This Privacy Policy describes how Constella App, Inc. (“Constella,” “Earshot,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use our applications, websites, and related services, including the Earshot web app, the Earshot Teleprompter app for iOS, and the earshot.to website (collectively, the “Services”). By using the Services you acknowledge the practices described in this Policy. If you do not agree with this Policy, do not use the Services.

Read this Policy together with our Terms of Service, which govern your use of the Services and set out your responsibilities for the content you create, the rules for cloning a face or voice, and the uses of synthetic media that we prohibit.


1. What the Services Do With Your Data, in Short

  • Teleprompter. We record video and audio of you when you tap record, upload the take to our storage, and send it to AI providers to trim it and add captions. Your script, voice memos, and answers stay in your account.
  • Clone Yourself. If you choose to, we process photos of your face and a recording of your voice to build an AI likeness. This is biometric data, and we only do it with your separate, explicit consent (Section 3).
  • AI creators. Wholly synthetic presenters involve no biometric data about you.
  • Publishing. When you connect a social or ad account, or ask us to post for you, we hold the tokens and the content needed to do that, and in some cases hand the content to human operators.
  • We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not let AI providers train their general models on your content, your face, or your voice.

2. Information We Collect

2.1 Information you give us

  • Account information: name, email address, and the identifier we receive from Apple, Google, or our sign-in provider when you sign in. Passwords are handled by our sign-in provider; we never see them. Payment details are handled by our payment processors or by Apple; we store only customer, subscription, and receipt identifiers, never full card numbers.
  • Scripts and ideas:scripts you type or paste, ideas you talk through, answers to the daily question, and the “what you talk about” context you give us so scripts fit your world.
  • Voice memos and interviews: audio you record to ramble an idea or answer interview questions. We send it to a transcription provider and keep the transcript; interview turns are held only for the session unless they become a script.
  • Takes: the video and audio the camera records while the teleprompter runs, plus edited versions with captions, titles, and, on free plans, a watermark.
  • Clone material: if you create a Clone, five to twenty photos of your face and a voice recording of roughly one to two minutes (Section 3).
  • Brand and product materials: product pages, images, logos, and briefs you submit, including pages we read from a website you give us.
  • Preferences: topics, tone, pace, caption style, reminder and notification settings, and whether you have agreed to let us use your content to improve the Services.
  • Connected Account data: authorization tokens, account identifiers, and post and campaign metadata for any social or advertising account you connect.
  • Communications: messages you send us, including support requests, takedown reports, and feedback.
  • Help and feedback in the app: what you type into Help, and your answers to the occasional short question we ask in the app (for example, why you stopped before editing a take, or how happy you are with a video). An AI assistant answers Help messages: before your first message we ask for your permission, then your message, the screen you were on, and basic device details (model, iOS and app version) are sent to our AI providers (Anthropic and Google, through OpenRouter) to write the reply. Your name and email are not sent to them unless you type them. We keep the conversation and your answers so our team can read them and follow up, delete them when you delete your account, and include them in Download my data.

2.2 Information collected automatically

  • Usage data: which features you use and when, such as starting a take, how far through a script you got, which ideas you opened, which template you picked, and whether an edit finished. On the web and in the app this is collected through our analytics provider and linked to your account.
  • Device and app data: device model, operating system, app version, browser type, language, IP address, time zone, and a push notification token if you allow notifications.
  • Guest session identifier: before you sign in, a random identifier stored in your browser or in the secure keychain on your iPhone. Our servers store only a hash of it.
  • Crash and performance data: on iOS, crash reports reach us only through Apple and only if you have opted in to share analytics with app developers in iOS settings.
  • Cookies and similar technologies on our websites, as described in Section 12.

2.3 On-device speech recognition

The iOS app can show the last few words you said while you talk through a story, and can turn dictation into a pasted script. Where your device supports it, this recognition runs on the device. Where it does not, Apple's speech service processes the audio under Apple's privacy terms. The app asks for your permission before using speech recognition.

