Version 2026-08-24-v8
Conversations privacy notice
Current public workspace: you may use Nkomo without providing an email. Nkomo creates a pseudonymous guest session and processes only the text or microphone audio you deliberately submit to provide the requested reply. Raw recordings are not retained as conversation history. Typed and workspace-microphone Converse turns use a bounded 30-day operational quality and cost log keyed to the pseudonymous guest or account identifier. Signing in remains optional for account features. Product-update email and voice contribution remain off unless you explicitly enable them; neither enables the other.
What we currently process
- Your email address, to issue a one-time sign-in link and maintain your account. If you separately opt in to product updates, Neuralis also stores that preference and may use the same address to send occasional Neuralis product news.
- Hashed login, session and abuse-prevention identifiers. Raw login links expire after 15 minutes; sessions expire after seven days.
- Your cloud-consent, history, newsletter and voice-contribution preferences, plus the version and time of this notice that you accepted.
- During an active voice session, microphone audio, an automatic transcript and the generated response. Twi and English speech recognition and speech synthesis run on Neuralis-operated infrastructure. An approved cloud language-model provider generates the answer.
- Long-form Speak jobs: when you are signed in and submit more than 3,000 characters, the request text is encrypted in the private job store while it is queued. The resulting WAV and encrypted request become unavailable after at most one hour; cancelling the job revokes its download immediately. These jobs are for service delivery only and are not training contributions.
- Operational security and aggregate performance records such as request time, outcome, latency and keyed rate-limit identifiers.
- Content-free issue reports: if you choose Report issue, we retain the task mode, exact language, request identifier, public capability state, issue category and app surface for up to 90 days. We do not include your entered text, transcript, translation or audio. Signed-in reports use a pseudonymous account identifier, appear in your export and are deleted with your account. Anonymous reports cannot later be linked to an account.
- Logged Converse turns: typed questions and workspace-microphone recognized messages, their generated replies, and provider usage/cost figures are retained for up to 30 days so the Neuralis operator can review answer quality and account for language-model costs. These records are keyed to a hashed account identifier, appear in the account export while retained, are deleted with the conversation or account, and are never used for advertising or shared outside Neuralis. Legacy realtime Voice transcripts and replies are not written to this log.
Product-update email (optional, off by default)
The sign-in and account screens offer a separate choice to receive occasional Neuralis product updates. It is off by default. Turning it on does not enable voice contribution, cloud help or conversation history. You can turn it off in account settings at any time; Neuralis retains the preference with your account until you unsubscribe or delete the account. Essential one-time sign-in and security messages are not marketing and may still be sent when this option is off.
Contributing your voice clips (optional, off by default)
Your account has a separate switch called “Contribute my voice clips to improve Twi voice AI”. It is off unless you turn it on, and nothing else you change in your privacy settings can turn it on for you.
- While it is off (the default), the audio you speak during a voice session is used only to answer you in that moment and is discarded when the connection closes. Nothing is kept.
- While it is on, the voice clips you speak during voice sessions and the machine-generated transcripts of those clips are retained by Neuralis and used to improve Neuralis’s Twi speech recognition and speech synthesis models. Nothing else changes about the conversation itself.
- Retained clips are stored under a pseudonymous speaker key — a one-way keyed hash of your email address. Your email address itself is never attached to the recordings.
- Contributed clips and their transcripts are deleted when you delete your account, along with the rest of your account data.
- You can turn the switch off at any time in the account dialog. New voice sessions stop being retained immediately, and Nkomo creates a traceable purge instruction for clips captured under that account before withdrawal. Account deletion creates the same instruction. A delayed purge remains retryable by the operator until it is completed.
- Contributed clips are used for Neuralis speech-model work only. They are never used for advertising and are not sold.
What we do not store
Unless you have switched on voice-clip contribution as described above, Conversations does not save raw voice recordings, and it never saves recordings or turn logs as user-visible conversation history. To make a safe retry return the same result instead of running the model twice, completed Speak, Translate, Transcribe, generated-audio and workspace Converse responses may remain in a session-bound replay cache for up to 10 minutes. Workspace-microphone Converse keeps its recognized message and reply, and typed Converse keeps its typed question and reply, in the bounded 30-day operational quality/cost log described above. Legacy realtime Voice and Transcribe results are not added to that turn log. It does not access contacts, location or unrelated device content. Microphone access stops when you press the microphone again, close the page or end the browser session.
Saved notes on this device (optional, off by default)
If you explicitly change Saved notes from Off to This device, you may bookmark an answer and its displayed source links in this browser. Those notes use browser storage only: Neuralis does not receive or sync them. Turning the setting off deletes the local note vault, and you can also delete individual notes or all notes from the Saved notes dialog. Clearing browser site data may delete them as well.
Low-data mode: while a voice session is open, the browser may keep up to three audio-only replies in bounded memory so you can replay them without another request. This cache is never written to browser storage and is erased when the voice session closes, when you return to Standard mode, or when the page closes.
Why and how long
We process voice data to provide the conversation you requested. Raw audio is held transiently for the active request and cleared when it closes unless you have opted into voice-clip contribution. Completed task responses become unavailable from the retry cache after at most 10 minutes and are then scheduled for automatic deletion; they are also cleared when that session is revoked or the account is deleted. Encrypted long-form Speak input and its private generated WAV expire after at most one hour and are reclaimed by the job sweeper. Voice and typed Converse turns also use the 30-day operational log described above; Transcribe results do not enter that longer-lived log. Login tokens expire after 15 minutes, sessions after seven days and rate-limit records after their configured window. Account preferences remain until you delete the account.
Your controls
Voice requires an account, acceptance of this notice and Cloud help set to This session. You can stop the microphone immediately, change the preference, unsubscribe from product updates, switch voice-clip contribution on or off, manage or delete device-only notes, export account information (including retained session records, voice-training purge status, still-retained operational Converse turns, signed-in issue reports, optional settings and developer records), sign out or permanently delete the account. The export uses opaque device identifiers and does not contain session credentials, CSRF hashes or internal account digests. Session cloud consent is cleared at sign-out and is not saved as a standing permission.
Service providers and safeguards
Account records, speech recognition and speech synthesis use Neuralis-operated infrastructure. Email is relayed through the configured mail provider using TLS. Generated answers may be processed by Google Gemini, with Anthropic available as an operational fallback. Provider keys and Studio credentials are never sent to the browser.
Contact
Questions or deletion problems can be sent to hello@neuralis.it.com. Material changes require a new notice version and renewed acceptance.