YOUR DATA, EXPLAINED
Privacy policy
What the hosted SvaraCraft studio receives, why it needs it, and the choices you have.
1. About this service
SvaraCraft is a narration service operated by N Chaitanya Kumar as an individual (“we”, “us”). This notice covers the website and hosted studio at svaracraft.com. For privacy questions or complaints, contact N Chaitanya Kumar at nalamalan@gmail.com.
2. Information we receive and why
- Account information: your email, display name, internal account and workspace identifiers, verification status and account timestamps. Email/password accounts store a salted password hash, not the plaintext password. We use these records to sign you in and keep customer workspaces separate.
- Your studio content: scripts, project and passage text, pronunciation rules, voice descriptions, uploaded reference recordings, consent notes, settings, generated audio, selected takes, exports and related production records. We process and store this to carry out your requests and let you return to saved work.
- Jobs and usage: request identifiers, job status, results, timestamps and narration allowance records. These support queued processing, recovery, limits and troubleshooting. Unfinished jobs may retain a working copy of their input.
- Billing records, if you subscribe: internal account/workspace references, subscription, payment and invoice identifiers, amounts, currency, billing periods, payment and cancellation status, verified allowance and refund/dispute information. We use these records to verify payments, provide paid allowance, manage renewals, prevent duplicate credit and review billing requests. See payment processing.
- Security and diagnostics: IP/client information, browser/request metadata, timestamps, request paths, response status and authentication-attempt counters. Some counter identifiers are hashed; this does not make all logs anonymous. We use this information to operate the service, prevent abuse and investigate failures.
- Messages you send us: your contact details and the contents of support or privacy correspondence, used to respond to your request. Do not include passwords, one-time codes, government IDs or unnecessary private recordings.
We do not sell your personal information, place our own advertising trackers in the studio, or use your scripts and recordings to train models as part of this service. Generating narration uses existing models; it is not a promise about independent providers’ separate services. Optional payment checkout has its own provider data practices, described below.
3. Google sign-in
Google sign-in is optional and currently limited to approved pilot accounts. We request only the identity scopes openid, email and profile. We use your Google account identifier, verified email and display name to create or identify your studio account. Google may include a profile-picture claim in its response; the studio does not use or save that picture.
We do not request access to Gmail messages, Drive files, contacts or offline access. Google access and identity tokens are processed for the sign-in exchange and are not saved in the account database. Short-lived, browser-bound sign-in state is used to protect the flow. We do not automatically merge a Google identity with an existing email/password account.
You can remove SvaraCraft’s access in your Google Account connections. This prevents future use of that grant; it does not itself erase the SvaraCraft account, saved files or an already-issued studio session. You can sign out and contact us to review account closure.
4. Cookies and browser drafts
The studio uses an essential sign-in cookie with a maximum lifetime of seven days and a Google-flow cookie lasting up to five minutes. In production these are Secure, HttpOnly and SameSite=Lax. Signing out invalidates the current studio session; password resets revoke that account’s studio sessions.
Account-scoped browser sessionStorage holds drafts, settings and pending-job references. This is not cloud backup. Explicit logout and password-reset flows clear relevant drafts in the tab where the flow runs; other open tabs may retain drafts until closed or cleared. An expired session alone can leave drafts on the device. Shared-device users should sign out and close all their studio tabs. Blocking essential cookies can prevent sign-in. The public informational pages do not load analytics, advertising scripts or a Google sign-in SDK.
5. Hosting, email and other providers
- Hostinger: hosts the VPS running our application and stored studio data. Hosting infrastructure also processes connection/security information. See Hostinger’s privacy policy.
- Resend: delivers verification and password-recovery mail. Delivery requires the recipient address, sender, subject and email body, including the one-time link. See Resend’s privacy policy. Our automated sending address is not necessarily a monitored support inbox.
- Google: handles your optional Google authentication. Separately, Google email services process support and privacy messages sent to our listed Gmail contact address, whether or not you choose Google sign-in. See Google’s privacy policy.
