Privacy policy
Last updated: August 2026 | lioraflow.com
IN SHORT
Voice is not stored. Audio is translated in flight and is gone the moment it has been delivered: no recordings, no transcripts, no text of the translations, in any language and in none of our products. There is nothing to hand over, nothing that can leak and nothing that can be seized, because there is nothing.
In the messaging app, messages and files are stored, encrypted and with an expiry date, for one reason only: so they reach every one of a person's devices. There is a single period and it covers everything: fifteen days.
What else we keep is the account, what is needed to invoice it, and a count of how much was translated: seconds, sentences and characters. Numbers, which are what your invoice is made of and which say nothing about what was said.
And one thing almost nobody can say: the translation engine runs on our own machines and calls no third-party service. Your voice does not pass through any AI provider's cloud. That is why the list in section 6 is short.
1. WHO IS RESPONSIBLE
GEEK DEVOPS S.L. ("Liora Flow"), tax ID B40639494, registered office in Valencia, Spain.
Data protection contact: [email protected]
2. THREE DIFFERENT SITUATIONS
For your account, your billing and this website we are the data controller: we decide what is collected and why, and this policy explains it.
For the content that passes through the Service — the audio of your rooms and meetings, your users' messages and files — we are the processor and you are the controller. We handle it on your instructions. If you need the Article 28 processing agreement with the list of sub-processors, write to [email protected] and we will give it to you.
And in an on-premise deployment we are neither: the engine runs on the customer's hardware, the content never leaves their network and we see nothing. There is nothing there to entrust to us.
If you use an app carrying your organisation's brand, the policy that app shows you is theirs, and the controller towards you is them, not us.
3. WHAT WE COLLECT AND WHY
Account: your organisation's name, your email, your password (kept only as a hash, never as you typed it), the country you chose and the language you use the panel in. To provide the Service you asked for.
Billing: legal name, tax number, address and billing email. To issue the invoices the law requires us to issue.
Payment: handled by Stripe. Your card number never reaches us. We keep the identifier Stripe assigns to your organisation and, when a card is used, the fingerprint Stripe derives from it: it is not the number and cannot be turned back into it, it is a stable identifier that tells whether two accounts pay with the same card. We use it for two things and only two: so that nobody collects a referral reward for inviting themselves, and so that free trials are not chained with the same card under different emails.
Service usage: for each room and each day, how many seconds of speech there were, how many seconds of translated speech, how many sentences and how many characters. Numbers, and nothing more: see section 5.
File jobs: when you send us a recording, a document or a text to transcribe, translate or subtitle, we process that file to do the job you asked for, and its result so that you can download it. Nothing else: we do not read it, we do not analyse it and we do not use it for anything else.
In the app: profile — name, email, phone and photo, if you set them — contacts if you allow access to them, messages, files, meetings and calendar, and each device's identifier so we can send you notifications.
Location: only if somebody chooses to share it inside a message. The map is drawn in one of two ways and they are worth telling apart. When we request the image ourselves — which is what our map proxy does — the map service receives the coordinates and nothing else: not the network address and not the identity of whoever is reading the message. When the message carries the image as an address belonging to the map service itself, which the apps still accept for LocationIQ and for Google Maps, that image is requested by the device doing the reading, and in that request the map service does see its network address.
Connections: when a device joined or left a room and, if it was rejected, why. So you can tell whether your equipment is working. Deleted after fifteen days.
Web: if you accept analytics cookies, site usage statistics. If you do not accept them, nothing. The detail is in the Cookie Policy.
Support: what you write to us, for as long as it takes to deal with it and afterwards as a record of what was agreed.
4. ON WHAT BASIS
Providing the Service and maintaining your account: performance of the contract with you.
Invoicing and keeping accounts: legal tax and commercial obligations.
Keeping the Service secure, preventing abuse and pursuing unpaid bills: legitimate interest.
Analytics on this website: your consent, which you may withdraw at any time.
5. WHAT IS KEPT, WHAT IS NOT, AND FOR HOW LONG
What is never kept: voice. We do not record the audio we translate. This holds for rooms, for the integrations, for Microsoft Teams, for the app's calls and meetings and for the files you send us to process — there the audio is deleted the moment the job finishes, waiting for nothing — and it has no exceptions.
