Skip to content

SONICVOX PRIVACY POLICY

Effective Date: June 1, 2026
Last Updated:
July 6, 2026

Version: 1.0

This Privacy Policy is provided by WP Global Syndicate LLC, an Oklahoma limited liability company, doing business as SonicVox (“Company,” “we,” “us,” or “our”).

1. INTRODUCTION

WP Global Syndicate LLC dba SonicVox (“Company,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal information.

This Privacy Policy explains how the Company collects, uses, stores, shares, and protects your personal data when you use our websites, applications, APIs, and services (collectively, the "Services").

By using the Services, you acknowledge this Privacy Policy. Where required by applicable law—including for biometric or other sensitive personal data—the Company obtains your consent through separate, explicit consent mechanisms.

2. SCOPE

This Privacy Policy applies to:

    1. visitors to our website(s);
    2. registered users of the SonicVox platform;
    3. API clients and integrations;
    4. users interacting with SonicVox speech synthesis, voice cloning, workflow tools, conversational agents, and translation services;
    5. business customers and their end users (subject to separate Data Processing Agreements); and
    6. job applicants (subject to separate applicant privacy notice).

3. INFORMATION WE COLLECT

3.1 Information You Provide

    1. Account registration data: name, email, password
    2. Payment information: Payment information is processed exclusively by third-party payment processors such as Stripe or PayPal. The Company does not store full credit card numbers, CVV codes, or complete payment credentials on its systems. We may retain limited transaction-related information (such as billing name, transaction ID, payment status, and billing address where required) for accounting, fraud prevention, and legal compliance purposes
    3. Audio samples you upload for voice cloning or testing
    4. Text input for TTS or translation
    5. Preferences and settings for voices, styles, and languages
    6. Communications with customer support
    7. Survey responses and feedback
    8. Company information (for business accounts)
    9. Testimonials for site publication

3.2 Information Collected Automatically

    1. Device and browser type, operating system
    2. IP address and approximate location (city/country level based on IP, not precise geolocation)
    3. Usage activity (e.g., pages visited, features used)
    4. API calls, timestamps, and request/response data
    5. Performance data and error logs
    6. Cookies and similar technologies (see SonicVox Cookie Policy)

3.3 Voice & Speech Data

3.3.1 Biometric Information Overview

We collect and process voice recordings and derived voice biometric data as part of speech synthesis, voice cloning, and transcription services. Because voice data may constitute biometric identifiers or special category personal data under applicable law, the Company applies heightened data protection standards to all biometric information it collects, processes, stores, and destroys. The categories of biometric data we collect, the purposes for which we use it, and the legal frameworks governing its processing are described in detail below.

3.3.2 Categories of Biometric Data Collected

Voice recordings and voice biometric data constitute "biometric information" or "biometric identifiers" under applicable laws, including:

    1. Illinois Biometric Information Privacy Act (BIPA) – 740 ILCS 14/1 et seq.;
    2. Texas Capture or Use of Biometric Identifier Act - Tex. Bus. & Com. Code § 503.001;
    3. Washington Biometric Privacy Laws - RCW 19.375;
    4. European Union GDPR Article 9 (Special Categories of Personal Data); and
    5. California Consumer Privacy Act (CCPA) as "sensitive personal information."

We collect and process the following voice biometric data:

3.3.2.1 Raw Audio Recordings

    1. Audio files you upload for text-to-speech processing
    2. Voice samples submitted for voice cloning features
    3. Speech-to-text audio input
    4. Purpose: To provide speech synthesis, voice cloning, transcription, and translation services
    5. Retention: Raw audio recordings are retained only for the period necessary to complete the requested processing and service delivery, and in no event longer than thirty (30) days after processing completion, unless you elect to store such content within your account. Where audio is stored within your account, it will be retained for the duration of your account or until deletion is requested. Backup copies are securely deleted within ninety (90) days.

