Hearleaf Back to Hearleaf

Privacy Policy

Hearleaf Privacy Policy

Effective date: August 23, 2026. This policy explains how Hearleaf handles information in the Hearleaf mobile app, signed-in web Studio, and the cloud services that support storage, audio preparation, voice authorization, authentication, quota, and abuse prevention.

Short Version

Hearleaf turns photographed pages and manually entered creator scripts into private, cached audio. Voice recordings, photographed pages, extracted text, scripts, and generated audio are personal data. Android stores its working Library and Studio projects on that device. Signed-in web Studio privately stores voice profiles, scripts, generated audio, and playback state with your account so they can sync between supported browsers.

We do not sell your personal data. We do not use your voice recordings, page images, scripts, or generated audio for advertising or to train models.

Who We Are

Hearleaf is a voice workspace for web and mobile that helps people turn photographed pages and manually entered creator scripts into AI-generated speech. Hearleaf is the product name. Prathmesh Palande is the developer identified in the Google Play listing and operates the current Hearleaf Open Testing release.

Privacy questions and deletion requests can be sent to palande.prathmesh@gmail.com. You can also use the developer contact channel shown in the Hearleaf Google Play listing.

Information We Access, Collect, Or Process

Depending on how you use the app, Hearleaf may access, collect, or process the following information:

App Permissions

Hearleaf requests microphone access in the mobile app and web Studio only when you choose to record a voice profile. The mobile app requests camera access so you can photograph pages and optional cover images. Android builds may also request vibration permission for local touch feedback.

Hearleaf does not use microphone or camera permissions for background advertising, background tracking, or unrelated profiling.

How We Use Information

We use information to provide and protect Hearleaf, including to:

Where Information Is Stored And Processed

Your voice profiles, recordings, book library, creator projects, page images, script text, generated audio, playback progress, and related app state are primarily stored locally on your Android device. Signed-in web Studio stores profile clips, project and block data, generated audio, and playback state in private Google Cloud and Firebase storage associated with your Firebase user ID.

Some features require cloud processing. Voice authorization sends the one-time challenge recording to Hearleaf's private GPU processor for blind phrase verification. Standard page text detection runs on your device. For page or Studio-block audio preparation, the app sends the text you reviewed or entered, the active voice-profile version identifier, and the selected authorized voice reference through a secured gateway for speech synthesis. The standard path does not upload the page image. If you explicitly choose Improve text detection, Hearleaf also sends that page image through the secured gateway for private hosted OCR and subsequent audio preparation. These requests are transmitted over HTTPS.

Hearleaf uses Google Cloud and Firebase as service providers for Google and anonymous authentication, App Check, quota, page-job queueing, private temporary and durable web-account storage, service logs, and hosted OCR and speech-synthesis processing. When product measurement is enabled, Firestore also stores pseudonymous event receipts, identity membership, and aggregate counters that are available only through an owner-local console.

Hearleaf's current durable web Studio storage and primary processing services run in Google's us-east4 region in the United States. Authentication, App Check, DNS, logs, and other managed-service control data may be processed in other locations used by Google under its service terms.

Public page-processing status uses delayed, rounded, sanitized job metadata. Country or region appears only as aggregate buckets after enough completed jobs share the same coarse device-region code.

How Information Is Shared

We do not sell personal or sensitive user data. We share information only in limited ways needed to operate the app:

Retention And Deletion

Local app data remains on your device until you remove it. Use the app's available delete controls for individual books, projects, pages, script blocks, or voice profiles. To remove all Hearleaf data stored by that installation, clear Hearleaf's app storage in Android settings or uninstall the app. This includes local profiles, recordings, books, projects, page images, scripts, cached generated audio, and temporary exports.

Android Studio share files are held only in the app cache. Hearleaf removes stale share copies after 24 hours, and Android may reclaim cached files sooner when storage is needed.

