Privacy policy
Version v1 · Effective date: April 2026
What we collect
The following categories describe the personal information we collect. The CCPA category labels in parentheses map each category to California Civil Code §1798.140(v).
- Account data (CCPA: Identifiers; Internet or electronic activity) from Clerk: email address, user identifier, sign-in metadata, authentication tokens, password hash stored by Clerk.
- Billing data (CCPA: Identifiers; Commercial information) from Stripe: customer ID, subscription status, plan, invoice history, billing country and ZIP (for tax), last 4 digits and brand of the payment method. We do not store or have access to full payment card numbers.
- Usage data (CCPA: Internet or electronic activity; Inferences): model invocations, text length, audio duration, request timestamps, IP address, user-agent, rate-limit counters, and derived plan-enforcement signals. Used for billing, abuse prevention, and service operation.
- Text submitted for synthesis (CCPA: Electronic activity; possible Inferences). Text is processed through the model pipeline and discarded from memory after response; it is not persisted beyond operational logs scrubbed of content.
- Audio submitted for transcription (CCPA: Electronic activity): transcribed text may include whatever the speaker said. We apply optional PII redaction (emails, phones, IPs, IBAN, SSN, credit cards) before returning results when requested. See "Retention and deletion" for retention schedule.
- Uploaded reference audio (CCPA: Sensitive Personal Information — biometric information used to identify a consumer): cached for up to seven (7) days by default (
REFERENCE_AUDIO_TTL_HOURS=168) to enable voice cloning. Automatically deleted after the TTL expires, on user request, or on account deletion — whichever first. See the Biometric Information Notice below. - Generated audio (CCPA: Commercial information; possible Inferences): retained on disk for a configurable TTL (default 72 hours,
AUDIO_TTL_HOURS=72) then automatically deleted by a scheduled cleanup task. A database record of the generation (duration, model, timestamp) is retained for billing and audit. - Consent records (CCPA: Identifiers): we log when and what you consented to (terms acceptance, voice-cloning attestation, age-13+ attestation), plus timestamp, IP address, and user-agent, for our compliance records.
- Abuse reports (CCPA: Identifiers; Electronic activity): when someone reports a voice clone or generation as abusive, we record the report, the submitter's contact details, and the target reference or output.
Sources of personal information
We collect personal information from the following sources:
- Directly from you: when you sign up, upload reference audio, submit text, or transcribe audio.
- Automatically from your device: IP address, user-agent, request timing, and other telemetry your browser or client sends with each request.
- From our subprocessors (listed below): Clerk for authentication signals, Stripe for billing status, Cloudflare for request metadata.
- From third parties submitting abuse reports: when a non-customer contacts us to report abuse of the Service.
How we use it (business and commercial purposes)
We use personal information only for the purposes disclosed at or before the time of collection. The business purposes under CCPA §1798.140(e) for which we process personal information are:
- Providing, operating, and maintaining the Service (synthesizing speech, transcribing audio, serving the web app).
- Processing transactions, billing, and managing subscriptions.
- Authenticating users and securing accounts.
- Preventing, detecting, and investigating abuse, fraud, and security incidents.
- Enforcing our Terms of Service and responding to legal process.
- Debugging errors and improving Service reliability (we do not use customer inputs or outputs to train our models — see "Model training").
- Complying with legal, accounting, and tax obligations.
We do not sell or share personal information as "sell" and "share" are defined by the CCPA/CPRA. We do not and will not exchange personal information for money or other valuable consideration, and we do not share personal information for cross-context behavioral advertising.
We do not use or disclose Sensitive Personal Information (including voice biometrics) for purposes beyond those authorized by CCPA §1798.121 — namely, to provide the Service you requested, to detect and resist abuse, and as required by law.
Legal basis (GDPR)
For users in the European Economic Area, we process personal data under the following bases: (a) contract performance (providing the Service), (b) legitimate interest (security, fraud prevention), and (c) consent (where explicitly given, e.g., voice cloning attestation). You may withdraw consent at any time without affecting prior processing.
Your rights (summary)
Depending on where you live, you may have some or all of the rights listed below. Two jurisdiction-specific sections follow (California and EEA/UK) that describe how to exercise them and the response windows that apply.
- Access / right to know — request a copy of the personal information we hold about you.
- Correction — request we correct inaccurate personal information.
- Deletion — request we delete your personal information.
- Portability — receive your data in a structured, machine-readable format.
- Opt-out of sale or sharing — we do not sell or share personal information; this right is satisfied by that practice.
- Limit use of Sensitive Personal Information — restrict our use of SPI (including voice biometrics) to purposes permitted by CCPA §1798.121.
- Non-discrimination — we will not deny Service, charge a different price, or provide a different quality of Service because you exercised any of these rights.
