Casola
ProductAvatarsPricingDocsBlogEnterprise
Sign in Start building
ProductAvatarsPricingDocsBlogEnterprise Sign in Start building

Privacy Policy

Last updated: August 2, 2026

Effective date: August 2, 2026

Casola, 440 N. Wolfe Rd, Sunnyvale, CA 94085. Contact: privacy@casola.ai.

If you only read one section, read Section 5. Conversations with our avatars are recorded, including the audio from your microphone.

1. Scope, and Our Two Roles

This Policy covers personal data we handle in two very different situations, and which one you are in changes almost everything below.

We are the controller for:

  • people who use the Casola consumer service (the app at app.casola.ai and the demos on this site),
  • visitors to casola.ai,
  • the individuals who register for, administer, or pay for an API account.

For these relationships we decide why and how the data is processed, and this Policy is the full description of it.

We are the processor for end-user personal data that an API customer routes through the Service. There, the customer is the controller: they decide what is sent, what it is for, and how long it is kept. Our agreement with that customer governs, including any Data Processing Addendum they have signed, and their privacy policy rather than this one describes the processing to their end users. If you reached an avatar through someone else’s product, they are who you should contact.

One narrow exception cuts across both: for the safety screening and reporting in Section 7 we act as an independent controller on our own legal duties, whatever a customer instructs.

Casola is established in the United States, so US law leads for our direct relationships. Where we process the personal data of people in the EEA or the UK, the GDPR and UK GDPR terms below apply. Regional detail is in the annexes at the end.

2. What We Collect

From consumer users

  • Account identity: your name, email address, profile picture, and the provider identifier from the Google or GitHub account you sign in with. We do not receive or store your password for those accounts.
  • Session recordings: the audio from your microphone, saved as one file per conversational turn; video clips of the avatar’s replies; and a recording of the whole session. Section 5 covers this in full.
  • Conversation content: what you say and what the avatar says back, including the transcript and any context you give it.
  • Session metadata: which avatar you spoke to, when, for how long, which language, how the session ended, and the technical records of the connection.
  • Voice and likeness samples, if you create a custom avatar or clone a voice. Section 5 covers what we derive from them and how long we keep it.
  • Subscription and billing data: your plan, billing period, and payment status. Card numbers are handled by our payment processor; we never see or store them.
  • Feedback and support requests you submit, including ratings, messages, the account and workspace they concern, and page, browser, or session details you choose to include.
  • Device and technical data: IP address, browser and device identifiers, and the logs we keep for security, rate limiting, and abuse prevention.

From API customers and their staff

  • Account and contact data: name, work email, company, role, and sign-in identity of the people who create or manage the account.
  • Verification (KYC) data we collect to approve and maintain access.
  • Billing data: plan, usage records, and billing contact.
  • Usage and technical data: API request metadata, logs, IP address, and identifiers used for security, rate limiting, and abuse prevention.
  • Support and communications: messages you send us and the records around them.

From site visitors

Pages viewed, referrer, approximate location from IP, and the analytics identifiers described in Section 6 and Section 13.

From an API customer’s end users

Inputs and Outputs passing through the API, and session captures where the customer has switched them on. We process all of it as that customer’s processor, on their instructions, and Section 1’s processor rules apply rather than the rest of this Policy.

3. How We Use It

For everyone:

  • Provide, operate, and secure the Service and your account.
  • Prevent fraud and abuse, enforce the Acceptable Use Policy, and keep the platform available.
  • Bill you, and verify business customers (KYC).
  • Answer support requests, and send service messages. Marketing goes out only with your consent where consent is required.
  • Comply with law, including the reporting duty in Section 7.

For consumer users, additionally:

  • Improve our own models. We use aggregated, de-identified logs from consumer sessions — not your voice or the recordings — to build internal evaluation sets and to tune our avatar and safety models.

We keep that use narrow:

  • It applies to consumer data only, never to data an API customer routes through the Service. See the Developer & API Terms, Section 10.
  • It stays with our own avatar and safety models. We do not sell personal data, share it for advertising, or let any third-party model train on it.
  • You can opt out in your account settings (or at privacy@casola.ai); we then exclude your future sessions. Because the logs are de-identified and aggregated, a session already in an evaluation set can’t be traced back to remove individually.

