01
1. Who we are and what this policy covers
Myra is an enterprise conversational voice-agent and neural speech platform operated by ARVINDCODEX (Myra, we, us, or our). We develop, adapt, orchestrate, and operate speech-to-text, neural speech synthesis, conversational intelligence, real-time evaluation, and continual-learning technologies for business customers.
This Privacy Policy applies to myra.arvindcodex.in, our APIs, developer consoles, customer support interactions, and the hosted software, speech models, orchestration pipelines, and dashboards we provide (collectively, the Services). It does not supersede a signed master services agreement, enterprise contract, or custom data processing agreement.
The Services are intended for businesses, software developers, and authorised commercial users, not for unregulated personal, household, or deceptive consumer impersonation.
02
2. Open-source model lineage and audio synthesis
Transparency regarding AI architecture and lineage is fundamental to our privacy and governance commitment:
- Open Source Foundation: Our core voice synthesis engine is derived from cloning and heavily updating the open-source foundational voice model rumik-ai/rumik-oss-1 (available on Hugging Face).
- Cloning, Fine-Tuning & Updates: We cloned the upstream open-source model weights (incorporating the Tiny Aya Fire multilingual backbone and Kyutai Mimi 24 kHz discrete neural speech tokenization) and developed proprietary acoustic fine-tuning, latency optimization, prosody refinement, and conversational adaptations to generate ultra-realistic, natural-sounding audio across 20+ languages.
- Isolation of Customer Data: While our base model is built upon open-source research, customer audio prompts, generated voices, proprietary text, and conversation logs are strictly isolated on our private infrastructure. No customer data or customer-synthesized audio is ever shared back to public Hugging Face repositories or unauthenticated open-source distributions.
- Delivery and Modulation Controls: Acoustic features such as pitch, speed, conversational fillers, breathing, and prosody tags are computed transiently in memory during inference to minimize data footprints.
03
3. Our role when processing customer data
A customer decides why and how its voice agent is deployed, which end-users interact with it, what scripts or texts are synthesised, and what telemetry is collected. For personal data contained in Customer Content, the customer acts as the Data Fiduciary (or controller), and Myra acts as its Data Processor, acting strictly on documented instructions.
Myra acts as an independent Data Fiduciary for account administrator profiles, billing details, API credential management, service analytics, fraud prevention, and security logs required by applicable regulations.
04
4. Information we collect
- Account and Developer Data: Contact names, registered email addresses, phone numbers, company affiliation, billing credentials, API tokens, and user preferences.
- Customer Content & Audio: Prompts submitted for synthesis, fine-tuning scripts, synthesised audio files, audio waveforms, call recordings, live transcripts, and agent instructions.
- Acoustic & Delivery Parameters: Pitch offsets, rate modifiers, speaker profile identifiers, language selection tokens, and conversational markup tags.
- Telephony and Integration Metadata: SIP trunk identifiers, call start/stop timestamps, latency metrics, duration, audio sample rates, and integration payload headers.
- Diagnostic and Security Telemetry: IP addresses, browser fingerprint, API error codes, memory footprint, inference compute latency, and audit logs.
Customers must not submit voice samples, biometric profiles, or third-party recordings for voice synthesis or cloning without explicit, verifiable consent from the individual speaker.
05
5. How we use information
- Execute real-time text-to-speech inference, neural speech generation, and conversation orchestration.
- Synthesize natural audio streams with low latency using our fine-tuned model checkpoints.
- Authenticate API requests, monitor rate limits, and provide developer dashboard analytics.
- Detect and prevent malicious speech synthesis, deepfake creation, fraudulent impersonation, or abuse.
- Ensure high uptime, benchmark speech token generation speeds, and optimize GPU cluster resource allocation.
- Provide customer support, billing reconciliations, and security incident investigations.
We do not sell personal information, and we do not monetize customer audio prompts or generated voice streams for targeted third-party advertising.