3.3.2.2 Voice Biometric Models

    1. Voiceprints and vocal characteristics extracted from your audio samples
    2. Cloned voice models generated by our AI algorithms
    3. Purpose: To enable custom voice synthesis and voice cloning features
    4. Retention: Voice biometric models and voiceprints are retained for the duration of your active account to enable continued access to voice cloning functionality. Upon account deletion or receipt of a verified deletion request, voice biometric models are permanently deleted within thirty (30) days. Backup copies are securely deleted within ninety (90) days thereafter.

3.3.2.3 Voice Synthesis Preferences (Non-Biometric)

    1. SSML markup, voice parameters, and settings you create
    2. Purpose: To store and reproduce your voice synthesis preferences
    3. Retention: Duration of your account or until you delete

3.3.3 Legal Compliance Disclosures

3.3.3.1 Illinois BIPA Compliance

    1. We collect voice biometric data solely for the purpose of providing speech synthesis and voice cloning services as requested by you.
    2. Voice biometric data is stored using encryption and industry-standard security measures.
    3. Retention schedule: The Company retains biometric identifiers only for the period necessary to fulfill the purpose for which they were collected, and in no event longer than the duration of an active account unless earlier deletion is requested. Biometric identifiers are permanently destroyed within thirty (30) days following account termination or receipt of a verified deletion request, unless a longer retention period is required by law.
    4. Destruction: Permanent deletion using secure data destruction protocols within 30 days of retention period end or account deletion request
    5. We do NOT sell, lease, trade, or otherwise profit from your biometric information.
    6. We do NOT disclose biometric information except:
      1. to service providers under confidentiality obligations;
      2. to complete a transaction you requested;
      3. as required by law; or
      4. with your written consent.

3.3.3.2 GDPR Article 9 (Special Category Data) Compliance

Legal basis for processing voice biometric data: EXPLICIT CONSENT (Article 9(2)(a) GDPR). Prior to collecting or processing any voice biometric data, the Company obtains the data subject's explicit, affirmative consent through a dedicated consent interface presented at the point of collection.

This consent mechanism:

    1. clearly identifies the nature of the data being collected (voice recordings and derived biometric identifiers);
    2. specifies the purposes for which the data will be processed (speech synthesis, voice cloning, transcription, and related services);
    3. discloses the applicable retention period; and
    4. informs the data subject of their right to withdraw consent at any time. Consent records, including the date, time, and scope of consent, are retained by the Company in accordance with applicable law.

You have the right to withdraw consent at any time.

Withdrawal of consent does not affect lawfulness of processing before withdrawal.

Upon withdrawal, we will cease processing and delete your voice biometric data.

3.3.3.3 CCPA "Sensitive Personal Information"

    1. Voice data qualifies as "sensitive personal information" under CCPA.
    2. You have the right to limit use of sensitive personal information.
    3. To exercise this right, contact privacy@sonicvox.ai.

3.4 Third-Party Data Sources

    1. Analytics providers (e.g., Google Analytics, Mixpanel)
    2. Advertising networks (for targeted marketing)
    3. API integrations (e.g., AWS Polly, DeepL, Google Translate)
    4. Payment processors (Stripe, PayPal, etc.)
    5. Customer support platforms
    6. Security and fraud prevention services

4. HOW WE USE YOUR INFORMATION

We use your data to:

  1. provide and improve services.
  2. personalize experiences.
  3. secure our platform.
  4. comply with legal obligations.
  5. marketing & communication (with opt-out options).
  6. specifically:
    1. process your requests for speech synthesis, voice cloning, transcription, and translation.
    2. create and maintain your account.
    3. process payments and prevent fraud.
    4. provide customer support and respond to inquiries.
    5. send service-related communications (e.g., account notifications, security alerts).
    6. analyze usage patterns to improve Services and develop new features.
    7. detect, prevent, and address technical issues, security vulnerabilities, and fraudulent activity.
    8. comply with legal obligations, court orders, and regulatory requirements.
    9. send marketing communications (with your consent where required; opt-out available).
    10. conduct research and development (using anonymized/aggregated data).
    11. enforce our Terms of Service and protect our legal rights.

