wavekat

Privacy Policy

Last updated 4 August 2026

WaveKat collects as little as it can. Your calls — the audio, the transcripts, the history — stay on your own computer unless you sign in to a WaveKat account and leave cloud sync on, or connect your account to another service yourself. This website uses Google Analytics and Google Ads to measure traffic. We have never sold personal data and we don't intend to.

This policy covers everything WaveKat runs: the website at wavekat.com, the WaveKat Voice desktop app, and WaveKat accounts.

Who is responsible for your data

WaveKat is the data controller for wavekat.com, WaveKat Voice, and WaveKat accounts. Write to [email protected] with any privacy question — that is also the address for exercising the rights described further down. We read every message.

What this website collects

You don't need an account to read wavekat.com and there are no forms on it — the only way to contact us is email. What the site does collect is measurement data:

  • Google Analytics 4 (measurement ID G-H8ZGBL04R7) records which pages you view, roughly where you are based on your IP address, your device and browser, and which site sent you here.
  • Google Ads conversion measurement records that someone who arrived from one of our ads later clicked an "email us" link. It records the click, never the message you then write.
  • Google Fonts are loaded from Google's servers, so Google sees your IP address when a page loads its typefaces.
  • Cloudflare, which hosts the site and serves app downloads, keeps ordinary server logs — IP address, the file requested, time, browser — to deliver pages and block abuse.
  • Email you send us is kept for as long as it takes to answer you and to keep a record of the conversation.

The legal basis for analytics and ad measurement is your consent where consent is required, and our legitimate interest in understanding how the site is used everywhere else. Hosting logs rest on our legitimate interest in keeping the site up and secure.

Cookies and browser storage

What Set by Why How long
_ga, _ga_* Google Analytics Tells repeat visits apart and counts sessions Up to 2 years
_gcl_au Google Ads Links an ad click to a later action on this site 90 days
theme WaveKat (local storage) Remembers whether you chose light or dark Until you clear it
lang-pref-dismissed WaveKat (local storage) Remembers you closed the "read this in your language" banner Until you clear it

The two WaveKat entries never leave your browser. The site does not show a cookie consent banner today; if you would rather not be measured, block third-party or analytics cookies in your browser settings, or install Google's Analytics opt-out add-on. You can also email us and we will exclude you.

Signing in, and what your account holds

A WaveKat account is optional — the desktop app works without one. When you do create an account, you sign in through GitHub or Google rather than with a password we hold. We never see your GitHub or Google password.

What that sign-in hands us, and what we store: your username or handle, your display name, your email address, your profile picture's address, the provider's account identifier, and the time you last signed in. It's what lets us recognise you next time and show you as signed in. You can connect both GitHub and Google to the same account, and disconnect either one as long as it isn't your last way in.

If you use the wk command-line tool, it signs in the same way and stores an access token, labelled with the name of the machine that requested it so you can tell your devices apart.

What WaveKat Voice keeps on your computer

WaveKat Voice is a desktop app for Mac and Linux, and it is local by default. If you never sign in to a WaveKat account, all of the following stays on your machine and never reaches us:

  • Call recordings. Recording is on by default, and each call is saved as an audio file with both sides of the conversation. Turn it off in Settings → Recording. There is no automatic cleanup — recordings stay until you delete them.
  • Call history — date, number, duration, and how each call ended, in a local database.
  • Transcripts. Live transcription is off by default. When you turn it on, the speech-to-text runs entirely on your computer — no audio is sent anywhere to be transcribed.
  • Your SIP account passwords, stored on your computer and encrypted by your operating system. They are never sent to WaveKat.

Recording and consent. Call-recording law differs by country: some places need only your consent, others need everyone on the call to agree. WaveKat Voice plays a short notice beep at the start of recorded calls so the other person knows. The beep is a courtesy, not a legal guarantee — complying with recording-consent law where you and the people you call are located is your responsibility.

What syncs to a WaveKat account

Nothing, until you sign in. If you sign in and leave Sync to cloud on — it is on by default once signed in — the app uploads your call history (date, number, timestamps, duration, and how the call ended), your call recordings, and your transcripts to your private WaveKat account, so your calls appear on every device you sign in on. Signing in also registers the computer — its name, operating system, and app version — so you can see which devices are connected.

Turn Sync to cloud off to keep everything on that computer; local recording and history keep working. The app also refuses to upload data belonging to a different WaveKat account than the one that first synced on that computer. Synced recordings, transcripts, and history are stored in our account with Cloudflare, whose infrastructure the whole platform runs on. We do not use your calls to train any model, and we do not sell them.

Sharing a recording with someone

You can turn a recorded call into a link and send it to someone. Anyone who has that link can open it — there is no sign-in on the other end — so treat the link itself as the key. Sharing is always something you start; nothing is shared automatically.

When you create a link you choose what the person on the other end gets. By default they hear the audio, the transcript is hidden, and the other party's identity is masked. You can turn each of those on or off, allow or block downloading, and choose which side's voice plays. Revoking the link stops it working.