4. Legal Bases (GDPR and UK GDPR)

Where the GDPR or UK GDPR applies, we rely on:

  • Performance of a contract to provide the Service, run your account, deliver a subscription, and provide support.
  • Legitimate interests for security, abuse prevention, service reliability, product improvement, and B2B marketing. For the model-improvement use in Section 3 we have carried out a balancing assessment: the data is de-identified and aggregated, confined to our own systems, not sold or shared, and not used to make decisions about you, and you can opt out at any time.
  • Consent where the law requires it, including analytics cookies in the EEA and UK, marketing where applicable, and the explicit consent for voice and biometric processing in Section 5. You can withdraw consent at any time; withdrawal does not affect processing that already happened.
  • Legal obligation for KYC, tax, and the safety reporting in Section 7.

5. Recording, Voice, and Biometric Data

This section is about the consumer service. For API sessions, see the end of it.

What we capture

When you have a conversation with an avatar, we store:

  • your microphone audio, saved as one audio file per turn you speak,
  • video clips of the avatar’s replies,
  • a recording of the whole session,
  • the transcript of both sides, and
  • logs tagged with the session identifier.

Your microphone is live only during a session. We do not listen when you are not in one.

Why

To deliver the conversation, to let you play back your own sessions, and to investigate faults and abuse. The model work in Section 3 uses de-identified logs, not these recordings.

How long

Recordings are deleted 30 days after the session, automatically. Section 8 has the full schedule.

Deleting your recordings, and objecting

  • Automatically. Every recording is deleted 30 days after the session, without you doing anything.
  • On request. Ask us at privacy@casola.ai to delete a session’s recordings sooner, or all of them, and we do.
  • Everything at once. Closing your account removes every recording attached to it. See Section 9.
  • Model improvement. To stop us using your recordings for the model work in Section 3, write to privacy@casola.ai. We act on it going forward, and it does not stop the Service from working.
  • Not recording at all. Recording is part of a live session. If you do not want to be recorded, do not start one.

Voice cloning and custom likeness

If you create a custom avatar from a face image, or clone a voice from a speech sample, we derive and store a voice or likeness model from that sample. A voiceprint of this kind is biometric data in some jurisdictions, including under Illinois’ BIPA and equivalent laws in Texas and Washington.

  • We collect it only to create and run the avatar or voice you asked for.
  • We do not sell, lease, trade, or otherwise profit from biometric identifiers.
  • We do not disclose them except to the subprocessors in Section 6 who run the inference, where the law permits, or where a warrant or subpoena requires it.
  • We keep them until you delete the avatar or voice, or you close your account, or three years after your last interaction with us, whichever comes first. Then we destroy them.
  • You may only submit a face or voice that is yours, or one you have the person’s express, written consent to use. Consent to be photographed or recorded is not consent to be cloned.

If someone has used your face or voice, write to privacy@casola.ai with enough detail for us to find the material. You do not need an account with us. We will ask you for enough to confirm the likeness is yours, and if we find it we stop the avatar or voice from being used, destroy the image, sample, and any derived model on the schedule above, and tell you when it is done. Revoking consent is free, takes effect for the future, and does not require a reason.

API sessions

Sessions created through the API can capture the end user’s microphone audio, the avatar’s reply clips, a whole-session recording, and session-tagged logs. The customer controls this per session: new integrations opt in explicitly (recording), and until every renderer generation honours that switch, a session whose customer says nothing may still be captured — treat capture as on unless the customer switched it off, which turns off everything. What we hold we hold as the customer’s processor, for their debugging and support only, and we never use it to train or tune anything of ours. Captures are deleted 30 days after the session. Disclosing the recording to their end users is the customer’s responsibility.

The anonymous demos on this website switch capture off on every session: demo conversations store no microphone audio, no clips, and no recording. The end screen shows a conversation ID — email privacy@casola.ai with it to have the session’s remaining records erased.

6. Who We Share With

We do not sell personal data. We share it with:

  • Subprocessors who run parts of the Service under contract and act only on our instructions. The current list, with what each one does and where, is published at Subprocessors. It includes our hosting and edge provider (Cloudflare, US), the GPU compute the models run on, our payment processor (Stripe, US), the OAuth providers you choose to sign in with, our analytics provider, and a self-hosted observability system on rented infrastructure in Germany that receives session and application logs.
  • Authorities, where the law requires it or where it is necessary to protect someone’s safety, including NCMEC (Section 7).
  • Corporate, meaning affiliates in our group and any successor in a merger or sale, subject to this Policy.

