Privacy Policy
Octana turns a description into a finished video: a script, a voiceover, visuals, and — if you ask it to — an upload to your own YouTube channel. To do that it holds your account details, whatever you type or upload, and the files it makes. If you clone a voice or train a presenter avatar, it also holds biometric data, which is the part of this document worth reading twice.
Effective 2026-09-03 · Nidrosoft
Pending legal review — not yet in force
This document is an accurate description of what the software does, written by the engineers who built it. It has not been reviewed by a lawyer and does not yet bind Nidrosoft or you. We are publishing it before review because you should be able to read what happens to your data before you decide to trust us with it — not because it is finished. The version below took effect on 2026-09-03 and will be replaced once counsel has been through it.
What this covers
This policy describes what Nidrosoft does with personal data in Octana — the web application, the render worker behind it, and the public API. It covers you whether you have an account or not: someone whose voice was cloned by one of our customers has rights here even though they never signed up, and this page is written to be readable by them.
For most of what happens in the product, Nidrosoft is the controller. There are two exceptions and both are stated where they arise: when a business customer uses Octana to process other people’s data, they are the controller and we are their processor — the terms for that are in the Data Processing Addendum. And when you connect your own vendor key, that vendor receives your content under your contract rather than ours.
Your account and billing
Sign-in is handled by Clerk. Clerk holds your credentials; we never see a password. We store a copy of your email address, your name, your profile image URL, and an opaque Clerk user id that links the two systems. We also keep your timezone and interface language when you set them, because a schedule that says “post at nine” needs a zone to mean anything.
Subscriptions run on Stripe. Card details are entered on Stripe and never reach our servers. What we hold is a Stripe customer and subscription id, your plan, and the credit ledger — every grant and every spend, with the reason and the balance after it. That ledger is how you can check a charge, so it is deliberately detailed.
What we collect, and why
Beyond the account itself:
- What you give the product. Topics, scripts, prompts, uploaded images, audio and video, product page URLs, channel settings and style profiles. This is the input; without it there is nothing to make.
- What the product makes. Rendered video, voiceover audio, generated images, thumbnails and the job records that describe how each one was produced.
- Connections you authorise. Access and refresh tokens for a YouTube channel or another platform you connect, and API keys you supply for your own model vendors. All of these are encrypted before they are stored.
- Operational records. An audit log of administrative and consent events — who did what, to which record, when. Error reports, with secrets stripped before they leave. For API keys, the time of last use and a coarsened network address: an IPv4 address is truncated to its first three octets and an IPv6 address to its first 48 bits, so it tells us roughly where a key is being used without recording where you are.
- Biometric data, if you use voice cloning or presenter avatars. Its own section follows.
We do not buy personal data, we do not sell it, and we do not build advertising profiles. Nothing you write or upload is used to train a general-purpose model of ours — we do not train models. Content sent to a model vendor is governed by that vendor’s terms, which is one of the reasons the vendor list below is worth reading.
Voices and likenesses
Octana can create a voice clone from recordings you upload, and a presenter avatar from reference footage of a person. Both are biometric data. Under Illinois’ BIPA and California’s AB 2602 they are a special category with their own rules, and we treat them that way.
What is collected
- For a voice clone: the audio you upload, a cleaned-up copy of it, and a voice replica held at the speech vendor you chose.
- For a presenter avatar: the reference images or video of the person, and a trained avatar held at the avatar vendor.
- For both: a consent record naming the subject and the rights-holder, the uses it was granted for, the term, a hash of the exact consent text that was shown, the time it was accepted, and the IP address and browser that accepted it. Where a third party signed a release, the signed document itself. Where a spoken liveness check was used, the phrase and the recording of it.
A consent record is required, not optional
A voice clone cannot exist without a consent record attached to it — the link is required by the database, not by a screen you could skip. The record has to name the subject and the rights-holder; a checkbox will not do. The consent text is shown in full before it is accepted, and a hash of it is stored so we can prove later which words were agreed to. Where the subject is not the account holder, or the name matches a category that needs a second look, the record waits for human review before anything can be made with it. Subjects who are political figures are refused outright, with or without authorisation.
