Privacy policy for the Koythu voice studio.
Voice is closer to a fingerprint than an ordinary preference. This page describes, without hedging, what data the Koythu studio collects, why, and what you can do about it.
What the studio collects
Three categories, and only these three.
- Account information. Name, email, company, role, and the login credentials for the studio. Collected when you sign up, stored to authenticate you and to reply to support requests.
- Content you submit. Scripts, tone selections, language selections, and any voice recordings you upload to create a consented clone. Stored to render audio and to keep a clone reproducible across sessions.
- Rendered output and metadata. Audio files the studio generates for you, plus timing metadata like phoneme and word boundaries. Stored so you can retrieve, re download and integrate them.
Beyond these three, nothing else is collected by the studio itself. No shadow analytics, no scraped browsing history, no third party trackers threaded through the pages you read.
Voice cloning and consent
Voice cloning is treated as its own category because it deserves to be.
- A voice can only be cloned if the voice owner completes a live identity check and signs a timestamped consent statement. No proxy submissions, no third party uploads.
- The voice owner declares the scope - narration, IVR, advertising, or all - at the point of consent. That scope is enforced at the API layer, not in a policy PDF.
- Consent is revocable at any time from the owner account. Once revoked, no new audio can be generated with the voice. Previously rendered files are not silently deleted, but future usage stops within minutes.
How long we keep it
- Scripts submitted to the studio expire after 24 hours unless you pin them to a project.
- Rendered audio is retained for 30 days by default. You can extend this on a per project basis, or delete files earlier from the account page.
- Consent records for cloned voices are retained for the lifetime of the voice profile plus seven years after revocation, so that any past usage remains auditable.
- Account information persists while your account is active. On cancellation, we retain it for 30 days for reactivation, then it is purged.
What we do not do
- We do not train the underlying models on your submitted content. Model fine tuning uses data we own or licence explicitly.
- We do not sell, rent or trade any account information, scripts, audio, or voice profiles. There is no data broker relationship, direct or indirect.
- We do not embed third party advertising trackers on this site or inside the studio. Aggregate, first party product analytics are used to keep the studio running.
Who can access your data
Only three categories of people.
- You, and the members of your workspace you invite. Roles are scoped, so an invited member sees only what their role allows.
- A narrow set of Koythu staff bound by contract, who need access to run the service or answer a support ticket. Access is logged.
- Sub processors for hosting, transactional email and error reporting. A current list is provided on request through the security desk.
Your rights
- Access - request a copy of everything the studio holds about your account.
- Correction - update any account information yourself, or ask us to correct records we hold.
- Deletion - close your account and have your data purged after the 30 day retention window.
- Portability - export your rendered audio and voice profiles in standard formats.
- Consent withdrawal - for cloned voices, the voice owner can revoke consent at any time.
Security
TLS 1.2 or higher in transit. Per project encryption at rest. Scope bound API tokens hashed on storage. Full detail sits on the security page.
Reaching us on privacy matters
Privacy requests reach the grievance officer through the contact form. Security disclosures reach the same team by email at security@koythu.com.