2.4 Public content from other creators

To show you ideas and reference examples, we retrieve public posts from TikTok and Instagram through a scraping provider: the creator's public handle, caption, view and engagement counts, and the public video or a frame of it. We store copies of these public posts so that examples load quickly and so that our scoring stays consistent. This is information about other people, not about you. If you are a creator whose public post appears in our systems and you want it removed, email team@earshot.to and we will remove it.

2.5 Information from third parties

When you sign in with Apple or Google we receive the name and email address you agree to share. If you connect a social or ad account, we receive the data that platform allows you to share with us. If you use outreach features, we receive replies from the people you contact.

3. Biometric Information: Face and Voice Clones

Creating a Clone requires us to process biometric identifiers and biometric information as defined under applicable law, including facial geometry derived from the photos you submit and a voiceprint derived from the recording you submit (“Biometric Data”). Wholly synthetic AI creators not modeled on any real person do not involve Biometric Data.

Consent. Before we process any Biometric Data we require your explicit, affirmative consent through a dedicated step in the Clone flow, separate from your acceptance of this Policy and the Terms. We record the time you consented and the version of the consent text you saw. Our Terms also require that the face and voice you submit are your own, or that you hold documented consent from the person depicted.

Purpose. We use Biometric Data solely to create, personalize, and maintain your Clone; to generate the videos you request with it; and to detect and prevent unauthorized use, impersonation, and misuse of the Services. We do not sell, rent, or trade Biometric Data, we do not share it for advertising, and we do not use it to train generalized AI models. Our model providers are contractually bound to use it only to fulfil your requests.

Where it goes. Photos and the voice recording are stored in our cloud storage. To generate a video, the relevant photos and the voice recording are sent to the AI model providers described in Section 5, which produce the video and return it to us. A provider may hold the material for the duration of the job and for the short period its own retention policy allows.

Retention and destruction. We keep Biometric Data only while your Clone remains active. When you delete your Clone or your account we permanently destroy the photos, the voice recording, and the derived models from active systems within 60 days, and in any event no later than three years after your last interaction with the Services, or one year for Texas residents, as described below. Backups are purged on the rolling schedule in Section 7.

Illinois residents. Under the Illinois Biometric Information Privacy Act (BIPA), we will not collect your Biometric Data without first providing this notice and obtaining your written release, and we will destroy your Biometric Data when the purpose for collecting it has been satisfied or within three years of your last interaction with the Services, whichever is first.

Texas residents. Under the Texas Capture or Use of Biometric Identifier Act (CUBI), we destroy Biometric Data within a reasonable time, not to exceed one year after the purpose for collecting it has expired.

Washington residents. Biometric Data may be health data under the Washington My Health My Data Act. We collect and share it only with your consent and only for the purposes above.

Your rights. You may withdraw consent and delete your Clone at any time from your account or by emailing team@earshot.to. Withdrawal does not affect the lawfulness of processing before withdrawal and does not affect videos you already downloaded or published.

Another person's likeness. If you submit a photo, video, or recording of anyone other than yourself, you are responsible for their consent as set out in Section 6 of the Terms; we process that material solely on your instructions, and the person depicted may ask us to disable the Clone at any time.

4. How We Use Information

We use information to:

  • provide the Services: turn ideas into scripts, run the teleprompter, record and upload takes, edit them, add captions, generate videos with Clones or AI creators, and publish where you direct;
  • process purchases, credits, and subscriptions, and manage your account;
  • send service messages, such as “your video is ready,” and, if you turn them on, daily reminders and marketing emails you can opt out of at any time;
  • provide support and respond to takedown reports and rights requests;
  • detect and prevent fraud, abuse, impersonation, misuse of Clones, security incidents, and violations of our Terms, including through automated review of scripts and Output;
  • comply with legal obligations and enforce our agreements;
  • understand how the Services are used and develop new features, using aggregated or de-identified data where practicable; and
  • if you have opted in to “help improve Earshot,” review your scripts and takes internally to improve prompts and editing quality. You can turn this off in settings at any time.

AI processing. The Services use machine-learning and generative-AI technologies, including third-party model providers acting as our processors, to transcribe, write, edit, generate, and score content. We do not permit these providers to use your content, Output, or Biometric Data to train their generalized models, and we contractually restrict them to processing data solely to provide services to us.

