Trust and safety

AI Transparency Notice

What is generated, what leaves Pynokio, how content is marked and what human review is required.

Version 2026-09-26-v1 · effective 26 September 2026

Who operates the system

<imię i nazwisko albo firma>, <adres>. Contact: [email protected].

What the service does

Pynokio is a generative-media platform. Depending on the selected tool it can create or transform text, speech, music, sound effects, images, video, avatars and 3D assets. Results are probabilistic. They may contain errors, bias, invented details, visual/audio artefacts or material resembling third-party work.

Provider categories and data flow

Language and planning

Prompt and limited project context are sent only to the configured language provider needed for the request.

Media generation

Prompt, selected parameters and necessary reference assets are sent to the chosen image/video/audio/3D provider.

Voice services

Text and, for cloning, authorised audio samples/transcripts are sent to Pynokio’s own speech engine on a dedicated GPU server rented from HyperAI outside the European Union. The server returns the audio immediately and keeps no copies of user files.

Infrastructure

Hosting, private storage (Backblaze B2, EU region; files are delivered only through Pynokio’s authorised gateway), transactional email, payments and security vendors process only data necessary for their role.

The exact commercial provider enabled by the operator can change. The administrator must maintain a current internal subprocessor register, DPA and transfer mechanism before enabling a provider. The service does not silently fall back to a mock or different real provider in production.

How AI-generated content is marked

Pynokio marks generated content in machine-readable ways that do not change what you see or hear:

Audio watermark (in the sound itself)

Every generated speech file (text-to-speech, voice clone and voice design previews) carries an inaudible AudioSeal watermark (Meta, open source) with the 16-bit Pynokio identifier 0x5643. It stays in the audio when the file is renamed, re-saved or converted.

Platform provenance record

New assets receive a signed provenance JSON record. File downloads include the HTTP header X-Pynokio-Synthetic-Media: 1 and a Link to the record; API asset objects expose provenanceUrl. The record identifies Pynokio, modality, model/provider identifier, operation and generation time without publishing the user's prompt or identity.

Signed file metadata (C2PA)

Embedding a signed C2PA manifest in downloaded audio files is being introduced. Until it is available, files do not contain it.

How to check a file

Anyone can check an audio file free of charge with the Pynokio Audio Detector. It reports whether the Pynokio watermark and its identifier are present and shows how much of the identifier was read. Ordinary recordings without the watermark read random bits and show no match.

The detector accepts WAV, MP3, OGG, FLAC, M4A or WebM files up to 32 MB. A machine-readable description of our marking and detection is published at /.well-known/ai-content-provenance.json. Regulators, researchers, media and fact-checkers who need higher volumes can contact [email protected].

Limits: the watermark is read reliably after common edits (MP3 at 128 kb/s or more, trimming, background music, reverb, bass or loudness changes). Heavy processing - telephone-band filtering, loud added noise, noise reduction, or changes of speed or pitch - can make it unreadable. A missing watermark therefore does not prove that a file was not made with Pynokio. Export or transcoding by other software can also remove headers and metadata. Users must add a visible or audible disclosure whenever context or law requires it.

Deepfakes and disclosure

Content that realistically depicts or imitates a person, place, object or event in a way that could falsely appear authentic must be clearly disclosed as artificially generated or manipulated. Voice clones and realistic avatars require particular care. Disclosure must be prominent to the audience and not hidden only in terms or metadata.

Human oversight

AI Act contact and records

The operator maintains technical logs, model/provider configuration and provenance necessary to investigate incidents and demonstrate transparency. Questions or requests concerning synthetic content may be sent to [email protected].