---
title: "Voice OS Security & Privacy: How Your Voice Data Is Processed, Stored & Protected"
description: "Voice OS processes audio on-device for wake word detection and uses encrypted, ephemeral cloud processing for commands. No voice recordings are stored. No audio is used for model training."
url: https://unlockedcrm.ai/blog/voice-os-security-privacy
canonical: https://unlockedcrm.ai/blog/voice-os-security-privacy
category: "ai-features"
published: 2026-02-18
updated: 2026-03-05
author: "Jacob Lock"
source: unLocked CRM — AI CRM for insurance agents
---

# Voice OS Security & Privacy: How Your Voice Data Is Processed, Stored & Protected

## TL;DR

Voice OS processes wake word detection on-device (no audio transmitted during passive listening) and uses encrypted, ephemeral cloud processing for commands — audio is converted to text and immediately deleted. No voice recordings are stored, no audio is used for model training, and no voice biometrics are collected. Command text logs and action audit trails are encrypted with AES-256.

## Key data points

- Voice OS deletes command audio immediately after text conversion — no voice recordings are stored, no audio is used for model training
- Wake word detection ('Hey unLocked') runs entirely on-device — ambient office conversations never leave the agent's computer

When agents speak CRM commands aloud — including client names, policy numbers, and health information — security is not optional. Here is exactly how Voice OS handles voice data.

## Voice Data Processing Architecture

### On-Device Wake Word Detection
The wake word "Hey unLocked" is detected entirely on-device. Your microphone audio is processed locally by the browser until the wake word is recognized. No audio is transmitted to any server during passive listening.

**What this means:** Your ambient office conversations, phone calls with clients, and background noise never leave your device.

### Cloud Processing for Commands
After wake word detection, the spoken command is transmitted to Voice OS's speech processing pipeline:

1. **Audio transmission** — Encrypted (TLS 1.3) transmission of command audio
2. **Speech-to-text** — Audio converted to text using insurance-trained speech recognition
3. **Intent parsing** — Text analyzed to determine the CRM action, target, and parameters
4. **Action execution** — Parsed command executed against the CRM database
5. **Audio deletion** — Command audio deleted immediately after text conversion

**Critical point:** Voice OS does not store audio recordings. Audio is converted to text, the text is processed, and the audio is discarded. There is no audio archive.

### Voice Feedback (TTS)
When Voice OS speaks back to you (confirmation, data queries, feedback), the text-to-speech generation happens in the cloud. The generated audio is streamed to your device and not stored.

## Data Protection Measures

### What Voice OS Never Does
- **Never stores raw audio** — Audio is ephemeral; converted to text and immediately discarded
- **Never uses voice data for training** — Your commands are not used to improve AI models
- **Never processes audio during passive listening** — Only the wake word detector runs during standby
- **Never transmits client health data via audio to third parties** — All processing stays within the unLocked infrastructure
- **Never associates voice biometrics with user profiles** — No voiceprint storage or speaker identification

### What Voice OS Does Store
- **Command text logs** — The text interpretation of your command (searchable command history)
- **Action audit trail** — What CRM action was executed, when, and by whom
- **Error logs** — Failed command interpretations for quality improvement (text only, no audio)

### Encryption Standards
- **In transit:** TLS 1.3 for all audio and data transmission
- **At rest:** AES-256 encryption for command text logs and audit trails
- **Processing:** Encrypted memory during speech-to-text conversion

## Compliance Considerations

### HIPAA
When agents speak client health information in voice commands ("Quote a diabetic 62-year-old"), Voice OS processes this data with the same protections applied to typed input:
- Minimum necessary principle — Only data required for the command is processed
- Access controls — Commands execute only for the authenticated user
- Audit trails — All actions logged for compliance review
- No persistent audio — Health information audio is immediately discarded

### State Insurance Regulations
Voice commands that create, modify, or access client records comply with the same data governance rules as manual CRM operations. Voice OS is an input method — it does not change how data is stored, accessed, or protected in the CRM.

### Recording Consent Laws
Voice OS does not record calls or conversations. The wake word system only activates on the specific trigger phrase. However, agents should be aware:
- If you use Voice OS during a client meeting, the client may hear your commands
- Commands spoken aloud may include client information
- Best practice: Use Voice OS for preparation before meetings and data entry after meetings — not during client-facing conversations

## Frequently Asked Questions About Voice Security

### Is my office always being recorded?
No. The wake word detector runs on-device using a lightweight model that only recognizes "Hey unLocked." No audio is transmitted or stored until the wake word is detected.

### Can someone else use Voice OS on my account?
Voice OS does not use voice biometrics for authentication. Anyone with access to your logged-in CRM session can use voice commands. Standard session security (login credentials, session timeouts) applies.

### What if I say something sensitive accidentally?
If you speak a command that is parsed but you do not want executed, use the 30-second undo window or say "Cancel." The command text log will show the cancelled action, but no audio is retained.

### Where are the Voice OS servers located?
Voice OS speech processing runs on US-based infrastructure. No audio or command data is processed outside the United States.

Voice OS was designed with the assumption that agents will speak sensitive information — client names, health conditions, financial details — aloud. Every architectural decision prioritizes the protection of that data.

## FAQ

### undefined



### undefined



## Related

- https://unlockedcrm.ai/blog/voice-os-insurance-crm-assistant
- https://unlockedcrm.ai/blog/voice-os-vs-manual-crm
- https://unlockedcrm.ai/blog/ai-insurance-data-privacy

---

Source: [Voice OS Security & Privacy: How Your Voice Data Is Processed, Stored & Protected](https://unlockedcrm.ai/blog/voice-os-security-privacy) — unLocked CRM, the AI CRM built for insurance agents. Citation permitted with attribution and a link to https://unlockedcrm.ai/blog/voice-os-security-privacy.
