Voyager · Legal

Privacy Policy

Last updated:

1. Who we are and what this policy covers

Nullframe, Inc. (“Nullframe,” “we,” “us,” or “our”) provides Voyager. This Privacy Policy explains how we collect, use, disclose, and retain personal information when you use Voyager’s websites, desktop applications, hosted services, APIs, command-line tools, and related features, or contact us.

This policy covers Voyager, including Voyager account and billing services accessed through moda.app. Nullframe also provides Moda; Moda’s privacy policy covers your separate use of Moda. A shared account can hold records relating to both products. If you use Voyager through an organization, that organization may also control how information in its workspace is used. Its policies and any applicable data-processing agreement govern processing we perform on its behalf.

Our Terms of Use describe the rules for using Voyager. This policy is a notice about personal information, not blanket consent to process another person’s face, voice, or other sensitive information. Contact us at support@voyager.so about this policy or a privacy request.

2. Information we collect

  • Account and contact information: your name, email address, sign-in identifiers, profile details, organization and workspace membership, access permissions, and communications or preferences you provide. We also receive information from your sign-in provider and workspace administrators.
  • Billing and service records: plan, purchases, credit balances, invoices, transaction and payment status, and payment-method details made available by our payment processor. Payment processors such as Stripe handle payment credentials through their own systems.
  • Content submitted for processing: prompts, conversation context, tool results, selected or agent-accessed files, images, videos, audio, reference material, and generated outputs that a workflow sends to our hosted services. These can contain information about you or other people. Local storage and cloud processing are explained below.
  • Technical and usage information: IP address, browser and device information, operating system, app version, timestamps, pages and features used, referring pages, identifiers, performance and error information, and the analytics, crash, and feedback data described below.
  • Request and safety records: account, organization, and provider request identifiers; model or operation; usage and cost; results or result references; status and errors; and information needed to investigate a report, confirm permissions, or prevent abuse.
  • Support and restricted-feature information: messages, reports, attachments, recordings, consent or authorization evidence, and verification information you or a person participating in a feature provide. We may receive a complaint or permission-withdrawal request from someone depicted or heard in content.

We receive information directly from you, automatically when you use the Services, and from providers, connected services, organization administrators, and people who contact us about your use. Providing some information is necessary to operate an account, process a payment, or perform the feature you request; without it, that feature may be unavailable.

3. Desktop storage, permissions, and local processing

Voyager’s desktop app stores project and conversation state, settings, caches, and diagnostic files on the machine running its app server. Project files and generated media may also be stored in folders you or an agent choose. When you connect a remote environment, relevant state and files may instead reside on that environment. Installing Voyager does not, by itself, upload every file on your computer to Nullframe.

Local installation does not mean all processing stays local. Depending on the task, connected provider, and permissions, an agent can read files and application context and send relevant content, conversation history, screenshots, or tool results to an AI provider or connected service. An authorized task can involve multiple requests without a separate prompt before each one. Review permissions, provider settings, and the content available to the agent before starting work.

Features may request access to your microphone, camera, screen, files, clipboard, or creative applications. Access depends on the feature and operating-system permissions. You can manage those permissions through your device and Voyager settings. Turning off a permission stops future access through that permission; it does not recall content already sent or saved.

Voyager’s built-in voice-input dictation transcribes microphone audio on the device. If you send the resulting text as a message, it becomes part of that workflow’s conversation context. Cloud speech generation, voice cloning, and other audio-processing tools are separate features and may transmit audio to providers.

Connected accounts may store credentials or authorization tokens on the machine running the connection and transmit them as needed to authenticate with the relevant service. Other tools can maintain their own credential stores. Protect access to your device and remote environments; disconnecting a service or deleting a local project does not necessarily delete records held by that service.

4. How and why we use information

We use personal information to provide requested features; authenticate users and manage organizations; route and complete AI and media requests; process payments and usage; respond to support and permission requests; diagnose problems and improve Voyager; communicate service updates and requested marketing; protect people and the Services; investigate abuse and disputes; and comply with legal obligations.

Where laws require a legal basis, we rely on performance of our contract with you for account, billing, and requested service processing; legitimate interests in operating, securing, supporting, and improving Voyager where those interests are not overridden by your rights; compliance with legal obligations for required records and disclosures; and consent where required for a particular activity. You may withdraw consent without affecting the lawfulness of processing before withdrawal. Special-category or biometric processing requires an additional legal condition where applicable.

We may review information submitted to our services to resolve a support request, enforce our terms, investigate misuse, and improve reliability. We may use aggregated or deidentified statistics to understand usage. Account-linked analytics are personal information, even if they do not contain your name or email. We do not use your private content, face, or voice in advertising without separate permission.

5. AI providers and connected services

Voyager can use AI providers and tools through either Voyager-managed access or accounts you connect yourself. Providers may include OpenAI, Anthropic, Google, fal and the model providers available through it, and ElevenLabs, depending on the feature and your configuration. They receive the prompts, context, media, request metadata, or other information needed for their part of the workflow. A service that receives a reference URL may retrieve the referenced content.

