Voxter mobile app

Mobile App Privacy Policy

This Privacy Policy explains how we collect, use, store, disclose, and otherwise process personal data when individuals access or use our website, mobile applications, and related services.

Last updated: May 13, 2026

This policy covers the Voxter mobile application. The separate privacy notice for the voxter.eu website and the waitlist is available .

This policy is published in English. The official Bulgarian translation is being prepared and will replace this notice once available.

Welcome to VOXTER (“Platform”, “we”, “our”, or “us”).

We are committed to protecting the privacy and security of our users and handling personal data transparently and in accordance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”).

The policy applies to all individuals whose personal data may be processed in connection with the use of the Platform, including registered users, visitors, and other individuals interacting with us.

The purpose of this document is to provide clear and transparent information regarding:

  • what personal data we collect;
  • how and why we use it;
  • the legal bases relied upon for processing;
  • how personal data may be shared;
  • how long data is retained;
  • what rights users have under applicable law;
  • and how users may contact us regarding privacy-related matters.

By accessing or using the Platform, users acknowledge that they have read and understood this Privacy Policy.

If you do not agree with this Privacy Policy, please discontinue the use of the Platform.

Section 1

Who We Are

The Platform is operated by VOXTER Ltd., a company duly incorporated and existing under the laws of the Republic of Bulgaria, with registered address at 1463 Sofia, 146 Vitosha blvd., body B, 6fl. (“Company”, “we”, “our”, or “us”).

For the purposes of applicable data protection legislation, including the GDPR, the Company acts as the data controller in relation to the personal data processed through the Platform, except where expressly stated otherwise.

The Company determines the purposes and means of processing personal data in connection with the operation, maintenance, administration, and security of the Platform and related services.

If you have any questions regarding this Privacy Policy or the processing of personal data, you may contact us using the following contact details:

Section 2

Definitions

For the purposes of this Privacy Policy, the following terms shall have the meanings set out below:

“Platform” means the mobile applications, infrastructure, functionalities, content-sharing features, and related services operated by the Company.

“Personal Data” means any information relating to an identified or identifiable natural person within the meaning of the GDPR.

“Processing” means any operation or set of operations performed on Personal Data, whether by automated means or otherwise, including collection, recording, storage, organisation, structuring, use, disclosure, transmission, restriction, deletion, or destruction.

“Data Subject” means the individual to whom the Personal Data relates.

“Controller” means the entity which determines the purposes and means of the processing of Personal Data.

“Processor” means a third-party processing Personal Data on behalf of the Controller.

“User” means any individual accessing, browsing, registering with, or otherwise using the Platform.

“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

“Third-Party Services” means external providers, platforms, infrastructure providers, authentication providers, analytics providers, payment providers, or other partners used in connection with the operation of the Platform.

Section 3

What Personal Data We Collect

The categories of Personal Data processed depend on how users interact with the Platform, the functionalities used, and the information voluntarily provided by users.

The Company may collect and process the following categories of Personal Data:

3.1 Account Registration Data

When users create an account on the Platform, the following information may be collected:

  • email address;
  • password credentials;
  • confirmation of minimum age requirements;
  • confirmation of acceptance of the Terms and Conditions;
  • country or region information.

3.2 Profile and User Information

Users may voluntarily provide additional profile-related information, including:

  • nickname or username;
  • biography or profile description;
  • profile picture or avatar;
  • other information voluntarily uploaded or displayed within the user profile.

Certain profile information may be publicly visible to other users depending on the Platform’s functionality and user settings.

3.3 Authentication and Login Data

Where users authenticate through third-party providers or integrated authentication services, the Company may process:

  • third-party authentication identifiers;
  • Google account identifiers;
  • Apple Sign-In identifiers;
  • authentication tokens;
  • account verification status;

The Company does not receive or store passwords associated with third-party authentication providers such as Google or Apple.