5. LEGAL BASIS FOR PROCESSING

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data only when we have a valid legal basis under the General Data Protection Regulation (GDPR). The specific legal basis depends on the purpose:

5.1 Consent (GDPR Article 6(1)(a) and Article 9(2)(a) for biometric data)

    1. Voice biometric data collection and processing for voice cloning
    2. Marketing communications and promotional offers
    3. Non-essential cookies and analytics
    4. Optional features requiring additional data processing

You may withdraw consent at any time. Withdrawal does not affect prior processing.

5.2 Contractual Necessity (Article 6(1)(b))

    1. Account creation and authentication
    2. Providing speech synthesis, transcription, and translation services
    3. Processing payments
    4. Delivering Services you have requested

5.3 Legitimate Interests (Article 6(1)(f))

    1. Fraud prevention and platform security
    2. Service improvement and optimization
    3. Network and information security
    4. Internal analytics using anonymized data

Note: We do not rely on legitimate interest for processing biometric data or special category data.

5.4 Legal Obligation (Article 6(1)(c))

    1. Compliance with tax, accounting, and financial reporting requirements
    2. Responding to lawful requests from law enforcement or regulatory authorities
    3. Complying with court orders or legal proceedings

5.5 Vital Interests (Article 6(1)(d))

Protecting life or physical safety in emergency situations (rarely applicable)

6. SHARING YOUR INFORMATION

6.1 General Statement (No Sale of Data)

The Company does not sell or share your personal information for cross-context behavioral advertising purposes. We may share your information in the following limited circumstances:

Where the Company processes personal data on behalf of business customers, the Company acts as a data processor, and such processing is governed by the applicable Data Processing Agreement (DPA), which prevails in the event of any conflict with this Privacy Policy.

6.2 Service Providers and Sub-Processors

We engage third-party service providers to perform functions on our behalf, including:

    1. Cloud hosting and storage (e.g., Amazon Web Services, Google Cloud)
    2. Payment processing (e.g., Stripe, PayPal)
    3. Customer support platforms
    4. Email and communication services
    5. Analytics and performance monitoring
    6. Security and fraud prevention

These providers have access to personal information only as necessary to perform their functions and are contractually obligated to protect your data and use it only for authorized purposes.

A current list of our sub-processors is available at Sub-Processor List and may be updated from time to time. For EU/UK customers, we will provide notice of sub-processor changes as required by GDPR.

6.3 Business Partners

With your consent, we may share information with business partners for joint offerings, co-marketing, or integrated services.

6.4 Legal Authorities and Compliance

We may disclose your information if required to do so by law or in response to:

    1. Valid legal process (subpoena, court order, search warrant)
    2. Government or regulatory requests
    3. Investigations of suspected illegal activity
    4. Protection of our rights, property, or safety, or that of users or the public
    5. Enforcement of our Terms of Service

6.5 Corporate Transactions

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred to the successor entity. We will provide notice before your personal information becomes subject to a different privacy policy.

6.6 Aggregate or De-Identified Data

We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you for research, marketing, or other purposes.

7. INTERNATIONAL DATA TRANSFERS

The Company is based in the United States. If you are located outside the United States, your personal information will be transferred to, stored in, and processed in the United States and potentially other countries where our service providers operate.

7.1 Transfer Mechanisms

7.1.1 Countries Where Data May Be Processed

    1. United States (primary operations)
    2. Other jurisdictions where our authorized service providers and sub-processors operate, as identified in our Sub-processor List.
    3. These countries may have data protection laws that differ from the laws of your country. We take steps to ensure your personal information receives an adequate level of protection wherever it is processed.
    4. FOR EU/EEA, UK, AND SWISS DATA SUBJECTS:
      1. We rely on the following mechanisms for international data transfers:

7.1.2 Standard Contractual Clauses (SCCs)

We use the European Commission-approved Standard Contractual Clauses (Decision 2021/914) for transfers of personal data to countries that do not provide an adequate level of data protection. Copies of our Standard Contractual Clauses (SCC) are available upon request at privacy@sonicvox.ai.

