Biometric information notice
Last updated 13 September 2026
What a Dub or Lip-Sync Does
To dub a video, a provider listens to the voice on it and produces a synthetic voice speaking the new words. To lip-sync it, a provider looks at the face and redraws the mouth to match. Both of those involve measuring the thing they are reproducing — the print of a voice, the geometry of a face. In several places that measurement is biometric data in law, and the law does not care that it was taken to make an advertisement.
Where a Face Travels
This is not only about video. A static creative goes to Google whole, and more than once. Two of those trips are steps you buy separately: once to be read, which is the cheap half and is bought on its own, and again to be redrawn. The redrawn image makes a third, so the words on it can be read back and checked against the line you sent — and where a line did not survive the drawing, the drawing and the check run again, which takes it to five, and a second re-draw to seven. The subprocessors page counts them. One more is possible and it is never automatic: if you buy a second opinion on a finished creative, the delivered image goes back once more to be looked at. If there is a person in it, their face is in what the model reads every one of those times — and where you buy the redraw, every pixel that comes back is something the model drew, including them. A still or a reference image you give Generate goes to Google whole in the same way — to be drawn from, and once more each time you press the rewrite button beside the prompt box, which sends the prompt and whatever you attached back to the same company to be read, so the wording can be rewritten to match the picture. What that tool has no step for is checking: no result of it is ever sent back to be read. One of those tools exists to hold a face steady across a shot, and the picture you attach for it is a picture of somebody.
Neither of them measures a voice: nothing you send to either is listened to, and no voice of yours is reproduced. A generated clip can come back with an audio track the model invented — it is not built from any voice you sent, because neither mode takes audio in — and no dubbing or lip-sync provider is involved in either. On the paid tier we call, Google’s terms say submitted content is not used to improve its models, and the subprocessors page carries that answer with the date we last read them.
What does not change is the consent you must hold. It has to cover every person whose face, voice or name is in what you send — in any file you upload, not only the ones in a video, and in the words you write — and anyone whom you describe in what you send, in a file or in words. On Music, which takes no file at all, and in the generation tool, where a prompt on its own is enough, a person is brought into the output by words alone; and a person is in a FILE without a face or a voice being in it when the narration speaks their name, when the copy on a creative prints it, or when the file describes them without naming them at all. It is required before the first thing you send from the upload, statics, music or generation page, and each of those four asks. It is required just the same where nothing asks you— the words you type to refine a creative you have already had drawn, or a set of captions you edit, go out on the record we already hold for that job, and no screen puts the question again. What that record is depends on when the job was sent: since 12 September 2026 it is your acceptance of the Terms, whose clause 3 carries this promise in those words; for a job sent between 27 August and 12 September 2026 it is the three separate confirmations that were taken then, which said the same thing and are still recorded and still readable; for an older one it is your acceptance of the Terms again, together with the versions of each document the job wrote down when it was created. Nothing is back-filled in either direction, because a record saying somebody saw words they were never shown would be a false record. The obligation is not weaker for those jobs: it is the same obligation, and it is on you either way. You collected that face, you are the controller of it, and what the consent has to cover is set out below.
What Cralio Does With It
None of that measuring. We do not extract, compute or store a faceprint, a voiceprint or any biometric template. There is no endpoint that accepts a voice sample and no way to pick a cloned voice; a search of this codebase for one returns nothing, and the video page says the same under “what it does not do”.
What we do is hold your video for your plan’s retention window — one day on the free tier, three on Starter, up to thirty on Scale, and the number is shown on every job. Access ends on that date: the moment it passes, nothing will serve the file. The bytes go with the next sweep after it, a day later, because the sweep leaves a day’s grace so that running late can never delete something the app still says you can fetch. While we hold it, we hand it to the provider named for that mode on the subprocessors page — and which provider that is depends on the mode: dubbing, lip-sync and translated captions go to one company, and recutting a video to another shape goes to a different one, which receives the whole picture and everybody in it. We never sell, lease, trade or otherwise profit from biometric data, and we have no arrangement under which anyone pays us for access to it.
What the Provider May Do With It
This is the part that is not ours to promise. Under its current terms, the provider that dubs a video, lip-syncs it or writes its translated captions may use what it receives — including the faces and voices in it — to improve its own models. That is its default for accounts such as ours. Translated captions belong in that sentence even though they change neither the picture nor the audio: the whole video is sent to that same provider, because the translation is its call. We do not negotiate that away on your behalf and we will not pretend to; the subprocessors page carries the answer per provider, beside the date on which we last read their terms. The company that recuts a video answers differently, and the difference is worth reading rather than summarising. Its API terms say that what a customer submits through API access, and what is generated from it, will not be used to train, fine-tune or develop its models — and API access is the only way we reach it. Its consumer terms take the opposite licence, which is why the row on the subprocessors page states the scope instead of printing a bare “No”. That company had received nothing at all when this notice was last edited: it was announced on 11 September 2026 and may not be sent anything of yours before the date its own row carries.
