Saylio · Legal

Saylio Privacy Policy

Effective date: 3 October 2026 · Last updated: 3 October 2026

Saylio – AI Voice Typing (“Saylio”) is provided by Astral Edge Studios (“we”, “us”, or “our”). This policy explains what Saylio processes, where processing occurs, why it is necessary, how long data is retained, and how you can delete it.

Contact: info@astraledgestudios.com
Published policy: https://astraledgestudios.com/saylio/privacy-policy
Deletion information page: https://astraledgestudios.com/saylio/support

What Saylio does

Saylio records speech only after you press a recording control or the user-enabled floating voice button. It sends that recording for speech-to-text processing and returns an editable transcript. If you enable Android Accessibility access, Saylio can insert the resulting text into the editable field you selected in another app.

Saylio does not display advertising, include an advertising SDK, continuously listen in the background, click Send, or intentionally collect contacts, photos, precise location, payment information, or passwords.

Data processed on your device

Saylio stores the following in app-private Android storage:

  • onboarding status and app preferences, including theme, language, mode, sound, haptics, and floating-button state and position;
  • optional transcript history, only when you turn on “Save local history”; history is off by default;
  • an anonymous Supabase access and refresh session encrypted with an Android Keystore key;
  • temporary 16 kHz mono PCM/WAV audio while a requested recording is captured or processed; and
  • short-lived Accessibility state needed to remember the destination package, focused editable field, selection, and insertion request identifier.

Normal audio cleanup deletes PCM during conversion and deletes the WAV after success, failure, or cancellation. If the process terminates abnormally, Saylio removes matching temporary audio files after they become older than ten minutes the next time the recording service starts. Android backup is disabled for the app.

Local transcript history remains until you delete individual entries, clear history, use “Delete account and data”, clear the app's storage, or uninstall the app. Android permissions are controlled separately through system settings and are not personal data stored by Saylio.

Data sent off the device

When you request transcription, Saylio sends over encrypted HTTPS:

  • the temporary audio recording;
  • the selected writing mode and language;
  • for Business mode, the selected template, output language, and details that you enter;
  • a random request identifier used to prevent duplicate provider charges; and
  • a pseudonymous Supabase user/session token used for authentication, rate limits, and account deletion.

The service returns transcript text and, for Business mode, may return a formatted draft or a list of missing details. Saylio does not send locally saved history as a collection and does not upload unrelated text from the active app.

AccessibilityService use

Saylio is not an accessibility tool. Its AccessibilityService is an optional app-functionality feature for voice typing into other apps.

When enabled, the service observes active-window and focused-editable-field events. It reads the active package/class, editability, focus, non-password text and selection only as needed to remember the field you selected and insert the transcript you requested. It rejects password fields. It performs only text replacement and cursor-selection actions; it does not click Send, submit forms, change system settings, or use Accessibility data for advertising or profiling.

Accessibility-derived window, field, and selection information remains on the device and is not sent to Supabase or Sarvam AI. The transcript inserted by the service was already created through the separate voice-processing flow described above.

Service providers

Saylio uses only the following processors for its current server voice flow:

  1. Supabase — anonymous authentication, authenticated Edge Functions, short-lived processing/idempotency records, usage limits, and account deletion. Supabase receives the authenticated request and audio before forwarding the audio to the speech provider. See Supabase Privacy.
  2. Sarvam AI, operated by Axonwise Private Limited — speech-to-text and, when Business mode is used, language-model drafting. Sarvam receives the audio and necessary text instructions/details to return the requested result. See Sarvam AI Privacy Policy.

These providers process data to deliver Saylio's requested functionality. Saylio does not sell this data or use it for advertising. Before production launch, the publisher must verify and record the Sarvam workspace's API retention and model-training settings. This codebase does not expose those dashboard settings and therefore does not claim a specific Sarvam retention period beyond Sarvam's applicable contract and configured workspace controls.

