← Back to SGH Voice

1. はじめに

本プライバシーポリシーは、新義豊株式会社(以下「当社」)が提供する「SGH Voice」アプリケーション(以下「本アプリ」)における個人情報の取扱いについて説明します。

最終更新日:2026年8月24日(モバイル版とダウンロード登録のプライバシー表示を更新)

2. 収集する情報

2.1 音声データ

本アプリは、マイクを使用して音声を録音します。この録音データは、音声認識(Speech-to-Text)処理のためにのみ使用されます。

  • iOS版の録音ファイルは端末の一時領域にのみ作成され、読み込み後、キャンセル時、またはアプリがバックグラウンドへ移行した時に削除されます。macOS版で音声バックアップを有効にした場合は10項をご確認ください。
  • 音声データは、選択された STT (Speech-to-Text) プロバイダー(OpenAI 音声認識 API / Groq 音声認識 API)にのみ送信されます。Android v2.7.2 では設定画面で実際のモデル ID を確認・選択できます。
  • LLM 後処理(Anthropic / OpenAI / Groq / OpenRouter / Ollama)には音声ではなく、文字起こし後のテキストのみが送信されます。
  • 当社のサーバーに音声データを保存することはありません。

2.2 API キー

ユーザーが入力した API キー(OpenAI / Anthropic / Groq / OpenRouter / ElevenLabs)は、端末内の保護領域に保存されます。iOS版はKeychain、Android版はEncryptedSharedPreferencesを使用します。macOS v2.4.0以降ではKeychainへの移行を進めており、それ以前のmacOS版では ~/.voice-input/config.json にファイルパーミッション600で保管されます。これらのキーが当社のサーバーに送信されることはありません。

2.3 辞書データ

カスタム辞書、候補頻度および短い修正ルールの保存先は端末内です。音声認識精度を高めるため、iOS版ではプリセット語彙、ユーザーが追加した語彙および選択中のシーンに関するプロンプトを、録音音声とともに選択されたSTTプロバイダー(OpenAIまたはGroq)へ送信します。Android版でも、プリセット語彙、ユーザーが追加した語彙および選択中のシーンに関するプロンプトを、録音音声とともに選択されたSTTプロバイダーへ送信します。短い修正ルールと候補頻度は送信せず、端末上で処理します。Android版はパスワード欄で音声入力と学習を無効にし、パーソナライズ禁止欄では学習だけを無効にします。Android版では、初回のクラウド処理前にこれらの送信内容をアプリ内で説明し、版管理された同意を取得します。

2.4 発話履歴

macOS版では、各回の音声認識結果と最終出力テキストを ~/.voice-input/history.json に保存し、Dashboardで参照・編集・削除できます。iOS版は発話履歴ファイルを作成せず、現在の結果を画面上に一時表示します。Android v2.7.2も完全な発話履歴ファイルを作成せず、個人化に必要な候補頻度と短い修正ルールのみを端末内に保持します。いずれも当社のサーバーには送信されません。

macOS版のスタイルプロファイル再生成は、直近最大100件を端末内で集計し、文章の長さ・句読点・言語混在等の特徴だけを保存します。本文を外部AIへ送信したり、プロファイルに原文を転載したりしません。端末内の診断レポートは内容プレビューを保存せずメタデータのみを記録します。自動トリアージレポートには、ユーザーが編集した短い修正候補が含まれる場合があります。

2.5 ウェブサイトでのダウンロード登録

Android または macOS 版をダウンロードする際、お名前またはニックネーム、メールアドレス、対象プラットフォーム、バージョン、表示言語および登録日時を収集します。これらはダウンロード状況の把握、重要な更新・セキュリティ情報等の必要なご連絡、お問い合わせ対応のために利用し、Google Firebase(Cloud Firestore)に保存します。

3. 情報の利用目的

  • 音声認識および文字起こし処理
  • AI による文章の後処理・校正
  • 繁体字中国語への変換
  • カスタム辞書による認識精度の向上
  • ダウンロード記録の管理および必要なご連絡