- Objection — object to processing based on legitimate interest (EEA/UK only).
- Withdraw consent — withdraw consent where processing is based on consent.
To exercise any of these rights, email our privacy contact from the address on your account, or use the in-product "Delete my account" flow. If you are asking on behalf of another person, see the authorized-agent instructions in the California Residents section below.
California residents — CCPA/CPRA notice
This section describes the rights of California residents under the California Consumer Privacy Act (Cal. Civ. Code §1798.100 et seq.) as amended by the California Privacy Rights Act. If you are a California resident, the rights below apply regardless of whether you are a current customer, a former customer, or a non-customer whose personal information we hold (for example, the subject of an abuse report).
- Right to know — the categories and specific pieces of personal information we have collected about you, the sources, the business or commercial purpose, and the categories of third parties (including subprocessors) to whom we have disclosed it, over the preceding 12 months.
- Right to delete — request deletion of personal information we have collected from you, subject to statutory exceptions (e.g., completing a transaction, detecting security incidents, complying with legal obligations).
- Right to correct — request correction of inaccurate personal information.
- Right to portability — receive your personal information in a structured, commonly used, machine-readable format.
- Right to opt-out of sale or sharing — we do not sell personal information and we do not share personal information for cross-context behavioral advertising, so there is nothing to opt out of. If that ever changes, a "Do Not Sell or Share My Personal Information" link will be added to every page of the Service.
- Right to limit use of Sensitive Personal Information — restrict our use of SPI (including voice biometrics) to the purposes permitted by CCPA §1798.121: performing the requested Service, preventing and investigating security incidents and unlawful behavior, ensuring short-term transient uses, and complying with law. We already limit our use of SPI to these purposes as a matter of policy; see the Biometric Information Notice below.
- Right to non-discrimination — we will not deny you Service, charge you a different price, provide a different level of quality, or retaliate in any way because you exercised your CCPA rights.
How to exercise these rights. Email our privacy contact from the address associated with your account. If you do not have an account, include enough information for us to reasonably verify your identity (for example, prior email correspondence or billing information you used with the Service). We will acknowledge receipt within ten (10) business days and respond to your request within forty-five (45) calendar days, which we may extend once by an additional forty-five days with written notice if reasonably necessary, as CCPA §1798.130 permits.
Authorized agents. You may designate an agent to submit a request on your behalf. Provide the agent with written, signed permission; we will independently verify your identity and confirm your authorization (typically by contacting you directly) before acting on the request.
"Shine the Light" (Cal. Civ. Code §1798.83). We do not disclose personal information to third parties for their own direct-marketing purposes, so no §1798.83 disclosure is required. If that ever changes, we will update this policy and provide an opt-out mechanism.
Retention. We retain each category of personal information only for as long as is reasonably necessary for the business purpose disclosed above, subject to the schedule in the "Retention and deletion" section below. We do not retain personal information longer than that schedule unless required by law (e.g., tax retention on invoices).
Notice of financial incentive. We do not offer any financial incentive in exchange for personal information, and we do not operate a loyalty or rewards program that would require notice under CCPA §1798.125(b). If we ever offer one, we will update this policy.
Information about the categories of personal information we collected, disclosed, sold, or shared over the preceding twelve months is covered under "What we collect," "Sources," "How we use it," and "Subprocessors." We have not sold or shared personal information (as those terms are defined by the CCPA) in the preceding twelve months.
Data transfers
The Service is operated from California, United States. Your personal information is processed on servers located in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States.
EEA / UK. For transfers of personal data from the European Economic Area or the United Kingdom to the United States, we rely on the European Commission's Standard Contractual Clauses (module 2, controller-to-processor) with each subprocessor, supplemented by the UK International Data Transfer Addendum where the transfer involves UK residents. Copies of the executed SCCs are available on request.
Subprocessors
We engage the following third parties to process personal information on our behalf. Each is bound by a data processing agreement that restricts the use of your data to providing their service to us.
- Clerk (US) — authentication, identity management, session tokens.
- Stripe (US) — payment processing, subscription management, tax calculation.
- Resend (US) — transactional email delivery (password reset, billing receipts, abuse-report notifications).
- Cloudflare (US) — tunnel ingress, DDoS protection, and edge TLS termination. Cloudflare processes request metadata (IP, user-agent, URL) in transit.
- PostHog (US) — product analytics, where enabled. We collect only pseudonymous usage events; no input content or generated audio is sent to PostHog.
- Hugging Face (US) — only for downloading open-source model weights. No customer personal information is transmitted to Hugging Face.
- Sentry (US, where enabled) — server-side error monitoring. Stack traces and request metadata may include IP and user ID; content of inputs is scrubbed.
