Who we are
What we collect
Account data — name, email, password hash, billing details handled by our payment processor, and the plan you are on. We never see your full card number. Biometric and likeness data — the photos you upload to create a twin, the voice sample you record, the consent recording, and the derived face and voice models. This is the most sensitive data we hold and it is treated as such throughout. Usage data — prompts, render settings, credit transactions, device and browser metadata, IP address, and error logs.
Biometric data, specifically
Your face embedding and voice model are stored in an encrypted key domain separate from the rest of your account data. They are never used to train shared or foundation models, never sold, and never made available to another account. They are retained for as long as the twin exists in your library, and deleted from live systems immediately on your request and from encrypted backups within 30 days. Residents of Illinois, Texas and Washington have additional rights under state biometric law; those rights are honoured for all users regardless of location.
Why we process it
Sharing
Retention
Rendered videos: kept in your library while your account is active, and for 90 days after cancellation. Twins, source photos and voice models: until you delete them, or 90 days after account closure. Prompts and credit history: 24 months, for billing disputes and abuse investigation. Consent recordings: retained for the life of the twin plus 3 years, because they are our evidence that the clone was authorised. Server logs: 30 days.
Your rights
International transfers
Security
Cookies
Children
Changes and contact
Still want the short version?
We hold your face because you asked us to, and we delete it when you ask us to.