4. 第三者への提供

用途別に、ユーザーが選択した以下の第三者プロバイダーにデータを送信します:

  • STT (Speech-to-Text):OpenAI 音声認識 API / Groq 音声認識 API — 選択したモデルで音声を文字に変換。iOS版およびAndroid版では、認識精度向上用の辞書語彙とシーンプロンプトも送信
  • LLM 後処理:Anthropic / OpenAI / Groq / OpenRouter / Ollama(ローカル)— 文字起こし結果を整理・校正
  • OpenRouter はリクエスト毎に内部で複数のモデルプロバイダー(Meta / DeepSeek 等)にサブルーティングする場合があります。本アプリは送信先モデルをユーザーが選択できる仕様としており、各サブプロバイダーのプライバシーポリシーをご確認ください。

ダウンロード登録情報の保管には Google Firebase(Cloud Firestore)を利用します。各AIプロバイダーに送信したデータの保存期間と削除方法は、ユーザー自身のプロバイダー契約、アカウント設定および各社のプライバシーポリシーに従います。当社はユーザーのBYOKアカウント内にあるプロバイダー側のデータを直接削除できません。それ以外の第三者への情報提供は行いません。

  • OpenAI:APIデータは初期設定で学習に使用されません。Abuse monitoring logには送信内容が含まれる場合があり、通常は最長30日間保管されます。承認済みのZero Data RetentionまたはModified Abuse Monitoring設定では条件が異なります。
  • Groq:推論の入力・出力は初期設定では保管されません。ただし、サービス信頼性または不正利用調査のためのログが最長30日間一時保管される場合があります。Zero Data Retention設定では条件が異なります。
  • Anthropic:Messages APIの通常の会話内容は初期設定では保管されません。ただし、Claude Fable 5はCovered Modelとして30日間のデータ保持が必須で、Zero Data Retentionでは利用できません。

最新条件:OpenAI Data Controls / Groq Your Data / Anthropic API and Data Retention

連携対象は、各社の契約条件、プライバシーポリシーおよび適用法に基づき、本ポリシーと同等以上の保護を提供するプロバイダーに限定します。ユーザー固有の法人契約やアカウント設定により保護条件が異なる場合、ユーザーは送信前に当該条件を確認し、必要な保護を満たさないプロバイダーを選択しないでください。

5. マイクの使用について

本アプリは macOS / iOS / Android 各プラットフォームのマイク権限(NSMicrophoneUsageDescription / android.permission.RECORD_AUDIO)を使用します。この権限は、ユーザーがホットキー押下または録音ボタンを操作した時の音声録音にのみ使用されます。バックグラウンドでの録音は一切行いません。

6. データの保護

  • APIキーはiOSではKeychain、AndroidではEncryptedSharedPreferences、対応するmacOS版ではKeychainまたは権限を600に限定した設定ファイルに保存
  • すべての API 通信は HTTPS / TLS 1.2 以上で暗号化
  • 音声データは処理後に即座に削除(音声バックアップを有効化した場合を除く)
  • アプリ内の音声・文字・API キーは当社のサーバーへ送信されません(ウェブサイトで明示的に送信するダウンロード登録情報を除く)

7. 声紋(生体識別データ)

本アプリは任意機能として「声紋検証」を提供します。有効化すると、ユーザー本人の声から抽出した MFCC 特徴量(80次元の数値ベクトル)が端末内(~/.voice-input/voiceprint.npy)にのみ保存されます。当該データは個人情報保護法上の「要配慮個人情報」に該当する生体識別符号として取り扱い、外部に送信することは一切ありません。

v2.4.0 以降、声紋登録には明示的な同意(オプトイン)が必須となっており、同意なき自動登録は行いません。Dashboard からいつでも削除できます。

8. 過去発話の文脈送信(Few-shot 機能)