3.4 User-Generated Content

The Platform may allow users to upload, publish, create, transmit, or otherwise make available content through the Services.

Such data may include:

  • video files;
  • images;
  • captions and descriptions;
  • comments and submissions;
  • metadata associated with uploaded content;
  • content categorisation or positioning information;
  • content duration and technical characteristics.

Uploaded content may be stored, displayed, processed, moderated, cached, or distributed through content delivery infrastructure in accordance with the operation of the Platform.

3.5 Platform Interaction Data

The Company may collect information relating to user interaction with the Platform and other users, including:

  • votes, reactions, and engagement data;
  • viewed content and interaction history;
  • participation in polls, rankings, or community features;
  • reports submitted regarding content or users;
  • community or follower-related interactions;
  • rewards, points, achievements, or similar activity records.

Such information may be used for platform functionality, moderation, analytics, personalisation, fraud prevention, and service improvement purposes.

3.6 Subscription and Transaction Data

Where subscription features, premium functionalities, or purchases are available, the Company may process:

  • subscription status;
  • entitlement identifiers;
  • transaction identifiers;
  • payment platform information;
  • subscription periods and renewal status;
  • purchase history related to the Platform.

Payment card information is not stored by the Company, where payments are processed entirely by third-party payment providers or app store operators.

3.7 Administrative and Moderation Data

In order to maintain platform integrity, safety, and compliance, the Company may process:

  • audit logs;
  • moderation actions;
  • enforcement records;
  • reports and investigation data;
  • suspension or restriction history;
  • communications relating to violations of platform rules or policies.

3.8 Technical and Device Information

When users access or use the Platform, certain technical information may be collected automatically, including:

  • IP address;
  • device identifiers;
  • browser type and operating system;
  • authentication tokens;
  • infrastructure and server logs;
  • security and fraud-prevention data.

Certain technical information may be processed through caching systems, security systems, monitoring tools, and cloud infrastructure providers.

3.9 Communication Data

Where users communicate with the Company or interact with support channels, the Company may process:

  • support requests;
  • email correspondence;
  • user inquiries;
  • feedback submissions;
  • reports or complaints;
  • communication preferences.

3.10 Automated Technologies and Platform Features

In connection with the operation, moderation, security, and functionality of the Platform, certain categories of Personal Data may additionally be processed through automated technologies or advanced platform features, including:

  • AI-assisted moderation tools;
  • automatic subtitle generation;
  • voice or audio processing;
  • content classification and safety review;
  • advertising or marketing integrations;
  • social or community functionalities;
  • verification, anti-abuse, and trust and safety mechanisms.
Section 4

How We Use Personal Data

Personal Data is processed only to the extent necessary for the operation, administration, security, improvement, and lawful provision of the Platform.

Depending on the nature of the interaction with the Platform, Personal Data may be used for purposes including:

  • creating and managing user accounts;
  • authenticating users and maintaining Platform security;
  • providing access to Platform functionalities and community features;
  • hosting, displaying, moderating, and managing user-generated content;
  • communicating with users regarding accounts, support requests, updates, or security matters;
  • preventing fraud, abuse, spam, unauthorised activity, or violations of the Terms and Conditions;
  • maintaining the safety, integrity, and technical functionality of the Platform;
  • analysing usage, improving performance, and developing new features or functionalities;
  • managing subscriptions, purchases, and related transactions;
  • complying with applicable legal and regulatory obligations;
  • establishing, exercising, or defending legal claims;
  • and operating automated or AI-assisted functionalities, including moderation, content analysis, subtitle generation, and safety-related tools.

Where appropriate, aggregated, anonymised, or de-identified information may be used for analytical and operational purposes.

Certain processing activities may involve automated technologies or third-party service providers in connection with the operation and improvement of the Platform.

Section 5

Legal Bases for Processing

The Company processes Personal Data only where a valid legal basis exists under applicable data protection legislation, including Article 6 of the GDPR.