The term ends the permission
Every consent records a term in months. Open-ended permission is not offered. For a voice clone this is enforced: an hourly sweep marks a lapsed clone expired, deletes the replica at the speech vendor, and tells you it did. You get a warning fourteen days before it falls due. Independently of the sweep, a render refuses to use a clone whose term is over — so a cron that failed to run cannot become a video that should not have been made.
Presenter avatars are the exception, and we would rather say so than let you assume otherwise. We record the term for an avatar and show it to you, but the hourly expiry sweep covers voice clones only today. The permission still ends when the term ends — that is what the subject agreed to — but the software will not currently do it for you. Revoke it yourself at Settings → Personas, and write to privacy@octana.one if you want us to confirm it is gone.
Revoking
You can revoke a voice clone at any time from Settings → Voices. We mark it revoked here and delete the replica at the speech vendor — ElevenLabs, Cartesia or Fish Audio, whichever made it. The record of the clone stays, because it is the pointer to the consent that authorised it; the thing that could speak in that voice does not.
Revoking a presenter avatar at Settings → Personas stops it being usable here, permanently and irreversibly. It does not delete the trained likeness at the avatar vendor: HeyGen publishes no avatar-deletion endpoint we have been able to read, so we tell you plainly that the likeness has to be removed by hand at the provider, rather than claiming an erasure we did not perform. We do not know how long HeyGen keeps a trained likeness after that. If that matters to you, do not train an avatar until it is answered.
Deleting your account
Account deletion runs the same vendor purge for every voice clone you have, and the run is marked failed rather than complete if a vendor refuses — a partial purge is not allowed to look like a finished one. The uploaded voice recordings, the cleaned copies, the avatar reference footage and the liveness audio are all deleted from our storage.
One thing survives account deletion, and it surprises people: the signed consent release. A release is a third party’s signature. It is the only proof that a video still published somewhere was authorised by the person whose voice is in it. Destroying it would leave that person’s own evidence gone along with the account of whoever collected it.
So the recordings go and the release stays — together with the consent record it belongs to, which still holds the subject’s name, the rights-holder’s name, and the IP address and browser that accepted it. Your own user record is anonymised. If you are a subject named on a release and you want it dealt with differently, write to privacy@octana.one — that is a conversation we would rather have than a rule we apply silently.
If a voice or a likeness on this platform is yours and you never agreed to it, you do not need an account to tell us. Use the reporting form.
Google and YouTube
If you connect a YouTube channel, we ask Google for these scopes and nothing else. The reason next to each one is the reason we actually use it for:
| Scope | Why we ask for it |
|---|---|
| https://www.googleapis.com/auth/youtube.upload Sensitive | To publish a finished video to the channel you connect. Nothing is uploaded without you choosing to publish it. |
| https://www.googleapis.com/auth/youtube.readonly Sensitive | To read your channel's own videos, so the planner can avoid repeating a topic you have already covered. |
| https://www.googleapis.com/auth/yt-analytics.readonly Sensitive | To read your own retention and reach figures, which is what the analytics screens display. |
Three things about this access, stated explicitly because they are the questions worth asking:
- We only ever touch the channel you connect. There is no path in the product that reads or writes anyone else’s channel.
- Nothing is published unless you choose to publish it. The upload scope is used when you press publish or when you have set up a schedule that you configured. It is never used to post something you have not asked for.
- Analytics access is read-only and limited to your own figures — the retention and reach numbers for your own videos, which is exactly what the analytics screens display.
Both tokens Google issues are encrypted before they are stored and decrypted only inside the server function that makes the call.
What “Disconnect” does, precisely. Disconnecting in Settings → Connections marks the connection revoked here, and the app stops using it from that moment. It does not notify Google, and the encrypted tokens stay in our database until the account is deleted, which erases them. To end Google’s grant itself, remove our access at Google’s permissions page. We would rather describe that gap than let one button sound like both actions.
Your use of Octana’s YouTube features is also subject to the YouTube Terms of Service and the Google Privacy Policy.
