A face is personal. Here is how we treat it.
Plain answers about likeness, consent, what visitors' microphones and cameras send, where your documents go, and what we keep. The legal versions are linked at the bottom.
Likeness and consent.
release
The person signs, not just the customer
An avatar of a real person is built only after that person signs a likeness and voice release: what it will be used for, for how long, how to revoke it, and a short spoken consent. Creation is blocked until it is signed.
disclosure
Always labelled as AI
A badge on every avatar (“AI avatar, not a real person”), an opening line, a truthful answer to “are you real?”, and an AI suffix on the name in Google Meet. Customers can remove our branding; they cannot remove the badge.
blocks
Refused at the door
Minors, deceased people, political candidates and officials, public figures without proof of rights, sexual content. Companion, romantic or therapy personas, hiring or interview use, child-directed deployments and outbound calling are prohibited by the acceptable use policy.
What a visitor's microphone and camera send.
audio
Microphone: speech, not recordings
Audio streams to the speech recogniser and is not kept as a recording by default. The transcript is kept for as long as the customer sets (default 30 days), then deleted.
vision
Camera: a still, only when asked
Off by default. Nothing is sent on a timer. When the visitor asks the agent to look, one still goes to the model for that answer and is discarded after the call, with no retention at the provider. The agent keeps a one-line text note of what it saw. It never reads people: no emotions, no faces, no identities, no inferred traits.
redaction
Sensitive things in view
The agent never reads out, and never notes, card numbers, government ID numbers or passwords it can see; it asks the visitor to read out only what is needed.
Your documents and images.
documents
Knowledge files
Stored encrypted in Google Cloud in the US, indexed for your agents only, deleted when you delete them. Never used to train anything.
providers
Studio images
Sent to the image provider (Google or OpenAI) only for the operation you asked for, with zero data retention and no training requested. Both are listed as subprocessors. Unsaved Studio versions are deleted after 7 days.
C2PA
Provenance
Generated images carry a manifest saying they are AI-generated and what was done; generated video and audio are watermarked. We never strip the providers’ own marks.
The infrastructure.
cloud
Where it runs
Google Cloud, us-central1. GPU workers are reachable only from our session relay, never from the internet; they hold a session’s data in memory for the life of the session and nothing after.
widget
The embed
Your snippet carries a publishable id, never a secret. It works only on the domains you allow, is rate-limited per visitor, and can be revoked in one click. Secret API keys stay on your server.
records
Audit and takedown
Avatar creation and deletion, voice cloning, key creation, domain changes and consent records are logged. Anyone can report a likeness through the public form; verified reports are removed within 48 hours.
The legal versions: Terms, Privacy notice, Acceptable use. Enterprise customers get a DPA with the subprocessor list; ask here.
Questions a questionnaire does not cover?
Security questions are answered by an engineer, not a form. Enterprise customers can request our full security overview.