// last updated July 27, 2026

Privacy Policy

Version 1.0. Effective July 27, 2026. Available in the United States to commercial customers only.


Speechify, Inc. (“Speechify,” “Vidify,” “we,” “us,” or “our”) provides Vidify, an AI service that generates advertising creative for software products. This Privacy Policy explains how we handle personal information in connection with the Vidify website, platform, CLI, and related services (the “Service”).

Controller vs. processor.Vidify is a business tool. For personal information about our Customers and their authorized users — account, billing, usage, and website data — we act as a controller. When our Customers direct Vidify at Sources that contain other individuals’ personal information so that we can generate their ads, we act as a processor on the Customer’s behalf, and our processing is governed by our Data Processing Agreement (“DPA”). If you are an individual whose personal information appears in a Customer’s Source, please contact that Customer (the controller); we will support them in responding.

1. Personal Information We Collect

Information you provide:

  • Account and contact data— name, business email, company, role, and login credentials.
  • Billing data— billing contact and transaction records. Card data is collected and stored by our payment processor (Stripe), not by us.
  • Communications— messages you send us and support requests.

Inputs and Sources you submit or connect:

  • Sources you direct Vidify to ingest (your product website, YouTube channel, blog, uploaded media, brand assets). These may contain personal information of third parties (for example, individuals shown or named in public media). We process this material to provide the Service to the Customer; see the controller/processor note above.
  • Prompts, directions, and Verdicts (keep/kill/revise signals and other feedback).

Voice and audio.Sources and Inputs you submit or direct us to may contain audio of real people speaking — for example, an existing advertisement, a product demo, or video from a channel you point us at. We process that audio to provide the Service, including to transcribe it and analyze its content. In some editing modes, we modify the video and retain the original audio track from your source media, so an Output may contain a real person’s recorded voice.

We never perform speaker identification. We do not create voiceprints or other voice templates. We do not use voice to recognize or verify anyone’s identity. Any voice we synthesize is text-to-speech or AI-generated.

Information collected automatically:

  • Usage and telemetry datafrom the website and the Vidify CLI — commands issued, batches generated, feature usage, timestamps, and error/diagnostic logs.
  • Product analytics. We use PostHog for product analytics and feature flags, subject to consent. We do not send your name or email address to PostHog: analytics events are keyed to opaque identifiers only. IP addresses are anonymized, automatic event capture is off, and analytics events exclude prompts, transcripts, customer copy, and media URLs. Session replay, where used, is masked and retained for 30 days. We honor the Global Privacy Control signal and do not start optional analytics for a browser sending GPC.
  • Error monitoring. We use Sentry for credential-redacted application-error reporting. It receives opaque account and user identifiers, code locations, device or runtime details, and timing information, error messages, and stack traces. Request bodies, headers, cookies, query strings, AI inputs and outputs, and session replay are stripped.
  • Device and log data— IP address, browser/OS, device identifiers, and similar technical data.
  • Cookies and similar technologies on the website, as described in our Cookie Notice.

Information from third parties:

  • Google Sign-In. If you sign in with Google, we receive your email address, Google account ID, and profile name. We use this information to create and authenticate your account. Our use of information received from Google APIs adheres to the Google API Services User Data Policy.

2. How We Use Personal Information

  • Provide the Service— resolve your brand, ingest Sources, generate and deliver Outputs, and operate the swipe/verdict loop.
  • Personalize your ad stream— use your Verdicts and history to tailor and improve the Outputs generated for you.
  • Improve the Service— using de-identified and/or aggregated data. See Section 3 (AI Training).
  • Security and integrity— authenticate access, protect keys, detect abuse and fraud, and maintain the Service.
  • Billing and administration— process payments, manage accounts, and provide support.
  • Communications— send service, security, and (where permitted) marketing messages. You may opt out of marketing.
  • Legal and compliance— comply with law, enforce our terms, and establish or defend legal claims.

3. AI Training

We use your Inputs, Outputs, and Verdicts to operate and personalize the Service for you.

Our own models. We do not use Customer-identifiable Inputs or Outputs to train our own general-purpose or shared AI models; we may use de-identified and/or aggregated data to develop and improve our models and the Service.

Third-party AI providers.To generate Outputs, we send Inputs — including prompts and the media you submit or direct us to — to the third-party AI and media-generation providers listed in § 4. These providers operate under commitments not to use submitted data to train their models, except where our subprocessor register records a provider’s position as still under confirmation. Where a provider does retain training rights, we cannot limit that use on your behalf. We publish each provider’s position at vidifyads.com/subprocessors.

4. How We Share Personal Information

Subprocessors and service providers. We use the providers below under contracts limiting their use of the data. A current list is maintained at vidifyads.com/subprocessors.

