Privacy Policy
Last updated October 6, 2026
VoiceLabs is a hosted voice studio: generation runs on our servers and streams to your browser. That makes us a custodian of sensitive data — your voice — so this policy is direct about exactly what we collect, where it lives, and what we will never do with it.
1. What we collect
To provide the studio, accounts, and billing, we collect:
- Account data — your name and email address, and either a securely hashed password or basic profile information from Google if you sign in with Google.
- Voice & content data — the audio samples you upload or record, the text you submit for generation, the voice profiles you create, and the audio we generate for you. This is stored on our servers so your library is available whenever you sign in.
- Text our browser extension reads aloud — the VoiceLabs extension for Chrome and Edge touches a web page only when you click its toolbar button or its right-click menu item; it has no standing access to the sites you visit. When you do, it takes the text you selected, or the main text of that page, and sends it with your API key to VoiceLabs (app.voicelabs.now) so we can make the audio. That text is then handled like any other text you submit for generation. The extension keeps your API key and chosen voice in your browser on this device only, never synced to your other devices, and keeps the passages of the current reading in your browser’s session memory, which is cleared when the browser closes. The extension itself contains no analytics, advertising or tracking code and sends your data to no one but VoiceLabs. You can delete the stored key at any time with “Disconnect” in the extension’s settings, or by removing the extension.
- Usage records — how much audio you generate each month, so we can meter the free allowance and the Pro fair-use limit.
- Subscription & billing data — subscription status and billing metadata from our payment providers (RevenueCat and Stripe). We do not receive or store full payment-card numbers; those are handled by the payment processor.
- Technical & security data — limited log data such as IP address and timestamps, used to operate the service securely and prevent abuse, plus error reports from our self-hosted monitoring software (Sentry) when something breaks. An error report carries technical detail — your browser type, the page you were on, the error itself — and your account identifier so we can tell whether a problem is affecting one person or everyone. It is not configured to attach your email address or request contents.
- Product-analytics data — we run our own PostHog instance, on our own servers, to understand how the app is used. It is not an advertising network and it is not shared with one. Specifically, it records:
- Page views and clicks. Which pages you open, and automatic capture of interactions with buttons and links.
- A small set of named product events — signing up, viewing pricing or billing, clicking upgrade, starting checkout, starting or cancelling a subscription, submitting a support request, and an app error that was visible to you.
- Installing or removing our browser extension. The VoiceLabs extension sends us nothing itself. When you install it, it opens a welcome page on our site, and when you remove it, your browser opens a goodbye page; each page records that event once, with the extension’s version and your browser (Chrome or Edge), and how you first found us if your browser already holds that. If you declined analytics, the event is still counted, but anonymously: no identifier links it to you or to any other visit.
- How you first found us. On your first visit we record the campaign tags or referring site that brought you (as
first_touch_*properties) and keep that first value; a later visit through a different link does not overwrite it. Campaign values are sanitized to a restricted character set before storage. If you arrive from an ad, the link can carry an ad click identifier (Google’sgclidor Meta’sfbclid); we keep it with the rest of your first touch, in a first-party cookie for up to 90 days and, when you sign up, on your account, so we can tell which ads and campaigns bring people to VoiceLabs, and we do not send it back to the ad networks. - Session replays. Replay is enabled: it reconstructs a visit as a sequence of page changes and interactions so we can diagnose bugs and confusing flows. To be precise about what is masked, because this matters: values you type into form fields are never recorded — every input, including passwords and payment fields, is masked, as is anything we have explicitly tagged as sensitive. Other text that is already visible on the page is not masked, so treat a replay as showing what your screen showed, minus what you typed.
- A technical tag on each event identifying the app, its version, the environment, and whether the session came from our own team (so we can exclude our own testing from the numbers).
- A profile of your account, attached to your analytics records. Once you are signed in we attach the following to the profile held under your account identifier, and keep it current as it changes:
- Your name and email address, and how you sign in (password or Google).
- Your plan and subscription state — free or Pro, whether you are trialing, active, past due or cancelled, and the date the current period ends.
- Purchase context from our payment provider — which product was bought, which store it came from, whether it was a trial period, and whether it was a test purchase.
- Your browser language and time zone, so we can tell where and in what language the product is being used.
