---
title: "voice-lock Privacy Policy | WISP"
description: "Privacy policy for the call recording encryption app voice-lock: what the server receives and does not receive, permissions, retention periods, outsourcing of processing, and how to delete data."
url: https://www.j2w2.org/voicelock-privacy.html
lang: ko
---

voice-lock

# Privacy Policy

This document describes what information the call recording encryption app "voice-lock" (package name org.j2w2.voicelock) handles and how. This English version is provided for convenience; if it differs from the Korean version, the Korean version prevails.

[Terms of Service](https://www.j2w2.org/en/voicelock-terms.md) [Privacy Policy](https://www.j2w2.org/en/voicelock-privacy.md) [Account and Data Deletion](https://www.j2w2.org/en/voicelock-account-deletion.md)

**Service** voice-lock **Package name** org.j2w2.voicelock **Developed and operated by** WISP **Effective date** October 4, 2026

**Summary —** voice-lock encrypts call recordings **on the device** with the user's password. Only **ciphertext that even the Company cannot open** goes to the server; the password, recovery code, encryption keys, audio, phone numbers and exact call times are not sent to the server. In local mode, used without logging in, no account information at all is sent to the server. No ad SDK or analytics tools are included.

## Article 1 (General Provisions)

WISP (the "Company") processes users' personal information in the Android application "voice-lock" (the "Service"), which the Company develops and operates, and uses this policy to inform users of the items processed, the purposes, the retention periods and users' rights. The Service is an Android app distributed only through Google Play and is not offered as a web or Toss mini app.

## Article 2 (Categories of Information the Service Handles)

The information the Service handles is divided into **information that stays only on the device** and **information sent to the server**. The Service is designed so that device-only information is never sent to the server.

| Information that stays only on the device (not sent to the server) |
|---|
| Call recording audio (plaintext), original file names and paths, the other party's phone number, exact call time and call duration |
| Master password, the 24-word recovery code, and all encryption keys used for decryption |
| The recording list database, device copies of encrypted recording files, and access permission to the recording folder the user selected |

Information shown in the recording list, such as names and dates, is created **in encrypted form** within the scope the user selects (information-in-title levels 1 to 4), and even when cloud sync is on, it is uploaded to the server only as ciphertext.

## Article 3 (Information Sent to the Server and Purposes)

The information below is sent to and stored on the server **only when the user turns on cloud sync with a Google account**. In local mode, no account is created on the server.

| Item | Details | Purpose of collection |
|---|---|---|
| Google account email | The email address verified by Google (stored as the login ID) | Identifying the cloud account; login |
| Authentication values | **Hashes** of the authentication values derived separately from the password and the recovery code (not the password or recovery code itself) | Identity verification; re-verification when deleting the account |
| Encrypted key envelope | The vault key wrapped with the password and recovery code, the public key and signatures | Used to open the vault with the password on another device (the server cannot unwrap it) |
| Encrypted recordings | Encrypted audio files, encrypted headers, encrypted list display information | Sync between devices, streaming playback, backup |
| Recording metadata | Recording date (year-month-day), file size, number of chunks, integrity hash, upload and modification times, deletion status | List sorting, sync, upload integrity checks, trash |
| Device information | Device identifier created by the app, Android version, last access time | Showing the device list, removing devices, keeping you logged in |
| Subscription information | Google Play purchase token (in encrypted and hashed form), product ID, expiry date, subscription status | Verifying the subscription; determining whether to provide cloud features |
| Access logs | Type and time of action, and a value converted (HMAC) so that the IP address cannot be restored | Detecting unauthorized access; security auditing |

Name, date of birth, phone number, address and payment method information are **not collected.** Payments are processed by Google Play, and the Company does not receive card information. The Service contains no ad SDK, no advertising ID (AAID), and no analytics or crash reporting tools.

## Article 4 (App Permissions)

| Permission | Purpose of use |
|---|---|
| Phone state | To know when a call has ended so the recording folder can be checked. It does not read call content or numbers. |
| Notifications | To notify processing results and when the free limit is reached |
| Foreground service | For a short task that checks the recording folder for a few seconds right after a call |
| Exemption from battery optimization | So that recording detection does not stop in the background |
| Receive boot completed | To re-register the periodic check task after a reboot or update |
| Biometric authentication | Unlocking the recording list (not used for playback) |
| Internet · network state | Cloud sync, Wi-Fi-only upload option |
| Billing | Google Play subscription |

The app does not request all-files storage access, microphone or contacts permissions. For recording files, it accesses **only the one folder** the user selects in the system folder picker. App data is excluded from device backup and device-to-device transfer.

