the box — privacy policy

Effective date: July 12, 2026 · Last updated: July 12, 2026

In plain English

We built the box because most AI products are surveillance products that track, collect, and share your data and information. The box isn’t one of those.

  • Your conversations stay on your box.They live on the box’s own storage — not on our servers — and can only be reached by signing in with your passphrase. We don’t have copies.
  • There is no server that watches what you ask.We can’t see your chats. There is no connection between your box and our systems.
  • The box doesn’t run telemetry or analytics. We don’t know how often you use the box, what you ask it, or whether you’ve used it on any given day. (Our website does use analytics — see Section 3 — but it can’t see anything on your box.)
  • The only data that reaches us is what you explicitly send. That should only be the support emails you write us (if any) and the order data from when you bought the box. That’s the entire list.
  • You can wipe everything by holding the power button for 15 seconds. That’s not just a marketing line — it’s the only recovery path. We can’t restore your data because we never had it.

The rest of this document is the long version of those five bullets, in the order a careful reader would ask the questions.

1. What data the box collects, and where it lives

The box collects and stores the following, on the box itself, not on our servers:

  • Conversations with the AI— the messages you send and the AI’s responses. Stored in the on-box memory system (Mnemosyne) and the AI’s chat log, on the box’s own storage. Access is gated by your passphrase; the plaintext of your passphrase is never stored (see Section 12).
  • Settings and preferences— your box name, your Wi-Fi configuration, which integrations you’ve connected.
  • Paired devices — a list of phones and laptops that have signed in with your passphrase.
  • Your passphrase, as a bcrypt hash.The plaintext passphrase is never stored — we couldn’t recover it if we wanted to.
  • Third-party service credentials (only if you connect a service that uses them) — access tokens for any outside service you link. Stored on the box and used only to talk to that service on your behalf. (Gmail and calendar connections are not available in the current version; this covers such services as they become available.)
  • Tailscale and Signal account material (only if you link them) — see Section 2 for what those services see.

All of this lives on the box’s local storage. None of it is uploaded to VoxCura.

2. What data the box transmits, and where it goes

The box has a small, deliberate list of outbound connections. Here is the complete list of connections the box makes with your data or on your behalf (as configured when it is delivered to you):

  • Signal Messenger (only if you enable it). If you link your box to Signal so you can chat with it from anywhere, messages flow through Signal’s encrypted network. Signal is end-to-end encrypted; Signal can’t read your messages, and neither can we. Signal’s own privacy policy (signal.org/legal) governs what Signal sees.
  • Tailscale (only if you enable it). Tailscale lets you reach your box from your phone or laptop when you’re not on your home network. The box joins your Tailscale “tailnet.” Tailscale Inc. coordinates the connection (the control plane — which devices are online, what their addresses are) but does not see your actual traffic (the data planeis encrypted point-to-point between your devices). You’ll need a Tailscale account; Tailscale’s privacy policy (tailscale.com/privacy-policy) governs what they see. We don’t receive anything from Tailscale.
  • Third-party services you connect (as they become available). When you link an outside service, the box talks directly to it using credentials you authorized. Those services have their own privacy policies. We’re not in the middle— there’s no proxy. (In the current version, the services you can connect are Signal and Tailscale, both described above.)
  • Daily version check. Once per day at a randomized time, the box asks https://updates.arxupdates.com/halo/stable/latest.json whether a new version is available. The request sends only the version your box is currently running (in the User-Agent header). It does NOT send a box identifier, your IP-derived location, your usage, or your conversation data. The request reaches a CDN edge — standard CDN access logs at the edge include your IP and request path, retained 30 days, and we use them only to troubleshoot delivery problems. You can turn the daily check off in Settings → Updates. With it off, you can still check for updates manually from the same page.
  • Optional anonymous reports (off by default). If — and only if — you opt in at Settings → Updates, your box sends one report per week to https://telemetry.arxupdates.com/halo/v1/checkin containing:
    • the version your box is running
    • your hardware tier (tier_64 or tier_128)
    • a country code (set once at the time you bought the box, from your shipping address, NEVER recomputed from your IP)
    • how many days the box has been up since its last reboot
    • a random ID that rotates every time you toggle this setting off and back on

    We use this to know which versions are still in the field, so we know how urgently to ship security fixes and when an old version can be retired. This bucket does not contain conversation content, usage metrics, or anything that ties to you personally. You can turn it off any time; the moment you do, the random ID is destroyed.