- Which surface and build you use — web or native app, the app identifier and the app version, plus the first ones we ever saw for you.
- The date your account was created, and the campaign, referring site and landing page that first brought you (the
first_touch_*values described above), plus a referral code if you arrived through one.
- Google Analytics — alongside our own analytics we run Google Analytics 4 on the public site and the app, to measure traffic and which pages people arrive on. It is a Google service, so this is the one place analytics data leaves our servers, and it is held to the same rules as the rest:
- It runs on exactly the same consent decision described in Section 6. In the EU, EEA and UK the tag is not loaded at all until you accept, and if you decline it is never loaded.
- It receives page views and your account identifier once you are signed in, plus two events our server sends it directly: that you signed up (and whether by email, Google or Apple), and, when you start paying for a subscription (not on renewals), that payment’s plan, amount and currency. Our server sends those two only if the Google Analytics tag had already run in your browser, reusing the identifier it set there; it never creates one for you. Nothing else about you: not your name, not your email address, and none of the profile fields listed above.
- Google’s advertising features are switched off in our configuration — Google signals and ad personalization are both disabled — so the data is not joined to Google’s advertising identity graph and is not used to target ads at you.
- Notifications — if you enable product notifications, we store the notification records shown in your in-app inbox on our self-hosted Notifly service. On the native app we also store the device push token your operating system issues, so a notification can reach that device. Refer & Earn updates about your referral link (described in Section 5 under Sendly) are kept the same way, with a record of which ones we have sent you so none is sent twice.
- Reports & support — information you choose to send us, such as a content report or a support message. When you send a support message from an error prompt, it carries the identifier of that error report so we can match your message to the technical detail.
2. How your voice data is processed
When you clone a voice or generate speech, your input is sent to VoiceLabs servers, processed on our GPU infrastructure, and the resulting audio is streamed back to your browser and saved to your library. Your voice profiles, samples, recordings, and generation history are scoped to your account — no other user can access them. Generated audio carries an inaudible, machine-readable AI watermark (see our Responsible Use policy).
3. How we use information
- To create and manage your account and authenticate you.
- To generate the audio you request and keep your voice library available to you.
- To meter your usage against your plan’s allowance.
- To process your subscription, trial, and renewals, and to prevent payment fraud.
- To operate, secure, and improve the service, and to detect and fix errors.
- To respond to support requests and content reports.
- To comply with legal obligations and enforce our Terms.
4. Storage & deletion of your content
Your voice samples, profiles, recordings, and generated audio live in your VoiceLabs library on our servers. You can delete voice profiles, uploaded samples, recordings, and items in your generation history at any time from within the studio, and deleting them removes them from your library.
You can delete your whole account yourself, from inside the app. Open Account in the app bar, scroll to the Danger zone, choose Delete account, and type DELETE to confirm. It takes effect immediately and cannot be undone. No email, no waiting on us. If you would rather ask a person, you still can — see Section 8.
Deleting your account removes, permanently:
- Your voice clones and everything they were built from — voice profiles, the reference audio samples you uploaded or recorded, and their avatars.
- Your generated audio and the text behind it — every generation in your history, every alternate and processed version of it, and the audio files themselves.
- Your captures and transcripts — the recordings you dictated or uploaded, their raw and refined transcripts, and the audio files.
- Your settings and usage records — your capture and generation preferences, your saved effect presets, and your monthly usage counters.
- Your credentials and connections — your sign-in details, every active session on every device, your API keys, and every AI app you connected.
- Your notification records — your in-app inbox and any device push tokens.
Two things deliberately outlive the account, and neither identifies you afterwards: the consent records in Section 6 (kept as an audit trail, with your account identifier removed from them, so what remains points at nobody), and the product-analytics events already recorded under your account identifier. Deletion also strips your name, email address and the other identifying fields off the analytics profile described in Section 1, leaving only the plan, purchase and acquisition-channel values that belong with those events — Section 7 sets out both halves. Deleting your account does not cancel a paid subscription; cancel that first, in App Store → Subscriptions or from your billing portal.
5. Sharing & service providers
We do not sell your personal information. We share limited data only with the providers that run the service on our behalf:
- Google — if you choose Google sign-in (OAuth).
