Privacy Policy
Last updated 2026-09-05 · Era Voice, a service of Erasmus Labs LLC
Erasmus Labs LLC, based in California, United States, operates Era Voice. This policy covers the portal, API and MCP service. We determine how account, security and service administration data is processed. When processing content for an organisation on its instructions, our respective roles and any required processing agreement depend on that use. Acceptance of this policy is not a substitute for a data-processing agreement where one is required.
1. What we collect
- Account and access: email, display name, password hash, optional Google identity, team membership, session and API-key hashes, and invitations.
- Voices: uploaded samples, speaker embeddings, voice names and descriptions, design prompts, and material supplied for requested custom training.
- Documents and audio: uploaded files and pasted text; extracted passages, titles and source references; Studio scripts, segments and generated audio; History text and clips; transcription and dubbing recordings, transcripts, timings and outputs; selected podcast excerpts, prompts, drafts and edits.
- Reviews: frozen copies of shared audio and script text, access credentials stored as hashes, expiry settings, reviewer names, comments and decisions. Anyone with a valid review link and any required passcode can access that review.
- Consent, usage and support: accepted document versions and voice attestations with timestamps, IP addresses and user agents; generation counts and durations; request metadata and errors; and messages sent to support.
- Billing, when enabled: Stripe customer and subscription identifiers, plan and payment status. Payment card details are entered with Stripe.
2. Purposes and training
We use this data to carry out the operations you request, deliver and store results, manage access and usage, provide support, investigate abuse, protect the Service and meet legal obligations. We do not sell personal data or use it for advertising. We do not use submitted documents, pasted text, scripts, transcripts, voice samples, embeddings or generated outputs for model training or fine-tuning without your express opt-in to that specific use. A request to generate speech or a podcast is not training consent.
3. Legal bases and voice data
Where GDPR or UK GDPR applies, relevant bases include performing our contract with you, legitimate interests in security and service reliability balanced against your rights, consent where required, and legal obligations. Voice samples and embeddings can be personal data and may be regulated biometric data depending on their use and applicable law. A user's attestation about a speaker's permission is not, by itself, a determination that every legal requirement for biometric processing has been met. Contact us about speaker consent or its withdrawal.
4. Processing locations and recipients
- Service infrastructure: our application, database, storage, backup and inference systems process content to provide the requested features. Speech and transcription use configured inference services. Document extraction does not send your source to the podcast writing service.
- Podcast writing: selected excerpts and drafting instructions are sent to the configured writing endpoint. Later drafting or repair requests may also include draft text and source references. The software default is Meta's API endpoint, but the operator can configure a different service. The active provider, processing location, retention and contractual safeguards must be confirmed for the deployment; contact us before submitting content with provider-specific restrictions.
- Cloudflare: the public network edge can process request traffic, including content passing through it, IP addresses and request metadata.
- Resend, when configured: recipient addresses and transactional email content, including verification and invitation links. Google, when chosen: sign-in identity and authentication exchanges. Stripe, when checkout is enabled: billing identity, plan and payment information.
- Error tracking: our configured self-hosted tracker receives diagnostic events. Logs are intended for operational metadata, not document bodies, audio, credentials or bearer links.
- People you share with: team members have account-level access according to their role; marketplace visitors can access published voice details and samples; review recipients see the frozen review and its comments. Exported or downloaded copies are controlled by their recipients.
Data may be processed outside your country. Provider terms, retention controls and any required transfer safeguards depend on the active deployment and agreement. This policy does not certify that a particular provider agreement or international-transfer arrangement has been executed. We may disclose information when legally required or transfer it to a successor operating the Service under this policy.
5. Retention and independent copies
- Account, voices and Studio: retained until deleted. Studio copies of imported text, approved podcast scripts and their provenance are independent of the original source; delete the Studio project separately to remove them.
- Imports and podcast drafts: imports expire after 30 days; a related podcast draft follows its source expiry. Deleting or expiring a source does not erase an already-created Studio project.
- Transcription: source recordings are removed after processing completes or finally fails. Original and edited transcripts expire after 30 days by default; limited job and usage metadata remain until account deletion. A transcript copied into Studio has the Studio lifetime.
- Private reviews: access expires after the selected period of 1–30 days. Cleanup removes the frozen audio, script and reviewer sessions after expiry or deletion; associated comments and decisions are deleted with those sessions. Review title and status metadata may remain until the account is deleted. Expiring a review does not remove the Studio source or recipients' downloads.
- History: the default 30-day sweep removes stored audio only. The History row, submitted text and usage fields remain until deleted. Audio streamed directly without a stored-history feature is not retained by that feature.
- Dubbing: jobs, source recordings and generated outputs have no automatic expiry; delete the job or request account deletion.
- Backups: deleted data can remain in restricted backups. The restore-point policy keeps six monthly snapshots, alongside shorter daily and weekly copies; snapshot ages can exceed six months if backup or pruning jobs stop. Restoring a backup requires reapplying recorded erasures before reopening the Service.
- Consent and required records: consent records are kept with the related voice or account and removed with their deletion. Support may retain a minimal deletion receipt or specific records necessary for a documented legal obligation or dispute, with a stated purpose and review or expiry date. Consent records are not retained indefinitely merely because they once evidenced consent.
- Logs and cookies: operational log retention depends on the logging system and its rotation policy. The sign-in session cookie lasts 30 days; the Google sign-in protection cookie lasts 10 minutes.
6. Access, export and deletion
Use the available delete controls to remove individual content. For an account export, correction, deletion, or a speaker's removal request, email era-support@erasmuslabs.ai. We verify authority and explain scope before acting. Account deletion covers the entire shared account, including team access and stored content, and requires stopping active processing. We aim to complete requests within one month of receipt and explain any lawful extension or exception. We record the outcome and any limited retention needed; backups expire separately as described above. We cannot erase copies already downloaded by recipients, but can investigate unauthorised voices and revoke copies inside the Service.
7. Your rights
Depending on applicable law you may have rights to access, correction, erasure, portability, restriction, objection and withdrawal of consent, and to complain to a supervisory authority. Contact the support address above to exercise them. Withdrawal does not undo processing that was lawful before withdrawal.
8. Security
Public access uses HTTPS. Passwords are hashed with bcrypt; API keys and session tokens are stored as hashes. Storage and production access are restricted. Some internal inference connections use HTTP over the private network, so encryption is not universal across every processing hop. No system is perfectly secure; report concerns to era-support@erasmuslabs.ai.
9. Children
Accounts are for adults. We do not knowingly collect children's account data. A minor's voice may only be submitted with a parent or guardian's authority and any other permissions required by applicable law.
10. Cookies and policy changes
The ev_session and ev_google_oauth cookies support sign-in. We do not use advertising or third-party tracking cookies. Material policy changes are presented for acceptance in the portal. The version appears above; questions can be sent to era-support@erasmuslabs.ai.