Last updated: 30 August 2026
1. Who we are
EPSpeak (“EPSpeak“, “we“, “us“, “the app“) is a voice-wellness application operated by MANOAI Pty Ltd (ABN 48 689 793 244, ACN 689 793 244) (“the operator”), of Capital Square Towers, Level 25, Tower 3, 1 Spring Street, Perth, WA 6000, Australia (www.manoai.ai). This policy explains what personal data the app collects, why, how it is stored and protected, and the choices and rights you have.
For any privacy question or request, contact us at admin@manoai.ai.
2. EPSpeak is a wellness app, not a medical device
EPSpeak helps you record daily voice samples and track wellness, medication, and voice-pattern trends over time for your own personal awareness. It does not diagnose, treat, cure, or prevent any disease or condition, and the scores it shows are not a medical assessment. Always consult a qualified healthcare professional about any health concern. Do not use EPSpeak for emergencies.
3. What data we collect
You provide most of this data directly by using the app; some is generated automatically by your device when you record or sync.
Data you create in the app
- Voice recordings. When you record a voice sample, the app captures an audio file (WAV) of you reading a short affirmation aloud. This is the core input the app analyses.
- Voice-analysis results. Acoustic “biomarker” values and a Combined Voice Change Score (0–100) derived from your recordings.
- Wellness check-ins. Your answers (each 0–3) to six self-report wellness questions, the total score, and an optional flag indicating you reviewed the check-in with your clinician.
- Medication log. Medications you choose to record: name, dosage, frequency, and dates of changes.
- Medication reminder responses. If you turn on reminders, each time you tap Taken or Skip we record which medication it was and when you tapped, so the app can tell how a recording relates to your dosing.
- Mood/context labels. An optional emotion and intensity you select before recording, and the text and language of the affirmation you read.
Data collected about you
- Motion-sensor readings. While — and only while — a voice recording is in progress, the app reads your phone’s accelerometer and gyroscope. It uses these to estimate how steadily you are holding the device: measures of tremor (how much the phone oscillates, and at what frequency) and of movement (how much and how smoothly you move while reading). The raw sensor stream never leaves your phone and is never stored — only these summary measures are uploaded, attached to the recording they were taken during. Sensing starts when you start recording and stops when the recording stops.
- Health and activity data from a connected wearable (optional). If you choose to connect a fitness tracker, we access your data through the Google Health API, with your separate consent given on Google’s own screen. We read daily and per-minute step counts, distance walked, recorded exercise sessions, sleep stages, heart rate and heart-rate variability, and from these derive daily movement summaries. Connecting also has to be approved for your Google address before it will work; that is arranged with the research team. You can disconnect at any time in Settings, which deletes our stored access to your Google account. If you never connect a tracker, none of this applies.
One of the permissions we must request is broader than what we use. To read heart rate and heart-rate variability, the Google Health API offers no narrower permission than googlehealth.health_metrics_and_measurements.readonly, which also grants access to other health metrics — body weight, blood pressure and blood glucose among them. Google’s consent screen will therefore describe more than we actually read. We do not request, read, derive from or store any of those other metrics; the app has no code that reads them. We are telling you this because the consent screen cannot.
- Demographic information. Provided once at first launch: sex, age range, country, and the type of medication you tell us you take.
- Identifiers. On first launch the app signs you in anonymously via Firebase Authentication and receives a randomly generated user ID (“uid”). This uid links your data to your installation. The app also derives a non-reversible hashed identifier from it. We do not collect your name, email address, phone number, or precise location.
- Device and technical information. Operating-system name and version, app version, and recording-quality metrics (e.g. signal level, noise estimate).
Data we do not collect
- No name, email, phone number, contacts, or precise/GPS location.
- No advertising identifiers, and we do not use the app for advertising.
4. How we use your data
We use the data above only to:
- Analyse your voice recordings and produce your voice-pattern scores;
- Show you your trends, wellness history, and medication log over time;
- Establish and refine your personal baseline so scores are meaningful for you;
- Maintain and improve the reliability of the app (e.g. distinguishing genuine recordings from offline-fallback estimates, diagnosing recording quality);
- Relate a recording to its context — where it falls in your dosing cycle, what your recent check-ins said, what you are taking — so that a change in your readings can be interpreted rather than just observed;
- Support the possible future development of voice-analysis models, using the data you have provided under this policy. Research use is limited to subjects who have separately and explicitly enrolled in the pilot study. Enrolment is done by us, by hand, for a named subject who has consented to it; it is not something an ordinary installation is placed into by default, and ordinary use of the app never contributes to model training.
- Produce aggregate statistics about how the app is being taken up: how many installations there were in a given month, from which countries, and their age band, sex and medication-type distributions. These are counts and nothing else. They carry no identifier, and each figure covers a single characteristic rather than a combination of them, so no figure describes a small enough group to point at anybody. Because they are not personal data they are not deleted with the rest of your records — see Section 8.
We do not sell your personal data, and we do not use it for third-party advertising or profiling unrelated to the app’s function.
5. Legal bases and applicable law
The operator is an Australian company, so the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to everything described here. Under the Act, health information — which is what voice recordings, motion measures, wearable data, wellness answers and your medication log are — is sensitive information, and APP 3 permits us to collect it only with your consent and only where it is reasonably necessary for our functions. That is why consent is requested up front, before any collection, rather than assumed.