後処理 LLM に現在の発話を送信する際、文体や用語の一貫性を保つため、ユーザーの過去発話のうち直近最大3件(音声認識結果と最終結果のペア)を文脈として併せて送信できる機能を提供しています。

v2.4.0 から初期設定では無効(送信件数 0 件)となっており、Dashboard で明示的に有効化した場合のみ動作します。利用時は、過去の発話内容も LLM プロバイダーに送信される点にご留意ください。

9. 医療モード利用時の注意

医療モード(medical / medical_consultation)を有効にした場合、生成テキストには診療内容・症状・処方等の医療情報が含まれる可能性があります。これらは要配慮個人情報に該当します。

SGH Voice iOS版は、利用者と送信先AIプロバイダーとの間に医療情報処理に必要な契約(BAA / DPA等)が存在することを確認しません。適切な契約と組織内ルールがない限り、特定の患者を識別可能な情報を入力しないでください。ローカルLLM(Ollama)は対応するデスクトップ版でのみ選択できます。

10. 音声バックアップ

iOS版は音声バックアップ機能を提供せず、録音ファイルを一時領域から削除します。対応するデスクトップ版でユーザーがDashboardから「音声バックアップ先」を明示的に指定した場合のみ、WAVファイルが当該ディレクトリに保管されます。保管された音声の管理責任はユーザーに帰属します。当社のサーバーには送信されません。

11. イベントログ(観測用メタデータ)

~/.voice-input/events.jsonl に、認識成否、レイテンシ、フォアグラウンドアプリの bundle id 等のメタデータのみを記録します。発話内容や音声波形は記録しません。最大 50MB で自動ローテートし、当社のサーバーには送信されません。

フォアグラウンドアプリ識別を無効化したい場合は、Dashboard 設定の「App awareness」をオフにしてください(v2.4.0 から初期設定はオフ)。

12. 国外移転(個人情報保護法 第28条 / PIPL 第38条)

選択された API プロバイダーが米国等の日本国外で運用されている場合、当該プロバイダーの契約条件に基づき個人情報が国外移転されます。プロバイダー別の所在国は次の通りです:

  • OpenAI(米国)— STT および LLM
  • Anthropic(米国)— LLM のみ
  • Groq(米国)— STT および LLM
  • OpenRouter(米国・モデル毎にサブプロバイダー有)— LLM
  • Ollama(端末内ローカル処理のため国外移転なし)

本アプリをご利用される際は、当該国の法令に基づく保護水準をご確認ください。

13. 削除請求(消去権)

Dashboard 設定 →「すべてのローカルデータを削除」より、以下のローカルデータを一括削除できます:

  • 履歴(history.json
  • イベントログ(events.jsonl
  • カスタム辞書(dictionary.json
  • 声紋データ(voiceprint.npy
  • 音声バックアップ(audio_backup/ 配下の WAV ファイル)
  • 使用統計(stats.json
  • 診断・自動トリアージレポート(reports/auto_triage_report.md
  • 破損した履歴・設定の隔離コピー(該当する場合)

API キーは別途、Dashboard 設定画面より個別に削除できます。

iOS版では、設定画面の「APIキー・辞書・設定を消去」からKeychain内のAPIキー、カスタム辞書および端末内の設定を削除できます。アプリを削除した場合、iOSのアプリ領域にあるデータも削除されます。

ウェブサイトのダウンロード登録情報は、上記利用目的に必要な期間に限って保管し、不要となった情報を定期的に見直します。開示・訂正・削除をご希望の場合は、登録したメールアドレスを明記のうえ、下記窓口までご連絡ください。

AIプロバイダーへ送信済みのデータを削除する場合は、ユーザー自身のプロバイダーアカウントまたは各社の問い合わせ窓口からお手続きください。

14. お問い合わせ

プライバシーに関するご質問は、以下までお問い合わせください:

新義豊株式会社(Shingihou Co., Ltd.)
所在地:福岡県福岡市
メール:info@shingihou.com

1. 前言

本隱私權政策說明新義豊株式會社(以下簡稱「本公司」)所提供之「SGH Voice」應用程式(以下簡稱「本應用程式」)如何處理個人資訊。

最後更新:2026 年 8 月 24 日(更新行動版與下載登記的隱私說明)