- RevenueCat & Stripe — to process subscriptions and payments. Beyond what a payment needs, we also send RevenueCat the details that make a subscriber recognisable in our billing dashboard and let us tell which marketing brought them: your name and email address, your account identifier, how you sign in, your browser language and time zone, the surface and app version you subscribed on, and the campaign, medium, keyword, ad creative and referring site recorded on your first visit. It is the same first-touch attribution described in Section 1, sent so that subscription revenue can be attributed to the channel that earned it. We do not send it your voice data, your generated audio, or anything you typed into the studio.
- Hosting & infrastructure — to host our web application, inference servers, and databases.
- PostHog — product analytics and session replay. We self-host it on our own infrastructure, so this data does not go to a third-party analytics company.
- Google Analytics — traffic measurement for the public site and the app. Unlike PostHog and Sentry this one is not self-hosted, so it is the one analytics provider that receives data on Google’s own servers. It gets page views and, when you are signed in, your account identifier; it does not get your name, your email address, your plan or your voice data, and we run it with Google signals and ad personalization disabled. It only runs once you have consented, where consent is required — see Section 6.
- Sentry — error monitoring, also self-hosted on our infrastructure.
- Devino Partners (Dub) — the partner platform behind our Refer & Earn program, a self-hosted Dub run by Devino on its own infrastructure (partners.devino.ca). Every account with a verified email address, and any account that opens Refer & Earn, or whose old referral code is visited, is enrolled there automatically, so that it has a referral link ready: we send it your account identifier, your name and your email address, and it keeps your partner account, your link with its clicks, sign-ups and commissions, and your payout details if you choose to set them up — so that a friend you invite is credited to you and you can be paid. If you signed up through someone’s link, it also receives your account identifier, name and email address so that referral can be credited, and the amount of each subscription payment so their commission can be calculated and, after a refund, taken back. It never receives your voice data or anything you made in the studio. It keeps your partner account for as long as the program runs, and commission and payout records for as long as tax and accounting rules require. Deleting your VoiceLabs account does not yet remove your partner account there automatically: email us (Section 8) and we will have it removed, keeping only the payout records the law requires us to keep.
- Sendly — our transactional email provider. It receives your email address and the message itself for the mail we need to send you: address verification, password reset, a welcome note, and subscription mail (trial started, trial ending, payment failed, subscription cancelled). It also carries Refer & Earn updates about your own referral link: what happened to it (a first click, a first sign-up, a commission, a payout) and, at most twice a month and only until you switch them off, a reminder to share it or a monthly summary. Every one of those emails has a link that switches the reminders off, and so does Refer & Earn in the app. Apart from them we do not send marketing email.
- Notifly — our self-hosted notification service, for the in-app inbox and push notifications, and the Refer & Earn updates above, which it holds your name and email address to deliver.
We may also disclose information if required by law or to protect rights and safety.
6. Cookies, storage & your analytics choice
Two kinds of thing are stored in your browser, and they are treated differently.
- Strictly necessary. A session cookie that keeps you signed in, plus small local-storage entries for preferences such as your light/dark theme choice and the choice you make below. If you arrive through someone’s referral link we also set a
dub_idcookie for voicelabs.now and app.voicelabs.now, holding only the id of that click, for 90 days, so that the person who referred you is credited when you sign up. Alongside it we set five small cookies so the site can tell you whose invitation you followed, and stop once you have an account. Four hold only a flag:voicelabs_ref_clicked(that a referral click exists, 90 days),voicelabs_ref_bar_dismissed(you closed the invitation bar, or created your account, 1 year),voicelabs_ref_signed_up(you created your account, so nothing greets you as invited again, 1 year) andvoicelabs_ref_signup_event(you just created your account through Google or Apple, so the page you land on can count that sign-up once; deleted as soon as it is read, and after 1 hour at most). The fifth,voicelabs_ref_via, holds the code of the referral link you followed (1 day, or 30 days once the click was recorded). That code is chosen by, or made for, the person who invited you, and can be made from their name or email address, so it may identify them; it says nothing about you. A browser that followed a referral link under our previous referral program may still hold avoicelabs_referralcookie with that person’s referral code, for up to 90 days from that visit; we no longer set it, and read it only once, when you sign up, to credit them. These are required to deliver the product you asked for, so they are not optional and we do not ask consent for them. - Analytics. PostHog stores an identifier in a cookie and in local storage so repeat visits can be recognized as the same browser. Google Analytics stores its own identifiers in cookies (
_gaand_ga_*) for the same purpose. We also keep a record of how you first reached us — the campaign tags on the link and the site that linked to it, never a full URL — in local storage and in avoicelabs_first_touchcookie shared between voicelabs.now and app.voicelabs.now, so that one visit spanning both is counted once and credited to the place it really came from. It is written at the same moment as the rest of analytics and only when analytics runs.
