1.Who we are
This policy explains how IntactVoice (“IntactVoice”, “we”) handles personal data when you visit our websites, use the API or the dashboard, or contact us. We are the controller of the personal data described here.
Questions or requests: support@intactvoice.com.
2.What we collect
We collect what we need to run your account, bill you and keep the service secure:
| Category | What it includes | Where it comes from |
|---|---|---|
| Account details | Email address, workspace name and sign-in records. Passwords are handled by our sign-in provider, Supabase, and stored hashed. | You, when you sign up |
| Billing records | Plan, invoices and payment status. Card details are collected and held by Stripe; we never see full card numbers. | You, through Stripe checkout |
| Usage records | Time, endpoint, status, word counts and timing for each request. Never the text. | Your use of the API and dashboard |
| API keys | Stored hashed, with a name and last-used time. We show a key once, when you create it. | You |
| Voice profiles | Style measurements of the samples you upload, which may include short excerpts. The samples themselves are deleted once the profile is built. | You |
| Support messages | What you write to us and our replies | You |
| Marketing site data | Pages visited, the ad you came from, and browser or device identifiers. Only if you allow analytics or advertising cookies. | Cookies and tags on our marketing pages |
Our hosting and service providers also keep operational logs, such as IP addresses and request times, under their own retention. We don't ask for sensitive data such as health, beliefs or biometrics. Don't include it in text you send or in support messages.
3.Your content
The text you send to the API, the rewrites and scores we return, and the samples you use to build a voice are your content. We use it only to do what you asked.
- Rewrites and detection. Your text is used to run the job and deleted when processing finishes. The result waits, encrypted at rest, until your webhook receives it or you fetch it, then it's deleted. Anything not collected is deleted after 60 minutes.
- Request logs. Request logs keep metadata only: time, endpoint, status, word count and timing. Never the text.
- Retries. Idempotency keys are remembered for 24 hours so retries aren't charged twice. Only the key, a hash of the request and the job ID are kept, never the text.
- Voice profiles. Writing samples are deleted once the profile is built. The profile is kept until you delete the voice. It holds style measurements and may include short excerpts the model uses to match your voice.
Our model provider. Rewrites use OpenAI's API with storage turned off (store: false). OpenAI doesn't train on API data by default, but under its policy abuse-monitoring logs can keep content for up to 30 days. We haven't been approved for zero data retention, so we don't claim it. What happens to your text shows each step.
We don't train models on your content.
4.How we use it, and our legal bases
We use personal data to sign you in, run the requests you send, build the voice profiles you ask for, deliver jobs and webhooks, bill you, prevent misuse, fix problems and answer support. If you are in the EEA or UK, the GDPR requires a legal basis for each use. Ours are:
| Purpose | Legal basis |
|---|---|
| Create and run your account, process requests, provide support | Performance of our contract with you |
| Bill you, collect payment, keep tax and accounting records | Contract, and legal obligation |
| Protect accounts, prevent fraud and abuse, enforce our policies | Legitimate interests in a secure service |
| Send service emails, such as email confirmations, password resets, receipts and security notices | Contract, and legal obligation |
| Send product news, if we do (you can unsubscribe in any such email) | Consent, or legitimate interests where the law allows |
| Measure our marketing site and ad campaigns | Consent, which you can withdraw at any time |
We don't make decisions about you based solely on automated processing that have legal or similarly significant effects.
5.Who processes it for us
These service providers process data on our behalf to run the service. Only OpenAI and our own API and inference servers receive your content, and only to process a request.
| Provider | Purpose | Receives your content |
|---|---|---|
| Vercel | Website hosting | No |
| Supabase | Sign-in and application database (US East, North Virginia) | No |
| OpenAI | Editing, style analysis and fact checks (API, storage off) | Yes, to process a request |
| Our API and inference servers | Run rewrites and detection in the United States | Yes, to process a request |
| Resend | Sign-in and account email | No |
| Stripe | Checkout, subscriptions and invoices | No |
| Porkbun and Google (Gmail) | Forward and hold support email sent to our support address | Only what you put in an email |
We may also disclose personal data if the law requires it, to protect people or the service from harm, or to a buyer as part of a merger or acquisition, under the same protections. We never sell or share your content with advertisers, data brokers or anyone else.