2. 蒐集的資訊

2.1 語音資料

本應用程式使用麥克風錄製語音。該錄音資料僅用於語音辨識(Speech-to-Text)處理。

  • iOS 版只會在裝置暫存目錄建立錄音檔,讀取完成、取消錄音或 App 進入背景時即刪除。macOS 版若啟用音訊備份,請參閱第 10 項。
  • 語音資料僅傳送至所選之 STT (Speech-to-Text) 服務商(OpenAI 語音辨識 API / Groq 語音辨識 API)。Android v2.7.2 可在設定畫面確認並選擇實際 model ID。
  • LLM 後處理(Anthropic / OpenAI / Groq / OpenRouter / Ollama)收到的是文字轉譯結果,並非原始語音。
  • 本公司不會在伺服器上儲存任何語音資料。

2.2 API 金鑰

使用者輸入的 API 金鑰(OpenAI / Anthropic / Groq / OpenRouter / ElevenLabs)儲存於裝置內保護區域。iOS 版使用 Keychain,Android 版使用 EncryptedSharedPreferences;macOS v2.4.0 起逐步遷移至 Keychain,更早的 macOS 版本則以檔案權限 600 儲存於 ~/.voice-input/config.json。這些金鑰不會被傳送至本公司的伺服器。

2.3 詞庫資料

自訂詞庫、候選頻率及短修正規則儲存在裝置本機。為提高語音辨識正確率,iOS 版會將預載詞彙、使用者新增詞彙及所選場景提示,與錄音一起傳送至使用者選擇的 STT 服務商(OpenAI 或 Groq)。Android 版也會將預載詞彙、使用者新增詞彙及所選場景提示,與錄音一起傳送至所選 STT 服務商。短修正規則與候選頻率不會上傳,而是在裝置上處理。Android 版會在密碼欄位停用語音與學習,在禁止個人化欄位只停用學習。Android 版會在首次雲端處理前於 App 內說明上述傳送內容,並取得版本化同意。

2.4 發話歷史

macOS 版會將每次語音辨識結果與最終輸出文字儲存於 ~/.voice-input/history.json,可從 Dashboard 檢視、編輯、刪除。iOS 版不建立發話歷史檔案,只在目前畫面暫時顯示結果。Android v2.7.2 也不建立完整發話歷史檔案,只在裝置內保存個人化所需的候選頻率與短修正規則。上述資料皆不會傳送至本公司伺服器。

macOS 版重新生成風格 Profile 時,只會在裝置本機彙整最近最多 100 筆紀錄,並保存句長、標點及語言混用等整體特徵;不會將原文傳送給外部 AI,也不會在 Profile 內重現原文。本機健康報告不保存逐字稿預覽,只記錄後設資料;自動分類報告可能包含使用者已編輯的短修正候選。

2.5 網站下載登記

下載 Android 或 macOS 版本時,本公司會蒐集姓名或暱稱、Email、下載平台、版本、顯示語言及登記時間。資料用於掌握下載狀況、必要的版本或安全通知及回覆詢問,並儲存於 Google Firebase(Cloud Firestore)。

3. 資訊的使用目的

  • 語音辨識及逐字稿處理
  • AI 文字後處理與潤稿
  • 繁體中文轉換
  • 透過自訂詞庫提升辨識準確度
  • 管理下載紀錄及必要聯絡

4. 第三方資訊提供

依用途別,使用者所選之以下第三方服務商會接收對應資料:

  • STT (Speech-to-Text):OpenAI 語音辨識 API / Groq 語音辨識 API — 以所選模型將語音轉為文字;iOS 版與 Android 版也會傳送提升辨識率所需的詞庫詞彙及場景提示
  • LLM 後處理:Anthropic / OpenAI / Groq / OpenRouter / Ollama(本機)— 整理潤稿文字結果
  • OpenRouter 可能依請求動態路由至內部多個模型服務商(Meta / DeepSeek 等子服務商)。請另行確認各子服務商之隱私權政策。

