Privacy Policy

Your voice stays yours.

Last updated: 25 July 2026

This policy explains what Feo collects, why, who else sees it, and how to get rid of it. It covers the Feo app on the web, iOS, Android, macOS, and Windows, and the site at feo.loha.dev.

1. Who we are

Feo is a Malagasy speech product operated by Loharano. Loharano is the data controller for the personal data described in this policy.

You can reach us about anything on this page — access, correction, deletion, or a complaint — at privacy@feo.loha.dev. We answer within 30 days.

2. The short version

Your recordings and your text belong to you. We do not sell personal data, we do not use it for advertising, and we do not track you across other companies' apps or websites.

The free sample on our public pages runs without an account, and its audio is never written to storage.

Nothing you say is used to train our Malagasy models unless you have asked to join the contributor programme. It is off on every account by default.

3. Data we collect

Account data. When you sign in, our authentication provider gives us an account identifier and, depending on the sign-in method you choose, your name, email address, and profile picture. Passwords and Google credentials are handled by that provider and never reach our servers.

Speech and text. Audio you record or upload, the transcript produced from it, text you type for speech synthesis, the audio we generate from it, corrections you make to a transcript, and the conversations you have with the Feo assistant.

Usage data. Seconds of transcription and generated speech per month, session length, word counts, and your plan. The monthly counters survive content deletion so that deleting data cannot reset your allowance.

Support data. The message, plan, name, and email address you include when you open a support ticket from inside the app.

Technical data. Standard request information — IP address, approximate region, device and browser type, timestamps — processed by our infrastructure provider to deliver the service and to block abuse.

Product counters. Aggregate counts of events such as "a sample was started" or "a transcript was returned", recorded with a page and a language and no account identifier.

We do not collect your contacts, precise location, photos, health data, or advertising identifiers.

4. The free sample, without an account

The sample on our public pages sends one short recording to our transcriber and returns the text to your browser. The audio is not written to storage and the transcript is not attached to any account.

Because that endpoint is open, we rate-limit it by IP address. The IP address itself is not stored: within a short time window it is converted into a keyed one-way hash, and only that hash is used as a counter key.

5. Microphone access

Feo asks for the microphone only when you start a recording, and capture stops when you stop. Feo never listens in the background. Refusing the permission disables recording and nothing else.

6. The Feo keyboard on iOS

Feo includes an optional Malagasy keyboard you can enable in iOS Settings. It needs Full Access, because a keyboard extension cannot reach the network without it, and Feo transcribes speech on our servers rather than on your device.

The keyboard sends only what you dictate: microphone audio, streamed to our transcriber, with your account token so the minutes count against your plan. The transcript comes back and is inserted where you are typing.

The keyboard does not send us what you type. It reads the single character immediately before the cursor, so it knows whether to add a space before inserting a transcript, and that character never leaves your device. Feo does not log keystrokes, and does not read or transmit the contents of the field you are typing in.

The keyboard uses the sign-in token your Feo app already stored, shared between the app and the keyboard on your device only. If you never grant Full Access, or never enable the keyboard, it captures and sends nothing.

7. How we use your data, and the legal basis

To transcribe your speech, generate speech from your text, and answer your questions about a transcript — necessary to perform our contract with you.

To show your history and let you replay audio — necessary to perform our contract with you.

To meter usage and enforce plan limits — necessary to perform our contract with you.

To keep the service available: rate limits, abuse prevention, and debugging — our legitimate interest in a working, non-abused service.

To improve reliability using aggregate counters that are not linked to an account — our legitimate interest.

To improve open Malagasy speech models using contributed recordings and corrections — your consent, given by enrolling, and withdrawable at any time.

To answer support requests — necessary to perform our contract with you.

To meet legal obligations where they apply.

8. Malagasy model improvement is opt-in

Feo builds open Malagasy speech models. Your recordings, transcripts, and corrections are used for that only if you are enrolled in the contributor programme.

Enrolment is off by default and is not something the app turns on by itself. We enable it on an account only after you ask us to and agree to it, by writing to privacy@feo.loha.dev.

While you are enrolled, a contributed item stores the recording, the model's suggestion, and your correction, linked to your account so that it can be withdrawn later.

