Privacy Policy

Last updated: August 2026

1. Information We Collect

We collect information you provide directly to us when using VCaaS, including:

  • Account Information: Your email address and basic profile information via Firebase Authentication.
  • Biometric Data (Voice References): Audio samples uploaded for the purpose of zero-shot voice cloning.
  • Prompts: The text inputs you provide for synthesis.
  • Usage Data: API call frequency, processing times, and diagnostic telemetry.

2. Handling of Biometric Data & Voice References

Because VCaaS deals with voice data, we handle it with extreme care. Voice reference files uploaded for zero-shot cloning are stored ephemerally. They are held in memory only for the duration of the inference process on our Render-hosted GPU instances and are not permanently saved to our databases unless you explicitly opt to save them to your account's Voice Library. We do not use your personal voice references to train our foundational models.

3. Deepfake Detection & Watermarking Logs

To comply with ethical AI guidelines, when you generate audio using our platform, we automatically embed a cryptographic watermark. We retain logs of generated watermarks (including timestamps, associated account IDs, and cryptographic hashes) to aid in the verification of deepfakes and the prevention of platform abuse.

4. Third-Party Data Processors

We rely on carefully vetted third-party services to operate the platform:

  • Google Firebase: Used exclusively for secure user authentication and account management.
  • Render: Hosts our secure backend inference APIs and processes the actual audio generation.
  • Vercel: Hosts our frontend web application and edge network.

These providers are contractually obligated to protect your data and do not have rights to use your biometric inputs for their own purposes.

5. Data Retention & Deletion

You can delete your account at any time from your settings page. Upon deletion, your email, saved voice models, and generation history are permanently purged from our active databases. Cryptographic logs of previously generated audio may be retained for security and audit purposes to trace malicious deepfakes if requested by law enforcement.

6. Security Measures

We implement strict access controls, transport-layer security (HTTPS/TLS) for all API communications, and encrypted at-rest storage for databases. However, no internet transmission is 100% secure, and we cannot guarantee absolute security.

7. Contact Us

If you have questions regarding this Privacy Policy, your biometric data, or wish to exercise your data rights (including GDPR and CCPA requests), please contact our privacy team via the Help center.