Operating-system housekeeping.Like any internet-connected computer, the box’s operating system also makes routine background connections that are not about you: it syncs its clock (network time), checks whether it actually has a working connection, resolves website names (DNS), and — only after you approve a system update — downloads software packages from the Linux distribution’s mirrors. None of this carries your conversations, and none of it identifies you to us.

Apart from that operating-system housekeeping, the list above is everything the box sends. No telemetry to us unless you opt in. No analytics. No “improve our AI” data collection. Your conversations never leave the box unless you separately export them or set up your own networking or backups or storage options separate from VoxCura.

3. What we collect at VoxCura's servers

This is the data that actually is transmitted to, received, used, and stored by VoxCura:

  • Support emails you send us. If you email support@voxcura.io, that email lives in our email system. Stored per Section 7.
  • Order and shipping data from when you bought the box. Your name, the address we shipped to, the date, what you ordered, and a payment confirmation. We use Stripe to process payments — we don’t store your card number. Stripe does.
  • Daily version check requests (unless you turned that off).At the CDN edge, the box’s IP and the version it’s running. Retained 30 days in CDN access logs, then deleted.
  • Optional anonymous version reports (only if you opted in).The payload described in Section 2: version, tier, country, uptime, rotating random ID. Stored 30 days as raw rows, then aggregated to version-share counts that don’t identify individual boxes; raw rows deleted.
  • Website data — our marketing site and waitlist. This is separate from your box, and none of it comes from your box. We use PostHog for website analytics, and it stays off until you turn it on. The first time you visit we ask; nothing non-essential is written to your device and no analytics run unless you accept. This is the same for everyone, wherever you are — analytics are on by default nowhere — and you can change your answer at any time from the control on this page. If you accept, we collect standard usage data: the pages you view, the links and buttons you click, the page you arrived from, your browser and device type, and your approximate location from your country only (we have PostHog discard your exact IP address and precise location). All of it is anonymous. We do not record your name, your email, or anything you type; we do not build a profile of you; and we never tie this browsing to who you are — even if you go on to join the waitlist, none of your waitlist details are sent to PostHog. We do not record your screen or your session — there is no session replay. If you decline, none of this runs and nothing non-essential is stored. Either way, the site honors your browser’s Do-Not-Track setting, and our web host keeps standard server logs (IP address, browser type, pages requested, timestamps) to keep the site running and secure. Separately, if you join the waitlist we collect your first and last name, email address, phone number (optional), the intents you select, any free-text description of your interest you choose to give us, your stated level of interest in our baseline and enhanced offerings, and whether you’d be willing to place a deposit. Those details go to our own systems, not to PostHog, and we only email you updates about the box if you tick the box asking us to.

That’s it.We have no “conversations” database and no record of what you ask your box or when you use it — those things don’t exist on our infrastructure because your box never sends them to us. We do keep the customer and waitlist records listed above, and if you joined our waitlist those are tied to your email address — but our website analytics stay anonymous and are never linked to you. What none of these records contain is anything about what you do on your box.

4. What we do NOT collect

To say it directly:

  • Your conversations with the AI — they stay on your box.
  • What you ask the AI — same reason.
  • Who you pair with or talk to through Signal — Signal handles that end-to-end.
  • When you use the box, for how long, or how often— there’s no “session start” event sent anywhere.
  • What’s on your home Wi-Fi— the box doesn’t scan your network. It joins one network, and that’s all.
  • Your location— beyond the IP address you connect from, we don’t track location.
  • Anything from third-party services you connect — those services give the box access; the data flows between the box and the service, not through us.

5. How we use what we do collect

  • Support emails:to answer you. We don’t use them to train AI, and we don’t share them.
  • Order and shipping data: to ship your box, process returns, and meet accounting and tax requirements.
  • Daily version check requests: to deliver the right update manifest to your box. Aggregate counts of versions-still-in-the-field inform how urgently we ship security fixes.
  • Optional anonymous version reports (if you opted in): same purpose as above — version distribution and uptime patterns across our entire customer base, never tied to individuals.
  • Website logs / analytics: to keep the site working and secure, and — only if you accept analytics — to understand how people find and use the site. The analytics are anonymous and are never tied to you. Joining the waitlist is separate: that is how we follow up with you, and those records are tied to your email address.

