speech.name Sign in

Amazon Web Services edition

Privacy policy

How Grid Heap, Inc. processes personal information on speech.name, and how to exercise your rights over it. Effective 8 September 2026.

Who we are and what this covers

Grid Heap, Inc. ("Grid Heap", "we", "us") operates speech.name: a public registry of how a person's voice may be used, a library of voices that speakers license for synthesis, and the tools that generate, watermark and verify that speech. This policy describes how we process personal information on speech.name, its consoles and the per-handle hostnames under speech.name, and in support conversations with us. It does not cover third-party sites we link to.

People in the European Economic Area and the United Kingdom should also read the section for European users below. Residents of U.S. states with privacy laws should read the state privacy rights notice.

Personal information we collect

Information you give us

  • Account data. Our sign-in provider, Clerk, gives us a user identifier, your email address, your name where you supplied one, and the sign-in method you chose. With Google or Microsoft sign-in that includes the identifier those services assign to your account. We never see your password.
  • Record data. Your handle, the grants you publish, the domain you name for verification, and the profile fields you choose to fill in. A published record is public by design.
  • Voice data. If you verify your voice, a recording of you reading a challenge phrase, and the sample enrolled on your account that the recording is compared with. If you list a voice in the library, the reference sample you enrol and the demo we generate from it. Voice recordings can identify a person, so we treat them as sensitive: we process them only for the verification or the listing you asked for, and only with your explicit consent given in the console when you record or upload.
  • Content you submit for synthesis. The text and settings you send to the Studio or the API, and the audio that comes back.
  • Payout data. If you opt in to be paid for licences, Stripe collects your identity and bank details directly and we never receive them. We hold your Stripe account identifier and the amounts we transfer.
  • Provider credentials. If you connect your own account with a third-party speech provider, the key you supply, which we store encrypted in a vault and use only to call that provider on your behalf.
  • Communications. What you send to our support, legal and security addresses.

Information collected automatically

  • Security and operational data. IP address, user agent, request timing, request identifiers and error records, kept in the operational log. Request bodies, audio and recipient identifiers are kept out of that log.
  • Usage data. Which features you use and how much: minutes of audio generated, files uploaded, resolutions served and API calls made. This is what plans and licences are metered on.
  • Plan data. On this edition every organisation is on an included preview plan, so we hold only the plan assignment. When paid plans arrive with the AWS Marketplace listing, the marketplace will supply order and entitlement identifiers; we will never see a payment card.

Information from others

  • Public verification uploads. Anyone can upload audio to the public verification page. We process it to detect a watermark and match a fingerprint, and discard it when the request completes.
  • Licence records. When a customer licenses your voice, we hold the record of that licence, the usage it produced and the amounts owed to you.

How we use it

  • To provide the service: sign you in, store and resolve your record, verify a domain or a voice you ask us to verify, list a voice you choose to list, generate speech a licensee is entitled to, watermark and fingerprint that speech, meter usage, and pay speakers.
  • To keep it secure: detect and prevent abuse, fraud and unauthorised access, and keep the audit records that let us show what a record said on a given date.
  • To communicate with you: service announcements, security notices, licence and payout notices, and answers to your requests. We do not send marketing email.
  • To meet legal obligations and to establish, exercise or defend legal claims.

What we do not do. We do not sell personal information. We do not use it for advertising or for profiling. We do not use your recordings, your voice samples or your content to train models: a voice sample is used only at the moment of synthesis, for the licence that authorises it. We do not make automated decisions about you that have legal or similarly significant effects.

Cookies

The consoles set only the cookies needed to keep you signed in, provided by Clerk on this domain and on clerk.speech.name. They are strictly necessary, so there is no consent banner and nothing to opt out of. We use no analytics or advertising cookies, no pixels and no third-party trackers. The public pages set no cookies at all.

How we share it

We disclose personal information only to the parties listed on the subprocessors page, each under a contract that limits their use of it, and in the situations below.

  • The public and other users. A published record, a voice listing and its demo are public by design. Anyone can see them, cache them and copy them, including search engines. A licensee receives audio generated with a licensed voice.
  • Third-party speech providers you connect. When you use your own provider account, the text you submit goes to that provider under your agreement with it, not ours.
  • A marketplace you buy through. The marketplace that bills your organisation receives what it needs to bill: plan, order state and metered quantities, never your content.
  • Authorities and legal process, where we believe in good faith that the law requires it or that disclosure is necessary to protect the rights, safety or property of a person or of the service.
  • Business transfers. If Grid Heap is party to a merger, acquisition, financing or sale of assets, personal information may be transferred as part of that transaction under the same commitments.

