8 Total
4 High severity
4 Medium severity
0 Low severity
Summary

ElevenLabs' privacy policy explains how the AI voice technology company collects and uses your personal data, including voice recordings you upload or generate on its platform. The most important thing to know is that ElevenLabs may use your voice recordings — which are biometric data — to train and improve its AI models, and this data may be shared with third-party partners and advertising services. You can request deletion of your personal data, including voice data, by contacting ElevenLabs at privacy@elevenlabs.io.

Technical Summary

This document is ElevenLabs' privacy policy governing the collection, use, and disclosure of personal data across its AI voice generation platform, with legal bases rooted in consent, legitimate interests, and contractual necessity under GDPR and equivalent frameworks. The most significant obligations include ElevenLabs' collection of voice recordings and biometric voice data submitted by users for AI model training, sharing of personal data with third-party service providers, advertising partners, and in the context of business transfers. Notably, the policy permits ElevenLabs to use user-submitted voice data to improve its AI models, which constitutes processing of biometric data — a category requiring explicit consent under GDPR Art. 9 and analogous state biometric privacy laws such as Illinois BIPA — yet the policy's consent mechanism for this processing is not clearly delineated. The policy engages GDPR (including Art. 6 lawful basis and Art. 9 special categories), CCPA/CPRA for California residents, Illinois BIPA for biometric data, and the EU AI Act given the biometric and voice-cloning nature of the service; material compliance considerations include adequacy of consent for biometric voice processing, sufficiency of data subject rights mechanisms, and the absence of explicit retention periods for voice model data.

Evidence Provenance
Captured April 29, 2026 08:12 UTC
Document ID CA-D-000450
Version ID CA-V-001028
Wayback Machine View archived versions →
SHA-256 c46d818d8ec7c8caf3c9e1c1f964ecb206500254d46ee155716f7423646fb3ec
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Cryptographically signed
Institutional Analysis

🔒 Institutional analysis locked

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Upgrade to Professional — $149/mo
Change Timeline
View full version history (0 captures) →
High Severity — 4 provisions
Medium Severity — 4 provisions

Cross-platform context

See how other platforms handle Data Retention and similar clauses.

Compare across platforms →