Privacy Policy

SelfSpeak Privacy Policy

Effective date: September 17, 2026 Operator: SelfSpeak LLC, 10232 Waller Dr, Dallas, Texas 75229, United States Privacy contact: info@selfspeak.com

1. About this Policy

This Privacy Policy explains how SelfSpeak LLC (“SelfSpeak,” “we,” “us,” or “our”) collects, uses, stores, discloses, and deletes information when you use the SelfSpeak mobile application, related websites, and supporting services (collectively, the “Service”).

SelfSpeak is a voice-affirmation application. It can create affirmations, create a private AI-generated version of a user’s own voice, synthesize affirmation audio, provide playback, schedule local reminders, and manage paid features.

This Policy applies to the SelfSpeak mobile application and related account services. It distinguishes among:

  • Raw voice recordings: audio you record when authorizing and creating a voice clone.
  • Derived voice models or clones: a provider-generated representation of your voice used to synthesize speech.
  • Voice identifiers: identifiers and related metadata used to associate your SelfSpeak account with a voice clone.
  • Generated audio: synthesized audio created from affirmation text using a selected or cloned voice.
  • Affirmation text and other user content: affirmations, themes, preferences, playlists, and related content you create, select, or save.
  • Account information: such as your email address, account identifier, sign-in information, and profile metadata.
  • Billing records: Apple App Store and RevenueCat transaction, receipt, product, subscription, and entitlement records.

2. Eligibility

The Service is intended only for people who are at least 18 years old. We do not knowingly permit children under 18 to create an account or use the Service. If you believe a person under 18 has provided information to SelfSpeak, contact us at info@selfspeak.com.

3. Information We Collect

3.1 Account information

When you create or use an account, we may collect:

  • Your email address.
  • Your name, display name, or profile information provided through an authentication provider.
  • A SelfSpeak or Supabase user identifier.
  • Authentication-provider identifiers and limited sign-in metadata.
  • Access and refresh tokens required to maintain your authenticated session.
  • Account status and timestamps associated with account activity.

If you use Sign in with Apple, Apple may provide a private relay email address instead of your personal email address. If you use another supported sign-in provider, that provider may share the account information you authorize.

3.2 Raw voice recordings

If you choose to create a voice clone, SelfSpeak asks for your express consent before recording. You record a short sample of your own voice and speak an authorization statement.

The raw recording may be transmitted:

  • To SelfSpeak’s server for temporary processing.
  • To an OpenAI-compatible service for transcription or classification of the spoken authorization.
  • To Cartesia and its service providers to create and operate the requested voice clone.

SelfSpeak uses the recording to verify the authorization statement and create the voice clone. SelfSpeak’s application is designed not to retain the raw recording as a permanent account record after processing completes. Temporary files may exist during recording, upload, transmission, or processing. A failed request, interrupted process, device or operating-system cache, provider log, security record, or provider backup may cause a copy or related metadata to remain for a period outside SelfSpeak’s direct control.

SelfSpeak does not authorize the voice-cloning feature to be used to impersonate another person. You must record and use only your own voice.

3.3 Derived voice models, clones, and voice identifiers

Cartesia creates and stores a derived voice model or clone from the voice sample. The derived model is different from the raw recording. It can be used to synthesize new audio that sounds like the recorded speaker.

SelfSpeak and Supabase may store:

  • The identifier used to locate the voice clone at Cartesia.
  • A voice name or related voice metadata.
  • The association between the voice identifier and your SelfSpeak account.
  • Consent and processing records, including consent version, confirmation status, processing status, timestamps, and error information.

Cartesia may store the derived voice model and related operational records in accordance with Cartesia’s terms, privacy policy, and retention practices.

3.4 Affirmation text and other user-generated content

We collect content and preferences you submit or save, including:

  • Affirmation text.
  • Topics, themes, or prompts used to generate affirmations.
  • Saved or selected affirmations.
  • Playlist and session preferences.
  • Voice, playback, and style selections.
  • Reminder preferences.

Affirmation text may be stored on your device and in SelfSpeak’s Supabase database. It may be sent to an OpenAI-compatible service to generate or transform affirmations and to Cartesia to synthesize audio.

