PRIVACY & SECURITY

Privacy & Security

Oralion puts privacy first by design: raw microphone audio never passes through our servers; captions and translated voice are encrypted in the browser before our servers relay them, and are not stored. This page explains how data flows, what we collect, and how optional features handle text.

Last updated: 4 August 2026

ONE-MINUTE SUMMARY

  • Caption content is end-to-end encrypted. Original captions, translations, and optional translated voice are encrypted in the speaker's browser. Our servers relay only ciphertext; the room key is never sent to us.
  • AI live correction. A speaker can turn this on in the console (on by default, off at any time). While it is on, plaintext captions are relayed to a language model to fix terminology; this is the explicit exception to encrypted delivery above. Full captions are not written to a database or log. However, terminology rules proposed by the model (find text, replacement, reason, and whether the safety check accepted them) are retained for administrator review and deleted with the account. When correction is off, Oralion receives only ciphertext on the normal caption-delivery path.
  • Raw voice never touches us. Microphone audio goes directly from your browser to the speech provider; we cannot see or store it. Optional translated voice is relayed to viewers only as end-to-end-encrypted ciphertext.
  • The provider is a US-based specialist that won't reuse your data. We use a speech provider headquartered in the US that commits to: no long-term retention after real-time processing, never using it to train or improve AI models, no selling, no other use.
  • We keep only the minimum. Account email, a hashed password or linked Google identity identifier, usage stats, and session metadata that contains no caption content.

1 · How data flows

Once you see how Oralion works, it's clear why your content is hard for us to reach. A broadcast involves four kinds of data, each on its own path:

① Audio

Your browser captures the microphone (or the tab/window audio you choose to share) and connects directly to the speech provider for real-time recognition and translation, using short-lived, per-session temporary credentials. Audio never flows through Oralion's servers, and we store no audio. Our real service key always stays on the server and is never handed to the browser.

② Caption text

Recognized and translated captions are encrypted in the speaker's browser before our room service relays the ciphertext to viewers; history replay uses a newly encrypted envelope too. Copied links carry the key in the URL `#` fragment, which browsers do not send to the server.

While AI live correction is on (speaker-controlled, on by default), plaintext captions are relayed in real time through our servers to a language-model provider. Full captions are discarded after processing and are not logged or stored. To audit correction safety and improve validation, we retain the model's proposed find/replacement fragments, reason, validation result, and model name; administrators alone can view these records, and they are deleted with the account. Turning correction off removes this plaintext path.

③ Optional recognition context

A speaker may enter an event description, names, or terminology to improve recognition. The field starts blank whenever the speaker page opens and never carries content over from the previous broadcast. When signed in, it is relayed through our server to a language model for organisation before the browser sends it to the speech provider. When signed out, timed out, or preparation fails, the original input goes directly to the speech provider. Oralion's servers write neither the input nor the organised result to a database or log. Clear the field to avoid this path.

④ Connection & ciphertext relay

Our room server relays encrypted envelopes, so it can observe room membership, connection times, ciphertext sizes, and timing, but cannot read content without the key. A viewer joining from a QR code first obtains the key from the speaker over a brief, secure browser connection, which closes after setup; restricted networks can complete this step through an encrypted relay.

2 · The speech provider's commitments

Recognition and translation are performed by a specialist real-time speech provider headquartered in the US, whose service and data handling are subject to applicable US laws and privacy standards. Privacy was central to our choice of partner. Per its privacy terms, the provider commits to:

  • A US-based company: operated by a US-headquartered team, following US data-protection practices.
  • Real-time processing, no long-term retention: audio and transcripts are used to return results in real time and not stored long-term.
  • Not used to train AI: your audio and text are never used to train or improve any AI/ML model.
  • No secondary use, no selling: your content is not used beyond delivering the service, nor sold or rented to third parties.
  • Encrypted in transit: the connection to the provider is encrypted throughout.

These are the provider's commitments under its privacy policy. Oralion itself never handles this audio, so it cannot and does not retain the content.

