Legal · Draft
Privacy Policy
What personal data Cinara collects, including voice recordings and consent records, why, who helps us process it, how long we keep it, and the rights you have.
Effective date: 15 September 2026 · Draft prepared September 2026
1. Who is responsible
Cinara is operated by APBLD, [Registered address]. APBLD is responsible for the personal data described here. This policy applies to cinara.ai, app.cinara.ai, api.cinara.ai and related tools. It explains how we handle data under applicable data protection laws, including India's Digital Personal Data Protection Act, 2023 and, where they apply, the EU and UK GDPR.
Grievance officer: Vikram Kumar, support@cinara.ai. We acknowledge complaints within 24 hours and resolve them within 15 days.
2. What we collect
Account details
- Your email address, name if you give one, and sign-in credentials (passwords are stored in hashed form by our authentication provider).
- Your mobile phone number and its verification status. We use it to confirm you are a real person and to allow one account per phone number.
- Workspace details, such as its name and members.
Content
- What you give the Service: text, scripts, lyrics, prompts, pronunciations, recordings, uploaded audio, images, video and documents.
- What the Service makes for you: speech, songs, sounds, transcripts, translations, subtitles, images, video and audiobooks, and the files in your Drive.
Voice data
- Recordings used to clone a voice or make a singing voice, the voice models made from them, and their previews.
- Consent records for each cloned voice: the speaker's name, the consent statement and its code words, how much of the statement was heard, how many speakers were heard, the length of speech, the confirmation given, and who created the voice and when.
Usage and technical data
- Generation history, linked to the account, workspace and API key that made each generation, plus credit charges and refunds. For API keys we store only a hashed form of the key and a short prefix.
- How often a public share link is opened.
- Log data such as IP address, browser and device type, and the time and result of requests, used for security and to keep the Service running.
- Payment details when paid plans launch. Card details are handled by our payment provider, not stored by us.
This website uses no advertising cookies. The app uses cookies and local storage that are needed to keep you signed in.
3. How we use it
- To provide the Service: run the generations you ask for, store and play your files, keep your history and credit balance, and power share links and the API.
- To verify accounts and prevent abuse: email confirmation, phone verification, rate limits, and the consent checks described in the Voice Consent Policy.
- To investigate misuse, enforce our Terms and respond to lawful requests, using the link between each generation and the account and key that made it.
- To support you, answer questions and handle reports, complaints and appeals.
- To keep the Service secure, fix problems and understand how features are used.
- To send service messages, such as confirmation emails and verification codes. We will ask before sending marketing messages where the law requires it.
- To meet legal obligations.
Our reasons for processing are: to perform our contract with you; our legitimate interests in running a safe, working service; your consent, where we ask for it; and compliance with the law. We do not use your uploads or creations to train AI models. Your content goes to AI model providers only to perform the task you ask for.
4. Voice recordings and voice models
Voice recordings and the voice models made from them can be biometric or sensitive personal data, and we treat them that way. We process them only to provide the features you ask for (such as cloning, speech in the cloned voice and singing voices) and to verify consent. We do not use them to train AI models, and we do not use them to identify people for any other purpose.
- When you delete a voice, or your account, its voice models, consent recordings and previews are deleted. Copies in backups roll off within 35 days.
- The consent record (the text details listed in section 2, not the recording) is kept for as long as the voice exists and for 3 years after it is deleted, so we can respond to disputes and legal requests.
5. Who we share it with
- Service providers who process data for us under contract, in these categories: cloud hosting and storage, AI model providers (only to perform the task you ask for), SMS verification, email, and payments when paid plans launch. We will share a list of our service providers on request.
- People you choose: anyone with a public share link you create, members of your workspace, and third-party tools you connect with an API key.
- Legal and safety: in response to lawful requests from authorities, when the law requires it, or when needed to protect people, investigate abuse or enforce our Terms.
- Business changes: as part of a merger, acquisition or sale of assets, with this policy continuing to protect your data.
We do not sell your personal data.
6. International transfers
Our cloud and AI model providers may process data in countries other than the one where you live, including outside India, the EEA and the UK. Where we transfer data across borders, we use appropriate safeguards required by law, such as contractual protections, and we follow any restrictions India's government places on transfers.
7. How long we keep it
- Account details: while your account is open.
- Generated and uploaded files: until you delete them or your account closes.
- After an account closes: account data is deleted within 30 days.
- Voice models and consent recordings: until you delete the voice or your account.
- Backups: deleted data rolls off backups within 35 days.
- Consent records: while the voice exists and for 3 years after it is deleted.
- Logs: 90 days.
- Records we must keep by law, such as invoices: for as long as the law requires.
8. Security
We use reasonable technical and organisational measures to protect data, including access controls, encryption in transit, hashed API keys and signed, expiring links for media. No system is completely secure, and we cannot guarantee absolute security. If a personal data breach affects you, we will notify you and the relevant authorities as the law requires.
9. Your rights
Everyone, including under India's Digital Personal Data Protection Act, 2023
- Access information about the personal data we hold about you and how it is used.
- Correct, complete or update your personal data.
- Erase your personal data, unless we must keep it by law.
- Withdraw consent where we rely on it (this does not affect what we did before).
- Grievance redressal: complain to our grievance officer and, if not satisfied, to the Data Protection Board of India.
- Nominate someone to exercise your rights if you die or become incapacitated.
Users in the EEA and UK
Where the GDPR applies, you also have the right to data portability, to restrict processing, and to object to processing based on our legitimate interests, and you can complain to your local supervisory authority.
How to make a request
Email support@cinara.ai from your account email if you can. We will verify your identity before acting, and respond within the time the law requires. If your voice was cloned by someone else, you can ask us to delete it; see the Voice Consent Policy.
10. Children
Cinara is not for anyone under 18, and we do not knowingly collect personal data from children. Don't upload children's personal data, including their voices or likenesses. If you think a child's data has been given to us, contact us and we will delete it.
11. Changes to this policy
We may update this policy. For material changes we will notify you by email or in the app at least 30 days before they take effect.
12. Contact
APBLD, [Registered address]. Privacy requests and complaints: support@cinara.ai. General questions: hello@cinara.ai.