Skip to content

Privacy Policy

Last updated:

This Privacy Policy explains how Voyager for Momentum Inc. ("Voyager," "we," "us," or "our") processes personal information in connection with voyager.fm, the Voyager macOS app, accounts, purchases, support, and related services that link to this Policy (collectively, the "Services").

It covers information you provide, information generated when you use the Services, and information received from service providers or external services you choose to connect. Feature-specific notices may provide additional details. Reading this Policy or accepting our Terms of Service does not replace any separate consent required by applicable law.

1. Who We Are and Scope

Voyager for Momentum Inc. is responsible for the personal information we process for the purposes described in this Policy.

Business registration number: 150-88-03654
Address: 2107-1-ho, 21F, 122 Jomaru-ro 385beon-gil, Wonmi-gu, Bucheon-si, Gyeonggi-do, 14556, Republic of Korea
Privacy & Security Team: privacy@voyager.fm
Account, purchase, and product support: support@voyager.fm

This Policy describes Voyager's processing, including processing performed for us by service providers. An external service that you choose to connect may also process information under its own terms and privacy notice. The information processed depends on the Services, features, and external connections you actually use.

2. Information We Process

We process information you submit, account and transaction information received from providers, technical information generated by the Services, and content or credentials involved in features you choose to use. These categories can include personal information about you or other people.

Local processing by the app, transmission to an external service you choose, and processing on Voyager-controlled systems are different activities. The sections below describe the relevant categories.

2.1 Information You Provide

Product and marketing communications. If you separately opt in to product updates, launch news, or promotional messages, we process your email address, subscription preference, consent record, and delivery, interaction, or unsubscribe information generated by our email service. Creating a Voyager account by itself does not enroll you in optional marketing. You can unsubscribe at any time.

Service communications. We may use your account or purchase email for messages necessary to operate the Services, including authentication, security, purchases, refunds, entitlement recovery, and material service notices. These service communications are handled separately from optional marketing.

2.2 Accounts and Authentication

We process your email address, provider-supplied name and profile image, account and provider identifiers, account status, session information, and technical information needed to authenticate and connect the app with your account. Authentication flows can involve access or refresh tokens and short-lived login or handoff tickets.

Free's core local file-browsing features do not require a Voyager account. This does not mean that no technical or diagnostic information is generated when the app or website is used.

2.3 Purchases and Entitlements

We process checkout and transaction identifiers, billing email, purchased product, payment and refund status, receipts, tax or chargeback information provided to us, and the account associated with a purchase. For the Early Supporter Pass, this includes preorder, activation, refund, and continuing entitlement records.

If you ask to restore a purchase, we process the purchase email and invoice or receipt you submit, the order reference, verification results, and any replacement-account association. Do not submit a full payment card number. Payment details are handled by our merchant of record and payment providers under their own notices; Voyager does not intentionally collect full card numbers through the app or website.

2.4 Support

We process messages you send us, relevant contact and conversation details, and attachments you choose to provide, such as screenshots, logs, invoices, or diagnostic information. Attachments may contain file names, paths, content, or information about other people. Share only information needed for the request and remove credentials or unrelated sensitive information where possible.

2.5 Website, API, Device, and Operational Information

Website and API requests can include IP address, browser or user-agent information, requested path or URL, referring source, timestamps, request identifiers, response status, latency, and error information. We use these records to operate the Services, investigate faults, and prevent abuse.

Depending on the feature, we also process app and macOS versions, a device or installation identifier, an optional device name, account or entitlement status, and device-binding or last-activity information. Technical identifiers can persist across sessions and can be used for access administration, fraud or abuse prevention, and diagnostics.

2.6 Analytics and Attribution

We use product analytics to understand page views, source attribution, account and checkout activity, purchase events, product use, and errors. Analytics events can include a persistent browser or device identifier, event time, route, referrer, browser or device information, and selected event properties such as product, plan, currency, purchase amount, or checkout reference.

When optional analytics is enabled, our analytics technology can store a persistent identifier in cookies or similar browser storage so that visits can be recognized across sessions. When you sign in or use an account-linked flow, we may associate analytics activity with an internal account-related identifier so that we can understand use across sessions and, where applicable, devices.