Analytics

We share pseudonymous analytics identifiers with Google (Google Analytics 4), and — when you are signed in to the dashboard — your internal Casola user identifier, which is never your name, your email, or sent to any advertising product. This runs only where analytics are permitted under the consent model in Section 13, and clearing your consent stops it.

7. Safety Screening and Reporting

We screen text you save as a script against a maintained list of patterns for prohibited content, including markers of child sexual abuse material, credible threats of violence, and incitement. Matches are blocked and logged, and they count towards enforcement. This screening does not run on live conversation, which reaches the model unscreened. Section 5 of the Acceptable Use Policy describes the enforcement stack.

Where we detect or are told about suspected child sexual abuse material, we are legally required to report it to the NCMEC CyberTipline under 18 U.S.C. §2258A, to preserve the related records, and to cooperate with law enforcement. For this we act as an independent controller. Those obligations override deletion requests for the specific records involved.

We do not make decisions with legal or similarly significant effects about you by automated means alone. Screening classifies content, not people.

8. How Long We Keep Things

WhatHow long
Session recordings (microphone audio, avatar clips, whole-session recording)30 days after the session, then deleted automatically
Transcripts and session-tagged logs30 days, on the same schedule as the recordings
Session records (which avatar, when, how long, how it ended)Life of the account, deleted when you close it
Operational and security logs, including tool-call and agent recordsUp to 90 days
Sign-in handshake stateTransient — deleted automatically once sign-in completes
Avatar memory (what an avatar remembers between conversations)Until you or the developer erase it, you close your account, or one year passes with no conversation using it. Erasure is immediate; for up to seven days afterwards we re-check that no copy was written back while a conversation was still ending
Voice and likeness modelsUntil you delete them, close your account, or three years after your last interaction, whichever is first
Account, KYC, and billing recordsLife of the relationship plus 7 years, for tax and legal compliance
Feedback and support requests you submitLife of the account, deleted when you close it
Safety and reportable records (Section 7)As long as legal, evidentiary, and abuse-prevention duties require, which may exceed every period above

Deletion runs on a daily schedule rather than at the exact minute a period expires, except for avatar-memory erasure, which happens when you ask and is re-checked hourly for a week afterwards.

For end-user data we process on an API customer’s behalf, we delete or return it within 30 days of the end of that relationship, except for Section 7 records. An executed DPA may set different periods.

9. Your Rights

Depending on where you live, you have rights to access, correct, delete, port, restrict, or object to the processing of your personal data, and to withdraw consent.

Self-serve, from your account settings:

  • Export. Download everything we hold about your account as a single file: your profile, your sign-in identities, your workspaces, your session history and usage, your API credentials’ metadata, your feedback and support requests, and an inventory naming every recording we still hold. The recordings themselves stream from your session history, which is where they are large enough to belong.
  • Delete your account. This erases your session recordings, deletes your sessions, transcripts, sign-in identities, API credentials, feedback, and support requests, and closes your workspaces. What remains afterwards is an account identifier with no personal data attached to it, kept because our billing and audit records point at it, and any record we must keep under Section 7 or for the tax periods in Section 8.

By email: write to privacy@casola.ai for anything else, including access, correction, restriction, and objection. We respond within the deadline the applicable law sets, and we tell you if we need longer and why. We may ask you to confirm you control the account before we act.

Where the GDPR or UK GDPR applies you also have the right to complain to your supervisory authority, and you can do that without going through us first.

If you reached an avatar through another company’s product, contact that company. They are the controller. We will help them respond as our agreement with them requires.

10. International Transfers

We are based in the United States and our infrastructure is primarily Cloudflare’s global network, so personal data is processed in the US and at edge locations worldwide. Our observability system runs on rented infrastructure in Germany, so application and session logs are processed in the EU.

For transfers out of the EEA or the UK we rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum for UK transfers, and we assess the destination before relying on them. Where an API customer routes EEA or UK end-user data through the Service and has executed our DPA, the mechanism in that DPA governs.

11. Children

The Service is for adults. You must be 18 or older to use it. We do not knowingly collect personal data from anyone under 18, and we do not direct any part of the Service, including the avatar personas, at children. If we learn that an account belongs to someone under 18, we close it and delete the data. If you believe a child has given us personal data, write to privacy@casola.ai and we will remove it.

12. Security

We use encryption in transit and at rest, scoped and short-lived credentials, role-based access control, and access logging. No system is perfectly secure; report a vulnerability to security@casola.ai.

13. Cookies and Similar Technologies

Cookies are small files a site stores on your device; pixel tags and local storage work analogously. We group them in two categories.