06
6. Customer Content and model improvement
Myra does not use Customer Content or customer-synthesized audio to train or fine-tune public models without explicit, written contractual authorization from the customer.
Audio inference requests are processed statelessly or cached only for the duration requested by the customer for playback and delivery. When customer-specific voice customisation or fine-tuning adapters are commissioned, those weights are strictly dedicated to that specific customer tenant.
We may use anonymised and de-identified operational metrics (e.g., token generation rate, packet jitter, codec compression efficiency) to optimize server infrastructure and audio streaming reliability.
07
7. Voice recordings, notices, and consent
Because our models produce exceptionally lifelike and natural voice audio, transparency is paramount. Customers deploying Myra agents in live phone calls or interactive sessions must provide clear, audible notice to listeners that the voice is artificially synthesised by artificial intelligence.
Customers are strictly prohibited from generating voice clones of living persons without express written authorization, or using synthesised audio to impersonate individuals for deceptive or fraudulent purposes. Myra reserves the right to terminate accounts that violate voice ethics and consent standards.
08
8. How we disclose information
- To the customer and authorized collaborators designated in the customer's workspace.
- To secure infrastructure and hosting subprocessors (e.g., GPU cloud compute providers, secure storage, and telecom networks) bound by strict confidentiality and data protection agreements.
- To competent legal authorities, regulatory bodies, or law enforcement only where mandatory under valid legal process or court order.
- In the event of a merger, acquisition, or restructuring of ARVINDCODEX, with notice provided to customers.
09
9. International transfers
Customer data may be processed in India and other secure cloud regions where our GPU compute clusters operate. Where cross-border data transfers occur, we enforce Standard Contractual Clauses (SCCs) and robust technical safeguards to guarantee equivalent privacy protection in accordance with Indian DPDPA and international standards.
10
10. Retention and deletion
We retain Customer Content and synthesized audio artifacts only for the duration defined in the customer's retention configuration or active subscription. Customers may trigger immediate deletion of generated audio files and transcripts via our API or dashboard.
Following account closure, customer audio records are permanently expunged within 30 days, except for financial and security audit logs required by law.
11
11. Security and inference isolation
We deploy state-of-the-art security controls to safeguard voice models and customer audio streams:
- End-to-end TLS 1.3 encryption for streaming audio WebSockets and REST APIs.
- AES-256 encryption at rest for stored audio tokens, cache checkpoints, and customer profiles.
- Hardware isolation for GPU neural inference workloads to prevent cross-tenant memory leakage.
- Strict RBAC (Role-Based Access Control) and multi-factor authentication for administrative operations.
12
12. Cookies and analytics
We use essential session tokens and performance analytics to ensure website stability, manage authentication, and monitor page loading speeds. You may control browser cookie preferences at any time.
13
13. Individual rights
Individuals have rights regarding their personal data, including the right to access, rectify, delete, or withdraw consent. Inquiries regarding customer-generated voice interactions should be directed to the responsible customer deploying the agent. For inquiries regarding data controlled directly by Myra, contact our privacy team at contact@arvindcodex.in.
14
14. Children
The Services are strictly designed for professional and enterprise use. We do not knowingly collect, synthesize, or process biometric or voice data from individuals under 18 years of age without explicit legal and parental authorization.
15
15. Legal compliance and changes
This Privacy Policy complies with India's Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023 (DPDPA), the DPDPA Rules, and international privacy principles. We may update this policy periodically to reflect updates to our models, regulatory developments, or new voice features.
16
16. Contact and grievances
For questions regarding this policy, model lineage, data protection, or grievance redressal, please contact:
ARVINDCODEX — Myra Legal & Privacy Office
Website: myra.arvindcodex.in
Official Email: contact@arvindcodex.in
Support: support@arvindcodex.in
This policy is governed by the laws of India. Courts having jurisdiction in India shall have exclusive authority over any disputes arising under this policy.