Privacy Policy
Current version: 2026-07-26
This Privacy Policy explains what personal data we process when you use Audio Estudio, for what purpose, and what rights you have over it.
Data controller and contact
The data controller is the Audio Estudio team. For any question regarding your personal data or this policy, you can reach us through the application's support email.
What data we collect
We only process the data needed to provide the service:
- Your email address (account identifier).
- The hash of your password (never the plaintext password).
- Your name and profile image, if you choose to provide them (optional).
- If you sign up or sign in with Google or GitHub, we receive from them your email address and, if available, your name and profile picture.
- The metadata of your projects, characters and clips (titles, descriptions, texts and positions).
- Your account and application preferences (UserSettings), such as the interface language.
- API usage logs (ApiLog): provider, action, status, duration and errors, without any audio content.
- Audio synchronization metadata (AudioSync) if you enable optional cloud sync: size and reference, never the audio itself unless you explicitly upload it.
What does NOT leave your browser
By design (privacy by design), certain information is never sent to our servers or database: the cloud TTS provider API keys (ElevenLabs, Gemini), the URL of any local TTS server you configure, the Google Drive or Dropbox access tokens, and the generated audio blobs (.wav/.mp3). All of this lives exclusively in your browser's local storage (IndexedDB). Audio only leaves your device if you enable cloud sync (see the next section), and in that case it goes to your own Drive or Dropbox account, not to us.
Cloud audio storage (optional)
By default, the audio you generate stays only in your browser. If you connect Google Drive or Dropbox from Settings, the app uploads your audio files (.wav/.mp3) to a folder dedicated to the app inside your own account, to sync them across your devices. That audio goes to your Google or Dropbox account, never to our servers. The access tokens that authorize this are stored only in your browser, never in our database. You can disconnect at any time from Settings. How Google or Dropbox handle those files is governed by their own privacy policies.
Data obtained from Google APIs
If you sign in with Google, we receive your email address and, if available, your name and profile picture; we use them solely to create and identify your account. If you also connect Google Drive, the application requests only the "drive.file" scope, the narrowest Drive scope: it grants access exclusively to the files the application itself creates or that you explicitly select, and it does not allow reading, listing or modifying the rest of your Drive. That access is used only to store and retrieve your audio files and sync them across your devices. We do not share this data with third parties, we do not use it for advertising or to train artificial intelligence models, and no human reads it unless you explicitly authorize it to resolve a support issue, where necessary for security purposes, or where required by law. Audio Estudio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke access at any time from Settings or from your Google account permissions page (google.com/permissions).
Legal basis
The legal basis for processing your email and account data is the performance of the contract: we need this data to give you access to the service and to provide it. We do not process this data on the basis of consent. The registration checkbox accepts the Terms and this Privacy Policy; it does not authorize additional processing.
Retention
We retain your data while your account remains active. If you request deletion of your account, we will erase your personal data and the associated metadata, except for what we must keep due to a legal obligation.
Third parties and data processors
To provide the service we rely on:
- Resend, for sending transactional email (for example, the password reset link).
- TTS providers, depending on which one you choose: ElevenLabs and Gemini (in the cloud, invoked directly from your browser with your own keys; we do not intermediate those calls), a local TTS server you configure (the clip text is sent to that URL), or Kokoro, which runs entirely in your browser without sending anything to any server.
- Our hosting provider, where the application runs and the metadata is stored.
- Google and GitHub, if you choose to sign in with them (OAuth identity providers).
- Google Drive and Dropbox, if you enable cloud audio storage: they receive the audio files you choose to sync, in your own account.
Your rights
You have the right to access your data, rectify it, request its portability and ask for its erasure. You can exercise portability and deletion directly from Settings: "Export my data" downloads your metadata, and the "Danger zone" lets you delete your account and its associated data. For anything else, you can contact support.
International transfers
Some of our processors may handle data outside the European Economic Area. In that case, the appropriate safeguards provided by the regulation apply (for example, standard contractual clauses).
Cookies
We only use strictly necessary cookies: the authentication session cookie and the language preference cookie (NEXT_LOCALE). We do not use analytics or tracking cookies, so we do not show a cookie consent banner. If in the future we introduce analytics or other non-essential cookies, we will add the corresponding consent banner.