7.2 Supplemental Measures

In accordance with the Schrems II Decision and EDPB Recommendations 01/2020, we implement supplementary technical and organizational measures, including:

    1. End-to-end encryption of data in transit and at rest.
    2. Strict access controls and authentication.
    3. Contractual and technical measure designed to limit unauthorized or unlawful access.
    4. Data minimization and pseudonymization, where feasible.
    5. Regular security audits and assessments.

7.2.1 EU-US Data Privacy Framework (if applicable)

The Company complies with the EU-U.S. Data Privacy Framework (DPF) as set forth by the U.S. Department of Commerce. Where applicable, we may rely on the EU-U.S. Data Privacy Framework (DPF) or similar frameworks once certified. Until such certification is complete, we rely on Standard Contractual Clauses and supplementary safeguards for international data transfers. To learn more about the DPF and to view our certification, please visit https://www.dataprivacyframework.gov/.

    1. Adequacy Decisions:
      1. Where applicable, we transfer data to countries that have been deemed to provide adequate protection by the European Commission.
    2. UK GDPR Compliance
      1. For transfers of personal data from the United Kingdom, we use the UK International Data Transfer Agreement or UK Standard Contractual Clauses as approved by the UK Information Commissioner's Office (ICO).

8. DATA RETENTION

We retain personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

8.1 Specific Retention Periods

8.2 Account Profile Information

Retained for the duration of your active account. After account deletion, account-related personal information is retained for up to thirty (30) days to allow account recovery and administrative processing, after which it is permanently deleted. Backup copies are securely deleted within ninety (90) days in accordance with our standard backup rotation schedule.

8.3 Voice Biometric Data (Critical - BIPA Requirement)

The Company retains biometric identifiers and biometric information only for the period necessary to fulfill the purpose for which such data was collected, or until the user requests deletion, whichever occurs first.

Raw audio recordings are retained for no longer than thirty (30) days after processing completion unless the user elects to store such content within their account.

Voiceprints, cloned voice models, and other biometric identifiers are retained for the duration of the user’s active account.

Upon account termination or receipt of a verified deletion request, biometric identifiers are permanently destroyed within thirty (30) days. Backup copies are securely deleted within ninety (90) days in accordance with system rotation schedules.

8.4 Biometric Data Retention Schedule and Destruction Policy (BIPA Compliance)

In accordance with the Illinois Biometric Information Privacy Act (740 ILCS 14/15(a)) and other applicable biometric privacy laws, the Company maintains a publicly available written policy establishing retention schedules and guidelines for the permanent destruction of biometric identifiers and biometric information.

The Company retains biometric identifiers only for the period necessary to fulfill the specific purpose for which the data was collected or until the user requests deletion, whichever occurs first.

Biometric identifiers are permanently destroyed when:

    1. the initial purpose for collection has been satisfied; or
    2. within thirty (30) days following account termination or receipt of a verified deletion request, whichever occurs first, unless a longer retention period is required by applicable law.

Destruction of biometric data is performed using secure, industry-standard methods designed to prevent reconstruction or recovery of the data.

This retention schedule and destruction policy is made publicly available and applies to all biometric data processed by the Company.

This policy is reviewed periodically and updated as necessary to reflect changes in legal requirements or business practices.

8.5 Transaction and Payment Data

The Company does not store full credit card numbers, CVV codes, or complete payment credentials. Payment processing is handled exclusively by authorized third-party payment providers such as Stripe or PayPal, in accordance with PCI-DSS standards.

Transaction Records: The Company retains transaction-related records, including invoices, billing details, and payment confirmations, for a period of seven (7) years as required for tax, accounting, audit, and financial compliance purposes, unless a longer retention period is mandated by applicable law.