How long we keep it

Voice recordings for verification, uploaded audio and generated audio expire 24 hours after creation. Enrolled voice samples are kept while a listing or a verification depends on them and deleted when you remove them. Records and grants are kept until you delete them, and their version history is kept because the registry's value depends on being able to state what a record said on a given date. Licence, usage, payout and procurement records are kept for as long as a dispute, an audit or the law can reach them. The full schedule is on the data retention page.

Where it is processed

This console runs on Amazon Web Services, in us-west-2 (Oregon), United States. Our subprocessors are U.S. companies. If you use the service from outside the United States, your personal information is transferred to the United States, whose laws may protect it less than the laws where you live. The section for European users explains the safeguards we rely on.

Security

We use technical and organisational safeguards designed to protect personal information, described on the security page. No internet service can guarantee security; if you believe your account has been accessed without your authorisation, contact security@gridheap.com.

Your choices and rights

  • Access and correction. Your record, your listings, your grants and your profile are editable in the console at any time.
  • Deletion. You can withdraw a record, remove a listing or delete your voice sample yourself. To delete your account, write to legal@gridheap.com from the address on the account. Deleting an account withdraws the record from public resolution; we keep only the minimum needed for the legal, security or financial obligations described above.
  • Export. Ask legal@gridheap.com for a machine-readable copy of the personal information we hold about you. In short: you can access, correct, export or delete your data, and we do not charge for it.
  • Consent for voice data can be withdrawn at any time by deleting the sample or the verification; withdrawal does not affect processing that already happened.
  • Sign-in providers. You can revoke our access in your Google or Microsoft account settings; that does not remove what we already hold.

We verify every request before acting on it, normally by requiring it to come from the email address on the account, and we answer within 30 days. If we refuse a request, we say why.

Children

The service is for people aged 18 or over. We do not knowingly collect personal information from anyone under 18; if you believe we have, write to legal@gridheap.com and we will delete it.

State privacy rights notice

This section applies to residents of U.S. states whose privacy laws apply to us, including California, Colorado, Connecticut, Virginia, Texas, Oregon and others with comparable laws. Those laws may give you the right to know what personal information we collect and why, to access it, to correct it, to delete it, to obtain a portable copy, and to appeal a refusal. Exercise any of them by writing to legal@gridheap.com; an authorised agent may do so with your written permission. We do not discriminate against anyone for exercising a right.

We do not sell personal information, we do not share it for cross-context behavioural advertising, we do not process it for targeted advertising, and we do not profile people in ways that produce legal or similarly significant effects. Because there is no sale or sharing, a Global Privacy Control signal changes nothing, though we treat it as an opt-out should that ever change. The only sensitive personal information we process is a voice recording you choose to make, used solely to provide the verification or the listing you asked for and not to infer characteristics about you. California residents may also request the disclosure described in Civil Code section 1798.83; we have made no such disclosures.

In the past twelve months we collected the categories described above (identifiers, account and record content, audio and biometric-like voice data, commercial and usage information, and internet activity in the form of security logs), from you and from the parties named, for the purposes listed, and disclosed them only to the subprocessors listed and as the sharing section describes.

Notice to European users

Controller. Grid Heap, Inc. is the controller of the personal information described in this policy for the purposes of the EU and UK GDPR. We have not appointed a representative in the EEA or the United Kingdom or a data protection officer; contact legal@gridheap.com.

Legal bases. We process account, record, content, licence, usage and payout data because it is necessary to perform our contract with you. We process security and operational data, and keep audit history, on the basis of our legitimate interest in running a secure and trustworthy registry, which we have balanced against your interests. We process voice recordings and samples on the basis of your explicit consent. We process data to meet legal obligations where the law requires it, and we ask for consent for any further use that is not compatible with the purpose the data was collected for.

Your rights. You may ask us to give you access to your personal information, correct it, delete it, restrict its processing, transfer a machine-readable copy to you or to someone else, and object to processing based on legitimate interests. Where processing rests on consent you may withdraw it at any time. Write to legal@gridheap.com. If you are not satisfied with our answer you may complain to the data protection authority where you live; in the United Kingdom that is the Information Commissioner's Office.

Transfers. We are a U.S. company and this console runs in the United States, which is not the subject of a general adequacy decision. Where a transfer needs a safeguard we rely on the standard contractual clauses approved for the purpose with our subprocessors, and otherwise on your explicit consent to the transfer when you use the service. You may ask legal@gridheap.com for a copy of the safeguards.

Changes and contact

We will post any change to this policy here with a new effective date, and tell account holders by email before a material change takes effect. Questions and requests go to legal@gridheap.com.