We don’t sell, rent, or trade any of this to third parties for advertising or other purposes.

6. Who we share data with

The full list of parties who ever see any data:

  • Payment processor — Stripe, Inc.Receives your payment details when you buy the box. They handle card data so we don’t have to. Their privacy policy applies to that data.
  • Shipping carrier (USPS, UPS, FedEx, etc.). Receives the shipping name and address. That’s it.
  • Email hosting provider — Hostinger (our support inbox). Stores support emails you send us.
  • Update-delivery and telemetry CDN — Cloudflare, Inc. Cloudflare fronts updates.arxupdates.com (daily version checks + update artifacts) and telemetry.arxupdates.com (the opt-in anonymous reports endpoint). They see request metadata (IP + URL path), retained 30 days in edge logs, used only for delivery troubleshooting. Their privacy policy (cloudflare.com/privacypolicy) applies to those records.
  • Tailscale Inc. (only if you choose to enable Tailscale on your box).They coordinate your remote-access tailnet. They see connection metadata; they don’t see your traffic. You have a direct account with them — we’re not in the loop.
  • Signal Messenger LLC (only if you choose to link Signal).They deliver your messages end-to-end encrypted. They don’t see content. We’re not in that loop either.
  • Website analytics provider — PostHog. If you accept analytics, receives the anonymous website-usage data described in Section 3. It never receives your name, email, phone number, anything you type, or any recording of your session, and nothing from your box reaches it.
  • Website hosting and storage — Amazon Web Services, Inc. Hosts the site and stores waitlist signups, on US infrastructure.
  • A future buyer of the business. If VoxCura is acquired, merges with another company, or sells the part of the business the box belongs to, the records described in Section 3 may transfer to the buyer as part of that deal. We would require them to keep honoring this policy for data collected under it, and we would tell you before your data became subject to a different one.
  • Law enforcement— only when legally compelled by a valid subpoena, warrant, or court order, and only the data described in Section 3. We can’t hand over conversations we don’t have.

That’s the complete list. We are not in the business of sharing your data with anyone else.

7. How long we keep what we collect

  • Support emails: 2 years from the last reply, then deleted.
  • Order and shipping data: 7 years (US tax records requirement).
  • Daily version check logs: 30 days at the CDN edge, then deleted.
  • Optional anonymous version reports: 30 days as raw rows, then aggregated to anonymous counts with no per-box rows retained.
  • Website logs: 30 days.
  • Website analytics events:retained for up to 7 years. (We don’t record sessions, so there are no recordings to keep.)
  • Waitlist records:until your box ships and we’ve finished waitlist outreach, or 24 months from the last time you heard from us or replied to us, or until you ask us to delete them — whichever comes first.

We may keep fully aggregated or anonymized data — counts that don’t identify any individual box or person — indefinitely.

If you ask us to delete your data (Section 8), we delete what we can with the exception of the above that we need to maintain for legal or other specified purposes.

8. Your rights

You have the following rights with respect to data we hold at VoxCura:

  • Access. Email support@voxcura.io and we’ll send you everything we have on you. (It will not be much.)
  • Correction.If something we have is wrong, tell us and we’ll correct it.
  • Deletion. Email support@voxcura.io to request deletion. We’ll delete what we can. We can’t delete order records before the 7-year tax retention period ends, for example; we can delete any personally identifying parts of older records.
  • Portability.Same email — we’ll send you a machine-readable export of what we have.
  • Objection. You can object to anything we do on the basis of our legitimate interests — Section 10 lists exactly which processing that is. If you object to marketing or follow-up contact, we stop. No balancing test, no exceptions.
  • Restriction.You can tell us to hold your data without using it — while we check a correction you’ve asked for, say, or while we work through an objection.
  • Withdrawing consent.Where we rely on your consent — website analytics, the marketing emails you opt into when you join the waitlist, and the box’s optional weekly report — you can withdraw it at any time, and withdrawing is as easy as giving it was. Withdrawing doesn’t make what we did beforehand unlawful; it stops what happens next.
  • No automated decisions about you.We don’t make decisions about you by automated means that produce legal or similarly significant effects, and we don’t profile you for that purpose.
  • Complaining to a regulator.In the UK, the Information Commissioner’s Office (ico.org.uk). In the EEA, the supervisory authority where you live, where you work, or where you think the problem happened. In the US, your state attorney general. We’d rather you came to us first, but you are not required to.
  • No retaliation.We won’t deny you a product, charge you a different price, or give you a worse experience because you exercised any of these rights.

