Legal · CelestLabs

Privacy Policy

Last updated 21 July 2026

This policy explains what CelestLabs collects when you use our website, API and dashboard, why we collect it, and the choices you have.

Information we collect

  • Account data, the email address and credentials you use to create an account, managed through our authentication provider.
  • Usage data, API requests, characters synthesised, models, voices and languages used, and billing metering, so we can run the service and bill per character synthesised.
  • Technical data, IP address, request metadata and logs for security, abuse prevention and reliability.
  • Product analytics, described in the next section.

We do not sell your personal data, and we do not use the text you submit for synthesis to train models.

Analytics and cookies

We run PostHog for product analytics, so we can see which pages and features get used and where people get stuck. PostHog stores a randomly generated visitor identifier in a cookie and in your browser's local storage. That cookie is set across our subdomains, because signing up takes you from celestlabs.ai to dashboard.celestlabs.ai and we would otherwise count one person as two.

What is recorded depends on where you are:

Public pages
Website, docs and this policy. We record page views, clicks and basic device and referrer information, plus session replays of how the page was used. Replays mask every input, so anything you type is not captured.
Signed-in dashboard
Hardened. Automatic click capture and session replay are both switched off, because those screens display API keys. Only a small set of explicit events is recorded, such as "a key was created".

Analytics never captures API keys, passwords, bearer tokens, the text you send for synthesis, or any audio you upload, record or generate. Playground events carry the length of a piece of text and nothing else.

We do not run advertising or ad-retargeting cookies, and we do not share analytics data with advertising networks.

Besides analytics, the dashboard sets a session cookie when you sign in. That one is strictly necessary: without it you cannot stay logged in.

Your choices on analytics

We do not currently show a cookie consent banner. Instead, analytics is switched off automatically for anyone whose browser sends a Do Not Track signal, and you can opt out at any time by visiting any page on this site with ?analytics=off appended to the address. Your choice is remembered in your browser, and you can reverse it with ?analytics=on. Clearing your browser storage clears both your opt-out and the analytics identifier.

How we use it

To provide and meter the API, authenticate your account, prevent abuse, understand and improve the product, comply with law, and send you service updates. Submitted text and generated audio are processed to fulfil your request and are retained only as long as needed to deliver and debug the service.

Sub-processors

We rely on a small set of providers to operate the service. They process data on our behalf, under their own security and privacy commitments:

  • Amazon Web Services, hosting, storage and networking, and outbound service email.
  • Supabase, authentication and the application database.
  • PostHog, product analytics and session replay, hosted in the United States.

Using these providers means your data may be processed outside your own country, including in the United States.

Your rights

Subject to applicable law, including the GDPR, you may request access to, correction of, or deletion of your personal data, and you may object to or restrict certain processing. Contact us to exercise these rights.

Retention and security

We keep data for as long as your account is active, or as long as needed for legal, billing and security purposes, then delete or anonymise it. We apply standard industry safeguards including encryption in transit and access controls. We do not currently hold a SOC 2 report or an ISO certification, and we will say so plainly rather than imply otherwise. No system is perfectly secure.

Contact

Questions about this policy: hello@celestlabs.ai.

This document is written in plain language for transparency and is not legal advice. The definitive terms are those executed with CelestLabs. Questions: hello@celestlabs.ai.