So here's the plain version: what we store, how long we keep it, how consent for cloning is enforced, and how data is protected. No overclaiming.
No voice is cloned without verified consent from the person it belongs to. That consent is recorded, tied to the specific voice, and can be revoked at any time, after which the cloned voice can no longer be used. This is enforced in the product itself, not a promise in a policy.
Call recordings and voice samples are stored only to run the features you use, transcription, outcome logging, and voice matching. Retention periods are set per account, and data can be deleted on request.
Cloning requires explicit, verifiable consent from the voice owner, with usage controls that limit where a cloned voice can be applied. Consent is revocable, and revocation takes effect on the voice going forward.
Data is encrypted in transit using modern TLS, and encrypted at rest in storage. Access to voice data is limited to the systems and people that need it to deliver the service.
We describe our security posture based on what is true today, not on aspirations. As we complete formal certifications and audits, we'll state them here specifically, with scope and dates, rather than implying coverage we don't yet hold. If you have a specific compliance requirement, talk to us and we'll tell you exactly where we stand.