Depending on the specific processing activity and the nature of the interaction with the Platform, Personal Data may be processed on one or more of the following legal bases:

5.1 Performance of a Contract

Personal Data may be processed where such processing is necessary for:

  • the creation and administration of user accounts;
  • the provision of access to the Platform and its functionalities;
  • the performance of obligations arising under the Terms and Conditions;
  • the delivery of requested services or features;
  • subscription and account management;
  • responding to user requests connected to the use of the Platform.

Without such processing, certain functionalities or services may not be available.

5.2 Legitimate Interests

Personal Data may be processed where necessary for the legitimate interests pursued by the Company or by a third party, provided that such interests are not overridden by the rights and freedoms of users.

Such legitimate interests may include:

  • maintaining and improving the Platform;
  • ensuring platform security and infrastructure stability;
  • preventing fraud, abuse, spam, and unauthorised activity;
  • enforcing the Terms and Conditions and internal policies;
  • conducting internal analytics and operational reporting;
  • protecting the rights, property, and safety of the Company, users, or third parties;
  • moderating content and maintaining community integrity;
  • developing new functionalities and improving user experience.

Where processing is based on legitimate interests, the Company seeks to ensure that such processing remains proportionate and respects the rights and expectations of users.

5.3 Compliance with Legal Obligations

Personal Data may be processed where necessary for compliance with applicable legal or regulatory obligations, including obligations relating to:

  • applicable data protection laws;
  • court orders or lawful governmental requests;
  • legal reporting obligations;
  • enforcement of legal rights;
  • cooperation with competent authorities;
  • prevention of unlawful activity.

5.4 Consent

Where required under applicable law, Personal Data may be processed on the basis of the user’s consent.

Consent may be relied upon, for example, in connection with:

  • optional functionalities;
  • marketing communications where legally required;
  • future AI-based or advertising-related features;
  • processing activities that require consent under applicable law.

Users may withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to such withdrawal.

Section 6

Data Storage

Personal Data is primarily stored and processed within the European Union and the European Economic Area (“EEA”).

In certain circumstances, some Personal Data may be transferred to or processed in countries outside the EEA in connection with the provision of the Platform, the use of third-party service providers, or technical infrastructure supporting the Services.

Where such transfers occur, the Company implements appropriate safeguards in accordance with applicable data protection laws in order to ensure an adequate level of protection for Personal Data.

Section 7

Third-Party Services

The Company may engage third-party service providers, contractors, partners, and technical infrastructure providers in connection with the operation, maintenance, security, and improvement of the Platform.

Depending on the nature of the Services, Personal Data may be processed by categories of providers such as:

  • cloud hosting and infrastructure providers;
  • authentication and account verification providers;
  • content delivery and storage providers;
  • analytics and monitoring providers;
  • payment and subscription management providers;
  • security and fraud-prevention providers;
  • moderation, AI, or automated processing providers.

Such third parties process Personal Data only where necessary for the provision of their services and subject to applicable contractual, confidentiality, and data protection obligations.

Where required under applicable law, appropriate safeguards are implemented in relation to any international transfer of Personal Data.

Section 8

Data Retention

Personal Data is retained only for as long as necessary to fulfill the purposes for which it was collected and processed, including for the provision and operation of the Platform, compliance with legal obligations, resolution of disputes, enforcement of agreements, and protection of the legitimate interests of the Company.

The applicable retention period may vary depending on:

  • the nature of the Personal Data;
  • the purpose for which the data was collected;
  • legal, regulatory, contractual, or operational requirements;
  • security and fraud-prevention needs;
  • and the necessity to maintain accurate business and audit records.

Account-related information is generally retained for the duration of the user relationship with the Platform and for a reasonable period thereafter, where necessary for legitimate business, legal, regulatory, or security purposes.

User-generated content may remain available on the Platform until deleted by the user, removed in accordance with Platform policies, or otherwise deleted in accordance with internal retention procedures.