Response time: within 30 days for most requests. If you are in the UK or the EEA, we will respond within one month, and if a request is complex enough to need up to two further months we will tell you inside that first month and say why. Requests are free— we would only charge for, or refuse, a request that is manifestly unfounded or excessive, and we’d explain the reason if that ever happened.

Verifying it’s you.Before we act on an access, correction, deletion, or portability request, we’ll take reasonable steps to verify your identity — usually by confirming the order email or details of your purchase. We may decline or delay a request where the law permits, where we can’t verify who you are, or where fulfilling it would compromise someone else’s privacy, conflict with a legal hold, or reveal confidential information.

On-box data is in your control directly.No request to us is needed. Factory reset (15-second power button hold) wipes the box’s storage. Individual settings can be cleared in the in-box admin pages.

9. Children

The box is sold to and intended for use by legally competent adults (18+). We don’t knowingly sell to or pair the box for children.

If you operate the box in a household with one or more children, that’s your call — but be aware:

  • The box has no cloud account that we manage on behalf of a child.
  • We do no content moderation beyond what you supervise.
  • The AI can be wrong, and may give a child a wrong answer with the same confidence as a right one.

If you believe we’ve received information about a child under 13 years old, email support@voxcura.io and we’ll delete it.

If you are in the UK or the EEA, the age at which you can agree on your own to an online service like our waitlist is 13 in the UK, and somewhere between 13 and 16 in the EEA depending on the country. If you’re under that age where you live, don’t submit the waitlist form without a parent or guardian — and if you already have, tell us and we’ll delete it.

10. Where you are

Most of this policy applies wherever you live. A few jurisdiction-specific notes:

  • California residents. You have the rights described in Section 8 under the California Consumer Privacy Act (CCPA / CPRA). We do not sell or share your personal information for cross-context behavioral advertising. We have not done so in the past 12 months and have no plans to.
  • Categories of personal information we collect (for CCPA/CPRA disclosure): identifiers (your name, shipping address, email, order number, and — at the CDN edge — the IP address you connect from); commercial information (what you purchased); and a narrow slice of internet/device activity (the daily version check, and, only if you opt in, the anonymous weekly report described in Section 2). Sources are you and your box. Purposes are those in Section 5. We do not collect biometric data, precise geolocation (beyond the IP address you connect from), or the contents of your conversations, and we do not sell or share any category.
  • Other US states. Where state privacy laws give you additional rights (e.g., Colorado, Virginia, Connecticut, Texas), those rights apply to you.
  • EU, UK, and Swiss residents. We do not sell the box outside the United States, and the box is intended for sale and use in the US only. But this policy is not only about the box. Our website is reachable from anywhere; we run analytics on it, and we accept waitlist signups from wherever people are. That is monitoring the behaviour of people in the EU and the UK, so the GDPR and the UK GDPR apply to the website processing described in Section 3 and to any support email or waitlist entry you send us — whether or not you ever buy a box. VoxCura LLC is the controller of that data.

The legal ground we rely on for each thing we do:

  • Website analytics (Section 3) — to understand how people find and use the site. Consent, Article 6(1)(a). It is anonymous, and nothing non-essential is stored on your device until you accept — the same for every visitor, wherever they are. You can withdraw at any time, and we do not record sessions.
  • Waitlist signup — name, email, phone, intents, free text (Section 3). We store your entry so we can keep your place and respond to what you told us — the steps you asked us to take before any purchase, Article 6(1)(b). We send you marketing updates about the box only if you tick the separate, unticked opt-in when you sign up: that part is consent, Article 6(1)(a), and you can withdraw it at any time.
  • Order and shipping data (Section 3) — to take payment and ship your box. Performance of a contract, Article 6(1)(b).
  • Keeping order records for seven years (Section 7) — US tax and accounting law. Legal obligation, Article 6(1)(c).
  • Support emails you send us (Section 3) — to answer you. Legitimate interests, Article 6(1)(f): replying to a question you chose to ask us.
  • Server logs, the origin allowlist, and the spam honeypot — to keep the site up and keep bots out. Legitimate interests, Article 6(1)(f): security and availability.
  • The box’s daily version check (Section 2) — to serve the right update and troubleshoot delivery. Legitimate interests, Article 6(1)(f): getting security fixes to devices in the field.
  • The box’s optional weekly report (Section 2) — to know which versions are still running. Consent, Article 6(1)(a). Off unless you turn it on, and off again the moment you turn it off.

