Speechify Biometric Data Retention and Destruction Policy

Effective

This policy explains how Speechify, Inc. (“Speechify”) collects, retains, and permanently destroys biometric data derived from people’s voices. It applies to all Speechify products and services that create or verify synthetic voices, including the Speechify API, Speechify Studio, and voices created for business customers.

1. What this policy covers

“Biometric data” in this policy means the following, to the extent they are biometric identifiers or biometric information under applicable law:

  • Voice samples: recordings of a person’s voice submitted to create a synthetic voice.
  • Voice models: synthetic voices, and the speaker embeddings or other numerical representations of a person’s vocal characteristics derived from voice samples.
  • Verification data: recordings made during Speechify’s voice owner verification process, and the voiceprint comparison data used to confirm that the person consenting is the person whose voice is being cloned.

2. Why we collect it

Speechify collects biometric data only to:

  • create and provide synthetic voices that the voice owner, or a business customer holding the voice owner’s written consent, has requested;
  • verify that the person whose voice is being cloned has consented; and
  • prevent misuse of voice cloning, including impersonation and fraud.

Speechify does not use biometric data to identify people for any other purpose. It does not sell, lease, or trade biometric data, or otherwise profit from it.

3. Retention schedule

Speechify permanently destroys each category of biometric data at the earliest of the times shown below.

DataPurpose satisfied24-month limitOther limit
Voice samples and voice modelsWithin 30 days after the voice is deleted by its owner or the business customer, consent is revoked, or the account closesVoices you create for yourself: 24 months after your last interaction with Speechify. Voices a business customer creates: 24 months after the voice is created or, if later, after the customer last notifies Speechify that the voice owner has renewed consent45 days after Speechify determines the data is no longer needed
Verification dataWithin 30 days after the related voice is deletedThe same 24-month limit as the related voice45 days after no longer needed

For voices a business customer created before the effective date of this policy, the 24-month limit runs from that effective date.

Consent records that contain no biometric data, such as the date, the consenting person’s name, and the text of the consent, are kept for 5 years after the related voice is deleted, to document that consent was given.

4. How we destroy it

  • Active systems. Biometric data is deleted from active systems within the periods above.
  • Backups and archived versions. Copies in database backups and archived storage versions are deleted automatically within 90 days, and are not restored for any other use in the meantime.
  • Legal holds. Speechify may retain biometric data longer only where required by law, a court order, or a legal hold for pending or reasonably anticipated litigation or investigation, and only for as long as that requirement lasts.

5. Disclosure

Speechify discloses biometric data only:

  • to service providers that host or process it for Speechify under written contracts requiring them to protect it and use it only for Speechify’s purposes;
  • with the consent of the voice owner or their legally authorized representative;
  • to complete a transaction the voice owner or their representative requested; or
  • as required by law, subpoena, or court order.

6. Security

Speechify protects biometric data using the reasonable standard of care in its industry, and in a manner at least as protective as it uses for its other confidential and sensitive information. Protections include encryption in transit and at rest, access limited to personnel who need it, and an annual independent SOC 2 Type II examination.

7. Incident response

If Speechify discovers a security incident that may have compromised biometric data, it will:

  1. contain the incident and preserve evidence;
  2. assess what data and which individuals were affected;
  3. notify affected individuals, business customers, and regulators as required by law; and
  4. review the incident and remediate its cause.

8. Requests and contact

To ask about your biometric data or request its deletion, contact legal@speechify.com. Speechify will act on a verified deletion request within the periods in Section 3.

If your voice was cloned by one of Speechify’s business customers, you may contact that customer or Speechify. When Speechify receives a verified request to delete a voice that a business customer created, Speechify will permanently delete the voice and its associated biometric data within the periods in Section 3, unless a legal hold described in Section 4 applies, and will then notify the business customer.

9. Changes to this policy

Speechify will review this policy at least annually and will post any update here with a new effective date.

Privacy preferences

Choose what we may store on this device. You can change this at any time from the footer.

Strictly necessary

Sign-in, security, load balancing, and remembering your privacy choices. These cannot be switched off.

Always on

Analytics

How the site is used in aggregate - which pages get read, where people get stuck - so we can improve it.

Marketing

Measures which campaigns bring people here, and lets us show relevant ads on other platforms.