Provenance marks. We may embed visible or invisible marks or metadata in Output that identify it as AI-generated. These marks do not contain your personal information beyond an identifier that lets us link the Output back to the generating account if it is misused.

5. Who We Share Information With

We share information only with the following categories of recipients:

  • Sign-in and identity: our authentication provider (Clerk), and Apple or Google when you use their sign-in.
  • Hosting and storage: our application host (Railway), web host (Vercel), and object storage (Cloudflare R2), which hold your account data, takes, Clone material, and Output.
  • AI model providers: providers of language, transcription, speech, image, video, voice-cloning, and lip-sync models, which receive the scripts, audio, photos, and video needed for a job. At the time of writing these include Google (Gemini), Anthropic and OpenAI via a routing provider (OpenRouter), a hosted agent runtime (HarnessRouter), WaveSpeed, Kie.ai, fal, and ElevenLabs. Each receives only what its job needs and is bound to use it only for that job.
  • Payments: Stripe for web purchases; Apple and RevenueCat for iOS subscriptions. RevenueCat receives an identifier for your account and your Apple receipt, not your name or email.
  • Analytics: PostHog and Vercel Analytics, which receive usage events, device data, and, once you sign in, your account identifier, name, and email so that we can support you. PostHog also receives the text of Help messages, the replies, and your answers to in-app questions, so we can see where people get stuck.
  • Messaging and email: Resend for transactional email and, if you have an account, at most an occasional one-question feedback email (each has a link to turn them off); Apple Push Notification service for push; Sendblue, Slack, or similar services when a posting package (your video and caption) is delivered to a human operator; and email providers we use to send outreach on your behalf.
  • Public content and web reading: a scraping provider (ScrapeCreators) receives your topic keywords to find public examples; a web-reading provider (Firecrawl) receives the URL of a product site you ask us to read.
  • Publishing and ads: the social and advertising platforms you connect, and an OAuth broker (Zernio) that holds the tokens for your ad accounts.
  • Human operators: contractors who post content for you receive the video, caption, and posting instructions for that job, under confidentiality obligations.
  • Legal and safety recipients, where we reasonably believe disclosure is required by law, legal process, or governmental request, or necessary to protect the rights, property, or safety of Constella, our users, a person depicted in content, or the public, including reports to law enforcement or child-safety organizations.
  • Corporate transaction parties, in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case this Policy will continue to apply or you will be notified of changes.
  • Parties you direct, when you share, export, or publish content.

We may share aggregated or de-identified information that cannot reasonably be used to identify you. We may change providers within a category; the current list is available on request.

6. Data About People Who Are Not Our Users

Your takes, Clone material, briefs, outreach messages, and Output may contain personal information about other people: someone in the background of a take, a colleague whose likeness you have permission to use, a creator you ask us to email, or a public creator whose post we show as an example. For that information you determine the purposes of collection and we process it on your behalf as a service provider. If a person contacts us about their likeness, voice, or data appearing in a user's account, we will direct the request to that user where appropriate, and we reserve the right to remove content, disable a Clone, or suspend an account that violates our Terms or applicable law. Reports can be sent to team@earshot.towith the subject line “Takedown.”

7. Data Retention and Deletion

  • Takes, scripts, projects, and Output are kept until you delete them or delete your account. Takes that you start uploading but never finish are discarded after 48 hours.
  • Guest sessions: anything recorded in a guest session that is never linked to an account may be deleted after 90 days of inactivity.
  • Account deletion is available in the iOS app under Profile, then Privacy, then Delete account, in web account settings, and by email. Deleting your account removes your takes, edited videos, scripts, projects, preferences, push tokens, receipts, and sign-in identity from active systems within 30 days, except where retention is required for legal compliance, dispute resolution, fraud prevention, or enforcement of agreements. Clone material follows the separate schedule in Section 3.
  • Backups are encrypted and purged on a rolling basis of up to 90 days.
  • Derived data such as transcripts, embeddings, and indexes generated from deleted content is deleted on the same schedule as the content.
  • Published content that you posted to a platform, downloaded, or handed to an operator is outside our systems and is not affected by deletion here.
  • Records of violations, takedown reports, and consent records may be kept for as long as needed to defend claims and comply with law.

