1 Who We Are
This privacy policy applies to WalkTalking, operated at walktalking.com. WalkTalking provides an embeddable voice comment widget ("VoiceBack") that enables readers to leave voice and text comments on web pages.
For any privacy enquiries, please use the contact details in Section 11 below.
2 What Data We Collect
We collect the minimum data necessary to provide the voice comment service:
| Data | Why we collect it | Legal basis |
|---|---|---|
| Anonymous user ID | Links your comments across sessions without requiring registration | Legitimate interest |
| Voice recordings (audio files) | To publish your voice comment on the article | Explicit consent (given before recording) |
| Text comments | To publish your text comment | Consent (submission = consent) |
| Transcription text | To make voice comments accessible and searchable | Consent (included in voice recording consent) |
| Page URL | To associate comments with the correct article | Legitimate interest |
| Emoji reactions | To display reaction counts on comments | Legitimate interest |
| Feature interaction events | Aggregate usage analytics — no personal identifiers stored | Legitimate interest |
We do not collect: real names, email addresses, stored IP addresses, device fingerprints, or payment information.
3 Voice Recordings
Voice recordings are the most sensitive data we handle. Here is exactly how we treat them:
- Consent first: The widget displays an explicit consent prompt before activating your microphone. You must agree before any recording begins.
- Stored securely: Audio files are stored on Railway infrastructure (US West region). Each file uses a unique randomised ID — it is not publicly guessable.
- Transcription: Voice recordings are transcribed to text using Groq's Whisper model to improve accessibility. The transcription is stored alongside your audio.
- No biometric profiling: We do not use your voice to identify you, build a voice profile, or link recordings to a personal identity.
- Deletion on request: You can delete your recording at any time (see Section 6).
4 AI Processing Disclosure
In compliance with the EU AI Act (Regulation 2024/1689), we disclose all AI-generated or AI-assisted content clearly in the widget:
- TLDR — Summarise: Article text is sent to Groq's Llama 3.3 70B model to generate a summary. Results are labelled "AI ✦" in the interface.
- ASK ME: Your spoken question and article text are sent to Groq's API for an AI-generated answer. Results are labelled "AI ✦".
- AI Enhance: Your typed comment text is optionally sent to Groq's API for grammar and clarity improvement. You choose whether to apply it before submitting.
- Transcription: Voice recordings are automatically transcribed using Groq's Whisper large-v3 model.
We do not use your data to train AI models. Data sent to Groq is processed under Groq's Privacy Policy.
5 Cookies & Tracking
We use a minimal cookie approach — strictly functional, no advertising:
- Anonymous session cookie: A JWT refresh token stored in an HttpOnly, Secure cookie. Required to maintain your anonymous session so your comments persist across page reloads. Expires after 7 days.
- No advertising or tracking cookies.
- UTM parameters (e.g.
?utm_source=google) from ad links are stored insessionStorageonly — this data stays in your browser and is deleted when you close the tab. - Reddit pixel: Currently disabled. If enabled in future, it will be disclosed here and require your consent first.
6 Your Rights (GDPR)
If you are in the European Economic Area (EEA) or UK, you have the following rights:
- Right of access: Request a copy of all data we hold about you.
- Right to rectification: Ask us to correct inaccurate data.
- Right to erasure ("right to be forgotten"): Delete all your data including voice recordings.
- Right to data portability: Receive your data in a machine-readable format (JSON).
- Right to object: Object to processing based on legitimate interests.
- Right to withdraw consent: Withdraw voice recording consent at any time.
For requests that cannot be completed self-service, contact us at the address in Section 11. We will respond within 30 days as required by GDPR Article 12.
You also have the right to lodge a complaint with your national data protection authority. Find yours at edpb.europa.eu.
7 Data Retention
| Data type | Retention period |
|---|---|
| Voice recordings & transcriptions | Until you delete them, or 24 months of inactivity |
| Text comments | Until you delete them, or 24 months of inactivity |
| Anonymous user ID | 24 months from last activity |
| Emoji reactions | Deleted when the associated comment is deleted |
| Feature analytics events | 12 months (aggregated, no personal identifiers) |
| Session JWT cookie | 7 days (auto-expires) |
8 Third-Party Services
We use the following sub-processors to provide the service:
| Service | Purpose | Data shared | Policy |
|---|---|---|---|
| Railway | API server & file storage | All server-side data | Link |
| Vercel | Landing page hosting | None (static pages) | Link |
| Groq | AI transcription & language model | Voice audio, article text, comment text (only when AI features are used) | Link |
| PostgreSQL (Railway) | Database | Comments, anonymous IDs, reactions | Link |
| Google Fonts | Typography (Inter, Playfair Display) | Browser user-agent & IP (Google standard CDN log) | Link |
9 Children
This service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has submitted data through the widget, please contact us and we will delete it immediately.
10 Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent version. For significant changes, we will display a notice inside the widget.
Continued use of the voice comment widget after changes are posted constitutes acceptance of the updated policy.
11 Contact Us
For any privacy questions, data requests, or complaints:
WalkTalking — Data Controller
We aim to respond to all privacy requests within 30 days as required by GDPR Article 12.