Avoid placing information in affirmation text that you do not want processed by SelfSpeak and these providers.

3.5 Generated audio

Generated audio is synthesized from affirmation text using a selected voice or your voice clone. It is different from both the raw recording and the derived voice model.

Generated audio may be:

  • Returned to your device for playback.
  • Stored temporarily in memory or in an audio cache on SelfSpeak’s server.
  • Stored temporarily in application, media, filesystem, or playback caches on your device.
  • Processed by Cartesia to perform text-to-speech synthesis.

Cached generated audio is generally retained until it is replaced, evicted, cleared, or removed through ordinary cache or application cleanup. SelfSpeak cannot guarantee immediate removal from every device, operating-system, provider, or backup cache.

3.6 Subscription and purchase information

If you purchase a subscription or lifetime product through the Apple App Store, Apple processes the transaction. SelfSpeak does not receive or store your full payment-card number.

SelfSpeak and RevenueCat may receive or process:

  • Product and package identifiers.
  • Purchase, renewal, expiration, cancellation, and entitlement status.
  • Transaction and receipt information.
  • Trial or introductory-offer eligibility.
  • Subscription-management information.
  • A SelfSpeak user identifier used to associate your entitlement with your account.
  • Device, store, and technical metadata generated by the purchase system.

Apple and RevenueCat maintain billing, receipt, fraud-prevention, tax, accounting, and transaction records under their own legal and operational requirements.

3.7 Marketing email information

Joining the SelfSpeak Inner Circle or another marketing list is optional and is not required to purchase or use a subscription. If you affirmatively opt in, SelfSpeak sends your authenticated email address and subscriber or group status to MailerLite.

MailerLite may process:

  • Your email address.
  • Mailing-list or group membership.
  • Delivery, open, click, bounce, complaint, and unsubscribe events, where enabled.
  • Suppression and compliance records.

Withdrawing marketing consent does not cancel your SelfSpeak subscription or delete your SelfSpeak account. MailerLite may retain suppression records or other information required to honor an unsubscribe request, prevent abuse, or comply with law.

3.8 Notifications

If you enable reminders and grant notification permission, SelfSpeak schedules local notifications on your device. Notification titles or bodies may contain affirmation text. Notification preferences and schedules may be stored locally.

Local notifications are generally delivered by the operating system rather than through a SelfSpeak remote-push campaign. Previously delivered notifications may remain visible in notification history until you or the operating system removes them. You can disable notifications in SelfSpeak settings or your device settings.

3.9 Local device information and storage

SelfSpeak may store information locally using application storage, secure storage, filesystem storage, and operating-system media or notification facilities. Local information may include:

  • Authentication session information.
  • Affirmations, topics, playlists, and preferences.
  • Voice and playback selections.
  • Reminder settings and scheduled notifications.
  • Generated or preview audio files and playback caches.
  • Limited diagnostic or error information.

Signing out, deleting an account, uninstalling the application, or clearing device storage may remove some local information, but these actions are not equivalent. Some operating-system backups, notification history, media caches, or temporary files may remain outside the application’s direct control.

3.10 Server, network, security, and diagnostic information

When you use the Service, SelfSpeak and its infrastructure providers may process:

  • Internet Protocol address and network metadata.
  • Request date and time.
  • Requested endpoint or operation.
  • Response status, errors, and diagnostic information.
  • Device, application, and operating-system information made available in requests.
  • Rate-limiting, authentication, fraud-prevention, and security events.

Logs are used to operate, secure, troubleshoot, and improve the Service. Logs may sometimes be associated with an account identifier or request. SelfSpeak does not use this information for cross-app advertising tracking based on the audited production implementation.

4. How We Use Information

We use information to:

  • Create and manage your SelfSpeak account.
  • Authenticate you and maintain your session.
  • Verify that you authorized use of your own voice.
  • Create, store, operate, replace, and delete a voice clone.
  • Generate, save, synchronize, and play affirmations.
  • Synthesize affirmation audio.
  • Provide personalization, playlists, playback, and local reminders.
  • Process and verify purchases, subscriptions, and entitlements.
  • Restore purchases and provide subscription-management links.
  • Send marketing email only when you separately opt in.
  • Respond to questions, support requests, and privacy requests.
  • Detect abuse, impersonation, fraud, security incidents, and service errors.
  • Maintain, troubleshoot, and improve the Service.
  • Comply with legal, tax, accounting, billing, and regulatory obligations.

