Privacy Policy
Last updated: May 28, 2026 · Effective: June 1, 2026
Contents
1. Plain-English summary.
Your content is yours. Your twin is yours. We never sell your data. We never train models for other users on your footage, your face, or your voice. If you delete your account, we delete the data — including all twin model weights, voice clones, and enrollment footage — within 7 days.
The rest of this document is the long version. Read it carefully if you operate in a regulated industry or under GDPR/CCPA/EU AI Act jurisdiction. Email privacy@encore.app with questions.
2. What we collect.
Account data
- Email address, name, password hash, billing information (handled by Stripe — we never see card numbers).
- Device identifiers, OS version, app version (for crash reporting).
- Usage telemetry (anonymized) to improve the product.
Content data
- Footage you upload, drag-drop, or pull from connected libraries (iCloud, Drive, Dropbox, Photos).
- Generated outputs (Library Mode + Twin Mode renders).
- Brand kit elements (colors, fonts, logo, voice samples).
- Posting history and analytics returned by connected social channels.
Twin data — special category
- Liveness check biometric (face + voice).
- Enrollment footage (2-5 min guided capture).
- Voice clone model.
- Trained twin model weights.
3. How we use it.
- To deliver the product. Render your video, train your twin, schedule your posts, return your analytics.
- To improve the product. Aggregated, anonymized usage patterns inform feature decisions. We never inspect individual content.
- To prevent abuse. Liveness checks prevent enrollment fraud. Embedding-distance checks prevent celebrity impersonation.
- To comply with law. Including EU AI Act transparency obligations and any applicable deepfake disclosure laws.
4. Your Twin data (special category).
Twin data is the most sensitive category we handle. We treat it accordingly.
- Only you can enroll your twin. Liveness check + account verification required.
- Your twin is cryptographically linked to your account. No one else can use it.
- We never use your twin to train models for other users. Ever. Under any circumstance.
- Every twin render carries an invisible watermark (C2PA-compliant) plus an entry in the immutable audit log.
- You can delete your twin at any time. Model weights, voice clone, enrollment footage — all purged within 7 days of request.
- Twin renders require 2FA after the first 24 hours from a new device. Push and email notification fire on every render.
5. Who we share data with.
We share narrow categories of data with the following processors, all under DPAs that prohibit secondary use:
- Cloudflare R2 / AWS S3 — video and footage storage.
- Stripe — payment processing.
- Anthropic (Claude) / OpenAI / Google (Gemini) — reasoning and video understanding (prompt + frame samples only).
- Hedra / HeyGen / ElevenLabs — twin and voice rendering (enrollment data + scripts).
- Persona / Veriff — liveness checks.
- Sentry / Datadog — crash reporting and observability.
We do not sell data to third parties. We do not run advertising. We do not share data for marketing purposes outside of ENCORE.
6. Your rights.
Depending on your jurisdiction, you have some or all of the following rights:
- Access. Request a copy of all data we hold about you.
- Deletion. Request full deletion of your account and associated data, including twin.
- Portability. Export your brand kit, content, and analytics in standard formats.
- Correction. Update inaccurate information.
- Objection. Object to specific processing activities.
- EU AI Act transparency. See the model used, the enrollment date, and the audit log for every twin render.
To exercise any right, email privacy@encore.app. We respond within 30 days (often within 72 hours).
7. Data retention.
- Active accounts: data retained as long as the account is active.
- Deleted accounts: full deletion within 7 days. Backups purged within 30 days.
- Twin audit logs: retained 7 years for compliance with deepfake disclosure laws, then purged.
- Anonymized aggregate telemetry: retained indefinitely. Cannot be linked back to you.
8. Security.
- TLS 1.3 in transit. AES-256 at rest.
- SOC 2 Type II audit in progress (targeted completion: Q3 2026).
- Bug bounty program active for verified researchers.
- Sub-processors audited annually.
9. Children.
ENCORE is not directed at children under 13 (or under 16 in the EU/UK). We do not knowingly collect data from minors. If you believe a minor has created an account, email privacy@encore.app and we will delete it.
10. Contact us.
Privacy inquiries: privacy@encore.app
General contact: hello@encore.app
EU representative: appointed prior to EU launch (Q3 2026).
Data Protection Officer: appointed for SOC 2 audit phase.
This document is written in plain English on purpose. If anything is unclear, that’s our problem to fix. Email us.