Privacy Policy
Last reviewed 15 September 2026
VoxSign processes a recording of your voice, which is about as personal as data gets. This page says exactly what we collect, who else touches it, how long it survives, and what you can make us do about it. It describes this service specifically, not a generic template.
Who we are
VoxSign Accessibility is a speech to sign language service operated from Room MIIC, Level 5, Block B, CIT, Makerere University, Kampala, Uganda. For the purposes of Uganda's Data Protection and Privacy Act 2019, VoxSign is the data collector and data controller for the personal data described below.
Questions about this policy, or any request about your own data, go to info@voxsign.co.ug or +256 770 680769. A named person handles these; you will get a reply from a human, not an autoresponder.
What we collect
We collect five kinds of data, and nothing else. There is no advertising identifier, no behavioural profile, no third party analytics script and no tracking pixel anywhere in this service.
- Account data
- Your email address, whether it has been verified, your name if you give one, and a securely hashed password if you set one. If you sign in with Google we store the account identifier Google returns and the email address on it. We never see or store your Google password. We also store the records that keep you signed in on your devices.
- Profile and preference data
- Your user type, student or educator, an optional gender field, an optional profile picture, your lesson and vocabulary counters, your accessibility settings such as text size and reduced motion, and your notification settings. Preferences are stored against your account rather than one browser so the app arrives set up correctly wherever you sign in.
- Voice and video you submit
- Audio you record for a live translation, and any video you upload for a learning session. Processing these produces a transcript of what was said, timed caption segments, and a timeline of which signs to play when. Audio and video are content you choose to send us, and they can contain anything you said or recorded, so please read the retention section below carefully.
- Plan, usage and payment data
- Which plan you are on and when any Premium time ends. On the Free plan, a record of each successful live translation, holding only the time it happened and never the audio or the words, so the allowance can be counted. If you pay, a record of each payment: our reference, Flutterwave's reference, the amount, the currency, whether it succeeded, and the dates. We never receive or store your card number or mobile money details; you enter those with Flutterwave.
- Support data
- If you report a problem, the category you chose, the description you wrote and any screenshot you attached. Screenshots are useful and they also show whatever else was on your screen, so attach them deliberately.
What we do not collect
- We do not ask for, and have no field for, any health, disability, biometric, religious or political data. Whether you are Deaf or hard of hearing is not something we record.
- We do not use cookies for advertising or cross site tracking. See the cookie policy for the small number we do set.
- We do not buy, sell, rent or share personal data with anyone for marketing.
Why we use it, and on what basis
Under the Data Protection and Privacy Act 2019 we have to have a lawful basis for processing your data, and tell you what it is.
- To give you the service you asked for
- Transcribing your audio or video, matching the words against the sign vocabulary, building the cue timeline, and playing it back. This is performance of the contract you enter by using VoxSign. Without it there is no product.
- To keep your account working
- Creating your account, verifying your email address with a one time code, signing you in, and letting you reset a password. Also contractual, and in part a legal requirement to keep the service secure.
- To honour your accessibility settings
- Storing and applying the preferences you set. Consent, given by setting them, and withdrawable by changing them back at any time.
- To answer you and to fix faults
- Handling problem reports and support messages. Our legitimate interest in running a service that works, and yours in having it fixed.
Automated decisions
VoxSign makes no automated decision about you. The speech model transcribes audio and the matcher selects signs; neither judges you, scores you, or decides anything that affects your rights or your access to anything.
We do not train our model on your recordings
Your audio and video are used to produce your translation and for nothing else. They are not used to train, fine tune, evaluate or improve the speech recognition model, and they are not added to any dataset. The Luganda speech model VoxSign uses was fine tuned on separately sourced training data before any user ever uploaded anything.
That is a statement about how the service works today, and it is the reason this page carries a review date. If we ever want to learn from user recordings, we will change this policy first, ask for your consent explicitly, and give you a way to say no, before a single recording is used that way. We will not do it quietly.
Who else processes it, and where
VoxSign is a small team and does not own data centres. The service runs on infrastructure providers who process data strictly on our instructions, as processors. All of them are outside Uganda, which means your data is transferred abroad for processing. We have listed each one and exactly what it touches, so you can judge that for yourself rather than take a blanket assurance.
- Vercel (website hosting)
- Serves this website and the app interface, and hosts the sign in system. Sees your email address and session when you sign in.
- Railway (application and database hosting)
- Runs the VoxSign API, the video processing worker, and the PostgreSQL database that holds your account, profile, preferences, support reports and session records.
- Cloudflare R2 (video storage)
- Holds an uploaded video while it waits for a worker and while it is being processed. This is the only place a raw upload is stored, and it is deleted on the schedule in the next section.
- Modal (speech recognition)
- Runs the Luganda speech model on a GPU. Audio is sent in short segments, transcribed, and the text returned. Modal is a compute provider, not a party we share data with for its own purposes.
