Legal

Security and data handling

How access to recordings, consent records and the lab is controlled, and how to tell us if something is wrong.

Section 01

Access to the registry

Registry screens, exports and the support inbox sit behind the site's access controls, and administrator actions behind a separate admin key. Speaker onboarding runs on single use invitation links, so a speaker never sees the roster or anyone else's record.

Section 02

Access to the lab

Ohùn Lab requires a plan or a 24 hour access pass. A pass binds to the device that first redeems it and expires 24 hours later. Credit use is metered per generation against the pass or plan that authorised it.

Section 03

Consent enforcement

Consent is checked server side on every generation, not in the interface alone. Corpus consent plus a signed and unexpired media and film use consent are both required before a voice can be cloned or spoken. A withdrawn or expired consent stops generation and removes the speaker's clips from exports.

Section 04

Provenance and audit trail

Verification records the named verifier and the time. Consent signatures record the time and date on the document itself. Every generation writes a provenance record, and every export writes a log row naming the clips included, the filter criteria and the timestamp. Deletion is the only irreversible action and asks for explicit confirmation.

Section 05

Payments

Card details are entered with our payment processor and never reach our database. We store the subscription state and the plan the account is on.

Section 06

Reporting a problem

If you find a way to reach data you should not reach, tell us through the contact page with enough detail to reproduce it, and give us time to fix it before publishing. Please do not test against real speaker records.

This page describes controls that are in place today. It is not a certification, an audit result or a guarantee against every risk.