Privacy Policy
Last Updated: 09/28/2026
This Privacy Policy (“Policy”) describes how VO.FM (“VO,” “we,” “us,” or “our”) collects, uses, stores, and discloses information, including personal data, in connection with our services (“Services”) available at https://vo.fm (the “Website”). We are committed to protecting your privacy and handling your personal data in a transparent and secure manner. Please read this Policy carefully. For additional details, please review our Terms of Service.
1. Information We Collect
1.1. Account Data. When you create an account or sign in with Google, with Apple, with an email address, or through an AI assistant connector (section 4), we collect basic profile information (email address, name, and, for Google, your public profile picture) for authentication and account creation. If you use Apple's Hide My Email, we receive only the relay address Apple provides.
1.2. Listening Data. The Services record what you listen to in the VO app: which episodes you play, which parts of them you hear, when you hear them, and the moments you save (highlights) together with any notes you attach to them. This is the core of the product and is used to build your listening memory, your listening notes (recaps), and the answers our AI features and connectors give you. Beyond this, we do not collect personal data except information you voluntarily provide (e.g., contacting support).
1.3. Cookies and Tracking. We use JSON Web Tokens (JWT) for authentication, which may create a cookie. We also use analytics services like Mixpanel and Google Analytics that employ cookies or similar tracking technologies to gather usage data for service improvement.
2. How We Use Your Information
2.1. Authentication and Communication. We use your account data (name and email) to authenticate your account, personalize your experience, and send product-related emails, and your listening data to power recall, listening notes, and the AI features and connectors described in section 4.
2.2. Analytics and Service Enhancement. We analyze usage data (Mixpanel, Google Analytics) to troubleshoot technical issues, monitor performance, and improve our Services.
3. Data Sharing and Disclosure
3.1. Service Providers. We rely on Amazon Web Services (us-east-1) for hosting, Mixpanel for analytics, and Google Analytics for user insights. These providers may access personal data when necessary to perform services on our behalf but are contractually obligated to maintain confidentiality.
3.2. Internal Access. Authorized personnel at VO (fewer than 10 people) may access user data for legitimate business reasons and under confidentiality obligations.
3.3. Legal Requirements. We may disclose your data to comply with applicable law or legal processes, or to protect the rights, property, or safety of our users or the public.
3.4. No Sale of Data. We do not sell or rent your personal data under any circumstances.
4. AI Assistant Connectors (MCP) and API Keys
4.1. Connecting an AI assistant. You can connect an AI assistant (such as Claude, ChatGPT, or another client that supports the Model Context Protocol, "MCP") to VO. When you do, you sign in through our authorization provider, WorkOS, and authorize that assistant to read your listening data on your behalf through our read-only connector tools. The assistant receives a short-lived access token; it never receives your password, and we do not store that token in any form. If the email address you sign in with has no VO account, we create a free VO account for that email so the connection can be completed; that account holds no listening data until you use the VO app with the same email. We record that the account was created through a connector and which assistant created it.
4.2. What a connected assistant can do. A connector access token is accepted by our servers only on the read endpoints the connector tools use: your account identity, your listening history, the transcript passages you heard, your saved moments, your listening notes, and the public podcast catalog. Every other VO endpoint rejects it, so a connected assistant cannot play, add, change, delete, share, or purchase anything in your account, and cannot manage your account, subscription, or API keys. The tool descriptions your assistant sees describe exactly this access.
4.3. What we log. For each connector request we log the outcome of authentication, the tool that was called, whether the call succeeded, an error code when it did not, how long it took, and the name and version the assistant reports for itself. We do not log tool arguments, tool response bodies, or the transcript, notes, or highlight content that passes through the connector. Each log entry also carries the time, your VO account identifier, the identifier of your sign-in, and the email address you signed in with. We use these connector logs only to run and debug the service, keep them for up to 30 days, and then delete them. Connector traffic is processed in AWS us-east-1.
4.4. The assistant's own handling of your data. When you use our tools from inside an AI assistant, your prompts and the tool inputs and outputs transit that assistant's infrastructure under its own terms and retention policy (for example, Anthropic's retention settings for your Claude account, or OpenAI's for your ChatGPT account). We do not control how the assistant provider stores that data. VO is not currently a zero-data-retention partner of any assistant provider.
4.5. Ending a connection. To end a connection, remove VO from that assistant's connector settings; the short-lived token then expires on its own. We do not currently offer a list of connected assistants on vo.fm. To have an authorization revoked on our side, or to delete an account that was created through a connector, contact contact@vo.fm.
4.6. API Keys. If you create a personal API key in your VO settings (for example, to run the VO connector locally on your own computer), that key authenticates requests as you with the same access as your account. Keep it private. You can deactivate a key at any time in your settings, and deactivation takes effect immediately.
5. Data Retention and Deletion
We store your personal data as long as your account remains active or as necessary to provide Services. If you wish to deactivate or delete your data, please contact us at contact@vo.fm. We will delete your data unless retention is required or permitted by law (e.g., for legal obligations or dispute resolution).
6. Data Security
We use commercially reasonable measures to protect your data. Despite our efforts, no security measure is infallible, and we cannot guarantee absolute protection against unauthorized access, hacking, or data breaches.
7. Children’s Privacy
The Services are not intended for individuals under 13. Children under 13 should not use our Services, and if we discover we have unintentionally collected such data, we will promptly delete it. Please notify us at contact@vo.fm if you believe we have collected a child’s information.
8. International Data Transfers
Our primary servers are in the United States (AWS us-east-1). If you access the Services from outside the U.S., you consent to your data being transferred and processed in the U.S., where data protection laws may differ from those in your jurisdiction.
9. Your Rights
Depending on your location, you may have rights under data protection laws (e.g., GDPR, CCPA) to request access, correction, or deletion of your personal data. To exercise these rights, please email us at contact@vo.fm. We will respond as required by applicable law.
If you reside in specific regions (e.g., EEA, UK, certain U.S. states), you may also have the right to object to processing, request data portability, or lodge a complaint with a supervisory authority.
10. Changes to This Policy
We may update this Policy to reflect changes in our practices or for other operational, legal, or regulatory reasons. If we make significant changes, we will notify you by posting a prominent notice on the Website or via email. Your continued use of the Services following the posting of the updated Policy constitutes acceptance of the changes.
11. Contact Us
If you have any questions about this Policy, or if you wish to exercise any of your legal rights, please email us at contact@vo.fm. We will make reasonable efforts to address your inquiry promptly.
12. Effective Date
This Policy is effective as of the date listed at the top of this page.
13. Acknowledgment
By using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.