下載登記資料使用 Google Firebase(Cloud Firestore)保存。送往 AI 服務商的資料,其保存期間與刪除方式依使用者本人的服務商契約、帳號設定及各公司隱私權政策辦理;本公司無法直接刪除使用者 BYOK 帳號內的服務商端資料。除此之外,本公司不會向其他第三方提供資訊。

  • OpenAI:API 資料預設不會用於訓練。Abuse monitoring logs 可能包含送出內容,一般最長保存 30 天;經核准的 Zero Data Retention 或 Modified Abuse Monitoring 設定適用不同條件。
  • Groq:推論輸入與輸出預設不保留,但因服務可靠性或疑似濫用調查所產生的紀錄可能暫存最長 30 天;Zero Data Retention 設定適用不同條件。
  • Anthropic:Messages API 的一般對話內容預設不保留;但 Claude Fable 5 屬於 Covered Model,必須保留資料 30 天,且無法在 Zero Data Retention 下使用。

最新條件:OpenAI Data Controls / Groq Your Data / Anthropic API and Data Retention

本服務僅整合依其契約條款、隱私權政策及適用法律提供與本政策相同或更高資料保護的服務商。若使用者本人的法人契約或帳號設定導致保護條件不同,使用者應在傳送前確認相關條件,且不得選擇未達必要保護水準的服務商。

5. 關於麥克風使用

本應用程式使用 macOS / iOS / Android 各平台之麥克風權限(NSMicrophoneUsageDescription / android.permission.RECORD_AUDIO)。此權限僅在使用者按下熱鍵或錄音按鈕時使用,不會進行任何背景錄音。

6. 資料保護

  • API 金鑰在 iOS 使用 Keychain、Android 使用 EncryptedSharedPreferences;支援的 macOS 版本使用 Keychain 或權限設為 600 的設定檔
  • 所有 API 通訊皆透過 HTTPS / TLS 1.2 以上加密
  • 語音資料處理後立即刪除(除非啟用音訊備份)
  • 應用程式內的語音、文字與 API 金鑰不會傳送至本公司伺服器(不含使用者在網站明示送出的下載登記資料)

7. 聲紋(生物特徵識別資料)

本應用程式提供可選之「聲紋驗證」功能。啟用後,從使用者本人聲音抽取的 MFCC 特徵(80 維數值向量)僅儲存於裝置內(~/.voice-input/voiceprint.npy)。該資料屬個人資料保護法上之「特種個人資料 / 生物特徵識別」,本公司不會以任何方式對外傳送。

v2.4.0 起,聲紋註冊必須經過明示同意(opt-in),不會自動註冊。可隨時於 Dashboard 刪除。

8. 過往發話的脈絡傳送(Few-shot 功能)

在傳送目前發話至後處理 LLM 時,為保持文體與用詞一致性,本應用程式提供將近期最多 3 筆過往發話(語音辨識結果與最終結果配對)作為脈絡一併傳送的功能。

v2.4.0 起預設為關閉(傳送 0 筆),僅在 Dashboard 明示啟用時才會運作。啟用時請留意,過往發話內容亦會傳送至 LLM 服務商。

9. 醫療模式使用注意

啟用醫療模式(medical / medical_consultation)時,生成文字可能包含診療內容、症狀、處方等醫療資訊。此屬特種個人資料。

SGH Voice iOS 版不會確認使用者與所選 AI 服務商之間是否具備醫療資訊處理所需的契約(例如 BAA / DPA)。若沒有適用契約與組織內規範,請勿輸入足以識別特定患者的資訊。本機 LLM(Ollama)僅可在支援的桌面版選用。

10. 音訊備份

iOS 版不提供音訊備份功能,錄音檔會從暫存目錄刪除。僅在支援的桌面版中,使用者於 Dashboard 明確指定「音訊備份位置」時,WAV 檔案才會保留於該目錄。所保存音訊的管理責任由使用者承擔。不會傳送至本公司伺服器。