- Infrastructure provider (US) — GPU host operator. Servers are located in the United States.
- Content moderation — automated classifiers and manual review tooling used exclusively to investigate abuse reports.
We will update this list when we add, remove, or change a subprocessor. Material changes are communicated via email to the account administrator and with at least thirty (30) days' notice for enterprise customers with a DPA in force.
Biometric Information Notice
This notice applies to reference audio you upload for voice cloning. Your voice may qualify as "biometric information" or "biometric identifiers" under the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), Washington HB 1493, Illinois GIPA, and similar laws.
- Purpose. We collect and process reference audio solely to produce the voice clone you request, to bill you for the work, to defend against abuse of the Service, and to comply with legal process.
- Retention. Reference audio is retained in volatile cache for up to seven (7) days by default and is permanently destroyed upon account deletion, upon completion of the purpose for which it was collected, or when the Service ceases to need it — whichever occurs first. A record of the cloning attestation (timestamp, user, IP address, user-agent) is retained in our compliance log.
- Disclosure. We do not disclose or share voice biometric data to any third party except our subprocessors listed above (solely to perform the Service on our behalf) and as required by legal process.
- Written release. Before uploading a third party's voice, you must obtain that person's written consent. We log your attestation at the time of upload; by uploading, you represent that such consent has been obtained.
- No sale. We do not and will not sell, lease, trade, or profit from your voice biometric data.
If you are a resident of Illinois, Texas, or Washington and would like a copy of the record we hold under this notice, or to withdraw consent, contact our privacy contact.
Model training
By default, we do not use your inputs, reference audio, transcribed audio, or generated outputs to train or improve our models. Where model-improvement involvement is offered (typically only on free-tier accounts), it is presented as an explicit in-product opt-in and can be disabled in account settings. Enterprise and paid accounts have training involvement off by default and contractually; see the Data Processing Agreement we execute with enterprise customers.
Voice-agent and robocall disclosure
Users deploying synthesized voices for calls, voice agents, or interactive voice systems must comply with applicable disclosure requirements. In particular, the U.S. Federal Communications Commission's February 2024 ruling treats AI-generated voices as "artificial" under the Telephone Consumer Protection Act (TCPA); prior express consent from the called party and caller-identity disclosure are required. See our Terms for the acceptable-use clauses that govern robocall and voice-agent deployments.
Retention and deletion
We retain each category of personal information only for as long as is reasonably necessary for the business purpose disclosed above. Specific schedules:
- Generated audio files (on disk): default 72-hour TTL (
AUDIO_TTL_HOURS=72). A scheduled cleanup task deletes expired files; a Prometheus alert fires if any generation past the TTL still has a file on disk, so overruns are caught. - Reference audio (voice-clone samples): default seven (7) days in Redis cache (
REFERENCE_AUDIO_TTL_HOURS=168). Deleted automatically on expiry, on user request viaDELETE /api/v1/voice-clones/{ref_id}, or on account deletion — whichever first. - Transcripts: returned to you in the API response and not persisted on our side beyond the lifetime of the request (plus operational logs scrubbed of content). Async jobs store the transcript until the job result is retrieved or 24 hours elapse, whichever first.
- Generation / transcription database records(metadata: user, model, duration, timestamp — not content): retained for the current billing period plus 13 months for billing dispute resolution.
- Usage logs (request-level audit log): retained for 90 days and then purged.
- Account data (email, subscription state, Clerk profile): retained while your account is active. Deleted within thirty (30) days of account deletion, except for data we are required by law to retain longer.
- Billing records (invoices, Stripe events): seven (7) years to satisfy U.S. federal and California tax-record retention requirements. This overrides the default deletion right for the billing category only.
- Consent records: retained for the duration required by applicable law (minimum two (2) years after last consent; longer for biometric consent under BIPA — see Biometric Information Notice).
- Abuse reports: retained for three (3) years from the report date to support investigation and any legal proceeding that may follow.
Cookies
We use only essential cookies required for authentication and session management (via Clerk). We do not use tracking cookies, analytics cookies, or advertising cookies.
Children
The Service is not directed to and not intended for individuals under 18 years of age. We require users to attest they are at least 13 years old (COPPA) at sign-up, and our Terms require users to be 18+ or the age of majority in their jurisdiction. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information to us, contact us immediately at our privacy contact and we will promptly delete the information.
California minors (CCPA §1798.120(c)). We do not sell or share personal information, so the CCPA affirmative opt-in requirement for the sale or sharing of information about consumers under 16 does not apply. If that ever changes, we will implement the required opt-in flow before any minor's information is sold or shared.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the Service. Continued use after changes constitutes acceptance.
Contact
Privacy questions and data requests: our privacy contact.