  • Infrastructure and operations:Railway (hosting, databases, workers), Cloudflare (R2 object storage for media and backups, signed links), Clerk (authentication/identity), Stripe (payments — stores card data), Resend (transactional email), Sentry (credential-redacted error monitoring; performance tracing currently off), Modal (agent sandboxes).
  • Analytics: PostHog (see § 1).
  • AI, media generation, and research: OpenAI (including all media transcription), Google/Gemini (including image and video generation), fal.ai (image, video, and audio generation and editing, avatars, and lip-sync, including generation fal.ai routes to underlying model operators), and Speechify TTS, which receive prompts, brand/product material, and/or media (often via short-lived signed links) needed to perform the requested operation.
  • Public-source research and browsing: Apify (crawls public websites and public social/ad-library material, including the Meta Ad Library).

Downstream model providers and country-of-concern routing. Some providers route requests to underlying model operators that are their own subprocessors: fal.ai routes certain generation and editing models to operators associated with China, including Kling/Kuaishou, ByteDance, and Alibaba. When you select one of these models, we send only the prompt and the specific media asset needed for that generation. We do not send account identifiers, user names or emails, billing data, telemetry, or your sourced brand report to these providers.

  • Affiliates— Speechify and its corporate affiliates.
  • At your direction— third parties you connect or instruct us to share with.
  • Legal and protection— where required by law or to protect rights, safety, and the integrity of the Service.
  • Business transfers— in connection with a merger, acquisition, financing, or sale of assets.

We do not sell personal information or share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.

5. Data Location and Country-of-Concern Routing

We are based in the United States and process personal information in the U.S. and, where a subprocessor operates elsewhere, as identified in our subprocessor register. At initial (US-only) launch we do not offer the Service to individuals in the EU, UK, or Switzerland; the EU/UK cross-border transfer framework (Data Privacy Framework, Standard Contractual Clauses, transfer impact assessments) is deferred and will be added before any international launch.

Certain optional model routes reach China-associated operators. We limit what is sent to those routes as described in § 4.

6. Retention

We retain personal information for as long as needed to provide the Service and for legitimate business and legal purposes, then delete, de-identify, or isolate it. Personal information processed on a Customer’s behalf is retained and deleted per the Data Processing Terms and the Customer’s instructions.

  • Account and identity data— duration of the account, plus 24 months.
  • Records of agreement acceptance (which version accepted, and when) 5 years after the account closes.
  • Billing and transaction records 7 years from the transaction.
  • Inputs, Sources, and generated Outputs— duration of the account, plus 90 days.
  • Encrypted database backups 35 days, on a rolling cycle. Information deleted from live systems is purged from backups within this window.
  • Error-monitoring data (Sentry) 30 days.
  • Product-analytics events (PostHog)— retained on the vendor’s fixed schedule; keyed to opaque identifiers, with no name or email.
  • Session replay (PostHog) 30 days.
  • Media and payloads held by AI providers 30 days (OpenAI abuse monitoring); 30 days payload / 7 days media (fal.ai).

We may retain information for longer where we are subject to a specific legal preservation obligation, and only for as long as that obligation lasts. We do not retain information indefinitely against the possibility that it may one day be useful.

7. Your Rights and Choices

Depending on your US state of residence, you may have rights to access, correct, delete, and obtain a copy of your personal information, and to opt out of sale/sharing and certain profiling. California residents have rights under the CCPA/CPRA (which also covers business-contact information); residents of other states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, and Texas) have analogous rights. To exercise rights, contact [email protected]. If your personal information appears in a Customer’s Source, direct your request to that Customer as controller; we will assist them.

  • Marketing opt-out— via the unsubscribe link or by contacting us.
  • Cookies — manage via the Cookie Notice and your browser.
  • Global Privacy Control (GPC)— We honor the GPC signal. If your browser or extension sends a GPC signal, we treat it as a valid opt-out request and do not start optional analytics or similar non-essential processing for that browser. Browser-level “Do Not Track” signals are not standardized and are not separately honored.

8. Security

We use technical, organizational, and administrative safeguards designed to protect personal information, including access controls and key management. Because you install and run the Vidify CLI on systems you control, you are responsible for the security of those systems and your keys. No system is perfectly secure.

9. Children

The Service is for business use and is not directed to, or intended for use by, individuals under 18. We do not knowingly collect personal information from children.

10. Notice to European and UK Users

The Service is offered in the United States only and is not directed to individuals in the European Economic Area, the United Kingdom, or Switzerland.

11. Changes to This Policy

We may update this Policy and will revise the “Last Updated” date; for material changes we will provide additional notice as required.

12. Contact Us

Speechify, Inc. · 382 NE 191st St PMB 69469 · Miami, FL 33179-3899. Privacy contact: [email protected].