11. 事件日誌(觀測用 Metadata)

~/.voice-input/events.jsonl 僅記錄辨識成功/失敗、延遲、前景應用之 bundle id 等後設資料不會記錄發話內容或音訊波形。最大 50MB 自動 rotate,不會傳送至本公司伺服器。

若欲關閉前景應用識別,可於 Dashboard 設定中將「App awareness」關閉(v2.4.0 起預設關閉)。

12. 跨境傳輸(個資法 / PIPL 第 38 條)

所選 API 服務商若於日本國外運作(如美國),則個人資料將依該服務商契約條款進行跨境傳輸。各服務商所在地如下:

  • OpenAI(美國)— STT 與 LLM
  • Anthropic(美國)— 僅 LLM
  • Groq(美國)— STT 與 LLM
  • OpenRouter(美國,依模型可能路由至各國子服務商)— LLM
  • Ollama(裝置內本機處理,無跨境傳輸)

使用本服務時,請確認所在國法令對應之保護水準。

13. 刪除請求(消去權)

於 Dashboard 設定 →「刪除所有本機資料」可一次刪除以下本機資料:

  • 歷史(history.json
  • 事件日誌(events.jsonl
  • 自訂詞庫(dictionary.json
  • 聲紋資料(voiceprint.npy
  • 音訊備份(audio_backup/ 內之 WAV 檔)
  • 使用統計(stats.json
  • 診斷與自動分類報告(reports/auto_triage_report.md
  • 損壞歷史或設定的隔離副本(如有)

API 金鑰可從 Dashboard 設定頁面個別刪除。

iOS 版可從設定畫面的「清除 API 金鑰、詞庫與偏好設定」刪除 Keychain 內的 API 金鑰、自訂詞庫與裝置內設定;刪除 App 時,iOS App 儲存區中的資料亦會移除。

網站下載登記資料只在上述使用目的所需期間保存,並定期檢視不再需要的資料。如欲查詢、更正或刪除,請於來信中註明登記時使用的 Email,並聯絡下方窗口。

如需刪除已傳送至 AI 服務商的資料,請由使用者本人的服務商帳號或各公司聯絡窗口辦理。

14. 聯絡方式

如有隱私權相關問題,請聯繫:

新義豊株式會社(Shingihou Co., Ltd.)
地址:日本福岡縣福岡市
Email:info@shingihou.com

1. Introduction

This Privacy Policy describes how Shingihou Co., Ltd. ("we", "us") handles personal information in the "SGH Voice" application ("the App").

Last Updated: August 24, 2026 (mobile and download-registration privacy disclosure update)

2. Information We Collect

2.1 Audio Data

The App uses the microphone to record audio. This recording data is used solely for speech-to-text processing.

  • On iOS, the recording file is created only in the temporary directory and is deleted after it is read, when recording is cancelled, or when the app enters the background. See Section 10 for optional audio backup on macOS.
  • Audio data is sent only to the selected STT (Speech-to-Text) provider (OpenAI Speech Recognition API / Groq Speech Recognition API). Android v2.7.2 shows and lets the user select the actual model ID in Settings.
  • LLM post-processing (Anthropic / OpenAI / Groq / OpenRouter / Ollama) receives only the transcribed text, not the audio.
  • We do not store any audio data on our servers.

2.2 API Keys

API keys entered by the user (OpenAI / Anthropic / Groq / OpenRouter / ElevenLabs) are stored in a protected location on the device. iOS uses Keychain and Android uses EncryptedSharedPreferences. Starting with v2.4.0, macOS gradually migrates to Keychain; earlier macOS versions store keys in ~/.voice-input/config.json with file permissions 600. These keys are never transmitted to our servers.

