Privacy

Last updated 15 August 2026

This describes what FuturVoice actually does with your data - checked against the running system rather than written from a template. Where something is imperfect, it says so.

The short version. Your account, voices, recordings and transcripts are stored on our server in France. To generate speech on the paid engines we send your text and your reference audio to a third-party speech-synthesis provider in the United States. We run no analytics and no advertising trackers of any kind. You can delete your account and everything in it from the app, at any time.

Who we are

FuturVoice operates futurvoice.com and is the data controller for the personal data described here. For anything in this document, including access, correction and erasure requests, write to privacy@futurvoice.com.

What we collect

Four kinds of thing, and nothing beyond what the product needs to work:

We do not collect anything for advertising, and we do not sell any of it.

Who else processes your data

Running this service means a small number of specialist providers touch parts of it: hosting, authentication, speech synthesis on the paid engines, transactional email, off-site backup storage, and error reporting. Each one gets only what its job requires, and none of them is permitted to use your data for anything else.

Most of this sits inside the European Economic Area. Some of it does not - speech synthesis on the paid engines in particular - and where personal data is transferred outside the EEA it is covered by the safeguards that transfer requires. Backups are encrypted by us before they leave our server, so the storage provider holds ciphertext and nothing else.

If you want to know which providers these are for a specific part of the service, ask at privacy@futurvoice.com and we will tell you.

What leaves our server, and exactly what is in it

Generation on the paid engines runs on a third-party speech-synthesis provider in the United States. For each request we send precisely this and nothing else:

No account identifier, no email address, no IP address and no session cookie is sent. Long scripts are split into chunks, so a long text crosses as a sequence of requests rather than one.

Deleting a voice deletes it there too. For one of the paid engines that provider caches a derived representation of your reference audio so repeat generations do not have to recompute it. When you delete a voice - or your whole account - we queue an erasure for that copy and it is removed within 24 hours. We queue it rather than send it immediately so that a provider outage delays the erasure instead of losing it.

Dictation runs entirely on our own server: speech-to-text and transcript cleanup never leave France.

Analytics and tracking

There are none. No Google Analytics, no advertising pixels, no session recording and no other analytics tool of any kind. No third-party code runs on this site at all, and errors in your browser are never sent anywhere.

We set one cookie, futurvoice_session. It is set by this site only, sent over an encrypted connection, unreadable to any script in your browser, and it expires after 30 days. It carries your user id and an expiry date, and nothing else. It is not a tracking cookie and there are no third-party cookies. Sessions created before 16 August 2026 may still carry this cookie under an earlier name until they expire; both names are accepted, and both are cleared when you sign out.

Backups

Backups are copied off-site to an object-storage provider, and are encrypted by us before they are uploaded - both the contents and the file names - so the storage provider holds only opaque blobs. The consequence you should know: when you delete something, copies persist in backups for up to about 30 days, and in weekly archives for about a month, before ageing out. Deletion in the app is immediate; deletion from backups is not.

How long we keep things

Voice samples, generated audio, captures and transcripts are kept until you delete them. There is no automatic expiry. Web-server access logs are kept for a maximum of 30 days because they contain IP addresses. Backup retention is described above.

Deleting your account

You can delete your account from the app at any time. It removes every voice profile and its reference audio, every generation and every version of it, every capture and transcript, your stories, your credit history, the files on disk, and your login. It is immediate and cannot be undone. Backup copies age out on the schedule above.

Your rights

If you are in the EU or UK you have the right to access your data, correct it, erase it, restrict or object to processing, and to data portability. You can exercise access and erasure directly in the app; for anything else write to privacy@futurvoice.com. You also have the right to complain to your local data protection authority.

Our legal basis is performance of the contract for the service you asked us to provide, and our legitimate interest in keeping the service secure and working.

Voices belong to people

You may only upload or clone a voice you have the right to use. Cloning someone's voice without their consent is not permitted and is grounds for closing an account. See the terms.

Security

Traffic is HTTPS only, with HSTS. Every piece of content is scoped to the account that owns it on every query, and a request for another account's data returns "not found" rather than "forbidden", so ids cannot be probed. Backups are encrypted before they leave the server. Server error reports are scrubbed of credential-shaped strings before transmission.

We should be straight about one thing: application-level separation is not the same as encryption at rest. Our server's disk is not encrypted, and as with any hosted service the operator has administrative access to the machine.

Changes

If this policy changes materially we will say so on this page and update the date at the top.