heyv16

For iPhone, iPad + Mac

The fine print, written to be read

Privacy Policy.

Effective July 18, 2026 · Perfroute Inc. · contact@heyv16.com

01 · Who we are

heyv16 is made and operated by Perfroute Inc., a company incorporated in Delaware, United States (“Perfroute,” “we,” “us”). Perfroute is the data controller for the processing described here. For anything in this policy, write to contact@heyv16.com.

heyv16 does one thing: it records what you say, transcribes it, cleans it up, and gives you the text. This policy describes exactly what that involves — no more, no less.

02 · No profile or password

heyv16 has no sign-up form. We do not ask for your name, email address, or phone number. Each installation creates a random identifier and a device-bound key. If you turn on Saved, an Apple passkey creates an opaque heyv16 account so your encrypted history can appear on your approved Apple devices. To us, these are random technical identifiers, not a profile about you.

We use Apple App Attest on supported iOS devices and DeviceCheck or a device-bound signing key where appropriate, plus short-lived service tokens, to verify legitimate installations and protect the service from abuse. Apple and Cloudflare process the technical data required to provide those protections.

03 · The default: nothing is saved

Out of the box, saving is off. In this mode each dictation is processed transiently: your audio is transcribed and cleaned to produce your text, the text is returned to your device, and we store no audio, transcript, or cleaned text in heyv16 history. Providers may retain limited request metadata for security and operations under their published terms. The recorder shows “Not saved,” which refers to heyv16 content storage.

A per-recording Incognito option does the same for a single dictation even when saving is on. Incognito recordings are never stored, synced, or indexed.

Recordings that have not been processed yet (for example while you are offline) exist only on your device until processing succeeds.

04 · If you turn saving on

When Saved is available, you can optionally turn on Saved. After transient processing, your device encrypts the raw transcript and clean text before uploading the saved copy. Original audio remains on your device. A passkey links the same anonymous Saved account across your Apple devices; there is no app password.

  • D1 stores ciphertext, not readable transcript text. The content key remains in your Apple Keychain and is not available to our staff or support tooling.
  • It is used for exactly one purpose: showing your notes back to you. We do not read it, analyze it for marketing, advertise with it, sell it, share it, or use it to train AI models. There are no exceptions to this.

Because the Worker and the disclosed AI providers see plaintext transiently to transcribe and clean it, we do not claim end-to-end encryption for processing. The exact promise is narrower: client-encrypted Saved history at rest.

05 · How your audio becomes text

In Automatic mode, eligible stages may run on your Apple device. For cloud transcription, audio chunks go through our Cloudflare Worker to Google Cloud Speech-to-Text V2 using Chirp 3. The resulting transcript goes to Cloudflare Workers AI, which runs Llama 3.1 to create the cleaned text. Meta does not directly receive your text. You approve this flow in the app before the first cloud-processed recording.

On device only never sends audio or transcript content to these providers. If a required local model is unavailable, your recording waits safely instead of silently falling back to cloud processing.

06 · AI provider matrix

This table is the plain-English production matrix that drives the app’s consent copy. We re-check it before each release and require new consent before a material recipient change.

Apple on-device models

Enabled when available
Data sent
Eligible on-device transcription and cleanup.
heyv16 storage
Audio and text stay on the Apple device for AI processing.
Provider posture
No content is sent to heyv16, Google, Cloudflare, or Meta for these stages.

Google Cloud Speech-to-Text V2 · Chirp 3

Enabled
Data sent
Audio chunks for transcription.
heyv16 storage
Not saved and Incognito audio is sent through the Worker and is not written by heyv16 to D1, R2, Vectorize, or Google Cloud Storage.
Provider posture
Google documents synchronous audio as processed in memory without storing customer content. Its Cloud terms prohibit model training on Customer Data without prior permission or instruction; limited request metadata may be logged for service operation and abuse prevention.

Cloudflare Workers AI · Llama 3.1

Enabled · Built with Llama
Data sent
Raw transcript cleanup, More literal, and explicit Reduce.
heyv16 storage
Not saved and Incognito requests are not written to heyv16 storage. Saved text may persist only as client-encrypted history.
Provider posture
Cloudflare says it does not use Workers AI customer content to train models or improve its or third-party services without explicit consent. Cloudflare runs the Llama model; Meta does not receive the transcript from heyv16.

We never put audio or transcript content in logs, analytics, crash reports, notifications, or provider-selection metadata. Provider and model names are operational facts, not everyday settings.

07 · What we measure

We use content-free operational facts such as request timing, failure stage, and retry state to operate the service. Production Worker logs and traces are disabled. Provider and infrastructure systems may process limited request metadata such as time, size, network address, authentication details, and security signals to deliver and protect the service. We never put audio or transcript content in analytics, crash reports, notifications, or application logs. The apps contain no advertising or tracking SDKs, and we do not track you across apps or websites.

08 · Export and deletion

Export: you can export the data available in the app, including encrypted-history text after local decryption and any local recovery audio the app still keeps, at any time.

Delete: deleting a single note removes it everywhere — storage, sync, and any derived index. “Delete everything” wipes all of your content from our active systems immediately, invalidates your identifier, and issues a fresh one; encrypted disaster-recovery backups expire within a maximum of 30 days. There is no account to “deactivate” — deletion is the end of the relationship.

09 · Your rights

Depending on where you live (including the EU/UK under GDPR, Brazil under LGPD, and various US states), you have rights to access, correct, export, delete, and restrict processing of your data. The app’s export and delete controls exercise the main ones directly, without asking us. For anything else — or if you have no device access anymore — email contact@heyv16.com and we will respond within the timelines required by applicable law. We do not discriminate against you for exercising any right. We do not sell or share personal information as those terms are defined in US state privacy laws.

Legal bases where required: performance of a contract (turning your speech into text), your consent (cloud provider processing and Saved history), and legitimate interests (abuse prevention and content-free service operation).

10 · Where data is processed

Our servers run on global edge infrastructure, and AI providers may process content in the United States. Where required, transfers are protected by recognized safeguards such as standard contractual clauses.

11 · Children

heyv16 is not directed at children under 13, and we do not knowingly process their data. If you believe a child under 13 has used the service, contact us and we will delete the associated data.

12 · Changes

If we change this policy, we will update the effective date above and, for material changes, tell you in the app before they take effect. We will never weaken the core commitments — no ads, no data sales, no sharing, no training on your content, delete means delete — without asking for your explicit consent first.