Certain technical information, logs, backups, and security records may be retained for limited periods where necessary for:

  • maintaining infrastructure stability and security;
  • preventing fraud or abuse;
  • investigating incidents or violations;
  • complying with legal obligations;
  • or protecting the rights and legitimate interests of the Company.

Where Personal Data is no longer required for the purposes for which it was collected, the Company will delete, anonymise, or securely dispose of such data, unless continued retention is required or permitted under applicable law.

Users may request deletion of their Personal Data in accordance with applicable law and the rights described in this Privacy Policy. Certain information may nevertheless be retained where necessary to comply with legal obligations, resolve disputes, enforce agreements, or protect legal rights.

Section 9

User Rights Under GDPR

Subject to applicable law, users may have certain rights in relation to the processing of their Personal Data under the GDPR and other applicable data protection legislation.

Depending on the circumstances, users may have the right to:

9.1 Right of Access

Users may request confirmation as to whether Personal Data concerning them is being processed and, where applicable, request access to such Personal Data and related information regarding the processing activities.

9.2 Right to Rectification

Users may request the correction of inaccurate Personal Data and the completion of incomplete Personal Data where appropriate.

9.3 Right to Erasure

Users may request the deletion of their Personal Data in certain circumstances, including where:

  • the Personal Data is no longer necessary for the purposes for which it was collected;
  • consent has been withdrawn, and no other legal basis applies;
  • the user objects to the processing, and no overriding legitimate grounds exist;
  • or the processing is unlawful.

This right is not absolute and may be subject to legal or regulatory retention obligations.

9.4 Right to Restriction of Processing

Users may request that the processing of their Personal Data be restricted in certain circumstances, including where the accuracy of the data is contested, or the processing is unlawful.

9.5 Right to Object

Where processing is based on legitimate interests, users may object to such processing on grounds relating to their particular situation.

Users may also object to the processing of Personal Data for direct marketing purposes at any time.

9.6 Right to Data Portability

Where applicable, users may request to receive certain Personal Data in a structured, commonly used, and machine-readable format and may request transmission of such data to another controller where technically feasible.

9.7 Right to Withdraw Consent

Where processing is based on consent, users may withdraw such consent at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.

9.8 Right to Lodge a Complaint

Users have the right to lodge a complaint with a competent supervisory authority if they believe that the processing of their Personal Data violates applicable data protection laws. In Bulgaria, the competent supervisory authority is the:

Users may also lodge a complaint with the supervisory authority in the EU Member State of their habitual residence, place of work, or the place of the alleged infringement, where applicable.

9.9 Exercising Rights

Requests relating to data protection rights may be submitted using the contact details provided in this Privacy Policy.

The Company may request additional information necessary to verify the identity of the requesting individual before responding to a request.

The Company reserves the right to refuse or limit requests where permitted under applicable law, including where requests are manifestly unfounded, excessive, or where the rights of others may be adversely affected.

Section 10

Security Measures

The Company implements appropriate technical and organisational measures designed to protect Personal Data against unauthorised or unlawful access, disclosure, alteration, loss, destruction, misuse, or other unauthorised processing.

Such measures are designed taking into account the nature of the Personal Data processed, the risks associated with the processing activities, the state of the art, implementation costs, and the nature, scope, context, and purposes of processing.

Security measures implemented by the Company may include:

  • access control mechanisms;
  • authentication and authorisation procedures;
  • encryption and secure communication protocols;
  • password hashing and credential protection measures;
  • infrastructure and network security protections;
  • logging and monitoring systems;
  • backup and recovery procedures;
  • security testing and vulnerability management;
  • internal access restrictions;
  • and measures designed to prevent unauthorised disclosure or misuse of Personal Data.

Access to Personal Data is limited to authorised personnel, contractors, and service providers who require such access for legitimate operational, technical, legal, or support purposes and who are subject to appropriate confidentiality obligations.

