Pynokio Privacy & Data Protection
Version 2026-09-22 · effective 22 September 2026 · updated 5 October 2026 (named storage and speech-processing providers, section 3)1. Controller and contact
The controller is <imię i nazwisko albo firma>, <adres>. Privacy contact: [email protected]. DPO/privacy officer contact, where appointed: [email protected].
2. Data, purposes and legal bases
- Account and authentication: name, email, password hash, sessions, security IP and user-agent data - contract performance and legitimate interest in securing the service.
- Prompts, uploads and generated media: information supplied to perform requested generations - contract performance. Do not upload third-party personal data without a lawful basis.
- Voice samples and clones: audio, transcript, declared rights basis and versioned consent evidence - performance of the requested service, consent where relied upon, and legitimate interests/legal claims. Voice can reveal sensitive information. Voice is biometric special-category data when technically processed for unique identification.
- Billing and ledger: package, amount, currency, transaction references and invoices - contract and legal accounting/tax obligations. Pynokio does not need to store full card numbers.
- Support and abuse prevention: correspondence, audit events and limited network data - legitimate interests in support, fraud prevention and legal claims.
- Free-credit abuse prevention (multiple accounts): free credits are intended for one account per person. To detect additional accounts, Pynokio uses a device identifier stored in a first-party cookie (
pyn_did), local storage and IndexedDB, technical characteristics of the browser and device (for example screen, graphics card, installed fonts, time zone and how the browser renders a test image and sound), and the IP address and its network. These values are stored only as keyed one-way hashes, never in readable form, and are not used for advertising or tracking across other websites. If an account is linked to an earlier account, it remains fully usable, but its free credits can be used only after purchasing a plan or credit pack. Legal basis: legitimate interest in preventing abuse of free credits and fraud (Art. 6(1)(f) GDPR). If you believe an account was linked by mistake (for example two people sharing one computer), contact us and we will review it. - Optional analytics/marketing: only after a valid choice where consent is required. See the Cookie Notice.
3. Recipients and international transfers
Data may be disclosed only as necessary to hosting/storage, transactional email, payment, security/support and the AI provider selected for a generation. Current provider categories and transfer safeguards are described in the AI Transparency Notice. Where data leaves the EEA, the controller must use an adequacy decision, Standard Contractual Clauses and supplementary safeguards as applicable. Prompts and media are not used by Pynokio to train public foundation models unless a separate, optional opt-in is presented.
- File storage – Backblaze, Inc. (European Union): generated media, uploads, avatars and voice samples are stored in a private Backblaze B2 bucket in the EU Central region. Voice samples are additionally encrypted by Pynokio before upload. Files are never public; they are delivered only through Pynokio’s authorised download gateway.
- Speech processing – HyperAI (outside the European Union): text for speech synthesis and, for voice cloning, voice design, transcription and sample clean-up, the necessary audio samples and transcripts are processed by Pynokio’s own speech engine on a dedicated GPU server rented from HyperAI and located outside the European Union. This is a transfer outside the EEA, made with the safeguards described above. Data is sent over an encrypted connection and accepted only with Pynokio’s private key. The server keeps no copies of your files: each request is processed and the result is returned to Pynokio immediately, and temporary working files are deleted (see Retention).
4. Retention
- Active account data and private assets: until deletion by the user or account closure.
- Expired sessions and security rate-limit records: normally up to 90 days; shorter technical buckets expire automatically.
- Hashed device signals used for free-credit abuse prevention: up to 24 months after their last use, also after account deletion, so that deleting and re-creating an account does not grant free credits again.
- Voice samples: until the clone is deleted or consent is withdrawn; minimal consent evidence may be retained for legal claims.
- Speech-processing server (outside the EU): no stored copies. Temporary working files are deleted after each request (leftovers of an interrupted request within 1 hour); a short voice clip derived from a sample for cross-language cloning is kept in temporary storage for at most 24 hours and removed when the server restarts.
- Support correspondence: up to 24 months after closure unless a dispute requires longer retention.
- Orders, invoices and accounting ledger: for the period required by tax/accounting law, normally up to 5-6 years depending on jurisdiction.
- Encrypted backups: rolling retention defined by the operator, normally 14-30 days; deleted data disappears when backups rotate and is not restored except for disaster recovery.
5. Your rights
Subject to legal conditions, you may request access, rectification, erasure, restriction, portability and objection, and withdraw consent without affecting earlier processing. A machine-readable account export and account deletion are available in account settings/API. You may complain to Prezes Urzedu Ochrony Danych Osobowych (UODO) or your local supervisory authority.
6. Automated decisions and children
Pynokio does not use account data for decisions producing legal or similarly significant effects solely by automated means. Model outputs are probabilistic and require human review. The self-service service is intended for adults. Voice cloning involving a minor requires verifiable guardian authority and enhanced review; the standard workflow must not be used to evade that requirement.
7. Security and incidents
Controls include TLS, hashed passwords and tokens, least-privilege access, private object access, short-lived signed links, audit logs, upload validation, rate limits, encrypted backups and provider allowlists. No system is risk-free. Suspected incidents should be reported immediately to [email protected]. The controller assesses notification duties under GDPR Articles 33-34.