How we handle your data.
Every line here restates something already written into our Privacy Policy or Terms. Nothing on this page is aspirational.
Certifications
ISO/IEC 27001
In progressWe are working towards certification. We are not certified yet, and this page changes the day that does.
DPDP Act 2023 · GDPR
How we operateHow we operate: collect only what the service needs, use it for the purposes we have stated, and delete it on request.
Your data
Your output is yours
As between you and Kenpath Labs, you own the audio you generate from your own text and from reference audio you have consent to use.
Retention is bounded
Request logs and submitted audio are kept only as long as needed for the purposes in the Privacy Policy, then deleted or anonymised.
Zero data retention
Available on Enterprise, so requests and audio are not retained at all.
Deletion on request
Ask us to delete your data, or delete your account yourself from the console at any time.
Where it runs
Enterprise plans can pin processing to a single jurisdiction. If you need to know the default region for your account, or need processing confined to one country, ask before you build.
- European Union
- United States
- India
Security practices
Encryption in transit
All API and console traffic is served over TLS.
Scoped API keys
Keys are issued and managed per account, and scoped so a key is more than a shared password.
Access controls
Access to production data is limited to the people who need it to run the service.
Abuse prevention
We monitor for unauthorised voice cloning, fraud and Terms violations, and act on what we find.
No system is completely secure, and we do not pretend otherwise — section 8 of the Privacy Policy says the same thing in the same words.
What we will put in writing
The policies above are what applies to every account. A review often needs something firmer than a public page, and that is what an agreement is for.
How your content is used
Our Privacy Policy allows processing to monitor, debug and improve model and infrastructure quality. If your procurement needs a narrower commitment than that, say so and we will put the specific terms in the agreement rather than leaving you to infer them.
Retention, residency and deletion
Zero data retention and single-jurisdiction processing are Enterprise terms, and both go in the contract with the detail your team needs — including how long anything is held and how deletion is evidenced.
Report a vulnerability
Email us the details and how to reproduce it, and give us a reasonable chance to fix it before disclosing publicly. We do not run a paid bounty programme, and we will not pursue you for good-faith research.
[email protected]DPAs and questionnaires
For a data processing agreement, a security questionnaire, or anything this page does not answer — tell us what your review needs and we will tell you what we can and cannot sign.
Talk to sales