Draft — not legal advice. This is placeholder boilerplate pending review by counsel. TODO: replace with the final, reviewed policy before launch.
Security & data handling
Last updated: July 2026
How we treat your audio, your text and your keys. Everything below is in force today; where something is not, it says so.
Your content is not training data
We do not train models on customer transcripts, reference audio, or generated audio. Your requests are used to render your audio, and nothing else.
What we store, and for how long
Transcripts. Processed in memory for the render, and not kept after the response completes.
Generated audio. Streamed to you. Short-lived edge buffers exist to smooth cold-start continuity; they are bounded and recycled. No durable archive of your renders is kept.
Voice references. A cloned reference is fingerprinted so a repeat call with the same clip skips re-cloning, which is what makes instant cloning instant. The cache is keyed by fingerprint and holds derived voice features, not a copy of your library.
Usage. We keep counts per key. They are numbers, not content.
Keys and transport
All traffic is TLS-encrypted in transit, over HTTPS and WSS. API keys are per-customer and signed, and you can rotate or add one at any time by writing to contact@gandr.ai.
Keys never appear in generated audio, in publicly served logs, or in error bodies.
Every render is watermarked
All audio generated by Gandr carries an inaudible, machine-readable watermark applied at generation. If a clip is ever in question, we can verify whether it came from our engine.
What that proves is where a clip was made, not whose voice it is. We say the narrower thing because it is the true one.
Infrastructure
Serving runs in multiple US regions and an EU region, and requests route to the nearest healthy region. GPU workers are stateless for content: no transcript or rendered audio persists on a worker beyond the request lifecycle.
Responsible use
Voice cloning requires audio you have the right to use. Together with the per-render watermark, that is our line against impersonation. Report suspected misuse to contact@gandr.ai and we will investigate against the watermark record.
Compliance
We are two people and we say only what is true: formal certification, SOC 2 included, is on the roadmap and is not complete. The practices above are in force today. Enterprise buyers can ask for our current security overview at contact@gandr.ai.
Reporting a vulnerability
Mail contact@gandr.ai with [security] in the subject. We read every report promptly and we do not pursue good-faith researchers.
