Gripspeak Privacy Policy
Version 2026-10-13 · Last updated October 13, 2026
The sole proprietor in Texas, USA, doing business as Gripspeak ("we," "us") makes Gripspeak, a voice-typing app for the Steam Frame, and is responsible for the personal data described here. Our address is 605 W 9th Street, Unit #4108, Austin, Texas 78701, USA. You can reach us at support@gripspeak.com.
We wrote this policy to be short and literal. If Gripspeak changes in a way that makes any of it untrue, we'll update the policy.
The short version
- Your voice never leaves your headset. Speech recognition runs on the headset. We don't record, store or receive your audio.
- We don't receive what you dictate, unless you choose to send it to us in a feedback message.
- AI polish is optional. It's off unless you connect an OpenRouter account. When it's on, the text of each dictation goes to OpenRouter through your own account, never through us.
- Gripspeak contacts our server to activate your license, to check about once a day that it's still valid, to check for and download updates, and when you send feedback or vote for a language.
- We don't sell personal information or share it for advertising. Gripspeak has no analytics or ad trackers.
What stays on your headset
- Audio is processed in memory and discarded. It's never saved to disk.
- Recent dictations. Gripspeak keeps a history of what you dictated (the text, what it heard before cleanup, where it went and how long it took) in
~/.local/state/gripspeak/history.jsonl, so you can copy or fix recent dictations. Whenever the file grows past 256 KB, Gripspeak trims it to your last 500 dictations, so depending on their length it can hold up to roughly 2,000. You can turn this off in Settings under "Keep recent dictations." Turning it off stops new entries but doesn't delete the existing file; you can delete it yourself. - Password fields. When Gripspeak can tell that you dictated into a password field, it doesn't keep that dictation in the history, doesn't send it for AI polish, and doesn't learn from that field. It can tell in Steam's own text fields and in desktop apps that publish their fields through the accessibility system, but not in every app.
- Your dictionary and learned corrections are kept in
~/.config/gripspeak/. If "Learning from corrections" is on (the default), Gripspeak re-reads the text field you dictated into for a short while afterwards (up to 30 seconds in Steam, 90 seconds in desktop apps) to learn the corrections you make. It does this on the headset, and nothing it reads is sent anywhere. - The accessibility system. To learn in desktop apps, Gripspeak switches on desktop mode's accessibility system. If you also turn on app access for a Chromium-based or Electron app, Gripspeak changes that app's settings so it publishes its text through that system. Other software on your headset can read text published there too. Turning app access off in Settings undoes the changes.
- Your OpenRouter key, if you connect an account, is kept in a file only your user account can read, and it's sent only to OpenRouter.
Like any file in your home folder, these files can be read by other software you run on the headset.
Deleting it all. Your settings, dictionary and OpenRouter key are in ~/.config/gripspeak/, and your history and saved license are in ~/.local/state/gripspeak/. Deleting both folders removes them from the headset. Uninstalling keeps them unless you use the purge option, so a reinstall picks up where you left off.
Optional AI polish
When AI polish is on, each dictation sends the following to OpenRouter (openrouter.ai), using your own OpenRouter account and key:
- the dictated text,
- the words in your custom dictionary, which help it spell names correctly,
- a fixed instruction telling the model to clean up the text.
Dictations of three words or fewer aren't sent. Connecting an OpenRouter account turns polish on, and you can turn it off at any time in Settings.
OpenRouter forwards the request to the model provider you pick in Settings:
- Groq (Llama 3.3 70B), the default. If Groq is busy, Gripspeak retries that dictation once on the backup below.
- OpenAI (GPT-5.4 nano), the backup, or your choice. OpenAI says it doesn't train on API data by default, but it keeps API request logs for up to 30 days to monitor for abuse.
Gripspeak tells OpenRouter to use only the provider it names, with no fallback to any other, and only providers that don't collect user data under OpenRouter's data policy setting. OpenRouter says it doesn't keep your prompts unless you turn on prompt logging in your OpenRouter account. It does keep account and billing records.
We never see this text or your key. These providers' own policies apply, and they can change:
- OpenRouter: privacy · terms · data retention
- Groq: privacy · data handling
- OpenAI: privacy · API data
What our server receives
Our server and database run on Cloudflare. Like any web host, Cloudflare processes your IP address to deliver each request.
