The account portal stores login identities only. Voiceprint registration remains a research prototype: raw recordings and plaintext features remain in local memory, and the server receives a fixed-length AES-GCM encrypted template plus minimal protocol metadata. Do not email recordings or identity documents.
Who operates this site
SoundTitle is currently operated as a research prototype by the project lead. Privacy, deletion and dispute requests can be sent to info@soundtitle.org; do not attach recordings or identity documents. The operating entity and jurisdiction for formal notices are still being established and will be added before any commercial release.
Current data flows
- Ordinary visits: the hosting and security provider may process IP address, request time, URL, user agent and related network/security data needed to deliver and protect the site.
- Record lookup: a registration identifier and optional purpose context are sent to the same-origin API. The application performs a read-only database lookup and returns a minimal status response. It does not add a lookup event to the rights-event chain.
- Public ledger lookup: the application returns limited receipt metadata only for records already classified as public. Restricted, sealed and missing records receive the same 404 response.
- Legacy pilot records: the database may contain a public label, privacy tier, selected purposes/languages, timestamps and hash-linked receipts submitted during the earlier minimum viable pilot. The current public verification response no longer exposes those profile fields.
- Identity account: the account service stores a normalized verified email address; the selected OAuth provider and its subject identifier; optional Apple-provided name; Passkey public keys and authenticator metadata; and account timestamps. It never stores an account password or Passkey private key.
- Authentication security: the account service stores hashed session, reauthentication and pilot-ticket tokens, authentication challenges, expiry/status timestamps, and limited request-security data used for abuse controls. Google or Apple receives the normal OAuth request when you choose that provider.
- Voiceprint registration: after authentication, a privacy-separated account commitment links the identity account to the voice pilot. The voice database does not receive the email address or OAuth subject. It stores the encrypted template, nonce, commitment, device public key, consent/governance records and minimal protocol metadata.
What the current site does not collect
The account portal does not collect recordings, voiceprints, embeddings, government identity documents, payment information or model-training consent. Do not send voiceprint material by email. In the voiceprint workspace, raw recordings and plaintext features stay in local memory only.
Public information and caching
Public receipt metadata may be visible to anyone who knows a public record identifier. API responses use Cache-Control: no-store, but no Internet service can guarantee that a recipient will not independently retain information already displayed to them.
Retention, correction and disputes
Active identity-account data is kept until the account is deleted. Expired email, OAuth, WebAuthn, reauthentication and pilot-ticket challenge records are normally removed 24–30 hours after expiry; expired or revoked sessions and revoked Passkeys are normally removed within 30 days and six hours. Account settings can revoke a Passkey, sign out other sessions, or immediately delete the identity account and its linked login data.
Identity-account deletion does not silently delete the separate voice-pilot record. A signed export and deletion-request flow is available after entering the voice workspace from the account portal; approved voice deletion requests have a 24-hour safety delay and are then fulfilled by the scheduled retention process. Public integrity receipts may preserve non-identifying commitments where deletion lawfully permits, while the live profile, encrypted template, device/session data and private linking material are removed. Requests or disputes can also be raised through the public contact channel.
Service providers and locations
The site is delivered using Cloudflare Workers, Static Assets and D1. Resend processes the destination email address when an email verification code is requested. Google or Apple processes the sign-in request only when that provider is selected. Provider infrastructure and security processing may occur in multiple locations. The research workspace sends its fixed-length AES-GCM encrypted template and minimal protocol metadata to the server.
Children and third-party recordings
Do not use this pilot for a child, a deceased person, a celebrity, a secretly recorded conversation or a recording containing another person. These categories require separate legal, consent and safeguarding processes that are not available here.
Changes and contact
This interim notice will change as the pilot governance and operator details are established. See the contact status page. Do not send personal or sensitive information outside the account and encrypted pilot flows described here.