Speech Ace / API Privacy Policy
Last updated: September 22, 2026
Speechace LLC created this privacy policy to provide You, Speechace API callers, with information on how we collect and use information, including personally identifiable information. As part of the normal operation of our services we receive information from API callers. This Privacy Policy is intended to inform You how we use and protect information that we collect. You may always opt out of any use or disclosure by contacting us and notifying us of Your choice, and by limiting what information you pass to the Speechace API.
This Policy forms part of our Terms of Service and applies to all use of the Speechace API.
Our API requires minimal data to fulfill its services. Names, email addresses, student or employee identifiers, and other personally identifiable information are neither required nor used for processing, and under our Terms of Service you must not submit them — including in file names, prompt text, or metadata fields. If you do submit an identifier, it is processed and expires in the same way as any other data you send, and you remain responsible for it.
Our API requires an anonymized audio recording of a user attempting a particular question and sufficient information about the question (for example, the prompt presented to the end-user) to evaluate the audio.
We do not use voice data to identify or verify the identity of any individual. We do not create, store, or compare voiceprints or other biometric templates, and we do not attempt to determine who a speaker is. Our models evaluate how speech is produced, not who produced it.
When You provide information through our API, the information will be sent to one of our API Cloud Service regions based on the choice you made when you requested an API Key. All processing and storage of that information will remain within your chosen region.
We use the information we receive to:
a. Deliver the services and products that You have requested;
b. Manage Your account and provide You with customer support;
c. Enforce our terms and conditions;
d. Manage our business;
e. Perform functions as otherwise described to You at the time of collection.
We do not use your audio data to train our machine learning models. Your data belongs to you and is used only to serve your requests and to support you. Specifically, we do not use audio you submit, transcripts derived from it, or scores computed from it to train, fine-tune, or develop any speech recognition, pronunciation, or assessment model, and we do not disclose it to any third party for those purposes.
We do use aggregate operational metrics — such as request volume, audio duration, latency, error rates, and language and endpoint distribution — to operate, monitor, secure and improve the Services. These metrics contain no audio, no transcripts, no scores attributable to an individual, and no personal data.
Where data relates to a child under 13, we do not use it, or any data derived from it that reasonably identifies a child, to train or develop any machine learning or artificial intelligence model under any circumstances.
We retain audio and associated request data for a default period of 90 days from the time we receive it. At the end of that period the data expires automatically and is deleted irreversibly. Deletion of expired data may take between 1 and 48 hours to complete. This 90-day default applies to all accounts and all subscribers.
We collect this data for one purpose: to compute and return a score to your application. We retain it for one business reason: to investigate and respond to support requests you raise. We do not use retained data for any other purpose, and we do not retain it indefinitely.
A retention period other than 90 days — whether shorter, longer, immediate expiration after processing, or set per API Key — applies only where it is expressly set out in a signed Enterprise Agreement, in which case that period governs in place of the default for the accounts it covers. Retention periods cannot be changed on a per-account or per-key basis outside an Enterprise Agreement.
You should keep your own copy of any data you need. We are not a system of record. Expired data cannot be recovered, and we have no obligation to return, export, or restore it. If you terminate your account, all data associated with it expires in accordance with this section.
We pseudonymize data on storage and do not retain any information that would let us identify an individual end user or isolate their records. We therefore cannot locate, retrieve, correct, or delete the data of a particular individual on request, and we do not process individual access, correction, or deletion requests.
Instead, deletion happens automatically: all data expires and is irreversibly deleted within 90 days of receipt, as described above. A request to delete an individual’s data is satisfied by the ordinary operation of our retention schedule, without any action needed from you or from us, provided you stop submitting that individual’s data.
If you are an end user, we do not know who you are and hold no account for you. Please contact the organization whose application you used — they hold your identity, they decide what is submitted to us, and they are responsible for responding to your request. If you contact us directly, we will refer you to them.
If you are an API caller and want to configure a custom data retention policy including Zero Day Retention, contact support@speechace.com and request upgrading to an Enterprise contract.
Our API is used by education providers whose learners include children. We do not have a direct relationship with those learners, do not know their identities, and do not knowingly collect any information about them beyond the audio and prompt data our customer submits.
Roles. As between Speechace and our customer, the customer is the “operator” under the Children’s Online Privacy Protection Act and the FTC’s implementing rule at 16 C.F.R. Part 312, and the controller of the data submitted. Speechace acts solely as the customer’s service provider and processor, and processes children’s data only on the customer’s instructions and only to provide the Services.
Consent. Our customers are required by our Terms of Service to obtain verifiable parental consent, or valid school authorization where applicable law permits a school to consent for a school-directed educational purpose, before submitting any child’s data to the Services. We rely on that requirement and on our customers’ representations; we are not in a position to verify consent for any individual child.
Retention. We collect children’s audio and prompt data for one purpose: to compute and return a score to our customer’s application. We retain it for one business reason: to investigate support requests our customer raises. We delete it within 90 days of receipt, automatically and irreversibly, unless a different period is set in that customer’s Enterprise Agreement. We do not retain it indefinitely.