8. Security

We implement administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, access controls, short-lived upload links, and logging. However, no system is perfectly secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials and device secure. If a breach affects your personal information we will notify you and regulators as required by applicable law.

9. Your Rights and Choices

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you; in the iOS app, Profile, then Privacy, then Download my data gives you a copy of your account data;
  • Correct inaccurate personal information;
  • Delete your personal information, your Clone, or your whole account;
  • Port your data in a machine-readable format;
  • Opt out of marketing email, daily reminders, and push notifications, in the app, in the email footer, or in iOS settings;
  • Limit use of sensitive personal information; we use sensitive information only to provide the Services you request;
  • Withdraw consentfor processing your Biometric Data and delete your Clone (Section 3), and turn off “help improve Earshot” in settings;
  • Not be discriminated against for exercising your rights.

You may exercise these rights through your account settings or by contacting us at team@earshot.to. We will verify your request and respond within the time required by law. You may designate an authorized agent where permitted. If we decline a request you may appeal by replying to our decision, and you may lodge a complaint with your local supervisory authority.

9.1 California residents

California residents have the rights described above under the CCPA as amended by the CPRA. In the preceding 12 months we have collected the categories of personal information described in Section 2 for the purposes in Section 4 and disclosed them to the categories of recipients in Section 5. We do not sell personal information or share it for cross-context behavioral advertising, and we have no actual knowledge of doing so for consumers under 16. Biometric Data you submit to create a Clone, and the contents of your takes and voice memos, are sensitive personal information; we process them only as described in this Policy and do not sell or share them.

9.2 EEA, UK, and Swiss residents

Where the GDPR or UK GDPR applies, Constella is the controller of your account data. Our legal bases are performance of a contract (providing the Services), legitimate interests (security, abuse prevention, product improvement, and service communications), consent (Biometric Data, optional analytics where required, marketing, and the improvement program), and legal obligations. Biometric Data is special category data under Article 9 GDPR and is processed only on your explicit consent, which you may withdraw at any time. For personal data about other people in your content we act as your processor. You also have the rights to object to and restrict processing. International transfers to the United States and to our providers are protected by Standard Contractual Clauses, the EU-US Data Privacy Framework where the recipient is certified, or other approved mechanisms. An EU or UK representative is not currently required.

9.3 Other regions

Residents of other U.S. states with privacy laws, Canada, Brazil, Australia, India, and other countries may have similar rights under local law. Use the contact details below to exercise them.

10. Children

The Services are for people 18 and older. They are not directed to children under 13 (or the higher minimum age in your jurisdiction), and we do not knowingly collect personal information, including Biometric Data, from them. Our Terms also prohibit submitting the face, voice, or image of any minor. If you believe a child has provided us personal information, contact us and we will delete it.

11. Push Notifications, Reminders, and Email

The iOS app asks permission before sending push notifications, which we use to tell you when a video is ready and, if you turn it on, for a daily reminder. You can turn them off in iOS settings at any time. We send transactional email about your account and videos; marketing email is sent only with your consent where required and always has an unsubscribe link.

12. Cookies and Analytics

Our websites use cookies and similar technologies for authentication, preferences, and analytics. You can control cookies through your browser settings and, where required, our consent banner. We honor Global Privacy Control signals where legally required. The iOS app does not use cookies; it uses the analytics described in Section 2.2 and does not use Apple's advertising identifier or track you across other companies' apps and websites.

13. Changes to This Policy

We may update this Policy from time to time. If we make material changes we will notify you by email or in-app notice before the changes take effect. Your continued use of the Services after the effective date constitutes acknowledgment of the updated Policy.

14. Contact Us

Constella App, Inc.

400 Concar Drive, C/O Constella, San Mateo, CA 94402

team@earshot.to

For unresolved privacy concerns, EEA and UK users may contact their local data protection authority.