Privacy Policy

This describes what we collect and why, in plain language. It is short because we collect very little — the site runs its own lightweight analytics rather than a third-party tracking stack, and the audio pipeline does not need to know who you are beyond your account.

What we store about your account

An email address, a display name if you provide one, a password hash if you signed up with a password, and a Google account identifier if you signed in with Google. We also store the country reported by our network provider, whether you last used a phone or a desktop browser, and a record of where you first arrived from — a search engine, a referring site, or direct.

We do not store your password. We store a bcrypt hash, which cannot be reversed into the original.

What we store about your content

Scripts, character cards and rendered audio belong to your account and are stored so you can come back to them. We do not use your scripts to train voice models, and we do not read them except when you ask us to investigate a specific problem and give us permission.

Deleting a project deletes its scripts and audio. Deleting your account deletes everything associated with it.

Analytics, and what makes ours unusual

Page views are recorded by a small first-party script that sends the path, the referring site and the language to our own server. It sets no cookie. Instead of storing your IP address, we store a hash of your IP, your browser string and a salt that changes every day — which means the identifier cannot be used to follow you from one day to the next, and cannot be reversed into an IP address.

If Google Analytics or Cloudflare analytics are enabled in production, they are configured without full IP addresses. Both are optional and are only loaded when the corresponding key is configured.

Voice clone recordings

If you create a voice clone, we store the sample recording, the derived model, and the spoken consent statement from the person whose voice it is. The consent statement is retained for as long as the model exists, because it is the record that makes the model legitimate.

The person whose voice was cloned may ask us to delete the model at any time, whether or not they hold the account that created it. We do not ask for a reason.

Who else sees your data

The speech synthesis provider receives the text being rendered and the voice identifier. It does not receive your account details. Which provider is in use is shown in the app, and the provider layer is designed so the answer can change without anything else changing.

We do not sell data, and we do not share it with advertisers. There are no advertising trackers on this site.

Your rights and how to use them

Email [email protected] to request a copy of your data, a correction, or deletion. We will do it. If you are in a jurisdiction with statutory data rights, this is how you exercise them; if you are not, the process is the same, because having two processes would be silly.

This document is a working draft written by the team, not a lawyer-reviewed final. It will be reviewed before payments are enabled, and this note will come off when it has been.