- Razorpay: processes payments and recurring mandates when you choose an available paid checkout. It receives checkout/contact and transaction information necessary for that payment flow and applies its own privacy policy. See the payment-processing details below.
- Operator backups: private copies of application data and configuration may be held on the server and on an operator-controlled computer for recovery.
Payment processing and checkout information
Paid checkout is available only when offered in your account. When you choose it, we supply Razorpay with the internal billing reference and prefill your account name and email. You may provide further contact or payment details in Razorpay’s checkout. We receive necessary payment/subscription metadata and verification responses to match a payment to your account and maintain the billing records described above. Your studio scripts and audio are not sent to Razorpay for payment processing.
Full card numbers, CVV values, bank passwords and OTPs are entered in Razorpay or the bank/payment provider’s flow, not in SvaraCraft’s forms; our application does not store those payment credentials. Razorpay checkout may process browser/device and connection information and use its own cookies or similar technology. The public pricing and policy pages do not load the checkout script. Never send payment credentials to support.
The current hosted studio generates preset narration on the studio server’s CPU. Remote GPU voice cloning and external transcript verification are not active. If introduced, those features require a clear disclosure before use: a remote voice worker can receive scripts and reference audio, and an external transcription service can receive generated audio. They are not covered by a promise that every future feature will be processed only on our server.
We may also disclose necessary information to comply with lawful requests or investigate security incidents. Service providers can process information in countries where they operate; we do not promise India-only storage. Contact us for deployment information before uploading location-restricted or confidential material.
6. Retention, deletion and backups
Saved content and account records remain available for the service and do not currently expire on an automatic schedule. Job payloads, security records, retained audit information and backup copies have different lifecycles. Billing records may need to remain for payment reconciliation, refund/dispute review and applicable recordkeeping requirements even after cancellation or account closure. Verification links expire after 24 hours and reset links after 30 minutes; a link’s expiry does not mean all related database records have been physically erased.
You can remove supported individual items in the studio. Deleting a voice’s source recordings does not remove earlier generated audio; a minimal voice audit record may remain. You can separately delete generated takes where that control is available.
Account closure is a manual review, not an instant-delete button. Use My account or contact us at nalamalan@gmail.com. The in-app request does not itself erase content, stop jobs, cancel a subscription, close provider accounts or remove backups. Manage renewal separately as explained in cancellation terms. Google-only users can contact us directly, or first set a local password through recovery to use the password-confirmed request screen. We may verify ownership without asking for your password.
The service does not yet have an automatic backup-expiry schedule or a guaranteed erasure turnaround. We must review live data, job records, applicable obligations and backup handling before confirming completion. We will explain the outcome and any information that must be retained; requesting deletion is not evidence that deletion is complete. Do not upload content that requires a deletion deadline the service cannot meet.
7. Security and appropriate content
We use HTTPS, password hashing, account/workspace separation and restricted administrative access. The hosted service is not end-to-end encrypted: necessary server processing and authorized operational support can access content. Backup scripts restrict access and protect transfers but do not encrypt the archives themselves. No service can guarantee absolute security.
This service is intended for adult educators, narrators and other adult creators, not children’s accounts. Do not upload students’ private records, children’s voices, highly sensitive personal information or material you lack permission to process. Contact us if you believe a child has provided personal data, so it can be reviewed.
8. Your choices and privacy requests
You may ask to access or correct account information, receive available copies, stop optional processing, or review deletion by contacting nalamalan@gmail.com. Explain the account email and your request; do not send login secrets. We will consider the rights and response requirements that apply to you. You retain any right to approach the appropriate regulator; this notice does not limit statutory rights.
You can choose verified-email signup instead of Google, remove a Google grant, decline to upload optional recordings, download available outputs and stop using the service. Some data is necessary to provide an account and stored-workspace service.
9. Updates to this notice
We will update the effective date when this notice changes. A material new use of Google or other personal data requires an appropriate notice and any required consent before that new use. A service update does not silently authorise advertising, model training or a new paid subscription.