Privacy Policy — MirrorVox
Version: 1.0
Effective date: on publication of this version (this version has not been published yet)
Last updated: 19 August 2026
1. Who is responsible for your data
The controller of your personal data is:
- Francisco Serralvo
- Calle La Unión Mercantil 33, 29004 Málaga, Spain
- NIF: 53693189B
- Contact: hello@mirrorvox.app
We are not required to appoint a data protection officer: we are not a public authority, we do not carry out regular and systematic monitoring of people on a large scale, and we do not process special categories of data on a large scale (Article 37 GDPR). We are established in Spain, so a representative under Article 27 GDPR is not applicable either. For any privacy question, write to hello@mirrorvox.app.
2. What data we process
- Account and profile data: name, email address and avatar as provided by Google sign-in, plan and account status, account creation date.
- Authentication identifiers: your user identifier and the session tokens handled by our authentication provider.
- Videos and associated metadata: the video files you upload, plus name, size, duration, format and storage location.
- Conversion records: which video, which voice, status, result, duration, minutes used and timestamps.
- Voice samples: the audio you upload to create a custom voice.
- Custom voice metadata: name, status, provider identifier and dates.
- Consent records for voice cloning: time of consent, consent text and version, language, provider and related identifiers.
- Usage and minutes: entitlements, purchases and consumption entries in our usage ledger.
- Billing data: subscription and customer identifiers from our payment provider, plan and period information, and payment events. We do not receive or store full card numbers.
- Purchase consent evidence: for each purchase started at checkout we record your user identifier, the kind of purchase, the plan identifier or number of minutes concerned, the environment, the Stripe checkout session identifier, the version and acceptance time of the Terms, the version and acknowledgement time of the Privacy Policy, the version and time of your express request that the service begin immediately, the language of the interface and the creation time of the record. The evidential timestamps are generated server-side by our database, and the record cannot be modified or deleted by users from the application.
- Transactional email data: your email address, the purchase details shown in the confirmation (plan or number of minutes, amount, currency, date, applicable document versions), the content of the message we send you, and the delivery metadata and events generated by our email provider (for example sent, rejected, bounced, complaint, unsubscribe or suppression events).
- Support and contact data: the content of the emails you send to hello@mirrorvox.app.
- Technical data strictly needed to run the service: the request data our hosting and infrastructure providers process to deliver the site and to secure it.
We do not run web analytics, advertising pixels or tracking tools, and we do not build advertising profiles.
3. Why we process it
- To create and maintain your account and let you sign in.
- To provide the conversion service: store your video, process it, generate and deliver the result, and show your history.
- To create and manage custom voices at your request.
- To keep a record that consent for voice cloning was given.
- To measure minutes and enforce plan limits and free usage.
- To take payments, manage subscriptions and comply with accounting and tax obligations.
- To keep evidence of the pre-contractual information and consents collected at checkout.
- To answer your messages.
- To keep the service secure and to prevent fraud and abuse.
- To handle account deletion requests and run our data-lifecycle purge.
4. Legal bases
| Purpose | Legal basis |
| --- | --- |
| Account creation and sign-in | Performance of the contract (Art. 6(1)(b) GDPR) |
| Video conversion and delivery of results | Performance of the contract (Art. 6(1)(b)) |
| Custom voice creation from your samples | Performance of the contract (Art. 6(1)(b)); the separate consent statement you accept is an authorisation regarding the use of a voice, not the legal basis for the processing |
| Keeping voice-cloning consent records | Legitimate interest in being able to demonstrate that the declaration was made, and in defending against claims (Art. 6(1)(f)) |
| Keeping purchase consent evidence | Legal obligation arising from consumer-protection rules on distance contracts (Art. 6(1)(c), in relation to Articles 97 and 103 TRLGDCU) and our legitimate interest in being able to prove them (Art. 6(1)(f)) |
| Minutes, quotas and free-usage control | Performance of the contract (Art. 6(1)(b)) |
| Payments and subscriptions | Performance of the contract (Art. 6(1)(b)) |
| Invoicing, accounting and tax records | Legal obligation (Art. 6(1)(c)) |
| Support correspondence | Performance of the contract where it concerns your contract, or legitimate interest otherwise (Art. 6(1)(b) or (f)) |
| Security, fraud prevention and service integrity | Legitimate interest (Art. 6(1)(f)), and legal obligation as regards security of processing (Art. 32) |
| Account deletion and purge | Compliance with your rights (Art. 17) and performance of the contract |
5. Account and authentication
Accounts are created with Google sign-in. When you sign in, Google provides us with your identifier, email address, name and avatar. Sessions are managed by our authentication provider, Supabase. We do not receive your Google password.
6. Videos and conversion data
The videos you upload are stored in our file storage, processed by our processing worker and sent to the voice provider only to the extent needed to generate the result you requested. The visual content of the video is not altered.
