Legal

Privacy Policy

Last updated: August 2026. This policy governs the collection, processing, and protection of your data by VoiceSeal Inc.

BIPA Notice

VoiceSeal collects voice biometric data (voice embeddings). Under the Illinois Biometric Information Privacy Act (BIPA) and similar biometric-privacy laws, we obtain explicit consent before collection, publish a retention and destruction schedule, and provide access and deletion rights. Consent is recorded per purpose and can be withdrawn at any time.

1. Information We Collect

We collect the following categories of information:

  • Account data: Name, email address, password (stored as a hash), and account/plan type.
  • Voice biometric data: Voice embeddings (numerical voiceprints) derived from audio samples you provide, generated using pre-trained speaker-embedding models (Resemblyzer / GE2E, and Wav2Vec2). Embeddings are stored in access-controlled cloud storage (Cloudflare R2).
  • Uploaded audio (Archive Enrollment): If you use Archive Enrollment, the audio files you upload are stored as your archival master records (marked with a C2PA content credential) in Cloudflare R2. Standard voice enrollment derives an embedding and does not retain the source recording as a separate archival file.
  • Verification submissions: Suspect URLs or files you submit to Rightsholder Verification (Beta), and the results of our team's review.
  • Usage data: API calls, authorization checks, login timestamps, IP addresses, and request metadata, used for security and audit.
  • Consent records: Timestamped records of your biometric consent, tracked per purpose (voice enrollment, verification, licensing, analytics) and per withdrawal.

2. We Do Not Train Models on Your Voice

We do not use your voice recordings or embeddings to train, fine-tune, or otherwise improve any machine-learning model. The models we use to generate embeddings are third-party, pre-trained models run in inference mode only. Your voice data is used solely to provide the services described in this policy — it is not training data.

3. Biometric Data Retention & Destruction

Voice embeddings (and any Archive Enrollment audio you have uploaded) are retained for the duration of your account or until you withdraw consent or request deletion, whichever comes first. On withdrawal of consent or account deletion, we permanently delete your biometric data within 30 days. We do not retain biometric data beyond the purpose for which it was collected.

4. How We Use Your Data

  • Rightsholder verification (Beta) — comparing a clip you submit against your enrolled voiceprint, with human review
  • Pre-synthesis authorization — returning your authorization decision and terms to platforms that query the pre-synthesis check API
  • Provenance — marking synthetic audio with a trusted C2PA content credential
  • Licensing management and revenue distribution
  • Platform security, abuse prevention, and audit logging
  • Service communications (account notices, verification results)
  • Compliance with legal obligations

5. Service Providers (Sub-processors)

We do not sell, trade, or rent your personal or biometric data. We share data only with the service providers that operate our platform, under their respective terms and data-processing commitments:

  • Railway — backend application hosting
  • Vercel — frontend/website hosting
  • Cloudflare R2 — storage of embeddings and Archive Enrollment audio
  • Trufo Provenance Platform — trusted C2PA signing of marked audio
  • Stripe — payment and payout processing
  • SendGrid — outbound transactional email
  • Zoho — inbound email handling

We may also disclose data to law enforcement or other parties when required by valid legal process.

6. Your Rights

  • Access: Request a copy of the data we hold about you.
  • Deletion: Request permanent deletion of your account and associated data.
  • Consent withdrawal: Withdraw biometric consent at any time via the dashboard or by contacting us.
  • Data export: Export your data in a machine-readable format.

To exercise these rights, use the dashboard settings or contact privacy@voiceseal.io.

7. Security

We protect data in transit using TLS, store biometric data in access-controlled cloud storage (Cloudflare R2, which provides encryption at rest), authenticate API access using signed tokens with brute-force lockout protection, and maintain audit logs of data-access events. No system is perfectly secure; we work to align our controls with recognized industry practices.

8. Contact

VoiceSeal Inc. • privacy@voiceseal.io • For BIPA-specific requests: bipa@voiceseal.io