The Company also implements measures intended to detect, investigate, and respond to security incidents, unauthorised activity, or potential breaches affecting the Platform or Personal Data.

Section 11

Children and Minimum Age

The Platform is intended only for individuals who are at least 14 years of age.

The Company does not knowingly collect or process Personal Data from individuals under the age of 14. Users under the age of 14 are not permitted to create accounts, access, or use the Platform.

By registering for or using the Platform, users confirm that they meet the applicable minimum age requirement.

Where required under applicable law, the Company may implement additional age verification measures or require parental or guardian consent for certain users or jurisdictions.

If the Company becomes aware that Personal Data has been collected from a child under the applicable minimum age in violation of this Privacy Policy or applicable law, the Company may take appropriate measures, including:

  • suspending or terminating the relevant account;
  • deleting associated Personal Data;
  • and restricting further access to the Platform.

Parents or legal guardians who believe that a child may have provided Personal Data in violation of this section may contact the Company using the contact details provided in this Privacy Policy.

Section 12

User-Generated Content and Sensitive Information

The Platform may allow users to upload, publish, discuss, or interact with content expressing personal opinions, beliefs, or viewpoints, including content relating to political, social, cultural, or other potentially sensitive topics.

Users should avoid disclosing sensitive Personal Data or special categories of Personal Data about themselves or others unless they intentionally choose to do so and understand the potential visibility and consequences of such disclosure.

The Company does not intentionally request or require users to provide special categories of Personal Data within the meaning of applicable data protection laws.

The Company reserves the right to moderate, restrict, remove, or otherwise take action in relation to content that violates applicable law, the Terms and Conditions, or Platform policies.

Section 12

Automated Moderation and AI Features

The Company may use automated technologies, artificial intelligence systems, and other technical tools in connection with the operation, security, moderation, and improvement of the Platform.

Such technologies may be used for purposes including:

  • content moderation and safety review;
  • detection of spam, fraud, abuse, or prohibited activity;
  • identification of potentially unlawful or harmful content;
  • automated subtitle or transcription generation;
  • content classification and organisation;
  • technical analysis of uploaded content;
  • improving platform functionality and user experience.

Certain user-generated content, including video, audio, text, metadata, or related technical information, may be processed through automated systems for the purposes described above.

Automated tools are intended to support platform integrity, safety, moderation efficiency, and operational functionality. Where appropriate, moderation decisions may additionally involve human review.

The Company does not use automated decision-making processes intended to produce legal effects or similarly significant effects on users within the meaning of Article 22 GDPR, unless otherwise permitted under applicable law.

Section 13

Cookies

The mobile application does not use cookies or browser-storage equivalents; authentication and session management on mobile rely on bearer tokens stored locally on the user's device.

The voxter.eu landing page does not currently use cookies, analytics, or third-party tracking technologies.

If, in the future, additional web interfaces are introduced or analytics, marketing, or measurement technologies are added to the landing page, this Privacy Policy will be updated accordingly, and where required by applicable law, a consent mechanism will be presented to visitors.

Section 14

Changes to This Privacy Policy

The Company reserves the right to amend, update, or modify this Privacy Policy from time to time in order to reflect:

  • changes to the Platform or its functionalities;
  • changes in applicable laws or regulatory requirements;
  • operational, technical, or business developments;
  • or changes relating to the processing of Personal Data.

The updated version of the Privacy Policy will become effective upon publication on the Platform unless stated otherwise.

Where required under applicable law, users may be notified of material changes through the Platform, by email, or through other appropriate communication channels.

Continued access to or use of the Platform following the effective date of an updated Privacy Policy may constitute acknowledgement of the updated terms, to the extent permitted under applicable law.

Users are encouraged to review this Privacy Policy periodically.

Section 15

Contact

Questions, requests, or concerns relating to this Privacy Policy or the processing of Personal Data may be submitted using the contact details below:

Where applicable, requests relating to data protection rights may also be submitted through the Platform or designated support channels.