Gripspeak Privacy Policy

Version 2026-10-13 · Last updated October 13, 2026

The sole proprietor in Texas, USA, doing business as Gripspeak ("we," "us") makes Gripspeak, a voice-typing app for the Steam Frame, and is responsible for the personal data described here. Our address is 605 W 9th Street, Unit #4108, Austin, Texas 78701, USA. You can reach us at support@gripspeak.com.

We wrote this policy to be short and literal. If Gripspeak changes in a way that makes any of it untrue, we'll update the policy.

The short version

What stays on your headset

Like any file in your home folder, these files can be read by other software you run on the headset.

Deleting it all. Your settings, dictionary and OpenRouter key are in ~/.config/gripspeak/, and your history and saved license are in ~/.local/state/gripspeak/. Deleting both folders removes them from the headset. Uninstalling keeps them unless you use the purge option, so a reinstall picks up where you left off.

Optional AI polish

When AI polish is on, each dictation sends the following to OpenRouter (openrouter.ai), using your own OpenRouter account and key:

Dictations of three words or fewer aren't sent. Connecting an OpenRouter account turns polish on, and you can turn it off at any time in Settings.

OpenRouter forwards the request to the model provider you pick in Settings:

Gripspeak tells OpenRouter to use only the provider it names, with no fallback to any other, and only providers that don't collect user data under OpenRouter's data policy setting. OpenRouter says it doesn't keep your prompts unless you turn on prompt logging in your OpenRouter account. It does keep account and billing records.

We never see this text or your key. These providers' own policies apply, and they can change:

What our server receives

Our server and database run on Cloudflare. Like any web host, Cloudflare processes your IP address to deliver each request.

WhenWhat we receiveWhat we keepWhy
Activating with your download linkYour itch.io download key, and a device ID for your headsetA one-way hash of the key, the device ID, the activation date, and a record of any moves between headsetsTo confirm your purchase with itch.io and keep it on one headset, including after a reinstall
Signing in with itch.io to activateA sign-in token from itch.io, and the device IDThe same as above. We use the token once to ask itch.io which account you are, use only the account number to find your purchase, and keep neither the token nor your account detailsThe same
Activating from your phoneFrom the headset: the device ID. From your phone: the 6-digit code and your download linkThe code with the device ID, until your headset collects its license or, if it doesn't, at our next cleanup after the code expires (codes expire after 15 minutes). A hash of your network address (the first part of the IP address of your phone, and of your headset when it asks for a code) and the time, cleared once it's more than an hour old, the next time anyone uses phone activationTo activate the headset showing the code, and to limit repeated guesses
A reinstall finding its license againThe device IDNothing newTo give a reinstalled headset its license back without the key
The daily license check, when onlineYour license token, which names your purchase (as a hash) and your headsetNothing newTo see whether the license has moved to another headset or the purchase was refunded
Checking for and downloading updatesThe app version, and your license token when downloadingNothingTo offer updates, and to deliver them only to activated copies
Sending feedback or a problem reportYour message; your email, if you give one; your license, if activated; diagnostics, unless you untick the boxAll of it, plus a hash of your network address (the first part of your IP address)To reply to you, fix problems and limit abuse
Voting for a languageYour license token and the languages you pickedYour license (as a hash), your languages and the dateTo count one vote per buyer
Visiting gripspeak.comWhat any website receives. We look at your browser's platform to send you to the right pageA count of installer downloads and short-link clicks per day, with nothing about whoTo send you to the right page, and see where people come from

The device ID is a one-way hash of your headset's chip serial number, or of the system's machine ID on a headset where the serial can't be read. We never receive the serial number itself.

Diagnostics are attached to problem reports unless you untick the box, and you can see exactly what's included before you send. They contain the Gripspeak, SteamOS, Steam and SteamVR versions; your button, hands-free, learning and polish settings; the results of health checks (such as whether the microphone and controllers are connected, and how many words your dictionary has); whether the license is active; and recent lines from Gripspeak's log. Gripspeak doesn't log what you dictate, and diagnostics also leave out any log line that quotes text.

Our web pages set no cookies of their own and load nothing from other sites.

What itch.io shares with us

itch.io sells Gripspeak and handles payment. For each purchase, itch.io shows us your email address, name, IP address, country and transaction ID. When we check a download key or sign-in with itch.io, its answer may include details of the purchase or your itch.io account; we use those only to confirm the purchase and don't store them.

We use purchase records only for support, refunds and license questions. We email you only about your purchase, and we never add you to a mailing list without your consent. itch.io's own handling is described in its privacy policy.

How long we keep it

Who we share data with

We share data only with services that run Gripspeak for us:

We may disclose information when the law requires it. If Gripspeak is transferred to another business, your data goes with it and stays under this policy. We don't sell personal information, and we don't share it for advertising.

Our database is placed in eastern North America. Cloudflare may process a request in the data center nearest to you.

Downloads from other services

The installer, which also runs during updates, downloads Python packages from the Python Package Index (pypi.org) and, on first install, the speech models from GitHub. Those services see your IP address like any download. Otherwise, Gripspeak connects over the internet only to our server, and to OpenRouter if you connect an account. Signing in with itch.io or OpenRouter happens in your browser, on their sites.

Your choices and rights

You can use Gripspeak without AI polish, feedback, diagnostics or votes, and you can turn off update checks, history and learning in Settings.

Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or send it to you in a portable format, and you can object to uses based on our legitimate interests. Email support@gripspeak.com with your download link or the email you bought with, so we can find your records. We'll answer within one month. If you're in the EU or UK, you can also complain to your data protection authority.

Children

Gripspeak isn't meant for children under 13, and we don't knowingly collect personal information from them. If you believe a child has sent us information, email support@gripspeak.com and we'll delete it.

Do Not Track

Gripspeak doesn't track you across websites, so there's nothing for a browser's Do Not Track signal to change.

Changes

If we change this policy, we'll update the date above. If a change is significant, we'll also tell you in the app and note it on the Gripspeak page on itch.io.

Contact

Gripspeak · support@gripspeak.com · 605 W 9th Street, Unit #4108, Austin, Texas 78701, USA