We do not process special-category data (Article 9). We don’t ask for it and we don’t infer it. If you volunteer something health-related in a support email or the waitlist free-text box, we use it only to answer you.

  • Where your data goes.VoxCura is a US company and everything we hold is processed in the United States. Where we transfer EU, UK, or Swiss personal data to the US, we rely on the European Commission’s Standard Contractual Clauses(Decision 2021/914) and the ICO’s UK International Data Transfer Addendum, and on the EU–US Data Privacy Framework and its UK Extension where the provider in question is certified under it. The data involved is marketing-site analytics, a waitlist entry, or an order record. Ask us and we will tell you which safeguard covers a particular provider.
  • Our representatives in the EU and UK. We have no establishment in either, so under Article 27 of the GDPR and of the UK GDPR we have appointed a representative in each. EU representative: [EU-REP-TO-BE-APPOINTED]. UK representative:[UK-REP-TO-BE-APPOINTED]. You can raise anything in this policy with them instead of us, in your own language, and they will deal with us on your behalf. That doesn’t stop you contacting us directly or complaining to your regulator.
  • Your rights are in Section 8 — access, rectification, erasure, portability, objection, restriction, withdrawal of consent, and complaint to the ICO or your national supervisory authority. They apply in full.

If we begin selling the box outside the US, we’ll publish any further terms that requires and notify you 30 days before the change takes effect.

11. Health, finance, and other sensitive topics

The box is a general-purpose AI appliance, not a medical, financial, or legal advisor. See the Terms of Use and the Safe Use Guide for the full disclaimer.

For privacy specifically:

  • If you ask the box about your health, the question and the answer stay on the box. We don’t see either.
  • We are nota HIPAA Covered Entity or Business Associate with respect to your use of the box. Don’t treat the box as you would a doctor’s portal or a medical record — it isn’t one.
  • The same is true for anything you might ask about your finances, your taxes, or your legal situation. We don’t see it, and we don’t make any representations or warranties regarding any results you receive.

12. Security

On the box:

  • Your passphrase is stored as a bcrypt hash. The plaintext of your passphrase is never written to disk.
  • Your data lives only on the box’s own storage. Reaching it requires signing in with your passphrase, and the box’s files are protected by the operating system’s file permissions. The box is originally configured to not upload your data anywhere.
  • Remote access is off by default. You enable Tailscale or Signal only if you want it.

On our servers:

  • TLS in transit for everything (HTTPS).
  • Encryption at rest for stored data (support emails, order records).
  • Access logging.

Breach notification. If we confirm that personal data we hold has been compromised, we will notify affected users without undue delay and as required by applicable law — and we aim to do so within 72 hours of confirming the breach. Where the data belongs to people in the UK or the EEA, we will also notify the relevant supervisory authority within 72 hours of becoming aware, as Article 33 requires, unless the breach is unlikely to put anyone at risk. Because we hold so little, the impact of a breach is correspondingly small.

13. Changes to this policy and to the software on your box

We may update this policy over time. When we do:

  • The new version will be posted on the box and on our website, with an updated effective date.
  • For material changes, we’ll use our commercially reasonable efforts to give you at least 30 days’ notice through the in-box update channel (Settings → Updates) and on the website.
  • Continued use of the box after the effective date of an update means you accept the new policy.

The box may install software updates that you have explicitly approved through Settings → Updates. We never install updates silently. If you’ve scheduled an update for tonight, for example, the box will restart and reboot at the scheduled time, and you’ll see a confirmation when you next open the chat surface. You can roll back a failed update at any time from Settings → Updates.

14. Contact

For privacy questions, data requests, or anything else: support@voxcura.io.

Mail: VoxCura LLC, 221 Main St, Ste N, Nashua, NH 03060

If you are in the EU or the UK, you can contact our Article 27 representatives instead of, or as well as, us:

EU representative: [EU-REP-TO-BE-APPOINTED]

UK representative: [UK-REP-TO-BE-APPOINTED]

The box itself is sold to customers, and for use, in the United States only. These representatives are appointed because our website reaches people in the EU and the UK — not because the box does.