Data processing terms

Effective 7 October 2026.

This page sets out how Voke works with the companies that handle your data for it. It adds to the privacy policy and doesn’t change it. If the two ever seem to disagree, the privacy policy applies.

1. Who is responsible

  • Voke is responsible for your data. Voke is run by Rida F’kih, an individual in Alberta, Canada. Voke decides what data is collected, why, and who handles it. In privacy law terms, Voke is the controller.
  • Voke’s service providers handle data only for Voke. They’re listed on the service providers page. Apart from Anthropic (see section 3), they act on Voke’s instructions and may not use your data for their own purposes. In privacy law terms, they’re Voke’s processors.
  • Voke doesn’t handle data for anyone else. Voke has no business customers whose data it processes, so it doesn’t act as a processor and doesn’t sign processing agreements as one.

Some companies get your data but aren’t Voke’s service providers:

  • Apple runs Sign in with Apple, notifications and TestFlight as an independent company, under its own privacy policy.
  • Google Health and Apple Health are sources you connect, under their own privacy policies.
  • AI apps you connect get the data you approve because you told Voke to send it. The company that runs the app is responsible for what it does with it. See the AI terms.

2. What the service providers handle

  • Whose data: people who use Voke, people who visit voke.co, people who ask for a beta invite, and people who email us.
  • What data: described in section 2 of the privacy policy. It includes health data, which Voke collects only with your express consent.
  • Why: only to run the features described in section 3 of the privacy policy.
  • How long: for the times in section 12 of the privacy policy. When a service provider’s work ends, the data it holds is deleted.

The service providers page lists, for each one, what it does, which data it handles and where.

3. What Voke requires of its service providers

Each service provider except Anthropic handles your data under its own published data processing terms. Voke uses them only where those terms:

  • limit it to handling your data on Voke’s instructions;
  • require the people who handle your data to keep it confidential;
  • require it to protect your data with suitable security;
  • require the same terms of any company it uses in turn;
  • require it to help Voke answer your privacy requests;
  • require it to delete your data when its work for Voke ends; and
  • require it to tell Voke about a security breach that affects your data.

The AI model hosts and TypeSafe AI are reached through Vercel. They work under Vercel’s agreements with them, which for Voke’s requests include keeping no copy and not training on your data. See the AI terms.

Anthropic is the exception. Voke’s operator tooling uses Claude, made by Anthropic, on a consumer subscription, and only when investigating an issue with the service. That subscription comes with no data processing contract. The tooling works with account and operations records, not health data.

4. How Voke protects your data

  • Each account has its own data key. Health data, Ask Voke chats, morning summaries and Google sign-in tokens are encrypted with keys derived from it (AES-256-GCM). The data key is encrypted by a key held in AWS Key Management Service.
  • Connections use TLS. The database and backups are encrypted at rest.
  • Each iPhone you sign in on has its own key, and uploads and sensitive actions must be signed with it.
  • Only Voke’s service can use the encryption keys, and every use is logged.
  • One person, Rida F’kih, has operator access to Voke’s systems, under the limits in section 5.4 of the privacy policy.

Voke’s server can read your data while it works, so this isn’t end-to-end encryption. How Voke protects your data has more detail.

5. Data outside Canada

Voke stores your data in Canada. Some service providers process data in other countries, as listed on the service providers page. Section 10 of the privacy policy says how these transfers are protected, including for people in the EU, EEA, UK and Switzerland.

6. Security breaches

If a breach of security safeguards creates a real risk of significant harm to you, we’ll tell you directly and report it to the regulators the law requires, as set out in section 11 of the privacy policy. We keep a record of every breach for at least 24 months.

7. Your requests

You can ask to access, correct or delete your data, or ask which companies received it. Email privacy@voke.co. We’ll answer within 30 days, and we’ll pass your request on to any service provider that needs to act on it. Section 14 of the privacy policy has your full rights and how to appeal.

8. Contact

Rida F’kih, operator of Voke, Alberta, Canada Privacy: privacy@voke.co Security: security@voke.co