Who else receives your data
Octana is built on other people’s services, and being vague about which ones is how a privacy policy becomes untrue. This is the whole list.
| Vendor | What they receive, and why | Your own key? |
|---|---|---|
| Infrastructure | ||
| Convex | Application database and backend functions. Holds every record described in this policy except stored media. | No |
| Cloudflare R2 | Object storage for rendered video, voiceover audio, images, uploaded sources and signed consent documents. | No |
| Vercel | Hosts and serves the web application. Sees request metadata including IP address. | No |
| Railway | Runs the render worker, which processes uploaded media and produces the finished video. | No |
| Identity and mail | ||
| Clerk | Account creation and sign-in. Holds the email address and name; we store a copy plus an opaque user id. | No |
| Resend | Transactional email — job outcomes and account notices. Receives the email address and the message. | No |
| Payments | ||
| Stripe | Subscription billing. Card details are entered on Stripe and never reach our servers. | No |
| Model and media vendors | ||
| OpenRouter | Routes script, assistant and default narration requests to selected AI models. | Yes |
| OpenAI | Text, image and speech generation. | Yes |
| Anthropic | Text generation. | Yes |
| fal | Image, video and audio generation. | Yes |
| ElevenLabs | Speech synthesis and voice cloning. Receives voice recordings when a clone is created. | Yes |
| Cartesia | Speech synthesis and voice cloning. Receives voice recordings when a clone is created. | Yes |
| Fish Audio | Speech synthesis and voice cloning. Receives voice recordings when a clone is created. | Yes |
| CleanVoice | Audio clean-up and separation. | Yes |
| HeyGen | Presenter avatars. Receives the reference likeness and the consent record reference. | Yes |
| PhotoRoom | Product image background removal and editing. | Yes |
| Higgsfield | Image and video generation. | Yes |
| Creatomate | Template-based video assembly. | Yes |
| Google (Gemini image) | Image generation. | Yes |
| BytePlus (Seedance) | Video generation. | Yes |
| BytePlus (Seedream) | Image generation. | Yes |
| MiniMax (image) | Image generation. | Yes |
| MiniMax (video) | Video generation. | Yes |
| Publishing | ||
| YouTube / Google | Publishes finished videos to a channel the customer connects, and reads that channel's own analytics. Only ever the customer's own channel. | Yes |
| Upload-Post | Brokered publishing to social platforms the customer connects. | No |
| Error reporting | ||
| Sentry | Error reporting from the web application and render worker. Payloads are scrubbed of secrets before they leave. | No |
What “your own key” changes
Most model and media vendors can be used in one of two ways. On the platform key, we hold the contract with the vendor, we send your content under it, and that vendor is our sub-processor — we are answerable for them. If instead you supply your own key for that vendor, your content reaches them under your account and your agreement with them. We pass it along; the relationship is yours.
That is not a billing detail. It changes who the controller is for that leg of the processing, whose terms govern how long the vendor keeps the content, and who a regulator would ask. If you have brought your own keys, read those vendors’ policies as well as this one — we cannot make commitments on behalf of a contract we are not party to. Your keys are encrypted at rest and never shown to us in the clear after you save them.
When we add a sub-processor, the build fails until this list names it. That is a mechanism rather than a promise, which is why it is worth telling you about.
Where the data goes
The vendors above are largely United States companies, and running Octana means personal data is processed in the United States and in whatever regions those services operate. If you are in the UK, the EEA or Switzerland, that is an international transfer.
We rely on the transfer mechanisms our sub-processors offer — Standard Contractual Clauses and the equivalent UK addendum, as published in each vendor’s own data processing terms. We will not claim more precision than we have: a complete, vendor-by-vendor account of the mechanism relied on and the transfer risk assessment behind it is not finished, and this section will be replaced with the specifics once it is. If you need that detail before then, ask us at privacy@octana.one and we will tell you where we have got to rather than send you a template.
How long we keep it
Every period below is one a scheduled job actually enforces, or a plain statement that something is kept. A retention promise nothing implements is worse than none.
| What | How long | Why |
|---|---|---|
| Account and content | Until you delete the account | Deletion is scheduled with a 7-day grace period during which it can be undone. After that, records and stored files are removed in batches. |
| Voice clones and their source recordings | Until revoked, the consent term expires, or the account is deleted | The replica is deleted at the voice vendor as well as here. A consent term that lapses disables the clone and purges it at the vendor. |
| Signed consent releases | Retained after account deletion | A release is a third party's signature and the only proof of authority for videos that remain published. The voice recordings it accompanied are deleted; the release itself is kept. |
| Billing records | As required by tax and accounting law | Held by Stripe under their own retention rules, and referenced here by id. |
| Audit log | Retained | Records administrative actions and consent events. Kept because its purpose is to show what happened after the fact. |
One open question we would rather name than hide: when a voice consent term lapses, the replica is deleted at the vendor and the clone is disabled, but the original uploaded recordings are not deleted at that moment — they go when the account is deleted. Whether a destruction schedule should take the source audio at term end too is a question for counsel, and it is on the list for the review this document is waiting on. You can delete your account, and with it the recordings, at any time.
