Privacy Policy

Last updated: July 28, 2026

1. Scope and Our Roles

This Privacy Policy describes how Prosody AI, Inc. ("Prosody AI," "we," "us") collects, uses, discloses, and retains personal information in connection with our websites, dashboard, APIs, and related services (the "Services").

Most voice data we process arrives through a customer organization's account (an "Organization"). When we provide the Services to an Organization, the Organization is the data controller (or "business" under US state privacy law) and we act as its processor or service provider, handling data on its instructions. When we use data to train and improve our models under Section 4, we act as an independent controller for that purpose. If your voice was recorded through an Organization's use of the Services, that Organization decides why your data was collected, and it is your first point of contact for requests; we support and honor its instructions.

2. Information We Collect

Audio and Session Data

Organizations submit audio to the Services for live streaming analysis or batch analysis. We process that audio and retain session records (audio, transcripts, tone timelines, per-speaker measurements, and analysis results) so the Organization can review calls after they end. Retention length is governed by the Organization's policy.

Voice Profiles (Biometric Information)

To tell speakers apart and recognize a returning speaker in later sessions, we derive a voice profile: a numerical representation of how a person sounds. A voice profile is not a recording and cannot be played back, but in some jurisdictions it is regulated as a biometric identifier. Voice profiles are scoped to the Organization whose sessions produced them and are never shared or matched across Organizations. A voice profile may carry a display name only if the speaker introduced themselves by name during a session or the Organization assigned one.

Derived Voice and Conversation Data

Analysis attributes measurements (pace, pitch range, loudness, pausing, and changes in these over time) to a speaker's profile so an Organization can understand how a person's delivery evolves across sessions. Where an Organization enables cross-session memory features, we also store compact acoustic snapshots of significant moments; these snapshots can include short encoded audio segments that are technically reconstructable as sound. Where an Organization uses voice synthesis features, a short voice reference recording is captured only under an explicit consent grant from the speaker with a defined retention period, and is deleted when that consent expires or is withdrawn.

Account and Billing Information

Information provided when creating an account or purchasing the Services: name, email address, company, role, and billing details.

Usage and Log Data

API call volumes, latency, error rates, device and browser information, IP addresses, and similar diagnostics used to operate and secure the Services.

3. How We Use Information

  • To provide, operate, secure, and support the Services
  • To process API requests and return analysis results to the submitting Organization
  • To recognize returning speakers within the Organization that heard them
  • To train, evaluate, and improve our models and services (Section 4)
  • To communicate about accounts, billing, security, and product changes
  • To detect and prevent fraud, abuse, and security incidents
  • To comply with legal obligations and enforce our agreements

4. Model Training

We train our models on licensed research datasets and on audio and derived data from use of the Services. Zero Data Retention Voice Authentication inputs, outputs, and voiceprints are excluded from model training. Training produces improvements to our models; it does not cause one Organization's data to be disclosed to another. Organizations are responsible for ensuring their notices and consents to individuals cover this use (see Section 5 and our Terms of Service). Organizations that require restricted data-use terms can contact us to put dedicated terms in place.

Deleting data under Section 8 removes it from our active systems and future training runs; it does not retract training already incorporated into a model before the deletion request.

5. Biometric Information Policy

Where biometric privacy laws apply (including the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, and Washington's biometric statute), the following governs biometric identifiers and biometric information we hold, including voice profiles:

Our public Zero Data Retention Voice Authentication Policy states the complete retention schedule and permanent-destruction guidelines.

  • Purpose. We collect, store, and use voice profiles for authentication of returning speakers within the Organization that enrolled them.
  • Consent. Before creating a voice profile, we require a written release electronically signed by the person or their legally authorized representative and record the signature timestamp.
  • No sale. We do not and will not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information.
  • Disclosure. We disclose biometric data only to the subprocessors listed in Section 7 as needed to operate the Services, with the individual's or Organization's authorization, or as required by law.
  • Retention and destruction. A voice profile is permanently destroyed when its authentication purpose ends or, at the latest, three years after the individual's last interaction through the Services.
  • Standard of care. We store biometric data using the security measures in Section 9, in tenant-isolated storage, with at least the care we use for other confidential information.