Each stored video asset — both the original you uploaded and the generated result — carries a purge date set 30 days after creation. The purge process only acts on assets whose purge date has passed and that have not already been purged; it deletes the stored object first and only then marks the asset as purged, so a storage failure leaves the asset pending and the operation can be repeated safely.
Metadata and internal references are treated separately from the media files: conversion records (which conversion ran, its status, duration and minutes used) and internal identifiers remain in your history until you delete them or your account is deleted, and, where they support billing, for as long as section 11 indicates. We do not claim that every record related to a video disappears after 30 days.
7. Voice cloning and voice samples
If you create a custom voice, you upload audio samples. Before the cloning attempt can start, you must accept a consent statement in the interface; the attempt is technically blocked without a recorded consent. The samples are then processed to create a personalised voice through our voice provider, ElevenLabs, which is used for certain voice cloning operations and returns a provider identifier that we store against your account. Using that identifier we can request deletion of the cloned voice at the provider; if that request fails, the failure is kept as a recoverable state so it can be retried.
How we classify this data. Your voice, your samples and the audio extracted from your videos are personal data. We do not use them to identify or verify the identity of any person by biometric means: they are used only to produce the voice conversion you request. For that reason we do not treat them as a special category of data under Article 9 GDPR. If we ever introduced a feature that identified people by voice, we would inform you beforehand and collect explicit consent. In the meantime we treat these samples as particularly sensitive material and restrict access to them.
If the samples are of another person's voice, you are responsible for having their authorisation; we do not verify it.
Retention policy for samples. Our policy is to keep voice samples for no longer than 30 days after the last activity of the voice they belong to, unless you delete them earlier. Today this limit is enforced when you delete a voice or your account; the automatic enforcement of the 30-day limit is a change we still have to implement, and we do not present it as already operating.
8. Consent records for voice cloning
Consent to voice cloning is stored as an append-only record that cannot be edited or deleted by users. It contains the time of consent, the consent text and version, the language, the provider and related identifiers, and it is linked to your account and to the voice concerned. We keep these records so that we can demonstrate that the declaration was made.
8 bis. Purchase consent evidence
When you start a purchase, MirrorVox records the evidence described in section 2 so that it can show which documents were shown to you, in which version and language, and when you accepted them and expressly requested immediate performance. The timestamps used as evidence are generated server-side by our database, and the record cannot be edited or removed by users through the application.
9. Billing and payments
Payments and subscriptions are processed by Stripe through its Embedded Checkout. Prices are resolved on our server, and Stripe collects the billing address and applies automatic tax calculation. Stripe receives the billing data needed for the transaction, our internal purchase identifiers and related technical metadata. We do not send videos, audio, voice samples or any other media content to Stripe. We store the identifiers and event data needed to know which plan you are on, what you purchased and whether payments succeeded. We do not receive your full card details.
Because our Stripe account is European, our contracting entity is Stripe Payments Europe, Ltd. Under Stripe's Data Processing Agreement, Stripe acts as our processor for part of the processing and as an independent controller for other purposes, such as its own fraud prevention and regulatory compliance. Stripe's own privacy documentation describes that processing.
9 bis. Purchase confirmation emails
After your payment provider confirms a purchase, we send you a confirmation email to the address associated with your billing customer record. The email is sent through Lovable Cloud Emails, the email service of the Lovable platform (Lovable Labs), which relies on Mailgun and Amazon SES as sub-processors according to its published documentation. Sending is performed in the United States; that transfer is covered by the Standard Contractual Clauses included in the corresponding data processing agreement.
The email provider only receives what is needed to deliver the confirmation: your email address, the message content, and the purchase details it contains (plan or number of minutes, amount, currency, date and document versions). We never send videos, audio, voice samples, previews, storage paths, your user identifier, tokens, credentials, worker metadata or your conversion history to the email provider. We do not use open or click tracking. Our provider records delivery events for operation and diagnosis, and maintains a suppression list for addresses that bounce, report spam or unsubscribe. We do not have confirmed information on the exact retention period applied by the provider to message content and to those event and suppression records, so we do not state one here; you can ask us at hello@mirrorvox.app.
The legal basis is the performance of the contract you have entered into (Article 6(1)(b) GDPR): these are transactional messages, not marketing. We do not send commercial newsletters from this service.
10. Usage and minutes
We record entitlements, purchases and each consumption entry so that we can calculate your balance, apply plan limits and the one free conversion, and resolve billing questions.
11. Storage and retention
- Videos and results: deleted by the purge process once their 30-day purge date has passed, or earlier if you delete them.
- Conversion records and internal references: kept in your history until deleted or until account deletion, subject to any billing-related retention.
- Voice samples: policy of a maximum of 30 days after the last activity of the voice, as described in section 7, and deleted when you delete the voice or your account.
- Custom voice metadata: kept while the voice exists in your account; deleted or anonymised on account deletion. Deletion of the model held at the provider is requested as described in section 7.
- Voice consent records: kept as append-only evidence for as long as claims relating to the use of the voice may be brought (as a general rule, five years for personal actions under Article 1964 of the Spanish Civil Code).
