Privacy and data
Privacy policy
Last updated:
Free Voice to Text for WhatsApp is an independent Chrome extension published by Naotho Machida. It converts WhatsApp Web voice messages into text when you request a transcription. It is not affiliated with, endorsed by, or sponsored by WhatsApp or Meta.
Information we handle
- Account information: your WhatsApp phone number, display name and account identifier, a device identifier generated by the extension, and email when supplied through account or payment functions. A reference to your own profile image and account metadata may also be stored locally to identify the connected account.
- Authentication information: verification codes, device identifiers and session tokens. The server stores hashes of verification codes and session tokens, together with their validity and verification or revocation status. The extension stores its session token locally to keep you signed in.
- Voice messages and transcripts: the voice message you choose to transcribe, the resulting text, message identifiers, audio hashes, duration and file size. When you request a new transcription, the previous transcript may be sent as context along with the audio.
- Service usage: transcription dates, completion or error status, processing provider and model, usage and cost measurements, plan allowance and consumed minutes.
- Subscription and payment records: selected plan, subscription status, checkout and payment identifiers, amount and currency. Stripe processes payment details. We do not store complete card numbers or card security codes in the application's database.
- Technical and security information: IP addresses and request counts used to limit authentication attempts. We do not request GPS access or collect precise device location.
The extension reads relevant WhatsApp Web page elements to display its controls and identify voice messages. It also recognizes verification messages issued by this service so you can verify a code from the conversation. It does not collect your general browsing history or monitor keystrokes and mouse activity across other websites.
When information is processed
The extension identifies your connected WhatsApp account and restores locally saved account information when it starts. When authenticated, it requests plan and usage information from the backend. Account verification sends the information needed to deliver and validate a verification code.
Audio is uploaded for transcription only after you request that transcription. Previously cached transcripts may be displayed without uploading the audio again. The service does not automatically upload every voice message or your full conversation history.
How we use information
Information is used to produce and display transcripts, maintain your session, reuse cached results, show your plan and usage, administer subscriptions and payments, and protect the service from abuse.
Transcripts are stored locally and in the service database. Authorized administrators can access service records. Handling of personal content is restricted to permitted purposes, such as support with your specific permission, security investigations or legal requirements.
Processing providers
- Google Gemini API: the backend sends selected audio and transcription instructions to Google to generate text. A previous transcript may be included when you request regeneration. This service uses a Google Cloud project with active billing. Under Google's paid-service terms, prompts and responses are not used to improve Google's products. Google may retain them for a limited period for security, abuse prevention and required legal disclosures. See the Gemini API terms.
- WhatsApp messaging provider: the service sends your phone number and the verification message to the configured messaging provider to authenticate your account.
- Stripe: account and transaction information is processed to create checkout sessions and manage paid subscriptions. Card information entered in Stripe's payment interface is handled by Stripe.
- Hosting and database providers: Vercel and Neon provide the hosting and database infrastructure that processes and stores information required to operate the service.
Processing providers may handle information in countries other than your own. Using the paid Gemini API does not mean that audio is processed entirely on your device or that provider-side retention is zero.
Storage and retention
The extension uses Chrome's local extension storage for account information, session information, device identifiers, usage snapshots and cached transcripts indexed by message identifiers or audio hashes.
The application database stores account, authentication, transcription, usage and billing records. These records, including transcript text, do not currently have a scheduled automatic deletion period in the application. Expiration of an authentication code or session prevents further use of it; expiration does not itself erase its database record.
The transcription route processes audio in memory and sends it to Gemini; it does not write original audio files into the application database. This describes the application's storage behavior and does not override processing providers' retention terms.
Signing out clears local session and usage information but does not erase all cached transcripts or server records. Removing the extension removes its local extension data; it does not delete account or transcription records already held by the service. You can request review and deletion of server-side personal data by emailing naotho@itbusiness.com.br. Such requests require verification of account ownership, and some billing or security records may need to be retained for applicable obligations.
Restricted use of data
The service's handling of data complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Data is not sold, used for behavioral advertising, used for credit or lending decisions, or transferred for purposes unrelated to the extension's disclosed functions. Transfers are limited to permitted cases such as providing the service, protecting security or complying with applicable obligations.
Access to personal content by an operator is restricted to permitted cases. The existence of an administrative interface does not authorize unrelated reading, sharing or reuse of transcripts.
Contact and data requests
For privacy questions, corrections or requests to delete your personal data, contact Naotho Machida at naotho@itbusiness.com.br. Include the phone number associated with your account so we can identify the relevant records and verify ownership. Do not send passwords, authentication codes or payment card details by email.