The transcript and the text of a room's translations are not kept either: they are delivered and they are gone.
What is kept, and only if you ask for it, is what you ordered. If you ask for a written record of a file, its result stays fifteen days in your folder so you can download it, and deletes itself: the document first, the row after. If you also ask for the summary, that text is kept encrypted and also for fifteen days.
One more thing about the summary, because it is the only part of this that can carry people's names: it carries them because somebody said them out loud in the meeting — "Jones is taking care of this" — not because we put them there. The transcript has no names anywhere: each voice is given a number, "speaker 0", "speaker 1", and the system does not know whose it is.
A finished record can be read by whoever administers that company's account, not only by whoever asked for it. Anybody outside the company is told it does not exist.
The record is emailed if you ask for that, and what remains of the sending is the row — which address, when, and whether it failed — never the text that was sent.
The summary is written by an engine of ours, on our own machines. It does not pass through any outside provider.
A written record of a live room works the same way, and it is switched on room by room: it comes off. Where it is on, the text of what was transcribed and translated is kept, with its timings and its voice attribution, because that is what the record is made of. Fifteen days, the same period as everything else, and the client can delete it sooner at any time.
Switching it on authorises nothing else: it trains no model, it is not analysed and it is not shared. Contributing material to improve the engine is a separate permission and has to be given separately.
A request to delete an account also leaves a record: the email address, what was asked and when. **That record does not expire, and that is deliberate**: it is the proof that we honoured the right to erasure, and proof with an expiry date stops being proof on the very day somebody asks. It is the only thing we keep with no time limit, and it holds nothing beyond that.
Crash reports from the apps. If the app closes on you, you can send us the report of what happened, and only if you switch it on: it comes off, and refusing costs you nothing. It goes to a system of ours, on our own machines, not to a third party's cloud. It carries the error type and the program trace, and it is cleaned before it leaves: no text of transcripts or translations, no room names, no participant names, no user identifier of yours. It does not record the screen. It is kept for ninety days and deletes itself.
What is kept, in the messaging app, encrypted and expiring automatically: fifteen days, and it covers everything. A message in a direct or group chat, a meeting's chat, an attached file, a message waiting for somebody who was not connected, and a meeting's record with its title and time: all five, fifteen days.
It is deliberately a single number. There used to be several, and that forces a promise written with exceptions, which is a promise nobody reads to the end. It also fixed something that never explained well: with different periods, long after what two people said to each other had been deleted, the line recording that they had spoken was still stored. With one period, they go together.
The clock starts when the message is sent, not from the last time anybody connected, and when the time is up it deletes itself: it does not depend on anyone remembering.
A meeting is counted differently, and reasonably so: its fifteen days start when the meeting ends, not when it was booked. Since a meeting can be booked up to forty-five days ahead, its record exists from that moment. And there is a hard ceiling for any that never take place: ninety days after it was created it is deleted anyway.
And it is kept for one reason only: so a message reaches every one of a person's devices. Somebody who writes from the desktop and opens their phone two days later has to find it there.
Where the conversation is really kept is the local database on your phone and your computer, encrypted as well: delete the app and it goes with it.
What is left of a translation session is a count: seconds of speech, seconds of translated speech, number of sentences and number of characters. Those numbers are what your invoice is made of, and they say nothing about what was said.
Consent leaves a record, and it is worth saying exactly what. When you accept this document, the Terms or permission for us to write to you, a row is kept with who accepted, which document, in which language, whether they said yes, the date to the millisecond and your IP address. And, above all, the version: twelve characters of the cryptographic digest of the text that was on screen. Without that, "they accepted" does not hold up, because documents change. With it, the day somebody asks what they accepted, the answer is that text and not "whichever one was live back then".
The IP address there is evidence, not identity, and that is why it may be missing: when a signup is made from our own systems there is no honest address to record, and none is recorded. A made-up IP in a consent record is worse than no IP.
That row lasts as long as your account does, because it is what proves the permission for as long as the permission holds, and it is deleted with it.
We do not analyse any of this, we do not build profiles, and we do not use it to train any model, ours or anybody else's.
6. WHO ELSE SEES IT
Stripe, for payments and invoices.
Hetzner Online GmbH, which hosts the servers the Service runs on and where files are stored.
