// Legal

Security

Last updated: July 3, 2026

How Vocce handles uploads, retention, and API access. For how we treat personal information, see the Privacy Policy.

Upload handling

  • All traffic is encrypted in transit (HTTPS/TLS), including uploads, API calls, and downloads.
  • Files are validated (type, size, duration estimate, plan limits, abuse signals) before processing.
  • Upload, processing, artifact, and checkout states are separated, so failed uploads do not burn credits.

Retention defaults

  • Raw uploads: deleted after processing or within 7 days by default.
  • Generated artifacts: deleted within 30 days by default unless you store or delete them earlier.
  • Transcript text is kept out of routine application logs.

API & agent safety

  • Scoped API keys for MCP, CLI, and agents; usage is metered and keys can be revoked from the dashboard.
  • Stable artifact names and schemas, so agents do not guess URLs or scrape pages.
  • Raw upload storage is not publicly exposed.

Reporting

Found a vulnerability? Email cmoonchat@gmail.com — we investigate all good-faith reports.