Server retention

Saylio's own Supabase schema applies these periods:

  • raw audio is not written by Saylio to Supabase Storage or Postgres; it exists in Edge Function/provider request memory while the request is processed;
  • a completed result containing transcript/draft text can remain in the protected saylio_processing_requests table for up to 15 minutes so an identical retry can return safely without another provider charge;
  • after the result is scrubbed, the request row and audio-derived SHA-256 payload hash can remain for up to 30 days to prevent a delayed retry from silently charging the provider again;
  • uncertain or failed provider outcomes can remain blocked for up to 30 days for the same duplicate-charge protection;
  • daily provider-usage counts, associated with the pseudonymous Supabase user ID, remain until the account is deleted; and
  • the anonymous Supabase Auth identity remains until the user invokes deletion or an authorized administrator deletes it.

Supabase infrastructure may separately process security and operational metadata such as IP address, timestamps, and request logs according to the applicable Supabase plan and agreement. Saylio application code does not log raw audio, transcripts, access tokens, refresh tokens, or provider credentials.

Why data is processed

Data is processed only to:

  • authenticate the anonymous session;
  • capture and transcribe speech requested by the user;
  • produce the selected translation, formatting, or Business draft;
  • insert or display the result;
  • enforce rate, concurrency, and provider-budget limits;
  • prevent duplicate processing and duplicate provider charges;
  • save optional on-device history; and
  • secure, troubleshoot, and operate the requested service.

Deletion

In the app, open Settings → Delete account and data → Delete permanently. Saylio then:

  1. authenticates the current anonymous Supabase session;
  2. hard-deletes the Supabase Auth user;
  3. relies on enforced database cascades to immediately delete all linked usage rows, processing requests/results/hashes, and concurrency leases;
  4. verifies that all three linked tables contain zero rows for that user;
  5. invalidates refresh sessions and clears the encrypted session and Keystore key on the device;
  6. removes local preferences, optional transcript history, and temporary Saylio audio; and
  7. returns the app to first-run onboarding.

If no server account has ever been created, the same action deletes the local data only. If server deletion fails, Saylio leaves the local session and history intact so you can retry. Existing access JWTs can remain cryptographically valid until expiry, but Saylio's Edge Functions validate the user against Supabase Auth on each request, so a deleted user is rejected.

Deletion information is also available at https://astraledgestudios.com/saylio/support, and privacy questions can be sent to info@astraledgestudios.com. Saylio has no name, email address, password, or other verified identity attached to its anonymous backend identifier, so the publisher must not promise that support can locate a particular anonymous record after the app and its encrypted session have been removed. Use the in-app deletion action before uninstalling or clearing app data. Saylio's own user-linked operational tables are removed immediately when authenticated automated deletion succeeds.

Data already sent to a processor is also subject to that processor's applicable retention controls and agreement. The publisher must ensure processor deletion/retention settings and contracts match this policy before launch.

Security

Saylio uses HTTPS for network transport, Android app-private storage, Android Keystore encryption for the Supabase session, authenticated Edge Functions, row-level security, service-role-only database functions, bounded requests, and server-side provider credentials. No security measure can guarantee absolute protection.

Your choices

You can decline or revoke microphone, overlay, notification, or Accessibility access in Android settings. Voice transcription requires microphone and network access. Cross-app floating voice typing requires overlay permission, and automatic insertion requires Accessibility access. You can use results without enabling local history and can disable the floating button at any time.

Depending on applicable law, you may contact info@astraledgestudios.com about access, correction, restriction, objection, portability, or deletion. Because the backend identity is anonymous, fulfilling a record-specific request outside the authenticated in-app flow depends on whether the publisher can safely match the request to that pseudonymous identity.

Children

Saylio is not directed to children and does not knowingly collect children's data. The publisher must configure the Play target-audience declaration consistently with the actual intended audience.

Changes

We may update this policy when Saylio's processing changes. The hosted policy will show the effective date. Material changes will be disclosed as required by applicable law and Play policy.

Contact

Questions about privacy or Saylio? Email info@astraledgestudios.com.