2.3 Dictionary Data

Custom dictionaries, candidate frequency, and short correction rules are stored on the device. To improve speech-recognition accuracy, the iOS version sends built-in vocabulary, user-added vocabulary, and the selected scene prompt to the selected STT provider (OpenAI or Groq) together with the recording. The Android version also sends built-in vocabulary, user-added vocabulary, and the selected scene prompt to the selected STT provider with the recording. Short correction rules and candidate frequency are processed on-device and are not sent. Android disables voice and learning in password fields, and disables learning only in no-personalization fields. Before the first cloud request, Android shows these data categories in the app and records versioned consent.

2.4 Transcription History

On macOS, each speech-recognition result and final output text is stored locally in ~/.voice-input/history.json and can be viewed, edited, and deleted from the Dashboard. The iOS version does not create an utterance-history file and displays the current result only in memory. Android v2.7.2 also does not create a complete dictation-history file; it stores only candidate frequency and short correction rules needed for personalization. None of these platforms send this local data to our servers.

On macOS, style-profile regeneration aggregates at most 100 recent entries locally and stores only broad traits such as sentence length, punctuation, and language mixing. It does not send source text to an external AI or reproduce source text in the profile. Local health reports store metadata without transcript previews. The local auto-triage report may contain short correction candidates from entries the user edited.

2.5 Website Download Registration

When you download the Android or macOS release, we collect your name or nickname, email address, target platform, version, display language, and registration time. We use this information to understand download activity, provide necessary release or security notices, and respond to inquiries. The records are stored in Google Firebase (Cloud Firestore).

3. How We Use Information

  • Speech recognition and transcription
  • AI-powered text post-processing and proofreading
  • Traditional Chinese character conversion
  • Improving recognition accuracy through custom dictionaries
  • Managing download records and necessary communications

4. Third-Party Sharing

Depending on the configured purpose, the following third-party providers receive data:

  • STT (Speech-to-Text): OpenAI Speech Recognition API / Groq Speech Recognition API — convert audio to text with the selected model; on iOS and Android, recognition vocabulary and the selected scene prompt are also sent
  • LLM post-processing: Anthropic / OpenAI / Groq / OpenRouter / Ollama (local) — clean up the transcribed text
  • OpenRouter may dynamically route requests to internal model sub-providers (Meta / DeepSeek, etc.). Please review each sub-provider's privacy policy.

Download registration records are stored using Google Firebase (Cloud Firestore). Retention and deletion of data sent to an AI provider are governed by the user's own provider agreement, account settings, and that provider's privacy policy. We cannot directly delete provider-side data held under a user's BYOK account. We do not share the information with other third parties.

  • OpenAI: API data is not used for training by default. Abuse-monitoring logs may include submitted content and are normally retained for up to 30 days; approved Zero Data Retention or Modified Abuse Monitoring settings apply different conditions.
  • Groq: Inference inputs and outputs are not retained by default, but logs for service reliability or suspected-abuse investigations may be retained temporarily for up to 30 days; Zero Data Retention settings apply different conditions.
  • Anthropic: Standard Messages API conversation content is not retained by default. However, Claude Fable 5 is a Covered Model that requires 30-day data retention and is not available under Zero Data Retention.

Current terms: OpenAI Data Controls / Groq Your Data / Anthropic API and Data Retention

We integrate only providers that, under their terms, privacy policies, and applicable law, provide the same or greater protection described in this policy. If a user's organization agreement or account settings result in different protections, the user must verify those terms before sending data and must not select a provider that does not meet the required level of protection.

5. Microphone Usage

The App uses each platform's microphone permission (NSMicrophoneUsageDescription on macOS/iOS, android.permission.RECORD_AUDIO on Android). This permission is used only when the user presses the hotkey or recording button. No background recording is performed.