8.6 Communications and Support Data

    1. Customer support correspondence: retained for three (3) years from the date of the last interaction, after which records are permanently deleted or anonymized. Where a support interaction relates to an active dispute, legal claim, or regulatory inquiry, records may be retained for the duration of such matter plus one (1) additional year.
    2. Marketing communications: retained until you unsubscribe or withdraw consent. Upon receipt of an unsubscribe request, your contact information will be removed from active marketing lists within ten (10) business days. A suppression record may be retained to ensure you are not inadvertently re-added to marketing lists.

8.7 Usage Logs and Analytics

System logs, including API request logs, access logs, and security monitoring records, are retained for up to one (1) year for security, fraud prevention, debugging, and operational integrity purposes, unless a longer retention period is required for legal or investigative reasons.

Aggregated Analytics: Aggregated and de-identified analytics data that does not reasonably identify an individual may be retained indefinitely for research, service improvement, performance optimization, and statistical analysis.

8.8 Legal Hold

We may retain information for longer periods if required by law, court order, legal proceedings, or to establish, exercise, or defend legal claims.

8.9 Data Destruction

When personal information is no longer needed, we securely delete or anonymize it in accordance with industry standards. Voice biometric data is permanently deleted using secure data destruction protocols to prevent recovery.

9. YOUR PRIVACY RIGHTS

    1. Access, correct, delete data
    2. Withdraw consent
    3. Request data portability
    4. Restrict or object to processing
    5. Opt out of targeted advertising
    6. GDPR & CCPA requests: privacy@sonicvox.ai
    7. Your rights vary depending on your location. Below we describe rights available under various privacy laws:

9.1 GDPR Rights (EU/EEA/UK)

9.1.1 Right to Access (Article 15)

Request a copy of your personal data we hold

9.1.2 Right to Rectification (Article 16)

Correct inaccurate or incomplete data

9.1.3 Right to Erasure/"Right to be Forgotten" (Article 17)

Request deletion of your data

9.1.4 Right to Restrict Processing (Article 18)

Limit how we use your data

9.1.5 Right to Data Portability (Article 20)

Receive your data in machine-readable format

9.1.6 Right to Object (Article 21)

Object to processing based on legitimate interests or for direct marketing

9.1.7 Right to Withdraw Consent (Article 7(3))

Withdraw consent for consent-based processing, including biometric data

9.1.8 Automated Decision-Making Rights (Article 22)

Request human review of automated decisions

9.1.9 Right to Lodge a Complaint

File complaint with your supervisory authority (see “Supervisory Authorities” below)

9.2 CCPA/CPRA RIGHTS (CALIFORNIA)

9.2.1 Right to Know

What personal information we collect, use, disclose, and sell

9.2.2 Right to Delete

Request deletion of your personal information

9.2.3 Right to Correct

Correct inaccurate personal information

9.2.4 Right to Opt Out

Opt out of sale/sharing of personal information (we do not sell)

9.2.5 Right to Limit Use of Sensitive Personal Information

Limit use of voice data beyond service provision

9.2.6 Right to Non-Discrimination

Not be discriminated against for exercising rights

9.3 How to Exercise Your Rights

To exercise any of the above rights, you may:

Email: privacy@sonicvox.ai

Mail to:

13148 Cottingham Road

Oklahoma City, OK 73142

9.4 Verification Process

To protect your privacy, we will verify your identity before fulfilling requests. We may ask you to provide information such as your email address, account details, or recent transaction information.

9.5 Response Time

    1. GDPR: We will respond within one (1) month, extendable by two months for complex requests
    2. CCPA: We will respond within forty-five (45) days, extendable by forty-five (45) days with notice

9.6 Fees

Requests are free. We may charge a reasonable fee for manifestly unfounded, excessive, or repetitive requests.

9.7 Authorized Agents (CCPA)

California residents may designate an authorized agent to make requests on your behalf. The agent must provide written authorization.

9.8 Supervisory Authorities (GDPR)

EU/EEA residents have the right to lodge a complaint with their local data protection authority:

    1. Find your supervisory authority: https://edpb.europa.eu/about-edpb/about-edpb/members_en
    2. UK: Information Commissioner's Office (ICO) - https://ico.org.uk/

10. SECURITY MEASURES

The Company implements appropriate technical and organizational measures to protect personal information against unauthorized access, alteration, disclosure, or destruction.

