Trust
Security
AltVoice is built around cloning only your own voice, account isolation, limited retention, abuse prevention, and practical controls for audio generation workflows.
Last updated September 15, 2026
1. Own-voice recording
Voice references are accepted only from a live microphone recording made inside the AltVoice interface, and the server rejects references that do not carry the recording marker. Audio files cannot be uploaded as references. Each recording is tied to a consent record that stores the confirmation text, a fingerprint of the audio, and pseudonymous account, network, and browser metadata. This does not make circumvention impossible, but it removes the ordinary path for cloning someone else's voice and leaves an audit trail when it is attempted.
2. Account protection
Access is protected through authenticated sessions and account-level ownership checks on every project, voice, generation, and billing endpoint. Sessions are invalidated when an account is deleted or its password changes. Media endpoints require an authenticated owner; some downloads additionally use short-lived signed links. Administrators can review content for moderation and support under internal access rules.
3. Audio storage
Recordings and generated results are stored only as needed to provide the service, support playback, and allow downloads. Demo recordings are deleted after 24 hours and account content follows the Data Retention page. Provider-side voice models are transient: each one is created for a single generation and queued for deletion as soon as it finishes, with automatic retries and an audit record of every deletion.
4. Abuse prevention
We use quotas, rate limits, audit logs, content restrictions, manual review, account suspension, generation blocking, and reference freezing during rights disputes to reduce misuse, fraud, attempts to clone a voice that is not the account holder's, and infrastructure abuse.
5. Third-party processors
AltVoice uses hosting, model-inference, email, payment, analytics, error-monitoring, and queue and storage providers. Provider credentials are separated from application data, and providers receive only the data needed for their function. Current providers are described in the Privacy Policy.
6. Incident response
If we identify a security issue that materially affects users, we will investigate, mitigate, and communicate based on severity and legal obligations. Where an incident is likely to result in a high risk to affected people, we notify them and, where required, the supervisory authority without undue delay.
7. Reporting a vulnerability
If you find a security vulnerability in AltVoice, email [email protected] with the subject line “Security report,” a description of the issue, steps to reproduce it, and how to reach you. We will acknowledge the report, keep you informed as we investigate, and credit you if you wish once the issue is fixed. We ask that you act in good faith: do not access, modify, or delete data that is not yours, do not degrade the service, and give us a reasonable time to fix the issue before disclosing it. We will not pursue legal action against researchers who follow these guidelines.