Skip to content
Early access is open
Repic
LoginJoin early access
← Back to the journal
Trust

Nine questions to ask before anything clones your voice

A buyer's checklist for voice and likeness cloning, written by a company that sells it — including the four questions our own product does not yet fully pass, and where each one stands.

By Saffi & JaveriaAugust 17, 2026 · 6 min read

A voiceprint is not a file you can rotate like a password. If it leaks, it is out, and the thing it identifies is you. That asymmetry is why the questions below are worth asking before you upload anything, and why "we take security seriously" is not an answer to any of them.

This is written by a company that sells voice cloning, so treat it accordingly. What we can offer is the list a vendor knows to be afraid of — and, at the end, the four items our own product does not yet fully pass, with where each one stands.

The nine

1. Can I clone a voice that is not mine?

If the answer is yes, or is a shrug, stop. A tool that will clone any uploaded audio is a tool whose main real-world use is impersonation, whatever the marketing says. Own-voice-only is a product constraint, not a policy sentence, and you can test it: try to upload something that is obviously not you and see whether anything stops you.

2. What exactly is the consent step, in the product, today?

Not what the policy aspires to — what happens on the screen. There is a real difference between ticking a box, recording a spoken statement, and a verified identity check, and vendors routinely describe the strongest one while shipping the weakest.

Ask for the specific interaction. If the answer is a paragraph rather than a sentence describing a screen, that is your answer.

Where we stand: ours is a required checkbox on the recording screen, carrying the use-and-retention statement, and you cannot start recording without it. It is not a spoken consent artefact. Our biometric policy says so directly, and says it would "rather tell you exactly where this stands than imply a gate that is not there yet".

3. Who else can use my voice inside the product?

Team accounts are where this gets loose. If a colleague can select your twin from a dropdown and generate audio, your voice is a shared asset and you should know that before it happens rather than after.

Where we stand: a twin belongs to one account and there are no team accounts today, so the answer is nobody. That is a true answer and a weak one, because it is true by absence rather than by design — the question gets harder the moment shared workspaces exist, and asking a vendor how they will handle it then is more informative than asking how they handle it now.

4. Does the provider train on my data?

Most voice cloning runs on a third-party model. The question is not whether the vendor trains on you — it is whether the vendor's provider does, which is a different contract you cannot see.

Ask for it explicitly. "We don't train on your data" is often true and often not the whole sentence.

5. Where does the voiceprint live, and can it leave?

A cloned-voice reference is a credential. It should be server-side only, never sent to a browser, and never included in an export. If a vendor cannot tell you which of those three is true, assume the least safe one.

6. What happens when I press delete?

This is the question with the biggest gap between what people assume and what happens, across the whole category. Pressing delete usually removes the item from your view. Whether it destroys the raw sample, the derived voiceprint, and the provider-side cloned voice is a separate question with a separate answer, and often a separate timeline.

Ask for all four: the sample, the derived identifiers, the provider-side model, and the deadline.

Where we stand, and this is one of the four: pressing delete removes the twin from your account. Full destruction of the underlying media and revocation of the provider-side voice is carried out by our team on request while the automatic controls are being built, on the schedule in our biometric policy. If you want it done now, you email privacy and we do it and confirm. That is worse than a one-click erase and it is what is true today.

7. What is the retention period if I do nothing?

"As long as needed" is not a period. There should be a number, and a maximum that applies even if you never come back.

8. Is there an audit trail?

If someone generates audio in your voice, is there a record of who, when, and what? Without one, a misuse investigation is impossible after the fact — including one where you are the person trying to prove something.

9. What happens to my twin if the company dies?

Most vendors in this category are small and some will not exist in three years. A voiceprint sitting in a wound-down company's storage, or transferred as an asset in an acquisition, is a real outcome. Ask what the shutdown commitment is.

This one almost never has a good answer, ours included. Asking it is still worth it, because how a company reacts to the question is informative even when the answer is "we have not decided".

The four we do not fully pass

A checklist a vendor publishes and then quietly passes on every item is a marketing page in a checklist's clothing. So, specifically:

Question 2 — the consent step is a checkbox, not a spoken artefact. A spoken consent recording is a stronger gate and we do not capture one. Wherever else on this site you see it described differently, the biometric policy is the document to trust: it is the binding one and it is the accurate one.

Question 6 — deletion is manual on request. The account-level delete is immediate; full destruction is a human process on a schedule. The policy states this plainly rather than implying a one-click erase, which is right, and it is still weaker than what we want it to be.

Question 8 — there is no per-generation audit trail on a twin. We went looking while writing this and did not find one. A record of who generated what, when, in whose voice is the thing that makes a misuse investigation possible after the fact, and we do not have it yet.

Question 9 — we have no published shutdown commitment. We are a two-person company in early access. We would rather say that than write a reassuring paragraph nobody could hold us to.

The remaining five we do pass, and they are checkable rather than asserted: own-voice-only is a product constraint rather than a request, the cloned-voice reference is server-side only and never reaches a browser or an export, providers are contractually barred from training their general models on it, the retention schedule is written with numbers and a maximum, and the biometric policy states all of it including the parts that are unflattering.

The thing to actually do

Ask questions 2 and 6 of any vendor you are considering, in writing, and compare the answer to what their marketing page says. The gap between those two is the most reliable signal available about how a company will behave when something goes wrong — more reliable than any of the individual answers.

We publish the standard we hold our own claims to, including how a stale claim expires, on our editorial standard page. The full biometric detail — what is collected, the retention schedule, and how deletion works today — is in the biometric policy, and the broader consent argument is in consent-first voice cloning explained.