Our provider of machines with graphics cards, where the translation engine runs. We rent the hardware from them, not a translation service: they see no more of what runs inside than any hosting provider does.
Cloudflare, which protects and delivers this website and the panel.
Apple and Google, to deliver notifications to phones: they receive the device identifier and the notification, not the content.
Google, if you sign in with your Google account or if you accept analytics cookies.
LocationIQ, to draw the map of a shared location: when we request the image ourselves it receives the coordinates and nothing else.
Google Maps and LocationIQ, when the map image is requested directly by the device of whoever is reading the message: they then also receive its network address. This is the second path in section 3, and it does not happen when the map comes through our proxy.
Profesional Hosting, to deliver the emails the Service sends you.
Each one acts under a contract that limits it to what we ask of it, and we answer for them as for ourselves. None of them is an AI provider, because the engine calls none.
Microsoft, Zoom and the app stores are not on this list, and that is not an oversight: when you use those platforms, you engage them under your own contract with them, not under ours.
We do not sell your data to anybody, ever.
7. WHERE IT IS
The Service is provided within the European Economic Area, and that is the commitment. Within that area we move capacity from one data centre to another as needed, without that changing your protection or your rights; if your compliance file needs to know exactly where, ask us in writing and we will tell you.
There are three routes by which data leaves the Area: notifications to phones, which go through Apple and Google; payment, which goes through Stripe; and the network that protects this website. In all three cases under the European Commission's standard contractual clauses or a valid adequacy decision, and what travels is the minimum.
8. HOW LONG WE KEEP IT
Messages and files: fifteen days from when they are sent, as set out in section 5.
A meeting: fifteen days from when it ends, and at most ninety from when it was booked.
Your account, for as long as it exists, and afterwards whatever any legal obligation requires.
Invoices and what backs them, six years, as Article 30 of the Spanish Commercial Code requires.
The file you upload for a job, for as long as the job lasts: it is deleted the moment it finishes, and does not wait for any cleanup. Its result, fifteen days.
Communication metadata — who spoke with whom and when, taking part in a group call, devices and presence: for as long as the account exists, because it is what the service needs to work. It goes with the person the day they are deleted.
Connection events, fifteen days.
An unused invitation, fourteen days. An unconfirmed verification email, twenty-four hours.
A device that stops reporting, sixty days before it is treated as abandoned.
Usage figures, for as long as your account exists, because they are the history of what you were charged.
Support correspondence, three years.
9. YOUR RIGHTS
You can ask us for a copy of your data, to correct it, to delete it, to restrict its use or object to it, and to hand it to you or to somebody else in a portable format. Where we rely on your consent, you can withdraw it without affecting what was done before.
To delete your whole account there is a page of its own, which works without installing anything: lioraflow.com/delete-account. It sets out what gets deleted, what is kept by legal obligation, and how long it takes.
For anything else, write to [email protected]. We answer within one month.
If your account is managed by your organisation, talk to them too: they are the ones who decide about that account's content, and we can only help them respond to you.
If you believe we have got it wrong, you can complain to the Spanish Data Protection Agency (www.aepd.es) or to the authority in your country.
10. MINORS
The app is for people aged sixteen and over. Anyone younger needs the authorisation of whoever holds parental responsibility or guardianship.
Where a school or an institution distributes an app among minors, it is that institution that is responsible for holding those authorisations.
11. SECURITY
Passwords are stored hashed and cannot be recovered from what we hold, only replaced. The same goes for API keys: we keep their fingerprint, not the key, so a lost key is not recovered — it is revoked and another is issued.
All traffic is encrypted. The databases are encrypted: ours — where messages and files wait out their fifteen days — and the app's local one on the phone and the computer. Messages, attached files and configuration secrets are each encrypted with a different key, so compromising one does not open the others.
Deletion is automatic on expiry, not manual: it does not depend on anyone remembering. What gets logged is what was done, not what was said.
It is not end-to-end encryption and we do not call it that, for two reasons we would rather state: to translate, the audio has to be processed, so at that moment the engine hears it; and the messages waiting on our server are encrypted with our keys, not yours.
The panel is entered by account, with roles that limit what each person can do. Cards never reach our systems.
12. CHANGES
If we change this policy we will publish the new version here with its date, and if the change matters we will tell you by email.