Legal — Privacy Policy
Privacy Policy.
Effective April 30, 2026
Introduction
Suspiro is a product of Bookit Labz LLC (“we”, “us”, “Suspiro”). This Privacy Policy explains how we collect, use, and protect your information when you use our service.
We’ve designed Suspiro with privacy as the foundation. The most sensitive data on our platform — your personal conversations, voice recordings, and the AI clones derived from them — is treated with the highest level of care.
Information We Collect
Account Information: email, name, password (hashed), profile photo if you choose to upload one.
Self-Clone Data: voice recordings, written messages, photos, and other materials you provide to create your own AI clone.
Loved-One Clone Data: chats, voice recordings, photos, and other materials you upload about another person to create their AI clone.
Conversation Data: messages you exchange with your AI clones, including text and voice.
Usage Data: how you interact with the service (page views, feature usage). We do not track you across other websites.
How We Use Your Information
- To create and operate your AI clones
- To provide the chat and voice interaction features
- To manage your account and billing
- To improve the service through aggregate analytics
- To respond to support requests
- To enforce our Terms of Service and Acceptable Use Policy
We do NOT:
- Sell your data to third parties
- Use your conversations or clone data to train foundation AI models
- Share your private clones with anyone (loved-one clones are always private)
- Use your data for advertising purposes
How We Share Information
Third-party processors: We use the following services to operate:
- Supabase (database, authentication, file storage) — data hosted in US
- Anthropic Claude (AI chat generation) — data processed under their privacy policy
- ElevenLabs (voice synthesis) — used for self-clones with voice cloning
- Resend (transactional emails)
Each processor signs a Data Processing Agreement and is contractually obligated to protect your data.
Legal compliance: we may disclose information if required by law, court order, or to protect our rights, users, or third parties.
Business transfers: in case of merger or acquisition, your data may be transferred to the acquiring entity, who must honor this Privacy Policy.
Self-Clones vs. Loved-One Clones
Suspiro distinguishes between two types of clones:
Self-clones
AI representations of yourself. You control privacy settings — public, private, or accessible only to friends you accept. You can change this at any time. Public self-clones are only accessible to authenticated Suspiro users (never anonymous visitors).
Loved-one clones
AI representations of another person. These are ALWAYS PRIVATE. Only you, the creator, can interact with them. We have built no mechanism to share them, make them public, or grant access to others. This is a core privacy commitment, not a feature limitation.
By creating a loved-one clone, you confirm you have legitimate access to the source materials and authorization to create the clone. You also confirm the person is not a public figure.
Data Retention
- Active account: retained while account is active
- Specific clone deleted: data permanently deleted within 30 days
- Account deleted: ALL data permanently deleted within 30 days
Some operational logs (anonymized) may be retained longer for security and legal compliance.
Your Rights
EU/UK users have full GDPR rights. California users have CCPA rights. Other users have:
- Access: request copy of all your data
- Deletion: request deletion of specific data or entire account
- Portability: receive data in machine-readable format
- Correction: update inaccurate information
- Objection: object to certain types of processing
To exercise rights: hello@suspiro.ai
Security
- AES-256 encryption at rest via Supabase infrastructure
- TLS 1.3 encryption in transit
- Two-factor authentication support
- Regular security audits
- Access controls and audit logs (including consent attestations)
We will notify you within 72 hours of any breach affecting your data.
Children’s Privacy
Suspiro is not intended for users under 18. We do not knowingly collect data from minors. If we discover a minor has registered, we will delete the account immediately.
International Data Transfers
Data is hosted on US servers. EU users: we rely on Standard Contractual Clauses for cross-border transfers.
Changes to This Policy
We may update this Privacy Policy. Material changes will be notified via email at least 30 days before they take effect.
Contact
- Email: hello@suspiro.ai
- Bookit Labz LLC, 30 N Gould St Ste N, Sheridan, WY 82801