What we do with it. Children’s data is processed only to return a score to the customer’s application. It is pseudonymized on storage. It is never used to train any machine learning or artificial intelligence model. It is never sold or rented, and never used or disclosed for advertising, profiling, or any commercial purpose unrelated to providing the Services.
Parents and schools. If you are a parent or a school and want a child’s data deleted, or want to know what has been collected, please contact the organization that provides the application your child used. That organization holds your child’s identity and controls what is submitted to us. We cannot identify an individual child’s data in our systems, and all such data expires within the applicable data retention period regardless. If you contact us at support@speechace.com, we will refer you to our customer and, where a customer’s identity is unclear to you, help you identify who to contact.
As a matter of policy, we do not sell or rent any information about You to any third party. We do not disclose audio, transcripts, or scores to any third party except to the sub-processors identified below, who process data only to help us operate the Services, and except as described under “Legal requests.”
We process your data in the cloud region you selected when you requested your API Key, and it stays in that region. You are responsible for choosing the region appropriate to your legal and contractual obligations.
We use cloud infrastructure providers as sub-processors to host and operate the Services. They are:
Sub-processor | Purpose | Processing location |
Amazon Web Services, Inc. | Cloud hosting, storage and compute | The region you select |
Microsoft Corporation (Microsoft Azure) | Cloud hosting, storage and compute | The region you select |
Google LLC (Google Cloud Platform) | Cloud hosting, storage and compute | The region you select |
These are third parties to which we disclose audio, transcripts, or scores, and they process that data only to help us operate the Services on your behalf. Each is bound by written terms imposing data protection obligations no less protective than those we owe you, and we remain responsible for their performance.
This list is the authoritative record of our sub-processors, and our Terms of Service refer to it rather than repeating it. We will give at least 30 days’ notice before a new sub-processor begins processing your data, by updating this section and notifying your account administrator. If you object to a new sub-processor, you may terminate your subscription before it begins processing; for accounts not under an Enterprise Agreement, that is the available remedy.
We process your data only in the cloud region you selected when you requested your API Key. Where we process personal data originating in the European Economic Area, the United Kingdom, or Switzerland outside those territories, we do so under the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 and, where applicable, the UK International Data Transfer Addendum.
Those clauses are incorporated into the “Data Processing Terms” section of our Terms of Service, which states the module and elections that apply and completes the required annexes. No separate agreement or signature is needed.
We cooperate with law enforcement agencies and other third parties to enforce laws, as well as investigate and prosecute unlawful activities such as frauds and scams. Where we receive a legally binding request for data we process on a customer’s behalf, we will, unless legally prohibited, notify the customer before disclosing and disclose only what the request requires.
We encrypt data in transit and at rest using current industry-standard cryptography. Data is pseudonymized on storage, and is processed and stored only in the cloud region you select. Production access requires a business need, a unique named account and multi-factor authentication, and is logged and reviewed. We scan for vulnerabilities on a regular cycle and after significant changes, develop and release software through a documented change control process, and require confidentiality obligations and security training of every person with access to customer data.
The full list of technical and organizational measures we maintain is set out in the “Data Protection and Security” section of our Terms of Service, where it forms our contractual security commitment and completes Annex II of the Standard Contractual Clauses.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
We will notify affected customers without undue delay after becoming aware of a personal data breach affecting their data, and will give them the information reasonably available to us so they can meet their own notification obligations. What we provide, and the limits of that commitment, are set out in the “Data Processing Terms” section of our Terms of Service.
Everything we commit to is contained in two documents: this Policy and our Terms of Service. Between them they describe what we process and why, how long we keep it, how deletion works, the security measures we maintain, the sub-processors we use, how international transfers are legitimized, and our obligations as a processor. There is no separate data processing agreement, security schedule, or sub-processor list to request, and nothing requires a signature. We will also answer reasonable written questions about that information where it is not already covered.
Additional assurance, including audit rights and completion of security questionnaires and vendor risk assessments, is available under an Enterprise Agreement. The scope of what we do and do not provide is set out in the “Data Protection and Security” section of our Terms of Service. Contact support@speechace.com to discuss enterprise terms.
You, the API caller, are the controller of the data you submit and the only party that knows who your end users are. Implementing and responding to data subject rights — including the rights of access, rectification, erasure, restriction, portability, and objection — is therefore managed within your application or service.
Because we pseudonymize data on storage and hold nothing that lets us identify an individual, we cannot respond to a request about a specific person. We assist you in two ways instead: by pseudonymizing on receipt, so there is less to disclose or delete, and by expiring all data within the applicable data retention period, so an erasure request is satisfied automatically once you stop submitting that individual’s data.
If a data subject or a supervisory authority contacts us directly about an individual, we will promptly inform you and will refer them to you rather than responding ourselves.
We may update this Policy to reflect changes in the law or in our practices. We will post the updated Policy with a new “last updated” date, and where a change is material we will give at least 30 days’ notice by email to account administrators or by notice in the Services before it takes effect. Changes required to comply with applicable law, or to address a security or legal risk, may take effect on shorter notice where we reasonably determine that is necessary. Previous versions are available on request.
If you do not agree to a change, your remedy is to stop using the Services and cancel your subscription before it takes effect.
Questions about this Policy: support@speechace.com.