6.Advertising and analytics on our marketing pages
We may advertise IntactVoice on Google, Meta (Facebook and Instagram) and TikTok, and use their tags to measure which ads bring visitors and sign-ups. These tags load only on our marketing pages, only after you allow them in the cookie banner, and never in the dashboard, the documentation or password pages.
| Partner | Purpose |
|---|---|
| Google (Analytics and Ads) | Measure visits and ad conversions |
| Meta Pixel | Measure ad conversions from Facebook and Instagram |
| TikTok Pixel | Measure ad conversions from TikTok |
If you allow them, these partners receive browsing data from our marketing pages: the pages you view, events such as starting a sign-up or completing a purchase (with the plan and amount, never your email or text), the ad you came from, and identifiers for your browser or device, including your IP address. They use it under their own privacy policies and may combine it with other data they hold about you.
7.Your privacy choices
- Cookie settings. Use “Cookie settings” in the site footer, or the button on the Cookie Policy, to allow or refuse analytics and advertising cookies, and to change your mind later.
- Opt out of sharing. Turning advertising off in Cookie settings stops advertising tags in your browser. You can also email support@intactvoice.com and we will apply the opt-out to your account.
- Global Privacy Control. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a request to opt out of sale and sharing, and don't load advertising tags.
- In the dashboard. You can revoke API keys and delete voice profiles at any time.
- Email. Service emails, such as password resets and receipts, are part of running your account. If we send product news, each one has an unsubscribe link.
We don't sell personal data for money. We don't use or disclose sensitive personal information.
9.How long we keep it
| Data | How long |
|---|---|
| Text you send (inputs) | Deleted when processing finishes |
| Results (rewrites and scores) | Held encrypted until your webhook receives them or you fetch them, then deleted. Deleted after 60 minutes if not collected. |
| Request logs | Metadata only, never the text. Kept while your account is open. |
| Idempotency keys | 24 hours. The key and job ID only. |
| Writing samples for a voice | Deleted once the profile is built |
| Voice profiles | Until you delete the voice or your account is deleted |
| Account details and API keys | While your account is open. Deleted within 30 days after you ask us to close it. |
| Billing records | Held by Stripe for as long as tax and accounting law requires |
| Content kept by OpenAI for abuse monitoring | Up to 30 days, under OpenAI's policy |
| Support messages | As long as needed to resolve your request and keep a record of it. Deleted on request where the law allows. |
| Your cookie choice | 6 months, then we ask again |
Deleted data can remain in our database provider's backups until those backups expire. A copy of a result your own webhook received is in your systems, not ours.
10.Security
- Traffic to the site and the API uses HTTPS. Connections to our database verify TLS certificates.
- API keys are stored hashed and shown once. Passwords are handled by Supabase and stored hashed. Card details are handled by Stripe, never by us.
- Access to production systems is limited to the people who run the service.
- These measures reduce risk; no service can promise absolute security. If a breach affects your personal data, we will tell you and the relevant regulators as the law requires.
11.Where your data is processed
Our database runs in the United States (Supabase, US East), our API and inference servers are in the United States, and our other providers process data mainly in the United States. If you are outside the US, your personal data is transferred there.
12.Your rights
EEA, UK and Switzerland
You can ask to access, correct, delete or export your personal data, to restrict or object to how we use it, and to withdraw consent at any time. You can also complain to your local data protection authority.
United States
Depending on your state, including California, Colorado, Connecticut, Virginia and others with similar laws, you can ask to know and access the personal data we hold, correct it, delete it, receive a portable copy, and opt out of its sale, its sharing for cross-context behavioral advertising, and targeted advertising. We won't treat you differently for using these rights. You can use an authorised agent, and you can appeal our decision by replying to it.
How to make a request
Email support@intactvoice.com from the address on your account, with “Privacy request” in the subject. We confirm it's you before we disclose, change or delete anything, and we respond within the time the law where you live requires. Account deletion is completed within 30 days. Your text is deleted after each job, so a request covers your account details, usage records, voice profiles and support messages.
13.Children
IntactVoice is not for anyone under 18, and we don't knowingly collect personal data from them. If you believe someone under 18 has given us personal data, contact support@intactvoice.com and we will delete it.
14.Changes to this policy
We will update this page when our practices change and change the “Last updated” date. For material changes we email account holders before they take effect.
15.Contact
Email support@intactvoice.com. The controller is IntactVoice.