This policy explains how Speechify, Inc. (“Speechify”) collects, retains, and permanently destroys biometric data derived from people’s voices. It applies to all Speechify products and services that create or verify synthetic voices, including the Speechify API, Speechify Studio, and voices created for business customers.
1. What this policy covers
“Biometric data” in this policy means the following, to the extent they are biometric identifiers or biometric information under applicable law:
- Voice samples: recordings of a person’s voice submitted to create a synthetic voice.
- Voice models: synthetic voices, and the speaker embeddings or other numerical representations of a person’s vocal characteristics derived from voice samples.
- Verification data: recordings made during Speechify’s voice owner verification process, and the voiceprint comparison data used to confirm that the person consenting is the person whose voice is being cloned.
2. Why we collect it
Speechify collects biometric data only to:
- create and provide synthetic voices that the voice owner, or a business customer holding the voice owner’s written consent, has requested;
- verify that the person whose voice is being cloned has consented; and
- prevent misuse of voice cloning, including impersonation and fraud.
Speechify does not use biometric data to identify people for any other purpose. It does not sell, lease, or trade biometric data, or otherwise profit from it.
3. Retention schedule
Speechify permanently destroys each category of biometric data at the earliest of the times shown below.
| Data | Purpose satisfied | 24-month limit | Other limit |
|---|---|---|---|
| Voice samples and voice models | Within 30 days after the voice is deleted by its owner or the business customer, consent is revoked, or the account closes | Voices you create for yourself: 24 months after your last interaction with Speechify. Voices a business customer creates: 24 months after the voice is created or, if later, after the customer last notifies Speechify that the voice owner has renewed consent | 45 days after Speechify determines the data is no longer needed |
| Verification data | Within 30 days after the related voice is deleted | The same 24-month limit as the related voice | 45 days after no longer needed |
For voices a business customer created before the effective date of this policy, the 24-month limit runs from that effective date.
Consent records that contain no biometric data, such as the date, the consenting person’s name, and the text of the consent, are kept for 5 years after the related voice is deleted, to document that consent was given.
4. How we destroy it
- Active systems. Biometric data is deleted from active systems within the periods above.
- Backups and archived versions. Copies in database backups and archived storage versions are deleted automatically within 90 days, and are not restored for any other use in the meantime.
- Legal holds. Speechify may retain biometric data longer only where required by law, a court order, or a legal hold for pending or reasonably anticipated litigation or investigation, and only for as long as that requirement lasts.
5. Disclosure
Speechify discloses biometric data only:
- to service providers that host or process it for Speechify under written contracts requiring them to protect it and use it only for Speechify’s purposes;
- with the consent of the voice owner or their legally authorized representative;
- to complete a transaction the voice owner or their representative requested; or
- as required by law, subpoena, or court order.
6. Security
Speechify protects biometric data using the reasonable standard of care in its industry, and in a manner at least as protective as it uses for its other confidential and sensitive information. Protections include encryption in transit and at rest, access limited to personnel who need it, and an annual independent SOC 2 Type II examination.
7. Incident response
If Speechify discovers a security incident that may have compromised biometric data, it will:
- contain the incident and preserve evidence;
- assess what data and which individuals were affected;
- notify affected individuals, business customers, and regulators as required by law; and
- review the incident and remediate its cause.
8. Requests and contact
To ask about your biometric data or request its deletion, contact legal@speechify.com. Speechify will act on a verified deletion request within the periods in Section 3.
If your voice was cloned by one of Speechify’s business customers, you may contact that customer or Speechify. When Speechify receives a verified request to delete a voice that a business customer created, Speechify will permanently delete the voice and its associated biometric data within the periods in Section 3, unless a legal hold described in Section 4 applies, and will then notify the business customer.
9. Changes to this policy
Speechify will review this policy at least annually and will post any update here with a new effective date.