| When | What we receive | What we keep | Why |
|---|---|---|---|
| Activating with your download link | Your itch.io download key, and a device ID for your headset | A one-way hash of the key, the device ID, the activation date, and a record of any moves between headsets | To confirm your purchase with itch.io and keep it on one headset, including after a reinstall |
| Signing in with itch.io to activate | A sign-in token from itch.io, and the device ID | The same as above. We use the token once to ask itch.io which account you are, use only the account number to find your purchase, and keep neither the token nor your account details | The same |
| Activating from your phone | From the headset: the device ID. From your phone: the 6-digit code and your download link | The code with the device ID, until your headset collects its license or, if it doesn't, at our next cleanup after the code expires (codes expire after 15 minutes). A hash of your network address (the first part of the IP address of your phone, and of your headset when it asks for a code) and the time, cleared once it's more than an hour old, the next time anyone uses phone activation | To activate the headset showing the code, and to limit repeated guesses |
| A reinstall finding its license again | The device ID | Nothing new | To give a reinstalled headset its license back without the key |
| The daily license check, when online | Your license token, which names your purchase (as a hash) and your headset | Nothing new | To see whether the license has moved to another headset or the purchase was refunded |
| Checking for and downloading updates | The app version, and your license token when downloading | Nothing | To offer updates, and to deliver them only to activated copies |
| Sending feedback or a problem report | Your message; your email, if you give one; your license, if activated; diagnostics, unless you untick the box | All of it, plus a hash of your network address (the first part of your IP address) | To reply to you, fix problems and limit abuse |
| Voting for a language | Your license token and the languages you picked | Your license (as a hash), your languages and the date | To count one vote per buyer |
| Visiting gripspeak.com | What any website receives. We look at your browser's platform to send you to the right page | A count of installer downloads and short-link clicks per day, with nothing about who | To send you to the right page, and see where people come from |
The device ID is a one-way hash of your headset's chip serial number, or of the system's machine ID on a headset where the serial can't be read. We never receive the serial number itself.
Diagnostics are attached to problem reports unless you untick the box, and you can see exactly what's included before you send. They contain the Gripspeak, SteamOS, Steam and SteamVR versions; your button, hands-free, learning and polish settings; the results of health checks (such as whether the microphone and controllers are connected, and how many words your dictionary has); whether the license is active; and recent lines from Gripspeak's log. Gripspeak doesn't log what you dictate, and diagnostics also leave out any log line that quotes text.
Our web pages set no cookies of their own and load nothing from other sites.
What itch.io shares with us
itch.io sells Gripspeak and handles payment. For each purchase, itch.io shows us your email address, name, IP address, country and transaction ID. When we check a download key or sign-in with itch.io, its answer may include details of the purchase or your itch.io account; we use those only to confirm the purchase and don't store them.
We use purchase records only for support, refunds and license questions. We email you only about your purchase, and we never add you to a mailing list without your consent. itch.io's own handling is described in its privacy policy.
How long we keep it
- Feedback and diagnostics: 12 months, then deleted automatically.
- Activation and move records: for as long as your license exists. If you ask us to delete them, your license stops working and can't be restored.
- Refunded purchases: we mark the license as refunded and keep that hashed record so the key can't be used again.
- Language votes: until you change them or we retire the feature.
- Phone activation records: as described in the table above, usually less than a day.
Who we share data with
We share data only with services that run Gripspeak for us:
- Cloudflare hosts our server and database, and forwards support email. Cloudflare processes this data for us under its data processing agreement.
- Our email provider receives your feedback messages, including any diagnostics and the email address you gave, so we can reply.
- itch.io sells Gripspeak, and we check download keys and sign-ins with it.
We may disclose information when the law requires it. If Gripspeak is transferred to another business, your data goes with it and stays under this policy. We don't sell personal information, and we don't share it for advertising.
Our database is placed in eastern North America. Cloudflare may process a request in the data center nearest to you.
Downloads from other services
The installer, which also runs during updates, downloads Python packages from the Python Package Index (pypi.org) and, on first install, the speech models from GitHub. Those services see your IP address like any download. Otherwise, Gripspeak connects over the internet only to our server, and to OpenRouter if you connect an account. Signing in with itch.io or OpenRouter happens in your browser, on their sites.
Legal bases (for people in the EU and UK)
- Contract: activation by any method, license checks, reinstall recovery and updates, so we can provide what you bought.
- Legitimate interests: answering feedback; diagnostics attached to a problem report, to fix the problem you reported; language votes, to decide what to build; hashed network addresses, to limit abuse; and keeping refunded licenses marked, to prevent reuse.
- Legal obligation: keeping purchase and refund records where tax or consumer law requires.
Your choices and rights
You can use Gripspeak without AI polish, feedback, diagnostics or votes, and you can turn off update checks, history and learning in Settings.
Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or send it to you in a portable format, and you can object to uses based on our legitimate interests. Email support@gripspeak.com with your download link or the email you bought with, so we can find your records. We'll answer within one month. If you're in the EU or UK, you can also complain to your data protection authority.
Children
Gripspeak isn't meant for children under 13, and we don't knowingly collect personal information from them. If you believe a child has sent us information, email support@gripspeak.com and we'll delete it.
Do Not Track
Gripspeak doesn't track you across websites, so there's nothing for a browser's Do Not Track signal to change.
Changes
If we change this policy, we'll update the date above. If a change is significant, we'll also tell you in the app and note it on the Gripspeak page on itch.io.
Contact
Gripspeak · support@gripspeak.com · 605 W 9th Street, Unit #4108, Austin, Texas 78701, USA