SpeechAnvil

Privacy policy

Last updated: [DATE]

Who we are

SpeechAnvil is operated by [LEGAL ENTITY / OPERATOR NAME], trading as SpeechAnvil. We are the data controller for the personal data described in this policy. Contact: [PRIVACY EMAIL].

Designed around data minimisation

SpeechAnvil is deliberately built to hold as little personal information as possible. We do not ask for your name or email address, we don't offer accounts, and we don't ask for surnames, addresses, dates of birth, venues, or dates - the speech doesn't need them. This reduces both the information we hold and the impact of any potential security incident. What we do hold is pseudonymised and encrypted - and we treat it fully as personal data under UK GDPR, because encrypted personal data is still personal data.

What we collect, and why it's needed

Your interview answers: first names, stories, and preferences you type about yourself, the person the speech is about, and their partner. Providing these is necessary to use the service - without your answers there is nothing to write your speech from. Your answers are first stored by us at the moment you choose to buy, so that your speech can be delivered whatever happens to your browser. If you start a purchase but don't complete it, those stored answers are deleted automatically within 24 hours. If you never start a purchase, your answers exist only in your own browser and are not stored by us at all.

Payment details are collected and held by Stripe. We never see or store your card number, name, or email address. Your email is held by Stripe with your payment; we retrieve it only at the moment we send you your speech, and we do not store it or use it for marketing.

What we do with data, and our lawful basis

What we doLawful basis
Generate your speech from your answersContract
Process your payment (via Stripe)Contract
Email your speech to youContract
Process information about people other than you (the person your speech is about)Legitimate interests
Secure the service and prevent fraud or abuseLegitimate interests
Keep accounting and tax recordsLegal obligation

Stories about other people

Most of what you tell us is about someone other than you - the person getting married, their partner, people in your stories. For you, our customer, we process data to perform our contract with you. For the people you mention, we rely on our legitimate interest in providing the service you have asked for: the processing is limited to writing your speech, the information is the kind shared in a wedding speech in any case, it is encrypted, never used for any other purpose, and deleted within 90 days. We have carried out and recorded a legitimate interests assessment for this processing. Please only share stories you would be comfortable telling in the speech itself.

AI, and automated decision-making

We use AI, including third-party AI providers, to generate speech text from your answers. Your answers are sent to the AI provider for generation and are not used to train AI models. This is not automated decision-making that produces legal or similarly significant effects within the meaning of Article 22 UK GDPR - it writes a speech, and you decide what to do with it.

How your data is protected

Your answers and finished speech are encrypted (AES-256-GCM) before storage, with the key held separately from the database. Records are stored against random identifiers, not your name. Everything travels over encrypted connections (HTTPS).

How long we keep things

Your answers and speech are deleted automatically 90 days after purchase; an automated job enforces this daily. You can request earlier deletion at any time. Our infrastructure providers (such as our hosting and payment providers) automatically create short-term technical logs - for example IP addresses in web server logs - for security and operations under their own retention policies; we do not use these logs to identify you.

Who processes data for us

Anthropic (AI generation), Stripe (payments), Neon (encrypted database hosting), Vercel (website hosting), and Resend (email delivery), each under a data processing agreement. Where personal data is transferred outside the UK, we rely on an appropriate safeguard such as the UK Extension to the EU-US Data Privacy Framework (where applicable), the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.

Finding your record

We do not collect names or email addresses, so records can only be located using the unique speech reference issued with your speech (in your delivery email, in the form SA-XXXX-XXXX) together with your payment reference or receipt. We require both, because neither identifies anyone on its own. If we cannot identify the relevant record from the information provided, we may ask for additional information before responding to your request, in line with Article 11 UK GDPR.

If you lose access to your speech (for example, your browser data is cleared before you save it), we can restore it once we've verified your identity the same way, using a one-time recovery link that expires after 7 days and can only be used once.

Your rights

You have the right to access your data, to have it corrected, to have it deleted, to restrict or object to processing, and to data portability where applicable. Where any processing were ever based on consent, you could withdraw it at any time. To exercise any right, email [PRIVACY EMAIL] with your speech reference and payment reference; we will respond within one month.

Complaints

If you are unhappy with how we've handled your data, email [PRIVACY EMAIL] with “complaint” in the subject line. We will acknowledge your complaint within five working days and respond fully as soon as we can. You also have the right to complain to the Information Commissioner's Office (ico.org.uk). Our ICO registration number: [ICO NUMBER - added on registration].

Cookies

Our own pages use only your browser's session storage to keep your progress - no analytics, advertising, or tracking cookies. Essential technical cookies may be set by our payment provider (Stripe) during checkout for security and fraud prevention.