We use these identifiers for product analytics, attribution, reliability, and conversion measurement - not to create third-party advertising profiles. We do not sell personal information or share it for cross-context behavioral advertising. Cookies and related choices are described in Section 4.

2.7 Diagnostics

We use diagnostic services to understand crashes, errors, app hangs, and performance. Automated diagnostic telemetry is configured not to transmit local file contents, file names, file paths, prompts, user-entered content, or other work context that could identify a person or reveal private work. Diagnostic records are limited to technical information needed to investigate reliability, such as error codes, stack traces after filtering, app and operating-system versions, component and environment tags, performance information, and a diagnostic installation identifier.

If you voluntarily send screenshots, logs, files, or other diagnostic material to support, the information you choose to send is handled as support information under Section 2.4.

2.8 User Content, AI, and Connected Services

User Content includes files, folders, documents, databases, storage objects, metadata, properties, relationships, collections, and work results that you access or manage through Voyager. It can contain personal information about you or others. Core local browsing works with files on your Mac; accessing a file locally is not the same as uploading it to Voyager.

When you use an AI service or agent, information you choose for the task - such as prompts, selected files or excerpts, task context, conversation history, tool inputs, and outputs - may be sent to the AI provider or agent you selected. The actual scope depends on your instructions, settings, and permissions. Information received by an external provider is also subject to that provider's terms, privacy notice, and account configuration. Voyager does not use your local files or prompts to train general-purpose AI models.

When you connect an external service, we may process account or workspace identifiers, credentials, permissions, connection status, and selected content or metadata as necessary to provide that connection. The scope depends on the service, feature, and permissions you choose. Additional information may be provided when you set up a connection.

2.9 Information Received from Providers

We receive information from authentication, billing, email, analytics, diagnostics, infrastructure, and connected-service providers as needed for the functions described above. This can include account claims, transaction status, delivery or unsubscribe status, analytics events, diagnostic results, and connection results.

3. How We Use Information

We use personal information to:

• provide accounts, authentication, app access, purchases, entitlements, connected services, AI and agent features, and customer support;
• process payments, refunds, purchase restoration, and other transaction or account requests;
• send service communications and, when you have opted in or another lawful basis applies, product or marketing communications;
• secure the Services, prevent fraud and abuse, enforce access rights, and investigate incidents;
• diagnose errors, measure reliability, understand product use, attribution, onboarding, and conversion, and improve the Services;
• comply with legal, tax, accounting, consumer-protection, privacy, and recordkeeping obligations; and
• resolve disputes and protect legal rights.

Where the GDPR or UK GDPR applies, our legal bases can include performance of a contract, compliance with legal obligations, legitimate interests for proportionate security, diagnostics and business administration, and consent where required for optional marketing, analytics, cookies, or other processing.

For processing subject to Korean law, we rely on an applicable legal basis such as consent, necessity for the requested contract, or a statutory obligation. Necessary processing and optional marketing or analytics are assessed separately.

4. Cookies and Similar Technologies

The Site uses cookies and similar browser storage for several purposes.

Necessary storage. We use storage needed for authentication, session management, security, fraud prevention, and other functions that are necessary to provide a feature you request.

Analytics and attribution. With optional analytics enabled, analytics technology can use persistent cookies or similar storage to recognize a browser across visits and measure product use, attribution, and conversion. If you sign in or use an account-linked flow, the analytics identifier can be associated with an internal account-related identifier. We also use an attribution cookie to remember a referring source or campaign for up to 30 days.

Choices. Where applicable law requires consent for analytics or attribution storage, we obtain it before enabling that optional processing. Where an applicable legal exception permits processing subject to an objection or other choice, we provide the required information and control. You can change your analytics and cookie choices through the privacy or cookie settings made available on the Site. Withdrawing a choice applies prospectively and does not automatically erase events already transmitted; you can contact privacy@voyager.fm to exercise applicable deletion or other privacy rights.

We do not use these technologies for cross-context behavioral advertising and do not sell personal information.

5. How We Disclose Information

We disclose personal information only as needed for the Services and the purposes described in this Policy.