If you are in the EU, EEA or UK, we ask before analytics runs: on your first visit a banner offers Accept and Decline as equal choices, and until you accept, analytics stores nothing and sends nothing. Declining costs you no functionality. Your choice is remembered in your browser; clearing your site data will make us ask again. Outside those regions analytics runs by default and you can turn it off at any time by clearing site data or using your browser’s Do Not Track / tracking-protection controls.
We do not use advertising cookies, ad networks, or third-party ad-tracking, and we do not sell your data. Google Analytics is a measurement tool here and nothing more: we run it with Google signals and ad personalization switched off, so it does not build an advertising profile of you and we do not use it to target ads.
7. Data retention
We retain your voice content — samples, profiles, recordings, and generated audio — while your account is active, or until you delete it from the studio. We retain account and billing records for as long as your account is active and as needed to meet legal, tax, and accounting requirements, after which we delete or anonymize them.
When your account is deleted, your whole library goes with it — the voice clones, the samples, the captures and transcripts, and the generated audio files, on the servers that hold them. Section 4 lists this in full.
What we keep afterwards, and why:
- Consent records, as the audit trail that shows a choice was recorded and honoured. Your account identifier is removed from them when the account goes, so the row that remains is not linked to you.
- Product-analytics events already recorded in our self-hosted PostHog. These are the page views and named product events described in Section 1, stored under the opaque account identifier we generated for you. They are not deleted automatically when the account is. If you want them erased too, email us and say so (see Section 8).
- Part of the analytics profile — but not the part that names you. Section 1 lists what we attach to that profile, and it does include your name and email address. When you delete your account we erase the identifying fields from it: your name, your email address, your phone number if we ever hold one, how you signed in, and your browser language and time zone. What stays is the part that describes a subscription and a marketing channel rather than a person — your plan and subscription state, the purchase context, the surface and app version, the account-creation date, and the first-touch campaign values — because it belongs with the events above and points at nobody once the identifying fields are gone. The erasure runs automatically as part of the deletion; if our analytics server cannot be reached, the failure is recorded for us to act on rather than silently skipped. You can also email us (Section 8) to have the whole profile and its events removed.
- Billing records held by our payment providers (RevenueCat and Stripe), which they retain independently of us so a refund or chargeback stays traceable.
- Your Refer & Earn partner account at Devino Partners (Section 5) — your name, email address, account identifier and referral link, with its commissions and any payouts. Deleting your account does not yet remove it automatically; email us (Section 8) and we will have it removed, keeping only the commission and payout records tax and accounting rules require.
- Error reports in our self-hosted Sentry, which carry the same opaque account identifier and expire on that system’s own retention schedule.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing.
To delete your account, you do not need to ask us. Sign in, open Account, and use Delete account in the Danger zone — that is the fastest and most complete route, and Section 4 describes exactly what it removes. The email route remains open as a fallback and for everything else: to exercise any of the rights above, to have your account deleted for you, or to ask us to erase the retained analytics events described in Section 7, email aladdin@devino.ca from the address on your account. Deletion is subject to legal retention requirements.
9. Children
VoiceLabs is not directed to children under 13, and we do not knowingly collect personal information from them.
10. International transfers & security
We may process data in countries other than yours. We use appropriate safeguards and reasonable technical and organizational measures to protect your information; no method of transmission or storage is completely secure.
11. Changes & contact
We may update this policy; when we make material changes we will update the “last updated” date above. Questions or requests? Contact aladdin@devino.ca.
Questions about this document? Email aladdin@devino.ca. See also Terms, Privacy, Responsible Use and Report Content.