For Voyager-managed requests, Nullframe’s infrastructure may receive and forward inputs and results and maintain account-linked service, billing, security, and request records. For a direct connection using your own account, content may go directly from your device or remote environment to that provider. Using your own account does not make its processing local.

Provider retention and model training vary. Providers process information under the applicable agreement, privacy notice, and account settings. Some permit content use for model improvement or training unless an opt-out or separate agreement restricts it. We do not promise that every provider excludes your content from training. Check your own provider’s settings, or contact us before using Voyager-managed access with material that needs specific data-use restrictions. Creating a requested personal voice model is itself a use of the supplied recordings for that feature.

Connected storage, email, creative applications, websites, plugins, and third-party connectors have their own permissions and privacy practices. For example, when you connect Google Workspace through a connector, review that connector’s notice and the Google permissions you grant. Content an agent reads from a connected service can become context for its AI provider. This policy does not expand a connector’s granted permissions or override restrictions on the data it accesses.

6. Faces, voices, and restricted generation

Where offered, face and voice features may process photographs, videos, voice recordings, transcripts, generated media, voice-model identifiers or representations, and consent or verification records. We and the relevant providers use this information to perform the requested generation, create or operate a requested voice model, confirm eligibility and permission, prevent impersonation and abuse, and address complaints or withdrawal requests.

Identifiable images and recordings are personal information. Depending on the processing and applicable law, derived face or voice information or identity verification may also involve biometric or other sensitive information. Separate notices, permissions, and retention requirements may apply; accepting the Terms or this policy does not replace them or authorize use of another person’s identity.

ElevenLabs may process recordings and voice data for voice modeling and speaker verification. See its Privacy Policy and Voice Processing Notice for its practices. Verification performed directly with a provider is also governed by that provider’s notice. We may receive permission records, identifiers, or verification results needed to administer access.

To report unauthorized use of your face or voice, withdraw permission, or request deletion or disabling of a voice model, email support@voyager.so. Include enough information to identify the relevant content or voice; do not send unnecessary identity documents or sensitive recordings. We may need to verify the request and coordinate with the account holder or provider. Stopping future use cannot recall copies of content already exported or shared. Feature eligibility and consent requirements are described in the Terms of Use.

7. Desktop analytics, crash reports, and feedback

Usage statistics. In current production desktop installations, “Share usage statistics” is on by default. You can turn it off in Settings → Privacy. Optional events report app and device characteristics, recognized provider and model categories, feature use, operation outcomes and durations, and sanitized error information to PostHog through Nullframe’s service. They are associated with your account identifier, not anonymous. Failed sign-in reporting can use a separate random installation identifier.

These usage events exclude conversation text, file contents, recordings, API keys, file paths, and command arguments. Desktop usage reporting does not include session replay. Network infrastructure still receives connection information such as IP addresses.

Crash reports. The same setting controls optional crash reporting to Sentry. Reports can include error information, stack traces, app and operating-system details, recent app-health events, and a profile-directory hash. They are not intentionally linked to your account. Native crashes may also include a minidump, which is a snapshot of process memory and may contain personal information present in memory at the time. We filter ordinary report fields, but cannot guarantee that memory snapshots contain no sensitive information.

Turning off usage statistics stops optional reporting and clears queued usage events; it cannot recall reports already received. Necessary hosted-service, billing, and security records, website analytics, and a connected provider’s own reporting are separate.

Feedback and support. Agent feedback has a separate control in Settings → Privacy and is on by default in current installations. When enabled, an agent may send a short report about a problem, together with thread, model, app, and recent-error context. A report can include the agent’s description or a short quoted excerpt; it is not an automatic upload of the full conversation. Reports appear as tool calls. You can disable agent feedback independently of usage statistics.

Feedback you send yourself and “Get help” support bundles are also separate from usage statistics. A support bundle can include conversation content and diagnostic information that you review before sending. We attempt to redact secrets and local identifiers, but you should review what you share. Reports are handled through our support and analytics systems, including internal Slack and PostHog; attached support bundles are shared with our support team through Slack.

8. Website analytics, cookies, and communications

Our websites and account services use cookies, browser storage, and similar technologies for sign-in, security, preferences, and analytics. Production Voyager websites use PostHog and Google Analytics to collect page views, referring pages, device and browser information, identifiers, and interactions such as clicks or form activity. Website session replay is disabled. These website tools are separate from the desktop privacy settings.

If you join the waitlist, your email is stored in our mailing-list service, Loops, and may be associated with earlier website activity in PostHog. A signup may also send an internal notification through Resend. Our email providers may record delivery and engagement information. Unsubscribe using the link in a marketing email or contact us; we may still send necessary account, billing, security, and service messages.

If you request a beta download link by email, Resend processes your email address to deliver that one-time message. We use digests of email addresses and IP addresses to limit repeated beta requests and prevent duplicate emails. Requesting a download email does not add you to a mailing list.