- Resend (email delivery)
- Sends your verification and password codes. Sees your email address and the contents of those messages. Note that a delivered email containing a one time code sits in a message log, which is one reason codes expire.
- Flutterwave (payments, only if you pay)
- Takes Premium payments by card or mobile money on its own payment page. Receives your email address, the amount, and the card or mobile money details you enter there, which we never see. Tells us whether the payment succeeded. If you stay on the Free plan, Flutterwave is not involved at all.
- Google (only if you choose it)
- If you sign in with Google, Google tells us your account identifier, email address, name and profile picture, and knows that you signed in to VoxSign. If you use an email address and password instead, Google is not involved at all.
We do not add a processor without a reason, and we will update this list when it changes. Beyond these, we disclose personal data only where the law requires it, and only to the extent it requires.
How long we keep it
Recordings are the sensitive part of this service, so they are kept on a short, automatic, enforced schedule rather than an intention. A cleanup pass in the video worker deletes the stored file first and the database record second, so a recording can never be left behind with nothing pointing at it.
- Uploaded video, session finished successfully
- The video and its transcript, captions and cue timeline are deleted around 24 hours after processing completes. The session is there to be watched, not archived. If you need a permanent copy, keep your own.
- Uploaded video, session failed
- Deleted around 15 minutes after the failure. That window exists only so the app can show you what went wrong before the record disappears.
- Uploaded video, replaced by a newer one
- You hold one learning session at a time. Uploading a new video marks the previous one for deletion immediately, and the next cleanup pass removes the file and the record.
- Live translation audio
- Never written to disk or to the database. It is held in the server's memory for the moment it takes to transcribe. The resulting text is kept in a short lived in memory cache of at most one hundred recent results and is gone when the service restarts.
- Account, profile and preferences
- Kept while your account exists, because they are what the account is. When you ask us to delete your account, it is closed and removed from the service. Where Ugandan law or regulation requires us to, we keep a copy of the account records for a limited period after deletion, for example to meet legal, tax or dispute obligations. That copy is not used to run the service or for anything else, and it is deleted when the required period ends.
- Plan and usage records
- Kept while your account exists, because the Free plan's total allowance is counted from them. Deleted with your account, subject to the same legally required retention period described above.
- Payment records
- Kept while your account exists, and after it is deleted for the period Ugandan law or regulation requires for accounting, tax and dispute purposes, including to handle a refund. They hold references, amounts and dates, never card or mobile money details, and are deleted when that period ends.
- Problem reports
- Kept while we need them to fix the fault and to check the fix held. Ask us and we will delete a specific report.
How it is protected
In short: everything travels over HTTPS, passwords are hashed and never stored in a readable form, the sign in session lives in a cookie your browser will not hand to another site, and every request for a session or a recording checks that it belongs to the account asking.
The detail, including the parts that are honestly imperfect, is on the security page. We would rather describe a weakness than imply there are none.
Your rights, and how to use them
Under the Data Protection and Privacy Act 2019 and the Data Protection and Privacy Regulations 2021, you have the right to:
- Be told what personal data of yours we hold, and ask for a copy of it.
- Have anything inaccurate corrected, and anything incomplete completed.
- Have your data deleted, including your whole account, except for records the law requires us to keep for a limited period, which we keep only for that purpose.
- Object to processing, and withdraw a consent you gave, without that affecting anything done before you withdrew it.
- Ask us to stop processing your data while a dispute about its accuracy is being resolved.
- Not be subjected to a decision made solely by automated means. As stated above, we make none.
Email info@voxsign.co.ug and say what you want. We will ask you to confirm you control the address on the account, which is the only identity check we can reasonably do, and then we will act on it. We aim to reply within seven days and to complete the request within thirty.
If we get it wrong
Tell us first, because we can usually fix it faster than anyone else can. If you are not satisfied, you have the right to complain to Uganda's Personal Data Protection Office, the supervisory authority established under the Act. You do not need our permission to do that and you do not need to come to us first.
Children and learners under eighteen
VoxSign is built with classrooms in mind, so learners under eighteen are plainly in scope. Under the Act, processing a child's personal data requires the consent of a parent, a guardian or another person with lawful authority.
We do not verify age at sign up, and we are not going to pretend otherwise. So, practically:
- If you are under eighteen, please use VoxSign with the agreement of a parent, a guardian or your teacher, and do not create an account without it.
- If you are a school or an organisation using VoxSign with learners, you are responsible for obtaining that consent, and we will support you with whatever information about this service you need in order to get it.
- If you believe a child has created an account without that consent, email us and we will delete the account and its recordings.
Recordings are the reason this matters more here than on an ordinary website. A learner's voice is personal data, and the retention schedule above applies to it exactly as it does to anyone else's.
Changes to this policy
When this policy changes we update the review date at the top. For a change that materially affects you, and using your recordings for model training would be the clearest example, we will tell you before it takes effect rather than after.