Two things follow. The consent you obtain from the people in your video has to cover it — not just that a machine will reproduce them, but that the company doing the reproducing may learn from the material, and, for a recut, that a second company redraws the frame around them. And if it cannot, there is a mode that reaches no dubbing provider at all. For captions in the video’s own language, no dubbing or lip-sync provider ever sees the file — but the transcription is not ours either: the audio alone goes to the speech-to-text provider named on the subprocessors page, which receives no picture and no face. What happens on our own infrastructure is the wrapping of those words into cues and the burning of them onto the picture. The job is priced to match: at what that transcription and our own encoding cost, rather than at a dubbing provider’s rate. About two credits on a thirty-second video.
Retention
Your video, and everything derived from it, stops being served on your plan’s retention window — the number is shown on every job and set out on the retention page — and the bytes go with the next sweep after that date, a day later, because the sweep leaves a day’s grace. There is no exception you control. Until 8 September 2026 the product put a Keep control on generated results that took one off your window; it is gone, and with it the idea that any single result can be held back from the schedule. One window applies to every delivered result, and what you want to have after it closes you download before it closes — that is the whole of what you can do, and it is said plainly here because a face or a voice you needed and did not save is not something we can produce again. Two things do stop the sweep, neither of them yours to press and neither of them a policy: a workspace it cannot read is left alone rather than guessed at, and so is a workspace whose window was set, before we stopped allowing it, to no limit at all. The thirty-day rule on the bucket collects those too, which is why it is the outer bound on this page for everything but one thing: material we are required by law to preserve is copied where no sweep walks and no storage rule reaches, and that is the last paragraph of this notice.
What the provider keeps is governed by the provider’s own retention, which the subprocessors page states for each of them. We cannot delete something out of a third party’s systems on your behalf, and we will not claim we can.
What You Must Obtain Before Uploading
You are the one who collected the face or the voice, and you are the controller of it. Laws including the Illinois Biometric Information Privacy Act require written, informed consent from each person before their biometric data is collected or disclosed to anyone else. The product asks you to confirm that you hold it before your first job — on the sign-up form, on the invitation screen, or in the product, on the upload, statics, music or generation page. Wherever you gave it, it is recorded against your account and it covers every file you send and every prompt you write afterwards. Until it is recorded, none of the four products will accept a new video, a new set of creatives, a new track or a new generation, and nothing is charged for a submission we refuse. A job you had already submitted is finished on the record we held when you sent it — your acceptance of the Terms, or the three separate confirmations for a job sent while those were being asked for, plus the document versions the job recorded — and where finishing it means another paid step, a re-render, a refinement, a deep-QA pass or a visualiser drawn from a track, that step runs on that same record and is charged as usual. What the consent has to cover is this:
- that their likeness or voice will be reproduced by an AI model, and that this is not a person imitating them;
- which languages the result will speak;
- where it may be published;
- how long the data will be kept;
- which companies will process it — named, or as a class that includes them, which is what makes the transfer on the subprocessors page something they agreed to rather than something they were not told;
- and that the processing provider may use the material to improve its own models where its terms allow that — which, for dubbing, lip-sync and translated captions, they currently do.
You will produce that consent to us within five business days if we ask, because a regulator, a court or the person themselves has asked us. You will not upload, or ask a model to produce, the face or voice of anyone under 18.
A model release for a shoot, an employment contract, a talent agreement or the fact that a video is already public is not that consent. None of them mentions a machine reproducing the person, because none of them was written when that was possible.
If You Appear in a File
If your face or voice is in something someone else uploaded, the person to ask is the one who uploaded it — they decided what to collect and why, and we hold it on their instruction. Write to us at info@cralio.app and we will pass it to them without undue delay and help them answer. We answer you within one month, and where a request is complex we may take up to two months more and will tell you so inside the first month — the same window the privacy policy sets out.
Two things are worth knowing before you write. We cannot look for you: nothing here measures a face or a voice, so there is no index of people to search. We can open an account and look at its jobs if you can tell us whose account it is likely to be; we cannot find you by your face. And the material may already be gone — a file is normally deleted on the uploader’s plan window, which is between one and thirty days after the work was delivered, and a day behind that date in practice, because the sweep leaves a day’s grace. Thirty days after the file was made is the outer bound on our own systems, and the single exception to it is the paragraph below. What a provider that received the file keeps is on that provider’s own retention, which the subprocessors page states for each of them.
What we can and cannot do ourselves. Deleting the file and stopping the job are the uploader’s own buttons, so what we can do is ask them to press them. What we can do without them is freeze the account, so no further work is bought, and preserve material where a court or the law requires it. We have no control that removes one person from a file somebody else uploaded, and material we are under a legal duty to preserve is the one thing we will not delete.