Operations

Security & data retention

What we keep (metadata), what we delete and when, training policy and compliance notes.

What happens to the text you send, how long we keep it, and what we don't do with it.

Data retention

DataKeptNotes
Request logsMetadata onlyTime, endpoint, status, word count, timing, error code. Never the request or response body; the database refuses one.
Your text (job input)Until processing finishesDeleted when the job succeeds or fails. A queued job keeps it only until it runs.
ResultsUntil delivered or fetched, at most 60 minutesDeleted once your webhook answers 2xx, you fetch it with GET /v1/jobs/{id} (or the event stream), or a sync response is sent. Not collected after 60 minutes: deleted. Afterwards GET answers 410 result_expired.
Webhook payload copiesUntil delivered, at most 60 minutesDeleted on a 2xx or after the last retry; all retries happen within about 40 minutes.
Idempotency keys24 hoursThe key, a hash of the request and the job ID. Never the text; a replay answers from the job.
Raw voice samplesUntil the profile is builtNever stored with the voice; deleted with the profile job's input. Deleting a voice before it's built cancels the job and drops the samples.
Voice profilesUntil you delete the voiceStyle measurements, a detector baseline and a style card that quotes 5–8 short sentences from your samples.
Usage recordsFor account and billing historyWord counts and metadata. Never the text.

Cleanup runs every minute in the API (and every five minutes in the database as a backstop). Database backups follow the provider's schedule.

Training

We don't train models on text sent through the API, on your voice samples, or on outputs. Voice profiles are used only for requests from your workspace.

Text processing providers

Editing, style analysis and fidelity checks can send submitted text, candidate outputs and voice samples or excerpts to OpenAI. We use its Responses API with store:false.

Our own deletion rules don't change provider retention. OpenAI describes its own abuse-monitoring and caching rules in its API data controls. Zero Data Retention approval has not been verified for this deployment.

Availability and hosting

The website runs separately from the API and GPU workers. Postgres and authentication use Supabase. Worker traffic travels over a private network.

Jobs wait in the queue when worker capacity is unavailable. We do not offer a contractual uptime guarantee at launch.

Note:

Check launch availability on the status page. Use async jobs and signed webhooks, and retry transient failures with backoff.

Encryption and access

  • Public endpoints use HTTPS. Remote workers are reached over a private encrypted network.
  • Production access is limited to the service operator.
  • API keys are stored hashed; we can't show a key again after creation.
  • Contact support to discuss deployment or retention requirements.

EU AI Act and disclosure

Transparency duties under Article 50 of the EU AI Act apply from 2 August 2026. Rewrite output is AI-generated text; if you publish it to people in the EU, you may have disclosure obligations. We don't strip or hide provenance, and we don't market the API as a way to avoid disclosure.

Warning:

This isn't legal advice. Ask your counsel how Article 50 applies to your use case.

Acceptable use

IntactVoice is built for publishers, content teams, agencies and people writing in their own voice. Use by students or in academic settings, use for any coursework, exam or educational assessment, use by or for government bodies, and any use to get around a government, regulatory or licensing requirement are prohibited. The full terms are in the Acceptable Use Policy. Report concerns to support@intactvoice.com.