The short version
The open-source desktop app is local-first and needs no account or Cloud connection. The public website processes ordinary request data, optional Text-to-speech preview text, and the details you deliberately submit through its early-access or commercial enquiries forms. A Pro or Lifetime purchase is completed with a third-party payment provider. The account and dashboard product and the Cloud API are not released in the current public build.
The local desktop app
Bundled local cloning, dubbing, transcription, and speech workflows run on your machine. Their recordings, generated audio, transcripts, and derived voice data are written to storage you control; this website and the `vssaas` control plane do not receive them.
The app can use the network when you ask it to check for updates, download a model, or configure an explicitly network-backed adapter. A network-backed adapter is a separate processing choice and follows that provider's notice and terms. Local operation remains available without an account, API key, or Cloud connection.
Website delivery and external resources
Cloudflare delivers this site and its same-origin API routes. It necessarily processes request metadata such as IP address, user agent, requested URL, timestamps, and security signals. The site sets no advertising cookies, runs no advertising scripts, and does not sell visitor information.
The maintainer avatar from GitHub and ranking badge from Trendshift can be requested directly by your browser. Those services receive ordinary request metadata, including your IP address and this site's origin-level referrer. Star, release, and download metadata are fetched by our server. Fonts, prerecorded audio, and other site assets are served from this domain.
Text-to-speech preview
The Studio showcase and voice cards primarily play prerecorded audio and never request microphone access. If you use an editable Text-to-speech preview, the same-origin route receives up to 200 characters of text and the selected voice settings. When a reviewed VoiceStudio preview backend is configured, the route forwards that request to it for on-demand synthesis; otherwise it returns a bundled sample. It never forwards preview text to a third-party TTS provider.
The application does not persist preview text or generated preview audio and excludes request bodies from application logs. The hosting edge still processes ordinary HTTP metadata as described above. Do not enter secrets, personal data, or text you are not allowed to process into a public preview.
Early access and commercial enquiries
If you enter your email on the Cloud page, we store the normalized address, your explicit consent and its purpose, submission time, delivery state, and a non-secret retry key. A commercial enquiry can also contain the company and message you choose to provide.
Early-access details are used for an automatic receipt and one Cloud launch notice. Commercial-enquiry details are used for an automatic receipt and to answer that enquiry. They are not used for training, advertising, a newsletter, or an unrelated campaign.
PostgreSQL is the authoritative record. Email, internal notification, and CRM/webhook delivery are bounded retryable projections. We keep active form records for at most two years, then delete the record and delivery history in bounded retention batches. Retry keys expire after 30 days. Distributed rate-limit buckets become eligible after their 10-minute or one-hour window and are removed by the next bounded retention pass.
For abuse prevention, the website edge sends the control plane a signed visitor IP address and edge request marker. The control plane immediately converts the IP address to a keyed one-way digest; it never stores the raw address in the marketing tables. A hidden honeypot and distributed IP/address limits supplement the edge's bot controls.
Approved notification, email, and CRM/webhook processors receive only the fields needed for the relevant delivery. Their identity, processing region, deletion support, and contract must be recorded in the deployment processor inventory before forms are enabled. Provider response bodies and submitted contact details are excluded from application logs.
Reply to a message, or write to privacy@voicestudio.sh, and we will handle a verified access, export, correction, consent-withdrawal, or deletion request. Deletion clears the contact fields and cancels pending deliveries. We retain only a keyed suppression digest so the address is not silently re-added; it is not used to contact or profile you.
A live-database deletion can remain in encrypted backups for no more than 35 days. A restored backup must reapply completed deletion cases before it can serve traffic.
Pro and Lifetime purchases
Buying Pro or Lifetime sends your payment details to a third-party payment provider chosen by billing country—Razorpay for India and Zoho Payments elsewhere, with PayU as a supported alternative—under that provider's own notice. VoiceStudio never receives or stores card or other payment details. The order record keeps your email, plan, seat count, billing country (and, for India, state and any GSTIN you give), amounts, any coupon code you enter, the payment provider used and its order or transaction reference, and the payment status, including failed attempts and the provider's reason for a failure. It also keeps the IP address your checkout request came from and the user agent your browser sent, which names your browser and operating system. To record which country that IP address is in, we send the IP address, and nothing else, to an IP-geolocation service and keep only the country it returns.
We use these details for fraud prevention and abuse limits (rate limiting), order support, tax and invoicing records, and investigating payment problems, and so the order and its Commercial License can be verified and refunded. Only VoiceStudio platform administrators can see order records, and every view of one is logged. Order records, including the IP address and browser, are kept indefinitely. The payment provider may process your payment outside your country under its own notice. Purchases are for adults; we do not knowingly collect children's data.
Retention, processors and deletion are summarised in the data policy. Refunds and delivery are covered in the refund policy and the delivery policy.
Account, dashboard, and Cloud previews
The public build does not offer account creation, the hosted dashboard, API-key issuance, or Cloud job submission. Documentation and disconnected screens that describe these surfaces are previews, not live services.
Before an account and dashboard release is enabled, this notice must be updated with its final processors, regions, and retention rules. The reviewed data inventory will include identity and session data, Organization and Membership records, project, Job and Artifact metadata, usage and Credit records, API credential metadata, customer text or uploaded media, generated outputs, support records, and security/audit evidence. A browser identifier never grants tenant or commercial authority; PostgreSQL remains the system of record.
Your rights and retention
You can ask what we hold about you, ask for a portable copy, correct it, withdraw consent, or ask us to delete it. Write to privacy@voicestudio.sh. If we do not resolve a complaint, our grievance officer and the escalation steps are on the contact page.
Changes
The VoiceStudio repository maintainers own this public notice. A material data-flow change must update the reviewed inventory, this page, and the effective date in the same release. Qualified counsel must review the intended launch surface and jurisdictions before hosted customer-content processing or payment is enabled.
Questions or rights requests go to privacy@voicestudio.sh. If a release cannot meet its published notice, the affected surface stays disabled or is rolled back; the local desktop product remains usable.