Please think before you send one. A shared recording contains someone else's voice and whatever they said believing they were talking to you. Sharing it is your decision and your responsibility — the masking defaults exist to help, not to make the decision for you.

Sending your calls to services you connect

A WaveKat account can pass your calls on to other systems you connect. Nothing is connected by default — every destination is one you add yourself, and removing it stops the flow immediately. While a destination is connected, call data leaves WaveKat for a service we don't run. There are two kinds:

  • Webhooks. You give WaveKat a URL and it posts a record of each call to it. By default that record carries the other person's number and caller ID, the full transcript, and a link that lets whoever holds it download the call audio for 24 hours. Three switches on each endpoint turn identity, transcript, or recording off — a field you switch off is left out of the message entirely, not blanked. Every request is signed so your endpoint can check it really came from us.
  • HubSpot. You connect your HubSpot account on HubSpot's own consent screen. After each call, WaveKat looks the other person up in your HubSpot contacts by phone number and files a call record on them: time, direction, outcome, duration, the numbers, a summary line, a link back to the call in WaveKat, and — unless you turn transcript sync off — what was said. When the call was recorded, that record also carries what HubSpot needs to play the audio. Two optional switches let WaveKat create a HubSpot contact when nobody matches the number, and archive the HubSpot record when you delete the call in WaveKat.

Your HubSpot credentials. Connecting gives WaveKat an access token and a refresh token for your HubSpot account. Both are encrypted before they are stored, are never returned by any part of our API, and are wiped when you disconnect — we also ask HubSpot to revoke them. Records already created in your HubSpot stay where they are: that is your CRM's data, and disconnecting an integration is not the same as deleting your history.

Once it arrives, it is theirs. Data that reaches your webhook endpoint or your HubSpot account has left WaveKat. What happens to it there is governed by that system's own privacy policy, and you are the one who decides how it is used.

A word about the other person on the call. These destinations receive the number of whoever you spoke to, their transcript, and — if you allow it — a contact record created for them in your CRM. That person is not a WaveKat user and never agreed to anything with us. Deciding whether you may log their number, their voice, and their words is the same responsibility as recording the call in the first place.

We keep a delivery log for 30 days — which event went where, what the destination answered, and how long it took — so a failure can be diagnosed. A destination that keeps failing is switched off rather than retried forever. Webhooks are free during the beta; the HubSpot integration is a Pro feature.

The voice prompt generator

WaveKat offers a tool that turns typed text into a spoken phone greeting. The text you type is sent to ElevenLabs, the speech synthesis service we use, which returns the audio. Don't type anything into it you wouldn't want to leave WaveKat — it is a greeting generator, not a private notepad.

You can use it without an account. When you do, we count usage against a scrambled form of your IP address so that one visitor can't exhaust the daily budget for everyone. It's a one-way scramble kept for the day's counting, not a profile of you, and we don't use it to track you across the site.

Crash reports and install counts

When the app crashes or hits an internal error it can send an anonymous report so we can fix the bug: the error, where in the app it happened, and what the app was doing just before. Reports go to Sentry, the error-reporting service we use. Before anything is sent, the app strips usernames, email addresses, IP addresses, file paths containing your username, and anything that looks like a credential. Crash reports never include call audio, call history, phone numbers, or contacts.

Once per launch the app also sends one anonymous ping so we know how many installs exist and which versions and operating systems to support. It contains a random install identifier, the app version, your operating system and its version, processor type, and language — no name, no account, no computer name.

Both are on by default and both are turned off by the single Send error reports switch in Settings → About. Checking for app updates downloads files from our update server — ordinary web requests with no personal data attached.

Who else processes your data

WaveKat runs on a small number of other companies' services. Each receives only what is described here, and we use each under its standard business terms — but they are large companies whose own practices are theirs, not ours, and their privacy policies govern what they do. These are the providers we chose; services you connect are a separate matter, covered in sending your calls to services you connect.

Provider What it does for us What it receives
Google Website analytics, ad measurement, web fonts Page views, IP address, device and browser, ad click attribution
Cloudflare Website hosting, app downloads, and the storage behind WaveKat accounts Server logs, and — if you turn cloud sync on — your synced recordings, transcripts and call history
ElevenLabs Turning typed text into spoken phone greetings The prompt text you type. Never call audio, transcripts, or contacts
Sentry Anonymous crash reports from the desktop app Error details with personal fields stripped — never call data
GitHub / Google Signing you in They tell us who you are; we don't send them anything about your calls

These providers are US-based, so data covered by this policy may be processed in the United States under the transfer safeguards in their standard data-processing terms. We do not sell personal data. We do run Google Ads conversion measurement, which several US state privacy laws treat as "sharing" for cross-context advertising — the opt-out below covers it.

How long we keep things

  • Website analytics — kept by Google under our Google Analytics retention setting, currently the standard window of about 14 months.
  • Crash reports — kept by Sentry under our plan's retention window, a matter of months rather than years.
  • Integration and webhook delivery logs — 30 days, then deleted automatically.
  • Recordings, history, and transcripts on your computer — until you delete them. We never delete them for you.
  • Data synced to a WaveKat account — until you delete it in the app or ask us to.
  • Email — as long as we need it to answer you and keep a record of the exchange.