3 · What we collect

We deliberately keep collection to a minimum. In practice it's only the following, none of which includes audio or caption content:

  • Account data: your email, a hashed password (we can't recover your original), the stable identifier when you choose Google sign-in, and usage/credit stats. We do not store Google access tokens.
  • Registration IP and rough city: kept once at signup, solely to spot duplicate registrations and prevent abuse — visible to admins only, never made public or used for anything else.
  • Room code and room password: held only in server memory to set up the live connection; they vanish when the broadcast ends, and are never written to the database or logs.
  • Anonymous trial metering: logged-out trials are metered temporarily by source IP (in memory only) to grant the free allowance and prevent abuse.
  • Broadcast session metadata: after a broadcast ends we keep a summary for operations and usage analysis — room code, language settings, consecutive/simultaneous mode, start/end times, and viewer count. Any geographic info is only a rough country/city (derived once from the IP, after which the raw IP is not kept), and it never includes audio or caption content.
  • Cookies: only the session cookie needed to keep you logged in — not used for ad tracking.

4 · What we never do

  • We don't store your audio.
  • We don't store your original or translated caption content — AI live correction relays it in real time and stores nothing either.
  • We don't sell or rent your content or personal data to anyone.
  • We don't use your data for advertising or cross-site tracking.
  • We don't reuse your content in any form or use it for AI training.

5 · Security measures

  • HTTPS/TLS everywhere: all pages and connections are encrypted in transit.
  • End-to-end encryption: captions and translated voice are readable only at the speaker and viewer ends.
  • Short-lived credentials: the credentials used to reach the speech service are short-lived and issued per session; our master key never leaves the server.
  • Hashed passwords: account passwords are stored hashed with an industry-standard algorithm, never in plaintext.
  • Server-enforced room passwords: for a password-protected room, an unauthenticated viewer can't obtain a connection at the server, so they never receive any captions.

No online service can guarantee absolute security, but we continually reduce risk through least-privilege and end-to-end-encryption principles.

6 · Retention & deletion

  • Account data: kept until you delete your account or request deletion.
  • Audio and captions: not retained by default. Raw microphone audio does not pass through us. Caption and translated-voice ciphertext is relayed in room memory only and never persisted. Full plaintext captions used for AI correction are not stored, but the terminology-rule audit records described above are retained. Optional transcript saving is covered in section 8.
  • Room code / password: cleared from memory when the broadcast ends.
  • Session metadata and server logs: kept only for the limited period needed for operations analysis and abuse prevention.

7 · Third-party services

To provide the service we use a few third parties:

  • Speech provider: real-time recognition and translation, plus any recognition context you choose to provide (see section 2 for commitments).
  • Language-model provider: used to correct captions while AI live correction is on, or to organise optional recognition context when a signed-in speaker enters it. This is the only third party that sees caption text; turning live correction off stops captions from being sent. Neither path includes your account, email, or room code.
  • Google: used only when you choose Google sign-in, to verify your identity and obtain your email and stable account identifier; access tokens are not retained.
  • Cloud hosting: runs our website and signaling/relay servers.
  • Email delivery: sends account confirmation and notification emails.
  • Noise-reduction model provider: used only when a speaker turns on background noise reduction. The processing runs entirely inside the speaker's own browser and no audio is sent to this provider; the browser only downloads a model file from them, so they see the speaker's IP address.

8 · Transcript saving (opt-in)

Captions are not stored by default. Only after you explicitly enable transcript saving in account settings will a finished broadcast be saved to your own account for export or deletion. We do not use these transcripts for training, quality evaluation, or any other purpose.

Scope and limits

  • Transcripts belong to your account and are kept until you delete them; closing your account deletes them too.
  • You can turn it off at any time in account settings, or delete individual transcripts or all of them. Turning it off stops new broadcasts being saved; what is already stored stays until you delete it.

Enable or disable transcript saving in account settings.

9 · Your rights

You can view, correct, or delete your account data at any time. Once logged in, update your email and password in account settings; to delete your account (including the Google sign-in identifier) or exercise other data rights, email [email protected] and we'll handle it within a reasonable time.

10 · Children's privacy

This service is not designed for children. We don't knowingly collect children's personal data; if you believe a child provided data without consent, contact us so we can delete it.

11 · Changes & contact

We may update this page from time to time; material changes will be marked with a new "Last updated" date here. Continued use of the service means you accept the updated terms.

Questions about privacy or security? Email [email protected].