Last updated: 21 June 2026
The short version. whisperbridge translates a live conversation between two people, each speaking their own language, and can play the translation back in a clone of the speaker's own voice.
Your voice is biometric data. We only capture it, and only create a voice clone, after you explicitly opt in — and you can use captions-only mode with no voice cloning at all. Live call audio is processed in real time and not stored by us. You can delete your account and voice data at any time.
whisperbridge ("we", "us") provides a real-time voice-translation service. The data controller is Priyanshu Mittal, an individual based in Indore, Madhya Pradesh, India. For any privacy question or to exercise your rights, contact privacy@whisperbridge.app.
| Data | Why | Legal basis (EU/UK GDPR) |
|---|---|---|
| Account info — email address and login credentials | Create and secure your account; let you sign in | Performance of our contract with you |
| Voice audio — microphone input during a session | Transcribe and translate your speech in real time | Contract performance + your explicit consent (special-category biometric data — see §3) |
| Voice model / voiceprint — created if you choose voice cloning | Re-render your translated speech in your own voice | Your explicit consent (Art. 9(2)(a)) |
| Translated text & captions | Show captions and produce translated audio | Contract performance |
| Usage data — e.g. minutes of voice translation used | Enforce plan limits and prevent abuse | Contract performance / legitimate interests |
| Technical data — IP address, device/browser, essential cookies/local storage | Run the service, keep you signed in, keep it secure | Legitimate interests / consent for any non-essential cookies (see §7) |
Under EU and UK data-protection law, voice data is biometric personal data, and a voice model created from it is a special category of data with extra protection. Because of that:
To deliver translation in real time we rely on a few categories of specialist providers ("sub-processors"), each handling only what its task requires, under that provider's data-processing terms. A current list of the specific providers we use is available on request at privacy@whisperbridge.app.
| Category | Purpose | Where |
|---|---|---|
| Speech-to-text providers | Transcribe spoken audio into text | US & India |
| AI translation providers | Translate the transcribed text | US & India |
| Text-to-speech & voice-synthesis providers | Produce the translated audio, including your voice clone | US independently certified: SOC 2 Type 2 · GDPR · HIPAA · PCI DSS |
| Real-time audio transport | Carry audio between participants | Cloud |
| Cloud hosting & authentication | Run your account and store your data | Cloud — Singapore (ap-southeast-1) |
Your data is never used to train these providers' models — we configure each so your audio and text are used only to deliver your translation. We do not sell your personal data.
Our processing backend runs in India, our hosting is in Singapore, and several providers are in the United States, so your data may be transferred across borders. For these transfers we rely on the safeguards built into each provider's data-processing terms — principally the European Commission's Standard Contractual Clauses and, for UK data, the UK Addendum — together with the providers' own compliance certifications (such as SOC 2 and GDPR alignment). Where a provider offers additional safeguards, we use them.
Our retention and destruction policy for biometric voice data: we keep your voice model only while your account is active, and we permanently destroy it — from our systems and our voice-synthesis provider — when you delete your account. We don't retain voice models beyond the life of your account, and we use them only to reproduce your voice in translations.
Security. The limited data we do store — your account and the reference to your voice model — is held on managed cloud platforms that encrypt it in transit and at rest.
We use only what's needed to keep you signed in and remember your settings (stored in your browser's local storage). If we ever add non-essential or analytics cookies, we'll ask for your consent first via a banner — and you'll be able to refuse them as easily as accept them.
Depending on where you live (EU/UK GDPR, India's DPDP Act, US state laws such as California's CCPA/CPRA and Illinois' BIPA), you may have the right to access, correct, delete, export, or restrict your data, to withdraw consent, and to complain to a regulator. To exercise any of these, contact privacy@whisperbridge.app. We won't charge you or treat you differently for using these rights.
whisperbridge is not directed to children under 18, and we don't knowingly collect their data.
If we make material changes to this policy, we'll update the date above and, where appropriate, notify you in the app.