Deleting your data

  • One recording — open the call on its details page and delete the recording there.
  • All recordings — Settings → Recording → Clear all recordings.
  • Everything on this computer — Settings → WaveKat account → Delete local data removes call history, recordings, transcripts, and your sign-in from that machine.
  • Data synced to your WaveKat account — email [email protected] and we will delete it.

Your rights

If you are in the UK, the EU, or another region with comparable law, you can ask us for a copy of your data, correct it, delete it, restrict or object to how we use it, take it elsewhere in a portable form, or withdraw consent you previously gave. You can also complain to your local data protection authority.

If you are in California or another US state with a privacy law, you can ask what we collect, ask us to delete or correct it, and opt out of any sale or advertising-related sharing. We will never treat you differently for exercising a right.

To use any of these, email [email protected]. WaveKat is a small operation, so please allow a little time — we answer as quickly as we can, and within the one month the law allows where it applies. We may ask you to confirm you control the account or email address in question, which exists to stop someone else claiming your data.

Security, and what we can’t promise

The sensible measures are in place. Everything that moves between you and WaveKat — this website, cloud sync, downloads — travels over encrypted connections. Sign-in runs through GitHub or Google, so there is no password of yours for us to lose. Credentials for services you connect are encrypted before they are stored. Recordings shared by link require the link. Your SIP passwords never leave your computer at all.

One honest caveat: the phone call itself travels over your SIP provider's network, and whether that leg is encrypted is between you and your provider — most business SIP traffic today is not. That is true of any phone using that line, not something WaveKat adds, but a page about privacy shouldn't leave it unsaid.

What we won't tell you is that this makes anything impossible. No online service is completely secure, and WaveKat is built and run by a very small team without a dedicated security department. If we ever discover that your data has been exposed, we will tell you what we know, as soon as we reasonably can, and say plainly what we don't know.

The strongest protection remains the one in your hands: WaveKat Voice keeps everything on your own computer unless you choose otherwise. If a call is sensitive enough that a breach would be serious, leaving cloud sync off — and not sharing or forwarding it — keeps it out of our reach entirely.

Children

WaveKat Voice is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with data, email us and we will delete it.

Changes to this policy

When this policy changes, the date at the top changes with it. If a change materially affects what we collect or who receives it, we will say so plainly on this page rather than quietly editing a sentence.

This page is a plain-language description of how WaveKat actually works, written by the people who build it rather than by lawyers. It is not legal advice, and it doesn't replace your own judgement about what you may record, store, or share where you live and work. If something here matters to your business and you need certainty, please check with someone qualified in your own country — and tell us if you find anything on this page that turns out to be wrong, because we would rather fix it than defend it.

Questions & answers

Does WaveKat listen to my calls?

No. WaveKat Voice records and transcribes calls on your own computer, and the speech-to-text runs locally — no call audio is sent anywhere to be transcribed. Recordings and transcripts only leave your machine if you sign in to a WaveKat account and leave cloud sync on. Crash reports never contain call audio, phone numbers, or contacts.

Does wavekat.com use cookies?

Yes. Google Analytics and Google Ads set cookies to count visits and measure which ads lead somewhere. WaveKat itself stores only two things in your browser — your light/dark preference and whether you dismissed the language banner — and neither is sent to us. There is no cookie banner today; you can block analytics cookies in your browser settings.

Do you sell my personal data?

No. WaveKat has never sold personal data and does not intend to. We do run Google Ads conversion measurement on this website, which some US state privacy laws treat as "sharing" for advertising — email [email protected] to opt out.

Do I need a WaveKat account to use WaveKat Voice?

No. Without an account the app is entirely local: calls, recordings, transcripts, and SIP passwords stay on your computer. The only things that leave are anonymous crash reports and an anonymous install count, and one switch in Settings → About turns both off.

Is it legal for me to record my calls with WaveKat?

That depends entirely on where you are and where the person you are calling is, and it is your responsibility rather than ours. Some places need only your consent; others require everyone on the call to agree, and getting it wrong can be a criminal matter. WaveKat Voice plays a notice beep at the start of recorded calls as a courtesy, but a beep is not legal consent. If you are unsure, say you are recording, or turn recording off in Settings.

What leaves WaveKat if I connect HubSpot or a webhook?

Each call you make after connecting: the other person's number, the call's time, direction, outcome and duration, and — unless you turn it off — the transcript and access to the recording. HubSpot also gets a call record filed against that person's contact, and can create the contact if none exists. Nothing is connected by default, every part is switchable, and disconnecting stops the flow immediately, though records already written into your HubSpot stay yours to delete there.

How do I delete everything WaveKat has about me?

For this computer, use Settings → WaveKat account → Delete local data, which removes call history, recordings, transcripts, and your sign-in. For anything synced to a WaveKat account, email [email protected] and we will delete it.

Contact us

Privacy questions, data requests, or something on this page that isn't clear — email us and a person will answer.

[email protected]