You can leave at any time by writing to privacy@feo.loha.dev. Leaving stops new contributions. Deleting your data marks your past contributions as revoked and excludes them from future training runs. Model versions already published before you withdrew cannot be un-trained, but no new model is trained on withdrawn data.

If you are not enrolled, none of your speech is used for training.

9. The Feo assistant and third-party AI models

When you use the assistant or ask a question about a transcript, that message and the relevant transcript text are sent through our gateway to a third-party model provider — OpenRouter, currently routing to Google Gemini — which generates the reply.

Only the text needed to produce the reply is sent. Your account identifier, your email address, and your audio are not.

Speech recognition and speech synthesis do not use a third-party assistant model. They run on Feo's own Malagasy models on GPU infrastructure we rent.

10. Who else processes your data

Clerk — authentication and account identity. United States.

Convex — application database holding transcripts, conversations, tickets, and usage counters. United States.

Cloudflare — API gateway, audio storage, rate limiting, and aggregate product counters. Global edge network.

Modal — GPU hosting for Feo's own Malagasy speech recognition and speech synthesis models. United States.

OpenRouter and Google — assistant replies, from the text described in the assistant section above. United States.

Each of these processes your data only on our instructions, under terms requiring protection at least equal to this policy. We do not sell personal data and we share nothing with advertisers or data brokers.

We may disclose data if we are legally required to, or to protect the rights and safety of our users. If Feo is ever transferred to another operator, this policy travels with the data and we will tell you before anything changes.

11. Where your data goes

Feo is used mainly in Madagascar, while our providers operate mainly in the United States and on global edge networks. Using Feo therefore transfers your data outside Madagascar.

Where the GDPR applies, those transfers rely on the European Commission's standard contractual clauses agreed with each provider.

12. How long we keep things

Free sample audio: not retained at all.

Transcripts, generated text, and assistant conversations: until you delete them or delete your account data.

Replay audio in your account: 7 days on Free, 90 days on Roso, 365 days on Feno, then deleted automatically.

Contributed recordings and corrections: kept while you are enrolled, and revoked from future training when you delete your data.

Monthly usage counters: kept for the current and past months so that deletion cannot reset a plan allowance.

Support tickets: until the request is resolved, and removed with your account data.

Aggregate product counters: kept in aggregate only, with no link to an account.

13. Your rights

You can ask for a copy of your data, correct it, delete it, take it elsewhere, object to or restrict a use, and withdraw a consent you gave. Withdrawing consent does not undo processing that was lawful before you withdrew it.

Transcripts and generated audio can be copied and exported directly from the app at any time.

Write to privacy@feo.loha.dev to exercise any of these. If you are in the EU or the UK you can also complain to your national data protection authority.

14. Deleting your data and your account

In the app, open the Source dialog, then Privacy, then "Delete account data". This deletes your sessions, transcripts, uploaded and generated audio, assistant conversations, support tickets, and contributed recordings, and revokes past contributions from future training. Monthly usage counters remain, so that a deletion cannot reset your plan allowance.

To delete the account itself, including your sign-in identity, write to privacy@feo.loha.dev from the address on the account. We complete the deletion within 30 days and confirm when it is done.

You can request deletion by email without installing or opening the app.

15. Children

Feo is not directed to children under 13 and we do not knowingly collect their data. Where local law sets a higher age of digital consent — 16 in parts of the European Union — users below that age need a parent or guardian to consent.

If you believe a child has given us personal data, write to privacy@feo.loha.dev and we will delete it.

16. Security

Traffic between your device and Feo is encrypted in transit. Your audio and transcripts are reachable only through your authenticated account, and access to production systems is limited to the people who need it.

No system is perfectly secure. Where the law requires it, we will notify you and the competent authority of a breach that affects your data.

17. Advertising and tracking

Feo shows no advertising, contains no advertising SDK, and does not track you across other companies' apps or websites. Our iOS build declares no tracking, and we do not use advertising identifiers.

18. Changes to this policy

We post every change on this page and update the date at the top. If a change materially affects how we use data you already gave us, we will tell you in the app before it takes effect.

19. Contact

Loharano — privacy@feo.loha.dev

Feo, Malagasy speech workspace. feo.loha.dev