heard rather than photographed, and you choose a handle rather than giving a real name. This policy says exactly what we hold, why we hold it, who else ever sees it, and how you get rid of it.
The short version. We keep an email address, a handle, your age and gender, an approximate location, and whatever voice notes and photos you choose to record or upload. Your phone number is stored only as a one-way hash after it has been verified. We never see or store card details. We do not sell anything about you to anyone.
1. Who we are
Velvet Voice (“we”, “us”) operates this service and is the controller of the personal data described here. We are based in India. You can reach us at the address at the end of this policy.
2. This is an adults-only service
You must be 18 or over to hold an account. We ask for your age at sign-up and refuse anyone below 18. If we learn that an account belongs to a minor we delete it and its content without notice.
3. What we collect
Account details
- Your handle, which is public inside the app.
- Your email address, used for sign-in, verification, security codes and account recovery.
- Your password, stored only as a bcrypt hash — we cannot read it.
- Your age and gender, and optionally your date of birth.
- A Google account identifier, if you choose to sign in with Google. We do not receive your Google password.
Your phone number
Activating an account requires a phone number so that one person cannot quietly run many accounts. The number is held in full only for as long as it takes to send and check the code. Once it is verified we keep a one-way hash of it and discard the number itself. The hash lets us recognise that a number has already been used; it cannot be turned back into a number, and it is never shown to another member.
Voice recordings and photos
Voice intros, voice messages, board posts and bottle messages are audio files recorded by you and stored on our servers. Photos you add are stored the same way and may be reviewed by a moderator before they are shown. Both are visible only to the people the app's own rules allow — never to the open internet.
Location
If you allow it, we store the coordinates your device reports, together with a city name and a rough accuracy figure, so the app can say how far away someone is. Other members are shown a distance band, never your coordinates and never your address. You can decline location entirely, or set a city by hand instead; the app works either way, with fewer filters.
Device and notification data
We store a push-notification token for each device you sign in on, and a token for any device you mark as trusted for two-factor sign-in. Push notifications carry counts only — never the content of a message.
Payments
Purchases are processed by Razorpay. Card, UPI and bank details are entered on Razorpay's systems and never reach ours. We store only the order and payment identifiers, the amount, and whether it succeeded.
Safety and usage records
We keep records needed to run the service and keep it safe: who viewed your profile, who you connected with, reports made about an account, moderation flags, a trust score, and the IP address attached to a verification or sign-in attempt so that codes cannot be brute-forced.
4. Accounts marked as AI
Some accounts in the app are not people. Every one of them carries a visible AI marker on its profile and on its card. If you send a message to an account marked that way, the text of your message and the recent thread are sent to our AI provider (Anthropic) to compose a reply, and are subject to that provider's own handling. Conversations with real members are never sent to an AI provider. If you would rather not have any message processed this way, do not message an account carrying the marker.
5. What we do with it
- Run the app: show profiles, deliver voice notes and messages, work out distances.
- Verify that you are who you say you are, and that one person is not running many accounts.
- Take payments and apply credits and plans.
- Keep the place safe: act on reports, detect abuse, enforce our rules.
- Send you service messages — a security code, a notice about your account. We do not send marketing email.
We do not build advertising profiles, and we do not sell or rent personal data to anyone.
6. Who else sees it
- Other members, but only what the app is designed to show them: your handle, age, gender, the sketch of your profile, your distance band, and whatever voice or photos you have chosen to share.
- Razorpay, for payments.
- Google (Firebase), to deliver push notifications, and Google Sign-In if you use it.
- Our SMS provider, to deliver activation codes.
- Anthropic, only as described in section 4.
- Law enforcement, where we are legally required to respond.
7. How long we keep it
Account data is kept while your account exists. Some things go sooner by design:
- When you leave or block a conversation, the messages and the audio files behind them are destroyed, not hidden. Neither side can recover them.
- Bottle messages expire on their own timer.
- Visitor records age out after the window set for the app.
A report already filed keeps its own copy of what it was about, so that erasing a thread cannot be used to destroy evidence of abuse.
8. Deleting your account
You can ask us to delete your account and everything attached to it at any time. See Deleting your data for how, and for what is removed and what is kept.
9. Your rights
You can ask us for a copy of the data we hold about you, to correct it, or to delete it. Write to the address below and we will answer within 30 days. If you are in a jurisdiction that gives you a right to complain to a data-protection authority, nothing here takes that away.
10. Security
The site is served only over HTTPS. Passwords are bcrypt-hashed and phone numbers are stored as hashes. Sign-in is rate-limited and can be protected with two-factor codes. No system is perfect, and we will tell affected members promptly if something goes wrong.
11. Changes
If this policy changes materially we will update the date at the top and, where the change affects what we collect, say so in the app.
12. Contact
Questions, requests, or anything in this policy you think is wrong: privacy@mescomp.online.
13. Child safety
Velvet Voice is an adults-only service with zero tolerance for child sexual abuse and exploitation. Our published standards, how to report it, and our point of contact are at Child Safety Standards.