We do not sell your raw voice recordings, derived voice model, affirmation text, or account information. Based on the audited implementation, SelfSpeak does not use your data for cross-app advertising tracking.

5. AI and Voice Processing

SelfSpeak uses automated and AI-supported processing to provide core application features.

5.1 OpenAI-compatible processing

SelfSpeak uses a production service that exposes an OpenAI-compatible interface for tasks such as:

  • Transcribing or analyzing the spoken authorization statement.
  • Classifying whether the required authorization was spoken.
  • Generating or transforming affirmation text based on submitted themes or prompts.

Depending on the operation, this service may receive raw voice audio, a transcript, affirmation themes, prompts, or affirmation text. Account and request metadata may also be available to SelfSpeak’s server or infrastructure providers.

The underlying processor and model may change as SelfSpeak updates its AI infrastructure. SelfSpeak does not claim that provider systems delete all inputs immediately. Provider retention, logging, backup, and model-improvement practices are governed by the applicable provider terms and SelfSpeak’s service configuration.

5.2 Cartesia

Cartesia provides voice cloning and text-to-speech services. Cartesia may receive:

  • Raw voice audio used to create the voice clone.
  • A voice name, voice identifier, and processing metadata.
  • Affirmation text submitted for speech synthesis.
  • Voice style, speed, volume, emotion, or related synthesis settings.

Cartesia creates and stores the derived voice model and returns generated audio. Cartesia’s retention of raw inputs, derived models, generated outputs, logs, backups, and related metadata is governed by Cartesia’s terms, privacy policy, contracts, and operational practices. SelfSpeak can submit deletion requests through Cartesia’s service, but SelfSpeak does not directly operate or control Cartesia’s production systems or backups.

6. Service Providers and Disclosure of Information

We disclose information only as needed to operate the Service, process a request you initiate, comply with law, or protect users and the Service.

  • Supabase — authentication and database services. Supabase processes email addresses, account identifiers, authentication sessions, OAuth metadata, profile information, voice identifiers, affirmation content, consent records, and related timestamps. Supabase and its infrastructure may also process network, security, and operational logs.
  • OpenAI-compatible processing service — AI generation, transcription, and classification. This service may receive voice audio, transcripts, affirmation themes, prompts, or affirmation text as described above. This service is limited to the processing purposes described above.
  • Cartesia — voice cloning and text-to-speech. Cartesia receives voice samples, voice identifiers, affirmation text, and synthesis settings to create and operate voice clones and generated audio.
  • RevenueCat — purchase and entitlement management. RevenueCat processes SelfSpeak user identifiers, product identifiers, purchase and subscription status, receipt or transaction information, entitlement information, and related device or store metadata.
  • Apple and StoreKit — App Store purchases and device services. Apple processes App Store transactions, subscriptions, receipts, refunds, and Apple account information. Apple also provides operating-system services such as Sign in with Apple, microphone permissions, local notifications, and device storage or backup features.
  • MailerLite — optional marketing email. MailerLite receives your email address and mailing-list status only after you affirmatively join the applicable marketing list. It may also process delivery, engagement, unsubscribe, and suppression records.
  • Hosting and infrastructure providers — application delivery and operations. Hosting providers may process requests, IP addresses, timestamps, errors, temporary files, and operational or security logs.
  • OAuth sign-in providers — authentication. If you select Apple, Google, or another supported provider, that provider processes the authentication request and shares authorized account information with SelfSpeak through Supabase.

We may also disclose information:

  • When required by law, legal process, or a valid government request.
  • To protect the rights, safety, and security of SelfSpeak, our users, or others.
  • In connection with a merger, financing, acquisition, sale, or transfer of all or part of SelfSpeak, subject to appropriate protections and notice where required.
  • With your direction or consent.

