Health data is about as personal as data gets. Here’s exactly what Voke does with yours, including the parts that are less flattering.
Each account has its own key
When you create a Voke account, Voke makes a data key that belongs to your account alone. Your health data is stored in small encrypted blocks, one per day per kind of reading, sealed with AES-256-GCM under a key derived from yours. Your Ask Voke chats, your morning summaries and your Google sign-in token are sealed under keys derived from it too.
Your data key never sits on disk in the clear. It’s stored wrapped by a master key in AWS Key Management Service, in Canada, which only the Voke service can use. Each time the server unwraps your key, AWS logs it.
Voke’s server can read your data, and here’s why
This isn’t end-to-end encryption. To work out your scores, show a night to your partner, or answer “how did I sleep this week?”, Voke’s server has to decrypt your data while it works.
We could have built Voke so only your phone holds the key. But then sharing with a circle, and the morning summary, would have to work very differently, and much of what makes Voke useful wouldn’t be possible. We’d rather tell you plainly that the server can decrypt your data than claim something that isn’t true.
What we do instead is limit what can read it, and log every time someone does.
You choose who sees what
Signing up shares nothing. Nothing leaves your account until you’re in a circle and have said what it can see.
When you make or join your first circle while setting up Voke, it suggests a start: sleep in full, heart as daily totals and your readiness score, already ticked. You can untick any of them before you go on. When you join a circle later, every category starts off and you pick what to turn on.
For each category you pick a level: scores only, daily totals, or full detail with charts and minute-by-minute data. A level applies to everyone in that circle. To share more with one person than with the rest, make a circle with just the two of you.
On the server, all of this goes through one check that runs before any data is opened. When someone’s level for a category is “scores only”, the data above that level isn’t decrypted for them at all. It isn’t fetched and then hidden.
Two categories are never shared with anyone, whatever you pick: body measurements, like weight, and heart rhythm events.
Every time another person reads your data, Voke logs who it was, which categories, and at what level. Sharing health data without oversharing walks through the levels.
When you change your mind, the change is immediate. Lower a level or remove someone, and their phone updates within seconds.
AI follows the same rules, and then some
AI reads go through the same check as people, with extra limits:
- Ask Voke and the morning summary read your data to answer you. Your question and the data looked up go to an AI model provider through Vercel’s AI Gateway, in the United States. Every request is sent with zero data retention: the provider deletes it after answering and doesn’t train on it. If no provider can take the request on those terms, it fails instead of going elsewhere. If an answer comes back from outside the US, Voke throws it away.
- We don’t store what the AI looked up. Chats keep only your words and the answer, sealed under your key, and are deleted after 30 days.
- Other people’s data needs their permission twice. Your Ask Voke can read someone in your circle only if they share that category with you, and they’ve also turned on “Let their AI see this too” in a circle you’re both in. That second switch is off by default, and it covers everyone in that circle.
- If they stop sharing, your chats forget them. Voke deletes your messages that used their data.
- AI apps you connect yourself get read-only access to the categories you approve. Once data reaches an app like Claude or ChatGPT, that company’s own privacy terms apply. We say so before you connect.
- One switch turns it all off. “Use AI features” disconnects every AI app, deletes your chats and summaries, and keeps your data out of everyone else’s AI too.
Where it lives
Voke runs on Amazon Web Services in Montréal, Canada. Backups go to Calgary, Canada. The encryption keys stay in Canada too.
What leaves Canada: Google sends your data from its own servers, Apple handles sign-in and notifications, and Ask Voke requests are processed in the US as described above.
Deleting means deleting
When you delete your account:
- In one step, you’re signed out everywhere, removed from every circle, and nobody can see your data any more.
- Voke revokes its access to your Apple and Google accounts, and deletes your health data, chats and summaries.
- Voke destroys your data key and leaves a marker so a new key can never be made for that account.
Database backups are kept for up to 35 days, so copies of your encrypted data stay in them for a while. But the key that opens them is kept in a separate store whose own backups only go back 7 days. After 7 days, no copy of your key exists anywhere, and the encrypted data left in old backups can’t be read by anyone, including us.
What we don’t do
- No ads, and no ad or analytics trackers in the app.
- We don’t sell data, and we don’t share it with data brokers.
- We don’t use data from Apple Health or Google to train AI models.
What we haven’t done yet
- Voke hasn’t had an outside security audit or certification.
- You can’t download a copy of your data from the app yet. Email us and we’ll send it.
- You can’t disconnect a source from inside Voke yet. You can remove Voke’s access in Apple Health or your Google account, which stops new data, and deleting your account removes everything.
There’s a shorter summary on our privacy page, and more on how the service is run on security. The full details are in our privacy policy. Questions go to [email protected].