Security & data handlingUpdated August 2026
How we treat your audio your text and your keys.
Everything below is in force today; where something is not, it says so.
Your content is not training data
We do not train models on customer transcripts, reference audio, or generated audio. Your requests are used to render your audio, and nothing else.
What we store, and for how long
Transcripts. Processed in memory for the render, and not kept after the response completes.
Generated audio. Streamed to you. Short-lived edge buffers exist to smooth stream continuity; they are bounded and recycled. No durable archive of your renders is kept.
Voice references. A cloned reference is fingerprinted so a repeat call with the same clip skips re-cloning, which is what makes instant cloning instant. The cache is keyed by fingerprint and holds derived voice features, not a copy of your library.
Usage. We keep counts per key. They are numbers, not content.
Keys and transport
All traffic is TLS-encrypted in transit, over HTTPS and WSS. API keys are per-customer and signed, and you can rotate or add one at any time by writing to [email protected].
Keys never appear in generated audio, in publicly served logs, or in error bodies.
Every render is watermarked
All audio generated by Gandr carries an inaudible, machine-readable watermark applied at generation. If a clip is ever in question, we can verify whether it came from our engine.
What that proves is where a clip was made, not whose voice it is. We say the narrower thing because it is the true one.
Infrastructure
Serving runs in multiple US regions and an EU region, and requests route to the nearest healthy region. GPU workers are stateless for content: no transcript or rendered audio persists on a worker beyond the request lifecycle.
Who else is in the path
A render, a payment, an email and a page view each pass through a company that is not us. We do not publish which companies, and that is deliberate: the list of what we run on is commercial information about this business, not a fact about your data.
What we will tell you is what LEAVES, which is the part that concerns you. A render carries the text you send and any reference audio, and it is not kept after the render. A payment carries your email address, the amount and our own order id; the card never reaches us. An email carries the address, the subject and the body. A page view carries the page, the event and the IP address the request came from.
Under contract to a customer, and to anyone with a security review to complete, the full processor list goes out in writing on request to [email protected], naming every company, what it is used for and what category of data reaches it. Asking for it is not a special favour and it is not a negotiation.
Two absences are deliberate. Our error reporting is wired and switched off: nothing is configured for it to report to, so no error leaves your browser and no third party receives one. And the one-click step on our quickstart writes your Gandr key into your own voice-agent assistant at Vapi, from your browser, using your own Vapi credential, that is your account and your vendor, and nothing on that path passes through us.
Responsible use
Voice cloning requires audio you have the right to use. Together with the per-render watermark, that is our line against impersonation. Report suspected misuse to [email protected] and we will investigate against the watermark record.
Compliance
We are two people and we say only what is true: formal certification, SOC 2 included, is on the roadmap and is not complete. The practices above are in force today. Enterprise buyers can ask for our current security overview at [email protected].
Reporting a vulnerability
Mail [email protected] with [security] in the subject. We read every report promptly and we do not pursue good-faith researchers.