Depending on where you live and the applicable law, SelfSpeak processes information:

  • To provide the Service you request and perform our agreement with you.
  • With your consent, including voice processing and optional marketing.
  • For legitimate interests such as security, troubleshooting, fraud prevention, and service operation.
  • To comply with legal, billing, tax, accounting, and regulatory obligations.

You can choose not to create a voice clone. You can deny microphone or notification permission, although the related feature will not work. You can decline optional marketing without affecting your paid subscription.

8. Data Retention

SelfSpeak retains different categories of information for different periods. We do not represent that every category is deleted within 24 hours or that no backup copies ever exist.

8.1 Raw voice recordings

SelfSpeak’s application is designed to use raw recordings for authorization verification and clone creation without retaining them as permanent account content after processing completes. Temporary copies may remain during processing or after failures. AI, voice, infrastructure, security, or backup providers may retain inputs or related logs under their own terms. Those periods require provider confirmation.

8.2 Derived voice models and voice identifiers

The derived voice model is stored by Cartesia while the voice feature remains active. SelfSpeak and Supabase retain the voice identifier and account association needed to use the clone. When deletion is requested, SelfSpeak attempts to delete the provider voice and applicable SelfSpeak records. Provider failures, logs, backups, or legal obligations may delay or limit complete removal.

8.3 Affirmation text and account information

Account information, saved affirmations, preferences, and related records are generally retained while your account is active. SelfSpeak attempts to remove eligible application database records when account deletion completes. Information may remain where required for security, dispute resolution, fraud prevention, legal compliance, or in provider backups for a limited period.

8.4 Generated audio and caches

Generated audio may remain in server memory caches, device files, application caches, playback caches, or operating-system storage until replaced, evicted, cleared, or removed. Cache cleanup is not the same as deletion of the raw recording or the derived voice model.

SelfSpeak may retain limited records of voice consent, deletion attempts, security events, errors, and service requests to demonstrate authorization, prevent abuse, resolve disputes, and maintain the Service. These records should be minimized and retained only as long as reasonably necessary for those purposes or as required by law.

8.6 Marketing and suppression records

If you withdraw marketing consent, SelfSpeak requests removal from the applicable MailerLite marketing group or list. MailerLite may retain an unsubscribe or suppression record so the address is not added again without permission, as well as limited compliance, delivery, or backup records.

8.7 Billing and subscription records

Apple, RevenueCat, and SelfSpeak may retain transaction, receipt, entitlement, tax, accounting, fraud-prevention, and customer-support records after your SelfSpeak account is deleted. These records are separate from your raw voice recording, voice clone, affirmation text, and ordinary profile content.

Deleting a SelfSpeak account does not cancel a subscription purchased through Apple. You must manage or cancel an Apple subscription through your Apple Account subscription settings. Apple determines when cancellation takes effect and how long Apple transaction records are retained.

8.8 Backups and provider-controlled retention

Supabase, Cartesia, RevenueCat, MailerLite, Apple, the OpenAI-compatible processor, and infrastructure providers may maintain backups, security logs, disaster-recovery copies, suppression records, or legally required records. SelfSpeak may request deletion where supported, but does not directly control these providers’ systems or guarantee immediate deletion from every backup. Data may remain inaccessible in backups until the provider’s normal deletion or overwrite cycle completes.

9. Account Deletion

You can request account deletion from SelfSpeak’s in-app Settings.

When the account-deletion process completes successfully, SelfSpeak attempts to:

  • Authenticate the request.
  • Identify voice clones associated with the account.
  • Request deletion of applicable Cartesia voice clones.
  • Remove the account from the optional MailerLite marketing contact system.
  • Delete eligible affirmation and profile records from Supabase.
  • Delete the SelfSpeak authentication account.
  • Sign the device out.
  • Cancel scheduled affirmation notifications.
  • Clear application-local storage on a best-effort basis.

Deletion involves several systems and may not occur as one instantaneous transaction. A network outage, provider error, inconsistent record, legal obligation, or service interruption may cause one or more steps to fail or require another attempt. If deletion does not complete, the application may report that the account remains available so you can retry or contact info@selfspeak.com.

