← Back

Biometric & Likeness Data Policy

Last updated: 2026-05-13

1. Scope

This policy explains how Leivar handles biometric and likeness data in two features: voice cloning (a voice fingerprint derived from a recording of your voice) and AI characters (images/video generated from a reference face or likeness). It supplements the Privacy Policy and the Acceptable Use Policy. Where it conflicts with the Privacy Policy on biometric specifics, this policy controls.

2. What we collect and why

  • Voice: an audio recording of you reading a fixed consent phrase, and the resulting voice fingerprint. Purpose: to enforce the voice-cloning consent gate and to produce voice output you request. We label synthetic audio with content credentials (C2PA) where technically supported.
  • Face / likeness: the reference image you supply for an AI character, and your recorded attestation that you are the person shown or hold the rights/consent to use that likeness. Purpose: to generate and animate the character you request and to maintain a record of the consent attestation.

We do not use biometric or likeness data for identification, surveillance, profiling, or to train AI models.

3. Consent and your representations

Voice cloning requires the in-product audio-consent process. Face/likeness generation requires you to affirmatively attest, in the product, that the depicted person is you or that you hold that person's documented rights/consent, and that you will not use the output to impersonate, defraud, defame, or harass. Cloning a third party's voice or using a third party's likeness without their documented consent is prohibited by the AUP and may violate biometric-privacy and right-of-publicity laws (e.g. Illinois BIPA, Texas CUBI, Washington biometric law, California Civil Code §§ 3344/3344.1, the Tennessee ELVIS Act, and the EU AI Act transparency obligations).

4. No sale, no profit from identifiers

We do not sell, lease, trade, or otherwise profit from your biometric identifiers or biometric information, and we do not disclose them except to the sub-processors strictly necessary to provide the feature you requested (see the Sub-processor list), or as required by law.

5. Retention and destruction schedule

We retain biometric/likeness data only as long as needed for the purpose it was collected, and then destroy it on the schedule below (subject to counsel review before launch):

  • Voice consent recording & fingerprint: for the life of the cloned voice plus 24 months after you revoke or delete it (defence + synthetic-media traceability), then permanent destruction.
  • Face reference image: retained with the character asset while the character exists; deleted when you delete the character or your account (storage-prefix wipe).
  • Consent attestation records: retained for the life of the derived asset plus 24 months, as the compliance record of the consent given, then destroyed.

Account deletion (Profile → Delete Account) cascades the underlying assets and storage; compliance consent records are retained for the limited window above and then destroyed.

6. Your rights

You may request deletion of your voice fingerprint/recording or a character's likeness data, withdraw consent, or ask what biometric data we hold, by writing to kamugishaibrah@gmail.com or using the data-subject controls described in the Privacy Policy. Withdrawing consent stops future processing; it does not affect processing already performed lawfully.

See also: Privacy · AUP · Terms · Sub-processors