6. Data Retention

  • Session data (audio, transcripts, timelines, results): retained per the Organization's retention policy.
  • Voice profiles and derived voice data: retained per the destruction schedule in Section 5.
  • Voice synthesis references: retained only for the period in the speaker's consent grant; deleted automatically on expiry or withdrawal.
  • Account and billing data: retained for the life of the account and as required by law (for example, tax and accounting records).
  • Usage and log data: retained for a limited period for security and operations, then deleted or aggregated.

7. How We Disclose Information

We do not sell personal information, and we never disclose one Organization's voice data to another. We disclose personal information only:

  • To subprocessors that host and operate parts of the Services under data processing agreements: Google Cloud (hosting and storage), Baseten (model inference), Pinecone (vector storage for voice profiles and memory), OpenAI (language processing for transcript-derived insights), and LiveKit (realtime media transport). Each processes data only to provide its service to us.
  • To professional advisors (lawyers, accountants, auditors) under confidentiality obligations.
  • For legal reasons, when required by law, subpoena, or court order, or to protect the rights, safety, or property of Prosody AI, our customers, or the public.
  • In a corporate transaction (merger, acquisition, or sale of assets), in which case this policy continues to apply to previously collected data.

8. Your Rights and Choices

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you and receive a copy
  • Correct inaccurate information
  • Delete your information, including voice profiles and derived voice data
  • Port your information to another provider
  • Object to or restrict certain processing, and withdraw consent where processing is based on consent
  • Not receive discriminatory treatment for exercising these rights

Account holders can exercise these rights by contacting privacy@prosodyai.app. We verify requests before acting on them and respond within the time required by law. If your voice was processed through an Organization's account, direct your request to that Organization. Under our Terms it is responsible for honoring End User requests, and we support and execute its deletion instructions. Organizations can delete individual speaker records directly in the product and can request deletion of all Organization data at any time; verified requests are completed within 30 days.

9. Security

We protect personal information with encryption in transit (TLS) and at rest (AES-256), tenant-isolated storage scoped to each Organization, least-privilege internal access, and audit logging. Our infrastructure runs on cloud providers that maintain SOC 2 Type II and equivalent certifications. No system is perfectly secure; we notify affected Organizations of personal data breaches as required by law.

10. International Data Transfers

We process and store data in the United States. Where we receive personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including Standard Contractual Clauses, for the transfer.

11. US State Privacy Disclosures

For residents of California and other states with comprehensive privacy laws: within the last 12 months we have collected the categories of personal information described in Section 2 (identifiers, commercial information, audio and sensory data, biometric information, professional information, and internet activity) for the purposes in Sections 3 and 4, and disclosed them to the service providers in Section 7. Voice profiles and audio are sensitive personal information; we use them only for the purposes described in this policy. We do not sell personal information and do not share it for cross-context behavioral advertising, and we do not use sensitive personal information to infer characteristics beyond the acoustic analysis the Services exist to provide. You may exercise the rights in Section 8, including through an authorized agent.

12. GDPR

For individuals in the European Economic Area and the United Kingdom: our legal bases are performance of a contract (providing the Services to your Organization or to you), legitimate interests (securing and operating the Services, and improving our models where not overridden by your rights), consent where we ask for it, and compliance with legal obligations. Where voice profiles constitute special category data under Article 9, the Organization submitting audio is responsible for establishing a lawful basis, typically explicit consent, that covers the processing described in this policy, including model training. You may lodge a complaint with your supervisory authority.

13. Children

The Services are not directed to children, and we do not knowingly collect personal information from children under 13. If you believe a child's data was submitted to the Services, contact privacy@prosodyai.app and we will delete it.

14. Changes to This Policy

We may update this policy from time to time. Material changes will be announced with reasonable advance notice on this page or by email. The "Last updated" date above reflects the current version.

15. Contact

Prosody AI, Inc.
Data Protection Officer: privacy@prosodyai.app