Updated: 2026-08-20 · Effective: 2026-08-20 · Applies to: v2.9.0 and later
Listen Step is a voice-guided step assistant that helps you follow protocols hands-free — in the kitchen, in the lab, and beyond. We take your privacy seriously. This policy explains exactly what we do with your personal information.
1. Personal information we process (item by item)
Microphone audio — Purpose: recognizing your spoken commands ("next", "check", "back", "repeat") to control step execution. Method: captured only when you turn on "Hands-free" on the execution page. Processing: speech recognition runs offline on your device (built-in sherpa-onnx component); audio never leaves the device, is never uploaded to any server, and no recordings are stored. If your device lacks the offline component, the app falls back to the device's built-in speech recognition service; in that case audio is handled by that service provider under its own privacy policy, and you can manage it in system settings.
Camera photos — Purpose: recognizing text on a printed protocol or SOP you photograph, to pre-fill the Steps box on the Create page. Method: a photo is taken only when you tap "📷 Scan printed protocol" and shoot. Processing: text recognition runs offline on your device (built-in Google ML Kit component); the photo is deleted immediately after recognition, is never uploaded to any server, and is never stored in your gallery.
Account info — Purpose: signing you in, keeping your session, and computing your trial/subscription entitlements. Method: Google sign-in (Firebase Authentication). Data: your Google account's display name, email address and user ID (UID). Processing: stored on Google's Firebase servers and cached on your device.
Purchase & entitlement records — Purpose: activating and restoring your Pro subscription, syncing it across your devices, and fraud prevention. Method: payments are processed by Google Play Billing; we never see your card details. Purchase verification and entitlement sync are handled by RevenueCat. Data: purchase token, product ID, order ID, subscription status and an app user ID. Processing: stored on RevenueCat's servers and cached on your device.
Usage data — Protocols and steps you create, your favorites, and your trial start time, used to provide the create/favorite/run/export and trial features. Stored only on your device.
We do not collect your contacts, messages, call logs, location, photo library, or device identifiers (IMEI, MAC address, Android ID).
2. Device permissions
Microphone — used only for the voice commands described above, requested only when you actively use a voice feature.
Camera — used only for scanning a printed protocol into text as described above, requested only when you tap the scan button on the Create page.
Vibration — used only for timer alerts.
Network — used for Google sign-in, subscription purchase and verification, and entitlement synchronization; also by the system speech recognition service in the fallback case above. Your voice audio and photos are never uploaded.
3. Where and how long your data is stored
Location: your protocols, favorites, settings and cached entitlement stay in the app's private storage on your device. Account info is stored on Google Firebase servers, and purchase/entitlement records on RevenueCat's servers (both may be located outside your country); no other remote transfer takes place.
Retention: on-device data is kept until you delete it, delete your account, or uninstall the app; uninstalling removes it via the system. Cloud account and entitlement data is kept while your account exists and is deleted when you delete your account.
4. Your rights and how to exercise them
Access & correct — view and edit your protocols and favorites in "My Steps".
Delete — delete protocols you created, unfavorite items, and manage exported Word files yourself.
Withdraw consent — open the side menu (tap the logo) → "Privacy Consent Settings" to change your choice at any time; voice features stop, everything else keeps working.
Cancel subscription — open the side menu → "Manage subscription" (opens Google Play's subscription page) to cancel at any time; access continues until the paid period ends.
Delete account — open the side menu → "Delete account"; your Google sign-in (Firebase account) is deleted immediately, with no review or waiting period. Local protocols and favorites stay on your device.
Contact & complaints — use the developer contact email on the Google Play store listing.
5. Children
This app is not directed at children under 14 and does not knowingly collect their personal information. If you are a minor, please use the app with a guardian's consent and supervision.
6. Third-party SDKs
See the "Third-Party SDK List" in the side menu. This app contains no advertising, analytics, or push-notification SDKs.
7. Changes to this policy
If this policy changes, we will notify you in the app. The latest version is always available in the side menu.