Strictly necessary. Required for the site to work — security tokens, session state, and fraud-prevention signals. These are set without consent, and disabling them breaks the site.

Analytics. We use Google Analytics 4 (Google LLC), which sets cookies (_ga, _ga_*) to distinguish visitors and measure how the site is used. On the marketing site these are pseudonymous identifiers only. When you are signed in to the dashboard we also pass Google Analytics your Casola user identifier, so we can count one person across their devices; that identifier is internal to us, is not your name or email, and is never sent to an advertising product. Google may transfer data to the US under its SCCs.

Consent model, by region. In the EEA, the UK, and Switzerland analytics are opt-in: nothing is collected until you accept the banner on your first visit. In the United States and the rest of the world they are on by default and you can turn them off at any time. Either way your choice reaches Google before any measurement, through Google Consent Mode v2.

Where your choice is stored. casola.ai keeps the full record in your browser’s local storage under casola-cookie-consent, and writes a short domain-scoped casola-consent cookie that app.casola.ai reads so the dashboard honours the same answer without asking again. Both are ours, neither is shared, and clearing either brings the banner back. The casola-consent cookie expires after 12 months; strictly-necessary cookies last a session to a year; analytics cookies up to two years (provider-set).

Changing your choice. Click “Cookie settings” in the footer to reopen the banner at any time.

14. Changes and Contact

We may update this Policy. For changes that materially affect you we give notice by email and in the app before they take effect. The “last updated” date at the top always reflects the current version.

Privacy: privacy@casola.ai. Security: security@casola.ai. Postal: Casola, 440 N. Wolfe Rd, Sunnyvale, CA 94085. If you are in the EEA or the UK and want to raise a data-protection concern, either address reaches us.


Annex A: California

This annex is our notice at collection under the CCPA as amended by the CPRA, and it describes the rights of California residents.

Categories we collect, with the purposes in Section 3 and the retention periods in Section 8: identifiers (name, email, IP address, account and device identifiers); commercial information (subscription, billing, usage); internet activity (pages viewed, session metadata); audio and visual information (session recordings, avatar clips, uploaded images); professional information (company and role, for business accounts); and inferences drawn for product quality and safety. Sources: you, your sign-in provider, and your device. We disclose these categories to the subprocessors and recipients in Section 6 for business purposes.

Sensitive personal information. Session recordings and the voice and likeness models described in Section 5 are treated as sensitive personal information. We use them only to perform the Service and to keep it safe and secure — not to build or train models, which use only de-identified logs (Section 3). You still have the right to limit our use of it. Email privacy@casola.ai with “Limit the use of my sensitive personal information”, and we confine it to performing and securing the Service; it does not stop the Service from working.

We do not sell personal information and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months. No one under 18 may use the Service at all, so we never knowingly sell or share a minor’s personal information.

Your rights: to know, to access, to correct, to delete, to port, to limit sensitive personal information, and not to be discriminated against for exercising any of them. Use the export and delete controls in your account settings, or email privacy@casola.ai. You may use an authorised agent; we will ask for proof of authorisation and may ask you to verify directly.

Annex B: EEA and UK

The controller is Casola, 440 N. Wolfe Rd, Sunnyvale, CA 94085. Write to privacy@casola.ai and it reaches the people who can act.

Your rights are set out in Section 9, and the legal bases we rely on are in Section 4. You have the right to object at any time to processing based on legitimate interests, including the model improvement in Section 3, and the right to complain to the supervisory authority where you live, work, or where the issue arose. Transfers are covered in Section 10.

Annex C: Other US States

If you are a resident of Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah, or Virginia, you have rights to confirm and access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, sale, and profiling with legal or similarly significant effects. We do not conduct any of those three activities.

Session recordings, and the voice and likeness models in Section 5, are sensitive data under these laws; we use them to perform and secure the Service, not to train models (the model work in Section 3 uses de-identified logs). Where your state gives you the right to limit or opt out, exercise it at privacy@casola.ai and we confine our use accordingly; you can also delete the recordings on request. Exercise your other rights through your account settings or at privacy@casola.ai. If we deny a request you may appeal by replying to our decision, and we will respond within 45 days and tell you how to contact your state attorney general.

We use analytics cookies to improve casola.ai. Cookie Policy

Casola

© Casola. Real-time avatar and video APIs.

DocsBlogPrivacyTermsDeveloper TermsAcceptable UseAI DisclosureSecuritySubprocessorsContact