Twinly LabTwinly Lab

Legal

Privacy Policy

Effective September 25, 2026 · Last updated September 25, 2026 · Twinly Lab Inc., United States

Twinly Lab lets creators build an AI twin — a video avatar with their face, voice, and knowledge — that their audience can talk to. That product only works if we handle personal data carefully. This policy explains what we collect, why, who processes it on our behalf, and how you can get it removed. It covers twinlylab.com, public twin pages, and the creator dashboard.

1. Who we are

Twinly Lab Inc. ("Twinly Lab", "we", "us") is a US-incorporated company. We are the controller of the personal data described here. For anything in this policy, contact us at aleks@servada.io.

2. Data we collect

Account data. Your email address and authentication details when you sign up, plus your creator handle, display name, headline, bio, links, and pricing.

Likeness and voice data. The training footage or photos you upload to create your avatar, and the voice recordings you provide to create your voice clone.

Knowledge base content. The text you write, and public content from social profiles or pages you explicitly link so your twin can answer accurately.

Consultation data. Session records (start and end time, duration, provider identifiers), leads captured by your twin, and safety events flagged by our guardrails.

Payment data. Payment and payout records, amounts, and status. Card details are entered directly with Stripe and never reach our servers.

Technical data. IP address, browser and device information, and pages viewed, collected through server logs and analytics.

3. How we use it

  • Create and run your AI twin — training the avatar, cloning your voice, and grounding answers in your knowledge base.
  • Deliver consultations to your visitors and keep them working reliably.
  • Process payments from visitors and pay out your share.
  • Send transactional email: sign-in links, receipts, avatar-training updates, and account notices.
  • Keep the platform safe — abuse prevention, guardrail enforcement, and debugging.
  • Measure and improve our own marketing, including advertising performance.

We do not sell your personal data, and we do not license your likeness or voice to anyone. Your avatar and voice clone are used solely to power your own twin.

4. AI processing

Twinly Lab is an AI product, and we want to be explicit about what that means for your data. Your avatar is generated by third-party avatar models (Tavus and Runway) from the footage or photos you upload. Your voice clone is created by ElevenLabs from your voice recordings. Conversations with a twin are processed by large language models to generate replies, and your knowledge base is supplied to those models so the twin answers in your words.

During a live consultation, the visitor's speech is captured and transcribed by our avatar providers so the twin can respond, and the resulting audio and video are generated on their infrastructure. Visitors are told, before a session starts, that they are speaking to an AI avatar and not to a live person.

We do not use your content to train our own general-purpose models, and we do not authorise our providers to train their public models on your consultations, likeness, or voice. AI output can be inaccurate — the twin is not a substitute for professional medical, legal, or financial advice, and platform guardrails are applied to every twin to enforce that.

5. Biometric data

What we collect. Face images and video, voice recordings, and the face and voice characteristics derived from them by us or our processors.

Why. To create and operate your AI twin, and to verify that the uploaded likeness belongs to the account holder — including an automated comparison of your consent video to your avatar photo.

Consent. We collect your written consent at signup and a recorded consent statement before your twin is created.

Processors. Biometric data is processed only by the providers needed to deliver the service:

  • Runway and Tavus — avatar creation and live video.
  • ElevenLabs — voice cloning and speech synthesis.
  • Our AI verification provider — likeness verification.
  • Stripe — identity verification for payouts.
  • Our hosting provider — secure storage.

No sale. We do not sell, lease, trade, or otherwise profit from your biometric data.

Retention. Biometric data is destroyed when the purpose for collecting it is fulfilled (when you delete your twin or account), and in all cases within 3 years of your last interaction with Twinly Lab. Consent videos are deleted within 30 days of account deletion. We keep a minimal consent log — timestamp, terms version, and attestations, with no images or audio — for up to 3 years for legal defense.

6. Service providers

We rely on a small set of processors to run the product. Each receives only the data needed for its function:

  • Hosting, database, authentication, and file storage — our cloud infrastructure provider.
  • Avatar and real-time video generation — Tavus and Runway.
  • Voice cloning and speech synthesis — ElevenLabs.
  • Payments and creator payouts — Stripe.
  • Public-content collection for knowledge bases — Apify.
  • Advertising measurement — Meta.
  • Transactional email delivery — our email provider.

7. Cookies and tracking

We use essential cookies to keep you signed in and to remember session state; the product does not work without them. On our production website we also run the Meta Pixel, which sets the _fbp and _fbc cookies to attribute sign-ups and purchases to our ads. You can block these cookies in your browser or with an ad blocker without losing access to the product.

8. Your rights and choices

You can access and correct most of your data directly in the dashboard. On request, we will provide a copy of your data, correct it, or delete it.

  • Remove your photo, voice recording, and knowledge base yourself from the dashboard at any time.
  • Ask us to delete your twin, avatar, and voice clone — we remove them from our systems and instruct our avatar and voice providers to delete their copies.
  • Close your account entirely by emailing us; we remove your profile, knowledge base, and media, and complete the request within 30 days.
  • Opt out of non-essential email; transactional messages tied to your account continue.
  • Ask us what we hold about you and receive an export.

Email aleks@servada.io and we will respond within 30 days. Some records — payment and payout history in particular — are kept where we are legally required to retain them.

9. Retention

We keep account, twin, and knowledge-base data for as long as your account is active. After you delete your twin or close your account, we remove the associated media and content from active systems, and purge routine backups on their normal rotation. Financial records are retained as long as tax and accounting rules require.

Biometric data follows the specific retention rules in section 5.

10. Security

Access to production data is restricted to the people who need it, database access is governed by row-level policies scoped to each account, and payment credentials are handled entirely by Stripe. No online service can promise perfect security, and we do not claim to; if a breach affects you, we will notify you.

11. Children

Twinly Lab is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a minor has created an account, contact us and we will remove it.

12. International transfers

We are based in the United States and our providers operate globally. If you use Twinly Lab from outside the US, your data will be transferred to and processed in the United States and other countries where our providers operate.

13. Changes to this policy

We may update this policy as the product changes. The effective date at the top always reflects the current version, and we will notify account holders by email about material changes.

14. Contact

Questions, requests, or complaints: aleks@servada.io. Twinly Lab Inc., United States.