Legal

Privacy policy

What we collect, why we hold it, and what you can make us do with it. Written to be read rather than to be survived.

Last revised 14 August 2026

In short

Your prompts, voice references and conversations are not sent to any third-party AI provider. Every model runs in a container we or you operate. That is a structural property of how this platform is built, not a policy promise that could be changed by a vendor.

We do not sell personal data. We do not use your content to train models for anyone else. The most sensitive things you give us — a voice sample, an intimate conversation — stay inside the deployment you are using.

What we collect

Account information

Email address, and authentication identifiers from the identity provider used to sign in. Passwords are not stored by us; sign-in is delegated.

Content you create

Characters, voice reference clips, generated audio, generated images and conversation history. Conversation memory is retained deliberately — it is what allows a companion to remember an earlier session.

Usage records

Which endpoints were called, by which API key, and how much quota was consumed. This is what lets you attribute usage across an organisation, and what lets us enforce a plan limit.

Technical information

IP address, request timestamps and error diagnostics. Rate limiting requires an identifier per caller and IP is what is used, including for the unauthenticated homepage demo. Cookies are limited to sign-in and security — the cookie policy lists them, and what we deliberately do not set.

How we use it

  • To operate the service you asked for — generating speech, holding a session, rendering an image.
  • To enforce quotas and rate limits, and to bill where a paid arrangement exists.
  • To investigate abuse reported under the acceptable use policy.
  • To diagnose faults.

We do not use your content to train models. We do not profile you for advertising. There is no advertising on this platform.

Sharing

We do not sell personal data. Content is shared with third parties only in these cases:

  • Infrastructure providers hosting the servers the service runs on. They process data on our instructions and do not use it for their own purposes.
  • The identity provider that authenticates sign-in, which necessarily receives your email address.
  • Where legally compelled, and we will tell you unless prohibited from doing so.

Notably absent from that list: AI model providers. There are none, because the models are self-hosted.

Retention

  • Account records — for as long as the account exists.
  • Generated content and characters — until you delete them, or the account is closed.
  • Usage records — retained for accounting and abuse investigation.
  • Diagnostic logs — short-lived, and rotated.

Your rights

Depending on where you live you may have the right to access, correct, erase, restrict or port your personal data, and to object to processing. We honour these regardless of whether a particular regime applies to you. The GDPR-specific position is set out on the GDPR compliance page.

  • Access — ask and we will tell you what we hold.
  • Correction — account details are editable in the dashboard.
  • Erasure — see the section below, which is more specific than the usual wording.
  • Portability — available on request. There is no self-serve export button yet; ask and we will produce it manually.

Erasure

Deleting your account removes your records and unlinks the files you own — voice reference clips, character portraits and the media generated from them. It is a deletion, not a deactivation: the account row is removed and the dependent records go with it.

The operation reports what it removed rather than simply claiming success. If any file cannot be deleted, you are told so explicitly instead of being given a clean confirmation, and you can contact us to have the remainder completed by hand.

An earlier version of this policy said erasure removed database records but not files. That was true of an earlier implementation — and the endpoint at the time did less still, merely marking the account inactive. Both have been fixed, and this section describes what the code now does.

Two limits worth stating. Records we are required to keep — for example to meet an accounting obligation — are retained for as long as that obligation lasts. And material you exported or published elsewhere is beyond our reach; we can only erase what is on our systems.

Security

  • Traffic is encrypted in transit.
  • API keys are stored hashed. A key is shown once, at creation, and cannot be recovered afterwards.
  • Uploaded material is served only to authenticated sessions, not from a publicly readable path.
  • Every mounted API route requires authentication, with automated tests asserting it stays that way.

We hold no security certification — see Enterprise for the full diligence position rather than a claim we cannot support.

Contact

For any request under this policy, or to ask what we hold about you, contact us. If you are dissatisfied with how we handle it, you may complain to your local data protection authority.

This policy sits alongside the terms of service, the acceptable use policy, the cookie policy and the age verification statement.

A request about your data?

Ask what we hold, have it corrected, or have it erased. A person reads every request.