Service providers and processors. We use providers for authentication and data infrastructure, hosting and network services, payments and billing, email delivery, analytics, diagnostics, and related operational functions. Providers acting on our instructions process personal information for the agreed service purposes under applicable contractual and security arrangements.

User-connected external services. When you choose to connect an external service, information is shared with that provider as necessary for the connection or action you request. The provider's own terms and privacy notice apply to its independent processing.

Legal and safety. We may disclose information where reasonably necessary and legally permitted to comply with law or legal process, prevent fraud or security incidents, enforce agreements, or protect rights and safety.

Business transfers. Information may be transferred as part of a merger, acquisition, financing, reorganization, or asset transfer, subject to applicable legal requirements and required safeguards or notices.

6. Service Providers and International Transfers

Voyager is based in the Republic of Korea and uses service providers that can process personal information in other countries.

We maintain a current Service Providers & International Transfers list on the Voyager website. The list identifies our principal service providers and, as applicable, their processing role, categories of information, purpose, destination or processing locations, retention criteria, and whether the processing is required for a requested service or optional. We update that list when a provider or material transfer arrangement changes.

Where personal information is transferred internationally, we use an applicable legal basis and safeguards for the specific relationship. This can include a transfer necessary for contracted processing or storage where the required information is publicly disclosed, separate consent where required, contractual safeguards, and appropriate technical and organizational measures.

The effect of refusing or withdrawing a transfer depends on the relevant function. Refusing an optional analytics transfer does not mean that you must refuse all account or core service processing. Contact privacy@voyager.fm for questions about international transfers or available choices.

7. Data Retention and Deletion

We keep personal information only for the period needed for the stated purpose, a continuing entitlement, security or dispute handling, or an applicable legal obligation. Our standard retention periods are:

• Account profile and account-contact data: while the account remains active, plus a 14-day recovery period after an account-deletion request where that recovery workflow is available, except for records retained separately below.
• Access and refresh tokens or equivalent active session credentials: until expiry, logout, revocation, replacement, or account deletion, whichever applies first.
• Device-binding and entitlement-access records: while the account or entitlement is active, plus the applicable 14-day deletion-recovery period.
• Early Supporter Pass entitlement proof: the minimum purchase and entitlement records needed to restore the right are retained for as long as the entitlement remains valid, and for up to 5 years after the entitlement ends where needed for legal or dispute purposes.
• Orders, payment, refund, withdrawal, tax, and supply records: 5 years where required or otherwise needed to satisfy applicable transaction-record obligations.
• Consumer complaint or dispute records: 3 years where required or otherwise needed for the applicable dispute.
• General customer-support records: 1 year after the support case is closed, unless a longer period is needed for a legal claim, security matter, or transaction dispute.
• Marketing consent records: while the subscription is active and for 3 years after withdrawal or unsubscribe as evidence of the consent and its withdrawal. A minimal suppression record can be kept longer where necessary to honor an opt-out.
• Identifiable analytics events: 90 days. Aggregated information that has been irreversibly anonymized so that it no longer identifies an individual can be retained longer.
• Attribution cookie: up to 30 days from its latest qualifying update.
• Diagnostic crash, error, and performance records: 30 days.
• General web and API operational logs: 30 days; security, fraud-prevention, or abuse-investigation logs: 90 days.
• Temporary authorization or handoff records used to connect a session or external service: removed after completion or expiry, and in any event within 24 hours unless a shorter technical expiry applies.
• Credentials for a connected external service: while the connection is active and as technically necessary to provide it; removed from Voyager-controlled active systems after disconnection, revocation, or expiry, subject to short-lived backups and records that do not contain the reusable credential.
• Connection and security audit metadata: 90 days unless needed for an active security investigation or legal obligation.
• Completed account-deletion workflow records: 90 days after completion, excluding separately retained transaction records.
• Backup copies of data deleted from active systems: removed through backup rotation within 30 days, unless a legal hold applies.

Local files and local-only indexes on your Mac are controlled by you and are not subject to Voyager server-retention periods merely because the App can access them.

