Privacy Policy

Last updated 17 September 2026

1. What Wokla is

Wokla is a voice messaging app for Apple Watch. Two watches pair with a five-digit code and send each other short voice messages. There are no accounts: nothing about you is asked for, and nothing about you is stored under your name.

This policy says what the app and its server keep, why, for how long, and who else handles it. "We" is the developer named at the end.

2. What we process

Voice messages. The recording you make, up to fifteen seconds, sent to the paired watch.

Transcripts. A text version of each voice message, produced by a speech-to-text service (see section 4). It appears in the notification on the paired watch and under its record button.

Your language. The watch's language setting (for example zh-Hant-TW) is sent with each recording so the transcript is produced in the right language and script. Nothing else about the device is sent.

A device key. A random string the watch generates the first time it runs and keeps in its Keychain. It identifies the watch to our server. The server stores a keyed hash of it, not the key itself, and never learns your name, email address or Apple ID. The app also shows a short device code in Settings, so you can name your device if you write to us.

Pairing. The pair code while it is live (two minutes), and the fact that two devices are paired.

Push token. The token Apple issues so we can send notifications to your watch. Stored while it is valid; dropped as soon as Apple rejects it.

Message details. When a message was sent, how long it is, whether the paired watch has seen it, and an identifier the watch gives it so a message that is sent twice counts once.

Request logs. Our web server records the IP address, path and status of each request, as web servers do, for fourteen days. The application itself logs device codes and error details, never recordings, transcripts or keys.

We do not process contacts, location, health data, analytics, or advertising identifiers.

3. How we use it

Only to run Wokla: to deliver your voice message and its transcript to the paired watch, to notify that watch (once when the message arrives, and once more a minute later if it has not been seen), to show you whether it has been seen, to keep the pairing working, and to limit abuse of the service. We do not use recordings or transcripts for advertising or for anything other than delivering them, and we do not sell any of it.

4. Speech to text

Wokla uses Groq, Inc. as a service provider to turn voice messages into text. Every voice message is sent to Groq, together with your language setting, for the sole purpose of producing its transcript; the transcript is then used for the notification on the paired watch and the line under its record button, and for nothing else. Transcription is part of how Wokla works and cannot be turned off in the app; if you do not want a recording transcribed, do not send it. If Groq cannot be reached, the message is delivered without a transcript.

Recordings and transcripts sent through Groq's API are customer data under Groq's Services Agreement, which does not permit Groq to use them to train or fine-tune models unless the customer says so, and we do not. By default Groq does not keep what it is sent for inference; it may log a request for up to thirty days, and only to troubleshoot a reliability problem or investigate abuse, unless the law requires it to keep it longer. We have not enabled any setting that would let Groq keep our data for other purposes. Groq and its subprocessors may process data in the United States and other countries where they operate.

What applies to this data is Groq's API agreement, not its website privacy policy: the Groq Services Agreement (section 4.2 on inputs, outputs and training), the Data Processing Addendum (section 8 on where data is processed, and its subprocessor list), and Groq's page on how it handles your data.

5. Who else handles the data

Cloudflare, Inc. stores the audio files and our database backups (R2 object storage).

Groq, Inc. produces the transcripts, as above.

Apple delivers notifications through the Apple Push Notification service. The notification carries the transcript, so Apple's service sees it in transit.

Each of them handles the data only to provide its service to us, under its own privacy policy and our agreement with it.

6. How long we keep it

Voice messages: only the latest one in each direction. Each watch's newest message to its partner replaces the previous one, which is deleted from storage. Unpairing deletes both messages at once. A message the partner has already seen is not kept any longer than one it has not.

Transcripts live and die with the message they belong to.

Pairing, device key hash and push token are kept while the watch is in use. A watch we have not heard from in ninety days is deleted, with its pairing and any messages, since a watch that quiet has been reinstalled, wiped or put away.

Backups of the database are taken daily and expire after thirty days. They contain the database — key hashes, pairings, timestamps and transcripts — but never the audio.

Request logs are kept for fourteen days.

The demo partner behind pair code 99999 is a device our server plays itself so a reviewer with one watch can try the app; anything sent to it is deleted within a day.

7. Deleting your data

There is no account to delete, so there are two ways:

Deleting the app removes the device key from the watch; the server's copy of your data then follows the ninety-day rule above.

8. Your choices

Microphone. Wokla needs the microphone to record. You can withdraw access in the watch's Settings; the app then cannot record until it is granted again.

Notifications. You can turn them off in the watch's Settings. Messages still arrive; the app checks for them while it is open.

Transcription cannot be turned off, as noted in section 4.

9. Security

All traffic between the watch and our server is over HTTPS. The device key never leaves the watch's Keychain except as a bearer credential over that connection, and the server stores only a keyed hash of it. Audio is stored under random object names that are never exposed as public URLs; the server streams it to the paired watch only. Requests are rate limited per device and per address. No system is perfectly secure, and we do not promise that ours is.

10. Where the data goes

Our server, Cloudflare and Groq operate in the United States and other countries, so your messages are processed outside the country you use the app in. Their handling is governed by our agreements with them and by the safeguards in their own policies.

11. Children

Wokla is not directed at children under 13, or under the age at which local law requires parental consent, and we do not knowingly collect information from them. Since there are no accounts, we have no way to tell a child's watch from an adult's; if you believe a child has used Wokla and want the data removed, write to us with the device code.

12. Legal requests

We disclose information only where the law requires it, or where it is necessary to protect the service, its users or others. Given what we keep, that is at most: key hashes, pairings, timestamps, the latest transcript in each direction and the latest audio.

13. Changes

If this policy changes, the date at the top changes with it, and a change that matters to you will be announced in the app.

14. Contact

Questions, or a deletion request: [privacy@wokla.app]
Developer: [Developer or company name]
Site: wokla.app