Privacy policy
Last updated 14 September 2026. Applies to natiq.studio.
This policy describes what natiq.studio stores when you use natiq.studio, why it is stored, how long it is kept, and what you can ask us to do with it. It covers the website, the Studio and the REST API.
1. What we collect
Account data
- Your username and email address.
- A hash of your password. The password itself is never stored and cannot be recovered from the hash.
- Whether your address is confirmed, and when.
- Whether you opted in to product news.
What you submit and what we produce
- The text you send for synthesis.
- The audio generated from it, stored as a file so you can download it again from your history.
- Metadata about each job: the voice used, the duration, how long inference took, and whether it succeeded.
Billing data
- Your token balance and every movement in it, with a reason for each line.
- Payment records: amount in dinars, the pack bought, the payment method, the gateway reference and the status.
- We never see or store your card number. Card details are entered on the Chargily payment page and stay with Chargily.
Technical and anti-abuse data
The free token grant is worth money, so the service checks that one device does not collect it many times. To do that it stores:
- A device identifier, derived from browser characteristics such as user agent, platform, screen size and time zone. It is hashed with a secret pepper before storage, so the raw fingerprint is never written to the database.
- IP addresses seen at signup, at login, and on API calls.
- Security events such as failed logins, blocked signups and rate limit hits.
- API request logs: method, path, status code, duration and tokens spent.
Feedback
If you answer the survey or rate a clip, we store your answers, the rating, and how much of the clip you played. This is optional and you can skip it.
2. Why we hold it
- To run the service you asked for: synthesize audio, keep your history, and let you download it again. This is performance of our contract with you.
- To take payment and keep accounting records. This is a legal obligation and contract performance.
- To prevent fraud and abuse of the free token grant, and to keep the service available. This is our legitimate interest in running a service that is not drained by automated abuse.
- To send you product news, but only if you ticked the box. This is consent, and you can withdraw it at any time.
We do not sell personal data, we do not run advertising trackers, and we do not share your text or your audio with third parties for their own purposes.
3. Model training
Your text and your generated audio are not used to train or fine-tune speech models unless you give separate, explicit consent. Aggregate counters, such as how many clips were generated in a month, contain no personal data and are used to run the service.
4. Who else processes your data
- Chargily, the Algerian payment gateway, processes payments and receives the amount, a reference and your account identifier. Card details go to Chargily and its banking partners, not to us.
- Our hosting and email providers process data on our instructions to keep the site online and to deliver account emails.
Each of these acts on our instructions under a contract. We do not authorise them to use your data for anything else.
5. How long we keep it
- Account data: while the account is open, then deleted within 30 days of closure, except where accounting law requires us to keep a payment record longer.
- Generated audio and the text behind it: while the account is open. You can ask us to delete a single clip or your whole history by writing to support@natiq.studio.
- Payment records: for the retention period required by the accounting and tax rules of Algeria.
- Security events, signup attempts and API logs: 12 months, then deleted.
- Device records: 24 months from the last time the device was seen.
6. Your rights
You can ask us to give you a copy of your data, correct it, delete it, or stop a particular use of it. You can withdraw consent to product news at any time from your account page.
Write to support@natiq.studio from the address on the account. We answer within 30 days. If you believe we have handled your data badly, you may complain to the data protection authority in Algeria.
7. Security
Traffic is served over HTTPS. Passwords are hashed, API keys are stored hashed and shown once at creation, and device fingerprints are peppered before storage. Access to production data is limited to the people who operate the service. No system is perfect: if a breach affects you, we will tell you and the relevant authority without undue delay.
8. Children
The service is not aimed at children under 16. If you believe a child has created an account, write to support@natiq.studio and we will remove it.
9. Cookies
The cookies this site sets are listed in the cookie policy.
10. Changes
When this policy changes, the date at the top changes with it. If a change affects how we use data you have already given us, we will email you before it takes effect.