Account deletion:

  • Does not automatically cancel an Apple subscription.
  • Does not require Apple, RevenueCat, or other providers to erase records they must retain for billing, tax, fraud prevention, security, or legal compliance.
  • May not immediately remove inaccessible backup copies or provider logs.
  • May not remove affirmation text already displayed in delivered device notifications.
  • May not remove all operating-system, device-backup, or media-cache copies.

10. Voice Deletion

You may request deletion or replacement of a voice clone through available SelfSpeak controls or by deleting your account.

A voice-deletion request is intended to:

  • Submit a deletion request for the derived voice model stored by Cartesia.
  • Remove or update the active SelfSpeak voice association.

Voice deletion is distinct from account deletion. It does not necessarily delete:

  • Your SelfSpeak account.
  • Saved affirmation text.
  • Apple or RevenueCat billing records.
  • MailerLite marketing status.
  • Consent, security, error, or deletion-attempt records that SelfSpeak reasonably retains.
  • Generated audio already held in device, playback, server, operating-system, provider, or backup caches.
  • Provider logs or backups that are subject to a provider’s retention practices.

If a provider deletion fails, the voice model or identifier may remain until the request is retried or reconciled. Contact info@selfspeak.com if the application reports a deletion problem or you need confirmation.

11. Marketing Choices

Marketing enrollment is optional. You may use SelfSpeak and maintain a paid subscription without joining the Inner Circle or another marketing list.

You can unsubscribe using the link in a marketing email or contact info@selfspeak.com. Withdrawing marketing consent does not cancel your subscription or delete your account. An unsubscribe or suppression record may remain to ensure your choice is honored.

12. Permissions and Device Controls

SelfSpeak may request:

  • Microphone permission when you choose to record a voice sample.
  • Notification permission when you enable reminders.

You can change permissions in your device settings. Disabling permission may prevent the associated feature from working but does not automatically delete information already processed.

You can manage Apple subscriptions through your Apple Account settings. You can also uninstall SelfSpeak or clear application data using available device controls. Uninstalling the application does not automatically delete your SelfSpeak account, voice clone, or subscription.

13. Security

SelfSpeak uses administrative, technical, and organizational safeguards intended to protect information. These may include authenticated access, access controls, encrypted network transport, secure device storage for session information, provider security controls, and monitoring for abuse or errors.

No system is completely secure. SelfSpeak cannot guarantee that information will never be lost, accessed without authorization, or affected by a provider or network incident.

14. Your Privacy Rights

Depending on where you live, you may have rights to:

  • Ask what personal information SelfSpeak processes about you.
  • Request access to or correction of eligible information.
  • Request deletion of eligible information.
  • Withdraw consent where processing depends on consent.
  • Opt out of marketing email.
  • Request a portable copy of eligible information.
  • Object to or restrict certain processing.
  • Appeal a denied privacy request or contact an applicable privacy regulator.

These rights may be limited by identity-verification requirements, applicable law, technical feasibility, security needs, and records SelfSpeak or its providers must retain.

To submit a privacy request, email info@selfspeak.com. We may ask you to verify your identity and account before acting on the request.

15. United States State Privacy Disclosures

Residents of certain U.S. states may have additional rights under applicable state privacy law. SelfSpeak will not discriminate against you for exercising an applicable privacy right.

Based on the audited production implementation, SelfSpeak does not sell personal information and does not share personal information for cross-context behavioral advertising. SelfSpeak does disclose information to service providers that process it for the operational purposes described in this Policy.

16. International Processing

SelfSpeak LLC is based in the United States. SelfSpeak and its providers may process information in the United States and other countries where they operate. Privacy laws in those locations may differ from the laws where you live. Where required, SelfSpeak will use appropriate safeguards for international transfers.

17. Changes to this Policy

We may update this Policy when the Service, providers, legal requirements, or data practices change. We will post the revised Policy with a new effective date. Where required, we will provide additional notice or obtain renewed consent before materially different processing begins.

18. Contact Us

For privacy questions, deletion issues, or rights requests, contact:

SelfSpeak LLC Dallas, Texas, United States info@selfspeak.com