## Article 5 (Retention and Use Period of Personal Information)

| Category | Retention period |
|---|---|
| Account information · key envelope · device list | Until the account is deleted |
| Encrypted recordings and metadata | Until the user deletes them or deletes the account. If the subscription has ended, the cloud copies are kept for 60 days (Standard) or 180 days (Premium), based on the plan at the time it ended, and then deleted |
| Incomplete uploads | Deleted after 48 hours |
| Login session token | Up to 30 days |
| Access logs | 90 days |

When you delete your account, your server account and the encrypted recordings you uploaded are deleted together without delay. How to delete is described on the [Account and Data Deletion](https://www.j2w2.org/en/voicelock-account-deletion.md) page.

## Article 6 (Provision to Third Parties)

The Company **does not sell users' personal information and does not provide it to third parties for advertising purposes.** It does not provide it externally except where there is a lawful request under applicable laws. However, because recordings on the server are ciphertext, the Company cannot decrypt and provide their content in response to any request.

## Article 7 (Outsourcing of Processing)

The infrastructure of the following providers is used to operate the Service. Each provider's processing policies also apply.

| Processor | Outsourced task |
|---|---|
| Google Cloud Platform | Operating the server (Cloud Run, Seoul region), encrypted recording storage (Cloud Storage), scheduled cleanup jobs |
| Company-operated database | Storing account information, key envelopes and recording metadata (in Korea, accessed only through a Cloudflare tunnel) |
| Cloudflare | Secure tunnel between the server and the database |
| Google Sign-In | Cloud account authentication |
| Google Play | App distribution, subscription billing and subscription status checks |

## Article 8 (User Rights and How to Exercise Them)

- **Access** — You can check the recording list, device list and subscription status directly in the app.

- **Deletion** — Recordings can be deleted individually, and Settings (설정) > **Delete account (계정 탈퇴)** deletes your server account and all recordings you uploaded.

- **Suspension of processing** — Cloud uploads can be turned off in Settings, and in local mode nothing is sent to the server. You can also remove other devices from the device list.

- **Export** — While subscribed, you can export recordings as original files to a location you choose. Exported files are not encrypted.

## Article 9 (Children's Personal Information)

The Service is not intended for children under 14 and does not knowingly collect children's personal information. If the Company learns that information of a user under 14 has been collected, it deletes that information without delay.

## Article 10 (Security Measures)

- Recordings are encrypted on the device with AES-256-GCM, and the encryption keys are wrapped so that they can be unwrapped only with the user's password (Argon2id) and recovery code.

- Original recordings are deleted only after the ciphertext is decrypted again and confirmed to match the original.

- Decrypted audio is kept only in memory during playback and is not cached to disk.

- App logs use structured logging that accepts only predefined values, so that phone numbers, file names, paths and keys are not recorded.

- Communication between the app and the server is encrypted with HTTPS, and the connection between the server and the database is not exposed to the public internet but goes only through a Cloudflare tunnel.

- Encrypted recordings are kept in private storage, and the server stores only hashes of the authentication values derived from the password.

## Article 11 (Changes to This Policy)

If the contents of this policy change, the changes and the effective date will be posted on this page. For changes that add collected items or purposes of use, the policy is revised before the relevant feature is released.

## Article 12 (Contact)

Please send inquiries about the processing of personal information and deletion requests to the contact below.

- Contact: WISP Privacy Officer

- Email: [nathak@j2w2.org](mailto:nathak@j2w2.org)

- Reply: within 7 business days

If you need counseling or want to report an infringement of personal information, you can contact the Personal Information Infringement Report Center (privacy.kisa.or.kr, 118 with no area code), the Supreme Prosecutors' Office Cyber Investigation Division (spo.go.kr, 1301), or the Korean National Police Agency Cyber Investigation Bureau (ecrm.police.go.kr, 182).

## Revision history

| Effective date | Changes |
|---|---|
| October 4, 2026 | Article 5 — retention of encrypted cloud copies after a subscription ends now depends on the plan (Standard 60 days, Premium 180 days) |
| September 26, 2026 | First enacted |

[Back to app info](https://www.j2w2.org/en/project-voicelock.md) [Terms of Service](https://www.j2w2.org/en/voicelock-terms.md) [Account and Data Deletion](https://www.j2w2.org/en/voicelock-account-deletion.md)