When information is no longer required, we delete it or otherwise dispose of it appropriately. Account deletion, disconnecting an external service, unsubscribing from marketing, cancelling a purchase, and removing local App data are separate actions. A deletion request to Voyager does not itself delete files on your Mac or information independently held by an external provider.

8. Security

We use administrative, technical, and organizational measures appropriate to the information and processing, including access and authentication controls, transport security, monitoring, provider management, and data-minimization measures.

No method of transmission or storage is completely secure. If we become aware of a security incident that requires notice, we provide the notifications required by applicable law.

9. Automated Decisions and Data Portability

We do not currently make solely automated decisions with legal or similarly significant effects on individuals, such as credit, employment, or insurance decisions. Automated security checks, entitlement checks, analytics, and user-directed agent tasks are not automatically the same kind of decision.

Where applicable law provides a right to data portability or transmission of personal information, contact privacy@voyager.fm. We assess eligible requests under the relevant legal conditions, identity-verification requirements, technical feasibility, and the rights of other people. This does not promise export or transmission of every local file or third-party record outside Voyager's control.

10. Your Rights and Choices

Depending on applicable law, you can request access to, correction of, deletion of, restriction or suspension of processing of, or a portable copy of personal information, and can withdraw consent or object to processing where those rights apply. You can unsubscribe from optional marketing at any time and can change optional analytics or cookie choices through the controls described in Section 4.

We may need to verify your identity. A request can be limited or denied where permitted by law, including where information is required for a legal obligation, fraud prevention, security, a transaction dispute, or the rights of another person. We respond within the period and with the explanation required by applicable law.

10.1 EEA and UK

Where the GDPR or UK GDPR applies, you may have rights to access and obtain a copy, rectify inaccurate or incomplete information, erase information, restrict processing, receive portable information, object to processing based on legitimate interests, object to direct marketing, and withdraw consent for consent-based processing, subject to applicable conditions. You may also lodge a complaint with the relevant data protection authority.

10.2 California

If the CCPA, as amended by the CPRA, applies to our processing, eligible California residents may have rights to know and access information about categories, specific information, sources, purposes, and disclosures; request deletion or correction; receive portable information; and exercise applicable sale, sharing, or sensitive-information choices. We do not sell personal information or share it for cross-context behavioral advertising, and we do not unlawfully discriminate against you for exercising applicable rights.

10.3 Republic of Korea

Where Korean privacy law applies, you may request access, correction, deletion, or suspension of processing, withdraw consent, and exercise transmission or automated-decision rights when their legal conditions are met. You or an eligible representative may contact the Privacy & Security Team at privacy@voyager.fm.

You may also contact the Privacy Infringement Report Center (118; privacy.kisa.or.kr) or the Personal Information Dispute Mediation Committee (1833-6972; kopico.go.kr) for complaints or dispute resolution.

10.4 How to Exercise Your Rights

Send privacy requests to privacy@voyager.fm. Provide enough information to locate and verify the relevant account, purchase, or interaction without sending unnecessary sensitive information. Account, purchase, refund, and product-support questions can be sent to support@voyager.fm.

We respond within the period required by applicable law and provide any explanation required for an extension, refusal, or limitation.

11. Children's Privacy

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. Contact privacy@voyager.fm if you believe a child has provided information to us.

Where Korean law requires consent for processing a child's information and the child is under 14, the required legal-representative consent and verification apply. We also apply any higher age or parental-consent requirement required for the relevant processing in another jurisdiction.

12. Changes to This Policy

We may update this Policy to reflect changes to the Services, our processing practices, legal requirements, or security needs. We make the current Policy available on the Site and update the effective or last-updated date when it changes.

Where a change materially affects personal-information processing, we provide any notice, choice, or additional consent required by applicable law before relying on the changed processing. A change to our Terms of Service does not by itself authorize a new use of personal information.

13. Contact and Language

Privacy questions and rights requests: Privacy & Security Team - privacy@voyager.fm
Account, purchase, refund, and product support: support@voyager.fm

This Policy is published in English. A Korean translation can be provided on request by contacting privacy@voyager.fm. Where applicable law requires a notice or explanation in another form or language, we provide it as required.