Web Studio voice-profile clips, projects, scripts, generated audio, and matching playback state remain in private account storage until you delete the related block, project, voice profile, generated audio, or account. Clearing generated audio preserves scripts and profiles. Browser audio caches are temporary and are cleared for that account at logout or deletion.

When you delete a web profile, block, project, generated-audio set, or account, the live data becomes inaccessible immediately. Hearleaf targets physical deletion of the related private objects within 24 hours and automatically retries incomplete cleanup. Temporary processing and export objects are normally removed sooner and have a maximum seven-day lifecycle fallback. Hearleaf does not retain assembled preview files, export history, or a permanent duplicate of an export.

Voice-challenge recordings are processed in request-scoped temporary storage by the private GPU service and are not intentionally kept after the request finishes.

Page-preparation request artifacts are private temporary objects. Request artifacts are normally deleted after a job succeeds or reaches terminal failure. Result artifacts are normally deleted after the app downloads the result and acknowledges it. If a job does not reach a terminal state or result acknowledgement is missed, its private artifacts become eligible for asynchronous lifecycle deletion after 7 days; the cloud provider may complete that deletion later.

Provider-controlled deletion and shared-storage garbage collection can complete after Hearleaf removes an object from its active namespace. Ordinary Hearleaf users cannot access provider-restricted recoverable copies.

Firebase, Firestore, Pub/Sub, Cloud Run, and other operational systems may retain authentication identifiers, quota records, queue metadata, request metadata, service logs, and error logs according to their configured retention behavior. Ordinary operational logs are retained for 30 days; Google Cloud required audit logs may be retained for 400 days. Those logs are designed not to contain voice or script content, Google name or email, or raw Firebase user IDs. Current quota and usage records are designed to expire after about 90 days.

Product-metric event receipts and aggregate counts may be retained so admitted and successful audio-generation totals and exact processing-time measurements can be reconstructed. Versioned one-way Firebase identity membership is retained until the related account-deletion workflow or an explicit metric reset. Deletion removes that linkable membership while preserving only its already-counted, non-user-level aggregate contribution; a later new Firebase identity may count as a new identity instance.

Web Studio provides Delete account after a fresh Google confirmation; it makes account data inaccessible and queues deletion of voice clips, projects, scripts, generated audio, playback state, per-account live and lifetime generation counts, quota, and linkable product-metric membership, then deletes Firebase Authentication last. A durable deletion marker blocks account reuse and safely retries partial deletion until Firebase confirms completion. Android clearing or uninstalling removes local data but does not by itself submit a server-side deletion request. To request manual deletion of server-side anonymous-identity, quota, product-metric membership, or operational records that can be reliably associated with your installation, email palande.prathmesh@gmail.com with the subject “Hearleaf deletion request” and describe the records you want removed. Do not attach page images, extracted text, voice recordings, or generated audio. We may need to ask for limited diagnostic information to locate the relevant records, and we will explain when records cannot be reliably linked to an anonymous installation. Some records may be retained where needed for security, fraud prevention, legal compliance, dispute resolution, or infrastructure integrity.

Voice Consent And AI-Generated Audio

Voice recordings are sensitive. Hearleaf is intended for your own voice, or for a voice you have explicit permission to use. Do not record or use another person's voice without their consent.

Generated speech is synthetic AI audio. If you share or publish generated audio outside the app, you are responsible for permission to use the underlying voice and source material and for any AI-generated-audio disclosure required by the destination platform.

Children

Hearleaf is not currently designed as a child-directed app. If child-directed or family account features are added later, this policy and the app's consent, safety, and deletion controls will be updated before those features are offered.

Security

Hearleaf uses HTTPS, Firebase Authentication, Firebase App Check, a secured gateway, quota checks, private Cloud Run services, and private temporary artifact storage to reduce unnecessary exposure of sensitive voice and page data. No app or internet service can guarantee perfect security. Temporary processing artifacts are minimized, while web Studio retains the synced content you choose until you clear or delete it.

Changes To This Policy

We may update this policy as Hearleaf changes. Material updates will be reflected by a new effective date and revised policy text at this URL.