- Purchase consent evidence: kept together with the corresponding billing records, so that pre-contractual compliance can be demonstrated for as long as the contract can give rise to claims.
- Invoicing, accounting and usage-ledger records: kept for six years from the last accounting entry, as required by Article 30 of the Spanish Commercial Code, and for longer where tax rules require it (the tax administration's four-year limitation period may be extended, and up to ten years apply to the verification of offset tax credits under Article 66 bis of the General Tax Act).
- Support emails: kept for three years from the last interaction, unless a legal obligation, a claim or the defence of rights justifies a different period. This is a retention policy applied by us; we do not claim that these emails are erased automatically by software.
- Account deletion records: kept as an audit trail of the deletion itself.
12. Account deletion
When you delete your account:
- your sessions are terminated and your access is revoked;
- your profile data is anonymised;
- the storage objects held for your account are deleted;
- your conversions and assets are processed through the deletion flow;
- your custom voices and samples are deleted, and voices held at the external provider are requested to be deleted where we hold a provider identifier for them;
- where the provider returns an error, the failure is kept as a recoverable state so the deletion can be retried;
- an internal deletion record is created;
- billing and usage-ledger entries, and certain operational records, are kept where there is an accounting or technical need;
- voice consent records are kept as append-only evidence;
- the underlying authentication record is retained for referential integrity, with access permanently blocked.
Because of the retention rules in section 11, we do not describe deletion as the immediate and total erasure of every record.
13. Service providers
We use the following processors and providers:
- Supabase — database, authentication and file storage. Our project runs in the European Union (AWS, Stockholm region, eu-north-1). Supabase publishes a Data Processing Addendum and a list of subprocessors.
- Stripe (Stripe Payments Europe, Ltd.) — payments, checkout and subscription management, under Stripe's published Data Processing Agreement.
- ElevenLabs — certain voice cloning and voice generation operations, under its published Data Processing Addendum.
- Fly.io — infrastructure that runs our media processing worker; the worker's primary region is Amsterdam, in the European Union.
- Lovable — the platform that hosts the web application and its server-side functions.
- Lovable Cloud Emails (Lovable Labs) — sending of transactional emails such as purchase confirmations, with Mailgun and Amazon SES as sub-processors. This processing takes place in the United States under the Standard Contractual Clauses.
Each provider only receives the data needed for its function.
14. International transfers
Our database, authentication, storage and media processing run in the European Union, in the regions stated in section 13. ElevenLabs processes data mainly in the United States; that transfer is covered by the Standard Contractual Clauses included in its Data Processing Addendum. Transactional emails are sent through Lovable Cloud Emails and its sub-processors Mailgun and Amazon SES, which process the data described in section 9 bis in the United States under the Standard Contractual Clauses. Where any other provider processes data outside the European Economic Area, it does so under the transfer mechanisms set out in its own data processing agreement. You can ask us for information about these safeguards at hello@mirrorvox.app.
15. Security
Access to your data is restricted by authentication and by database row-level security rules, so that each account can only reach its own records. Privileged credentials are held server-side and are not exposed to the browser, and our processing worker does not hold database credentials. Consent records are append-only. No system can be guaranteed to be completely secure.
16. Cookies and local storage
MirrorVox does not use analytics, advertising or tracking technologies. The storage we use ourselves is technical storage strictly necessary to provide the service you request: the session storage used by our authentication provider to keep you signed in, your language preference, and short-lived browser storage that keeps the state of the conversion and checkout flow. Under Article 22.2 of Spanish Law 34/2002 and the Spanish Data Protection Agency's guidance on cookies (May 2024), storage of this kind is exempt from the consent requirement, so we do not display a cookie banner.
The payment step is rendered by Stripe Embedded Checkout, which may set its own storage or cookies for the operation and fraud prevention of the payment you have requested. Stripe's cookie policy describes its practices. We therefore do not state that no cookies at all are involved.
If we ever added analytics or advertising technologies, we would ask for your consent before using them.
17. Your rights
You have the right to request access to your personal data, its rectification, its erasure, restriction of processing, objection to processing based on legitimate interest, and data portability. Where processing is based on consent, you can withdraw that consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
Some requests may be limited by legal exceptions, for example where we must keep accounting records or need to retain evidence of a consent declaration.
18. How to exercise your rights
Write to hello@mirrorvox.app. We may need to verify that the request comes from the account holder. We answer within the periods set by the GDPR.
Many actions are also available directly in the product: you can delete conversions and files, delete custom voices, and delete your account.
19. Complaints to the supervisory authority
If you believe your data has been handled incorrectly, you can lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD — www.aepd.es), or with the supervisory authority of your country of residence.
20. Changes to this Privacy Policy
We may update this policy. The current version, with its version number and date, is always published here. The checkout records which version of this policy was shown to you for each purchase, so the applicable version can always be identified.
21. Contact
hello@mirrorvox.app