Your rights, and where to use them
Depending on where you live, you have some or all of the following rights. Where the product implements one directly, the link goes to the screen that does it — that is faster than emailing us and it does not depend on us reading the inbox.
- Access and export. Settings → Export or deletebuilds a JSON file of your profile, projects, channels, schedules, credit ledger, publishing consents, referrals, voice clones and consent records, and gives you a link to download it. It deliberately excludes things that would be dangerous to put in a downloadable file — your provider keys, OAuth tokens and API key hashes are never in it, and neither are other people’s email addresses. Each section is capped at the 500 most recent records; if you need more than that, ask and we will get it for you.
- Correction. Your name and image come from Clerk — change them there and they update here on the next sign-in. Everything else is editable in the app; if something is not, tell us and we will change it.
- Deletion. Settings → Export or delete again. You confirm by typing your email address, and the deletion is then scheduled seven days out. During those seven days you can cancel it. After that a job works through it in steps: revoke connections, purge voice clones at their vendors, cancel the subscription, delete stored files, delete content and configuration, anonymise what is retained, and remove the identity at Clerk. What survives is described above.
- Objection and restriction. Write to privacy@octana.one. There is no screen for this because it needs a person.
- Withdrawing biometric consent. Revoke the clone or the avatar, as above. If you are the subject rather than the account holder, use the reporting form — you do not need an account.
- Complaining. If you are in the UK or the EEA you can complain to your data protection authority. We would rather you told us first, but it is your right and not conditional on that.
We do not charge for any of this and we do not treat you differently for asking. There is no automated decision-making that produces legal effects about you.
How it is protected
The measures we actually have, rather than the ones that sound good. The full list, with the detail a procurement team wants, is in the Data Processing Addendum.
- Provider keys, OAuth access and refresh tokens, and webhook signing secrets are encrypted at rest with AES-256-GCM and decrypted only inside the server function that uses them.
- API keys are stored as a SHA-256 hash. After the moment we show you a new key, no copy of it exists anywhere in our systems.
- Every record is owned by exactly one account, and access is checked on the server for every read and write. Hiding a link in the interface is not access control and we do not treat it as such.
- Transport is encrypted end to end by our hosting platforms. Outbound webhooks are restricted in code to HTTPS on port 443.
- Error reports are scrubbed of secrets before they leave, and the audit log the product shows you allow-lists which fields may reach a browser at all.
No system is perfectly secure, and we are a young product. If you find a vulnerability, report it to legal@octana.one; we will not pursue you for telling us.
Children
Octana is a tool for people running a channel or a business. It is not directed at children, we do not market it to them, and we do not knowingly collect personal data from a child. If we learn that an account belongs to one, we delete it. Any minimum age for holding an account is set by the Terms of Service rather than here.
Being straight about the mechanism: we do not verify anyone’s age. There is no age gate in the product, so the statement above is a rule we act on when we find out, not one the software checks up front. Separately, every video the product publishes to YouTube is marked as not made for children — that designation carries obligations under COPPA this platform does not meet, so the option to claim otherwise is not offered anywhere in the product.
If you believe a child has given us personal data, tell us at privacy@octana.one.
Changes, and reaching a human
When the substance of this policy changes, the effective date at the top changes with it — and if a change materially affects how we handle your data, we will tell account holders rather than leaving you to notice. Typos do not move the date; a version history nobody can trust is worse than none.
Privacy questions and rights requests: privacy@octana.one. Anything else legal: legal@octana.one. General support: support@octana.one. A voice or likeness used without permission: the reporting form, no account needed.
We have not yet appointed a data protection officer or an EU/UK representative. If one is required of us, we will appoint one and name them here.