Privacy Policy
What information supports your account, payments, and voice generation—and your choices.
Updated 24 September 2026 · Version 2026-09-24-1
Effective date: September 23, 2026
01Who handles your information
Salaysay Studio is responsible for the personal information it processes to operate your account and provide its services. Our business information and privacy contact are available on Contact & Requests. This policy explains what information we use, why we use it, and how to exercise your privacy rights.
This notice covers the studio. Providers may also process information under their own terms and notices, including on the PayMongo checkout page.
02Information we process
Information depends on how you use the service.
- Account: name, email, authentication identifier, verification status, account role, and account timestamps. Firebase Authentication handles password-based sign-in.
- Payments: billing name, phone number, email, selected pass, checkout and payment references, amount, currency, payment status, and access dates. Payment details are sent to PayMongo; we do not ask for your bank or e-wallet password or OTP.
- Generation: the script, voice, and delivery instructions needed to synthesize audio. The usage ledger records a request fingerprint, voice, status, timing, and duration; it is not a saved script or MP3 library.
- Agreement records: the policy version, account identifier, and server-recorded time of acceptance. We do not treat terms acceptance as permission for marketing.
- Service operation and support: request/error information, technical connection data handled by our hosting providers, and information you choose to provide when requesting help.
03Why we process it
We use account, script, and billing information to provide the service you request and perform our agreement with you. We use transaction records to meet applicable accounting and legal obligations. Necessary security, fraud prevention, and troubleshooting may rely on legitimate interests, subject to your rights and an appropriate assessment.
Where processing requires consent, it must be specific and separate from unrelated purposes. The current application does not include a marketing mailing-list signup. Do not include sensitive personal information, private credentials, or other people’s confidential information in your scripts.
Quota and payment checks automatically determine whether a generation or purchase can proceed. If you believe a result is incorrect, request a human review using Contact & Requests.
04Providers and international processing
Google Firebase supports account sign-in and database records. Google Cloud Text-to-Speech receives your script, voice choice, and delivery instructions to generate audio. PayMongo handles checkout and payment processing. Website hosting and delivery are provided through OpenAI Sites and Cloudflare or Firebase App Hosting and Google Cloud, depending on the website address you use.
Our providers may process information outside the Philippines. Firebase Authentication operates in United States data centers. Processing locations for other services depend on the provider and service configuration. See the provider notices on Contact & Requests for more information.
Information may also be disclosed when required by law or reasonably necessary to investigate fraud, protect rights, or resolve a dispute. Salaysay Studio does not sell customer information or advertising profiles.
05Storage and retention
Scripts and generated audio are processed to fulfill your request and are not saved as an account content library. Download audio you want to keep before leaving the studio. Downloaded files remain under your control.
Account, usage, agreement, and payment records remain in our database until removed through a deletion process. These records do not automatically expire when your paid pass ends. Signing out or clearing browser data does not delete them. You may request account or data deletion through our privacy contact. Requests are reviewed individually, with retention decisions based on the information needed to maintain your account, meet applicable recordkeeping obligations, and resolve payment or legal disputes. Support correspondence is held in our support and privacy mailboxes. Provider logs and backups follow the relevant provider’s retention practices.
Firebase keeps authentication-related IP logs for a few weeks and other authentication information until user deletion is initiated. Removal from its live and backup systems can then take up to 180 days. This provider timeframe applies to Firebase Authentication, rather than all Salaysay records. Google Cloud Text-to-Speech states that it does not log customer text or audio data. Hosting, payment, and account metadata are handled separately.
06Security and your rights
The service uses authenticated server requests, restricted database access, and payment verification. No online system can guarantee absolute security. We will address reportable incidents in accordance with applicable legal obligations.
Subject to applicable law, you may request information about processing, access, correction, portability, objection, restriction or blocking, and deletion of your personal information. Where consent is the basis, you may withdraw it without affecting earlier lawful processing. Some records may need to be retained to comply with law or resolve a dispute.
Use the Privacy or account deletion request on Contact & Requests. We may ask for proportionate identity verification before releasing or changing account data. Do not send your password, OTP, or a full identity document in an initial request. You may also raise a privacy complaint with the National Privacy Commission.
07Children and updates
The service is intended for adults aged 18 or older. If you believe a child has provided account information, notify the privacy contact so the matter can be reviewed.
This notice will be updated as practices change. Material changes will be communicated where required. Browser storage is explained separately in Cookies & Storage.
Need help with this policy?
Contact & Requests explains how to raise a billing, privacy, or content concern.