Where UK/EU data-protection law also applies, we rely on:
- Your consent, which you give at onboarding before any data is collected, and which you can withdraw at any time (see Section 9); and
- Our legitimate interests in operating and securing the app.
Voice recordings, motion-sensor measures, wearable health data, and wellness and medication entries constitute health data / special-category data. We process them on the basis of your explicit consent, given at onboarding (and, for a connected wearable, given separately on Google’s consent screen).
A note on biometric data specifically. A voice recording is capable of identifying you, and we analyse its acoustic characteristics; the same is true in principle of how you hold and move a device. We do not use either to identify or authenticate anyone, and we operate no voice- or motion-matching system — the analysis measures change in your own readings over time against your own earlier ones. Some jurisdictions nonetheless treat data of this kind as biometric regardless of that purpose, so we treat voice and motion data as special-category health data throughout this policy and process them only with your explicit consent.
6. Where your data is stored and how it is protected
Your data is stored using Google Firebase / Google Cloud Platform services (Firebase Authentication, Cloud Firestore, and Firebase Storage), which act as our data processor. Google may store and process data on infrastructure located outside your country, including in the United States.
Protections in place:
- Data is transmitted over encrypted connections (HTTPS/TLS) and encrypted at rest by Google Cloud.
- Access is scoped by security rules so that each installation’s data can only be read or written by that same signed-in user; one user cannot access another user’s data.
7. Sharing and disclosure
We do not share your personal data with third parties except:
- Service providers who process data on our behalf and under our instructions (currently Google, for the Firebase/Cloud services above);
- Where required by law, legal process, or to protect rights and safety.
We do not sell your data and we do not share it with advertisers or data brokers.
8. How long we keep your data
- Voice recordings (the audio files themselves) are deleted after 7 days unless you are an enrolled pilot-study subject. A scheduled job runs daily and removes them. If you are not in the study — which is the ordinary case — we do not keep your recordings; we keep only the scores derived from them.
- If you are not an enrolled pilot-study subject — the ordinary case — we delete everything else we hold for you once you have been inactive for 30 days. A scheduled job runs daily, finds the most recent dated record we hold for your installation, and if it is older than 30 days it removes the whole of your data: voice-analysis results, motion measures, wellness entries, medication entries, wearable summaries and demographics. There is nothing to opt into and nothing to switch off. Note what this means in practice: your cloud history is kept while you are using the app, and is cleared if you stop. The trends held on your own phone are not affected by this job.
- For enrolled pilot-study subjects, that data is retained for as long as your installation exists and you continue to use the app, so long-term trends can be seen.
- If you delete your data or request deletion (Section 9), we delete it as described there.
- An account we hold no dated record for is kept rather than removed, because we cannot tell how old it is.
- Aggregate counts are kept indefinitely, and they are not your data. When your installation is first seen we add 1 to a handful of running totals — how many installations that month came from your country, how many fell in your age band, and so on. Each total covers one characteristic on its own, never a combination, and none of them records an identifier. Note what follows from that, because it is the honest consequence rather than a loophole: deleting your data (Section 9) removes everything we hold about you, but it cannot decrement a total that no longer refers to anyone in particular. Nothing about your medications, your recordings, your check-ins or your movement data enters these totals.
9. Your rights and choices
Depending on where you live, you may have the right to access, correct, export, restrict, or delete your personal data, and to withdraw consent.
- Delete all your data (in-app). Go to Settings → Privacy & data → Delete my data. This permanently and immediately erases all of your data — voice recordings, scores, wellness check-ins, medication log, and demographics — from both your device and EPSpeak Cloud, and issues your installation a new anonymous identifier with a fresh start. Because the app uses an anonymous account tied to your device, you can perform this yourself without contacting us and without providing any identity. This action cannot be undone.
- On-device controls. You can also reset just your voice baseline in Settings without deleting everything.
- Access or export. Because we do not collect an email or identity, we cannot look your data up by name. For any access/export request, or if the in-app deletion fails, contact admin@manoai.ai; we will respond within 30 days (we may need information to help locate your data).
- Withdraw consent. You can withdraw consent at any time by deleting your data as above and discontinuing use of the app.
- Complaints (Australia). If you are not satisfied with how we have handled your personal information or a privacy complaint, you may complain to the Office of the Australian Information Commissioner (OAIC) — oaic.gov.au, 1300 363 992. We ask that you contact us first so we have an opportunity to resolve it.
10. Children’s privacy
EPSpeak is intended for users aged 16 and over and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
11. International data transfers
As noted in Section 6, your data may be processed in countries other than your own, including the United States. Where required, we rely on appropriate safeguards (such as Google Cloud’s standard contractual clauses) for these transfers.
For Australian users this is a cross-border disclosure under APP 8: we disclose your personal information to Google (Firebase / Google Cloud) as our processor, and it may be held on infrastructure outside Australia, including in the United States. We take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles.
12. Changes to this policy
We may update this policy from time to time. We will post the updated version here and change the “Last updated” date. Material changes will be brought to your attention within the app where appropriate.
13. Contact us
MANOAI Pty Ltd — ABN 48 689 793 244, ACN 689 793 244
Capital Square Towers, Level 25, Tower 3
1 Spring Street, Perth, WA 6000, Australia
Web: www.manoai.ai
Email: admin@manoai.ai
