Legal · Effective August 2026

Privacy Policy

What we collect, what we never receive, and how to make us delete it.

This Privacy Policy describes how Gaavala ("we", "us", or "our") collects, uses, and protects information when you use our real-time meeting translation service available at gaavala.com (the "Service").

We are committed to protecting your privacy in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and Turkish Personal Data Protection Law (KVKK — Kişisel Verilerin Korunması Kanunu No. 6698).


1. Data Controller

The data controller responsible for your personal data is Gaavala, based in Turkey. For all privacy-related inquiries, contact us at: privacy@gaavala.com

2. Information We Collect

2.1 Account Information (via OAuth)

When you sign in with Google or Microsoft, we receive the following data from the respective identity provider:

We do not receive or store your OAuth provider passwords. We never request access to your calendar, emails, files, or any data beyond basic profile information.

2.2 Usage Data

We collect limited usage analytics to improve the Service, including:

2.3 Audio and Transcription Data

Audio is processed identically for both Free and Pro subscribers:

2.4 Voice Clone Reference Sample (Pro)

If you enable Speak Mode's personal voice clone (a Pro feature), you record a short voice sample of up to 20 seconds. This sample is biometric data. It is stored encrypted at rest on Gaavala's servers using AES-256-GCM and is used only to create and maintain your personal synthetic voice — never for identification, advertising, or any other purpose. The sample is processed by our speech provider, Soniox, to build your voice (see section 5). You can delete your voice at any time; deletion removes the recording, the synthetic voice, and its provider-side data (sections 6–7). Unlike meeting audio (section 2.3), which is never stored on our servers, this reference sample is deliberately stored so your voice can be reproduced across sessions — encrypted, purpose-bound, and erasable.

3. How We Use Your Information

We use the collected information to:

4. Cookies and Local Storage

4.1 Authentication Cookies

We use a single httpOnly, Secure, SameSite=Lax cookie to store your refresh token. This cookie is inaccessible to JavaScript and is used solely to maintain your session across browser restarts. It expires after 7 days or when you sign out.

4.2 Local Storage

We store your language preference (e.g., en, tr) in localStorage so the application remembers your chosen UI language. This data never leaves your device.

4.3 No Third-Party Tracking Cookies

We do not use advertising networks, retargeting pixels, or third-party tracking cookies.

4.4 Chrome Extension — Local Data

The Gaavala Chrome Extension stores the following data locally inside your browser using the Chrome extension storage API. This data lives on your device and is never transmitted to Gaavala's servers unless explicitly noted:

You can clear all of this data instantly by removing the extension from chrome://extensions/, by signing out (which clears tokens), or by using the "Delete account" flow in the extension settings (which also wipes the corresponding records from our servers as described in section 6).

5. Data Sharing and Third Parties

We share data with the following third parties only as necessary to operate the Service:

We do not sell your personal data to any third party. We do not share your data with advertisers.

6. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law (e.g., financial records for tax purposes, which we retain for 5 years as required by Turkish tax law).

Voice-clone reference sample and synthetic voice — retained until you delete your voice or your account; deletion is immediate and propagates to Soniox.

7. Your Rights

Under GDPR and KVKK, you have the following rights regarding your personal data:

To exercise any of these rights, contact us at privacy@gaavala.com. We will respond within 30 days.

8. Security

We implement the following technical safeguards:

9. International Data Transfers

Your data may be processed in countries outside Turkey or the European Economic Area (EEA) by our service providers (e.g., Vercel's infrastructure in the US). Where required, such transfers are governed by appropriate safeguards such as Standard Contractual Clauses (SCCs).

10. Children's Privacy

The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a new effective date. Continued use of the Service after changes constitutes acceptance of the updated policy.

12. Contact Us

For privacy-related questions, requests, or complaints, contact us at: privacy@gaavala.com

You also have the right to lodge a complaint with your local data protection authority. In Turkey, this is the Personal Data Protection Authority (KVKK — Kişisel Verileri Koruma Kurumu).