You can use browser controls to block or clear cookies and site storage, and tracking controls to limit analytics. Google also provides an Analytics opt-out browser add-on. Blocking necessary storage can affect sign-in or other features. Clearing browser storage does not delete records already held by us or our providers. Contact us to exercise applicable privacy rights.

9. When we share information

  • Service providers: companies that help with hosting and delivery, authentication, payments, AI processing, storage, analytics, diagnostics, email, and support. Examples include Cloudflare and Google Cloud for infrastructure, Clerk for authentication, Stripe for payments, and the providers described above. They receive information relevant to their role.
  • People and services you choose: collaborators, recipients, connected providers, and publishing destinations involved in your instructions or sharing settings. Organization administrators may see membership, billing, usage, and workspace information available through their role. Organization membership alone does not upload all local files.
  • Safety, law, and disputes: when required by law or reasonably necessary to investigate abuse, respond to valid legal process, enforce agreements, or protect rights, safety, and the Services. Handling a copyright or identity complaint may involve sharing relevant information with an affected user or provider.
  • Business changes: advisers and parties involved in a merger, acquisition, financing, reorganization, or sale of the relevant business, subject to applicable protections.
  • With your direction or permission: for another purpose explained when you choose it.

We do not sell personal information for money. The analytics disclosures above still apply; privacy laws can define “sale,” “sharing,” or targeted advertising more broadly than a monetary sale. You may contact us about applicable opt-out rights, as described below.

10. Retention and deletion

Retention depends on the type of information, why it is processed, your account and settings, contractual commitments, and legal requirements. We consider whether information is needed to deliver an ongoing service, resolve support or permission issues, reconcile transactions, prevent duplicate charges or fraud, maintain security, or establish or defend legal claims.

Local projects, conversations, generated files, caches, and credentials remain on your device or remote environment until removed through the relevant application or storage controls. Uninstalling Voyager may leave data behind. Deleting local content does not automatically delete provider-held copies or hosted account records, and deleting a hosted account does not remotely erase independent local files.

Hosted account, support, analytics, and content records follow the applicable service and provider retention settings. Some billing and request records are maintained on an ongoing basis without an automatic expiry to support reconciliation and prevent duplicate processing; they are not automatically removed when you delete a local project. A generated-file URL expiring does not mean all related records have been deleted.

You may request deletion at support@voyager.so. We evaluate requests under applicable law, including retention needed for legal obligations, security, disputes, and other permitted exceptions. Backup copies may persist until they are overwritten or removed in the normal backup cycle. For a connected provider account, also use that provider’s deletion controls. For Voyager-managed face or voice features, contact us so we can address the relevant records and coordinate any provider-side request.

11. Your rights and choices

Depending on your location and applicable law, you may have rights to know about and access personal information, receive a portable copy, correct inaccuracies, request deletion, restrict or object to processing, withdraw consent, and opt out of sale, sharing, targeted advertising, or certain profiling where those activities and rights apply. You may have the right to limit certain uses of sensitive information and to appeal a denied request. We will not unlawfully discriminate against you for exercising your rights.

Email support@voyager.so with your request and the account or content it concerns. You do not need an account to report use of your face or voice. We may verify your identity or an authorized agent’s authority using information proportionate to the request. If we cannot fulfill a request, we will explain the applicable reason and any available appeal process. You may reply to request an appeal or lodge a complaint with your local data-protection authority.

You can also change available account details, revoke connected-service access, manage device permissions, turn off desktop usage statistics and agent feedback, and unsubscribe from marketing. If an organization controls the relevant information, we may direct the request to its administrator or help it respond. Tell us whether an account request concerns Voyager, Moda, or both so we can address shared records correctly.

12. Security and international processing

We use technical and organizational measures intended to protect personal information, including access controls and protections for transmission and storage appropriate to the service. No system is completely secure. Keep your devices, account credentials, and connected-provider accounts secure, and avoid sharing unnecessary sensitive information.

Nullframe is based in the United States. Information may be processed in the United States and other countries where we and the providers involved in your workflow operate; their data-protection laws may differ from those in your location. Destinations and transfer arrangements depend on the service and provider. Contact support@voyager.so for information about relevant destinations and applicable transfer safeguards, or to request a copy where available. This policy does not itself establish a cross-border transfer mechanism or waive protections required by applicable law.

13. Children

Voyager is intended for adults aged 18 and over. We do not knowingly permit children to create accounts. If you believe a child has provided personal information through an account or otherwise in violation of applicable requirements, contact us so we can investigate and take appropriate action. Content involving other people remains subject to their rights and the restrictions in our Terms, including restrictions on minors in face and voice features.

14. Changes and contact details

We may update this policy as Voyager and our practices change. We will post the revised policy and date here and provide additional notice of material changes where required. If a change requires consent, this notice alone does not supply that consent.

For privacy questions, rights requests, or concerns about personal information, contact:

Nullframe, Inc.
169 Madison Ave, Ste 2054
New York, NY 10016
United States
support@voyager.so