6. Data Security

  • API keys are stored in Keychain on iOS, EncryptedSharedPreferences on Android, and Keychain or a permission-600 configuration file on supported macOS versions
  • All API communications are encrypted via HTTPS / TLS 1.2 or higher
  • Audio data is deleted immediately after processing (unless audio backup is enabled)
  • In-app audio, text, and API keys are not transmitted to our servers (except download registration details explicitly submitted through the website)

7. Voiceprint (Biometric Data)

The App provides an optional "voiceprint verification" feature. When enabled, MFCC features extracted from the user's voice (an 80-dimension numerical vector) are stored only on the device (~/.voice-input/voiceprint.npy). This data qualifies as biometric data uniquely identifying a natural person under GDPR Art. 9(1), and as "sensitive personal information / 要配慮個人情報" under APPI. It is never transmitted externally.

Starting with v2.4.0, voiceprint enrollment requires explicit consent (opt-in); no automatic enrollment occurs. It can be deleted at any time from the Dashboard.

8. Few-shot Context Transmission

To preserve stylistic and terminological consistency, the App can attach up to 3 prior dictation pairs (speech-recognition result + final output) as context when sending the current utterance to the post-processing LLM.

Starting with v2.4.0, this feature is disabled by default (0 entries sent). It only operates when explicitly enabled in the Dashboard. When enabled, please note that prior dictation content is also sent to the LLM provider.

9. Medical Mode Notice

When the medical mode (medical / medical_consultation) is enabled, generated text may contain clinical content, symptoms, prescriptions, and similar medical information — which qualifies as sensitive personal information.

SGH Voice for iOS does not verify whether the user has an agreement with the selected AI provider that is appropriate for processing medical information (such as a BAA or DPA). Unless an applicable agreement and organizational policy are in place, do not enter information that can identify a specific patient. Local LLM processing with Ollama is available only in supported desktop versions.

10. Audio Backup

The iOS version does not provide audio backup and deletes recording files from its temporary directory. Only in supported desktop versions, when the user explicitly selects an audio backup directory in the Dashboard, are WAV files retained there. The user is responsible for managing retained audio. No audio is transmitted to our servers.

11. Event Log (Observability Metadata)

The App writes metadata only (recognition success/failure, latency, foreground application bundle id, etc.) to ~/.voice-input/events.jsonl. No utterance content or audio waveform is logged. The file auto-rotates at 50MB and is never transmitted to our servers.

To disable foreground-app identification, switch off "App awareness" in the Dashboard (disabled by default starting v2.4.0).

12. Cross-Border Transfer (APPI Art. 28 / PIPL Art. 38)

When the selected API provider operates outside Japan (e.g., the United States), personal data is subject to cross-border transfer under that provider's contractual terms. Provider locations:

  • OpenAI (United States) — STT and LLM
  • Anthropic (United States) — LLM only
  • Groq (United States) — STT and LLM
  • OpenRouter (United States, sub-providers may operate in additional jurisdictions per model) — LLM
  • Ollama (local on-device — no cross-border transfer)

Please review the data-protection standards applicable in those jurisdictions when using this App.

13. Right to Erasure (GDPR Art. 17 / APPI Art. 17)

Via Dashboard Settings → "Delete all local data", you can delete the following local data in one action:

  • History (history.json)
  • Event log (events.jsonl)
  • Custom dictionary (dictionary.json)
  • Voiceprint (voiceprint.npy)
  • Audio backup (WAV files under audio_backup/)
  • Usage statistics (stats.json)
  • Diagnostic and auto-triage reports (reports/, auto_triage_report.md)
  • Quarantined corrupt history or configuration copies, when present

API keys can be deleted individually from the Dashboard Settings page.

On iOS, “Clear API Keys, Dictionary, and Preferences” in Settings removes API keys from Keychain and deletes the custom dictionary and on-device preferences. Deleting the app also removes data from the iOS app container.

Website download registration data is retained only as long as needed for the purposes stated above, and records that are no longer needed are reviewed periodically. To access, correct, or delete this data, contact us below and include the email address used for registration.

To delete data already sent to an AI provider, use your provider account or contact that provider directly.

14. Contact Us

For privacy-related inquiries, please contact:

Shingihou Co., Ltd.
Location: Fukuoka City, Fukuoka, Japan
Email: info@shingihou.com