What MyAudioMessage collects, why we collect it, how long we keep it, and the rights you have over it.
Last updated 31 August 2026
MyAudioMessage (“we”, “us”) is a batch audio assembly service operated from the United States by an individual sole proprietor and available at myaudiomessage.com. This policy explains what personal data we collect when you use the service, why we collect it, how long we keep it, and what rights you have over it.
For the purposes of the UK and EU General Data Protection Regulation, we are the data controller for the information described below. If you have any question about this policy, or want to exercise any of the rights in section 8, write to jforeman@techsavey.com.
When you create an account we store your email address and, if you provide one, your name. If you sign in with an email address and password, your password is stored only as a bcrypt hash — we never hold it in a readable form and cannot recover it for you. We also store the date your email address was verified, and short-lived tokens used for email verification and password resets.
If you sign in with Google, Microsoft or GitHub, that provider tells us your email address, your name and your profile image, and we store the access and refresh tokens needed to keep the connection working. We do not receive your password for those accounts. Signing in with a provider that uses an email address already registered here links to the existing account rather than creating a second one.
We store the audio files you upload, the reusable segments you save, the batch outputs we generate from them, the names you give your batches and sections, and any templates you save. Audio is content, not metadata: we do not transcribe it, analyse it, or use it to train any model.
We record the number of batches you have completed so we can apply your plan’s allowance, along with each batch’s status, output count and timestamps. If you subscribe to a paid plan we store your Stripe customer and subscription identifiers, your plan name and its status. We never see or store your card details — those go directly to Stripe.
Our servers keep standard web logs, including IP addresses, which are used to apply rate limits and to investigate abuse and faults. If you generate an API key for the connector described in section 2, we store a hash of that key and the time it was last used.
We use the information above only to:
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not use your audio for any purpose other than producing the outputs you requested.
If you are in the UK or the European Economic Area, we rely on the following legal bases under Article 6 of the GDPR:
We keep the list of third parties deliberately short. Each one receives only what it needs to perform its function, and none of them are permitted to use your data for their own purposes:
| Provider | Purpose | What it receives |
|---|---|---|
| Stripe | Payment processing and subscription billing | Your email address and payment details, which you enter on Stripe’s own checkout |
| Brevo | Transactional email delivery | Your email address and the contents of verification and reset messages |
| Google, Microsoft, GitHub | Single sign-on, only if you choose it | The sign-in request itself; they tell us your email, name and profile image |
We may also disclose information if we are required to by law, or where necessary to establish or defend a legal claim. If the service is ever transferred to another operator, we will tell you before your information moves.
Depending on where you live, you have some or all of the following rights. We will not discriminate against you for exercising any of them.
Account deletion and data export are handled manually at present rather than by a button in your account. Email jforeman@techsavey.com and we will action your request and confirm when it is done. We respond within 30 days, and within one month for requests under the UK or EU GDPR.
If you are in the UK or EEA and are not satisfied with our response, you may complain to your local supervisory authority — in the UK, the Information Commissioner’s Office.
The service is hosted in the United States, so if you use it from the UK, the EEA or elsewhere your information is transferred to and stored in the US. Where we rely on a provider listed in section 5, those transfers are covered by that provider’s own safeguards, which for our current providers are the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
All traffic to myaudiomessage.com is encrypted in transit with TLS. Passwords are stored only as bcrypt hashes. API keys are stored only as SHA-256 hashes, so an exposed database would not reveal a usable key; access tokens issued to connected applications expire after 30 days. Batches, segments and outputs are scoped to the account that created them and are checked on every request.
No service can promise perfect security, and we do not. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulator as required by law.
The service is not directed at children and is not intended for anyone under 16. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact jforeman@techsavey.com and we will delete it.
We may update this policy as the service changes. The date at the top always reflects the current version. If a change materially affects how we handle your personal data, we will tell you by email or by a notice in the app before it takes effect.
For any privacy question, or to make a request under section 8, email jforeman@techsavey.com. Please tell us which email address your account uses so we can find it.