Where required by applicable law, including Article 35 of the General Data Protection Regulation (GDPR), the Company conducts Data Protection Impact Assessments (DPIAs) prior to initiating processing activities that are likely to result in a high risk to the rights and freedoms of individuals, including the large-scale processing of biometric or other sensitive personal data.

Our security measures include:

10.1 Technical Safeguards

    1. Encryption in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent)
    2. Secure authentication and access controls (multi-factor authentication available)
    3. Regular security testing and vulnerability assessments
    4. Intrusion detection and prevention systems
    5. Secure software development lifecycle practices
    6. Data backup and disaster recovery procedures
    7. Network segmentation and firewalls

10.2 Organizational Safeguards

    1. Access limited to authorized personnel on need-to-know basis
    2. Employee training on data protection and security
    3. Confidentiality agreements with employees and contractors
    4. Vendor security assessments and contractual obligations
    5. Incident response and breach notification procedures
    6. Regular security audits and compliance reviews

10.3 Limitations

No method of transmission or storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.

10.4 Breach Notifications

In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and applicable regulatory authorities as required under applicable data protection laws.

11. Children’s Privacy

Our Services are not directed to children under the age of 13 (or the applicable age of digital consent in your jurisdiction, such as 16 in certain regions)

We do not knowingly collect personal information from children under these ages. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@sonicvox.ai.

If we learn that we have collected personal information from a child under the applicable age without verifiable parental consent, we will delete that information as quickly as possible, typically within 30 (thirty) days.

11.1 Children’s Voice Data

We do not knowingly collect, process, or store voice recordings or biometric voice data of children under the age of 13 (or the applicable age of digital consent in your jurisdiction, such as 16 in certain regions). Voice cloning services require users to certify they are of legal age and have obtained appropriate consent for any voices processed.

11.2 Age Verification

We implement age verification mechanisms at account registration and require users to certify their age. Users who provide false age information may have their accounts terminated.

11.3 Parental Rights

Parents or guardians may request to:

    1. Review personal information collected from their child.
    2. Request deletion of their child's information.
    3. Refuse further collection or use of their child's information.

To exercise these rights, contact privacy@sonicvox.ai with verification of parental relationship.

12. LINKS TO OTHER SITES

We are not responsible for the privacy practices, security, or content of third-party websites or services.

Our Services may contain links to third-party websites, applications, or services. This Privacy Policy applies only to our Services. We are not responsible for the privacy practices, security, or content of any third-party sites.

We encourage you to read the privacy policies of any third-party sites you visit. Your interactions with third-party sites are governed by their privacy policies, not ours.

13. CHANGES TO THIS POLICY

We will post updates and notify you of material changes.

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Services. When we make changes, we will:

    1. Update the "Last Updated" date at the top of this policy.
    2. Post the updated policy on our website.
    3. For material changes, provide notice by:
      1. Email to the address associated with your account (at least 30 days before effective date);
      2. Prominent notice on our website or within the Services; or
      3. Pop-up notification upon login.

Material changes include: changes to purposes of processing, new categories of personal data collected, new third parties receiving data, changes to retention periods, or changes affecting your rights.

Continued use of the Services after the effective date constitutes acceptance of the updated Privacy Policy. If you do not agree to the changes, you must stop using the Services and may request deletion of your account and data.

14. CONTACT INFORMATION

For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:

WP Global Syndicate LLC dba SonicVox Privacy Team

Email: privacy@sonicvox.ai
Mail to:
13148 Cottingham Road
Oklahoma City, OK 73142
United States
Phone: (405) 563-5337

The Company has designated a privacy contact responsible for data protection inquiries. For privacy-related matters, including requests under applicable data protection laws, please contact privacy@sonicvox.ai.

©2025 SONICVOX AI · All rights reserved.

Service Status