Skip to main content

NaturalTTS Trust Center

Last updated: April 2026

NaturalTTS is built for educational institutions, accessibility offices, and content production teams. We take privacy, security, and compliance seriously. This page summarizes how we protect your data and operate responsibly.

Privacy

NaturalTTS is a content production platform used by educators, accessibility coordinators, and instructional designers. Students typically do not interact directly with the platform — they consume the audio output through your institution’s LMS or distributed files.

We collect minimal data:

  • Email address and name for staff account access
  • Workspace and content data uploaded by users (PDFs, DOCX, text)
  • Audio output stored in your workspace

We do NOT:

  • Collect student names, IDs, grades, demographics, or biometric data
  • Share or sell user data
  • Use data for advertising
  • Track users across third-party sites

Full privacy policy →

Security

  • Encryption at rest: All data encrypted using AES-256 at the storage layer
  • Encryption in transit: TLS 1.2+ for all client-server communication
  • Data hosting: Customer data hosted in Cloudflare R2 (S3-compatible) with geo-redundant storage
  • Database: PostgreSQL via Neon, encrypted at rest, automatic backups
  • Authentication: bcrypt password hashing, JWT session tokens, optional Google OAuth. Enterprise planssupport SAML 2.0 single sign-on with your existing identity provider (Okta, Azure AD, Google Workspace, OneLogin, JumpCloud, and any SAML 2.0–compliant IdP). SSO users authenticate against your IdP — NaturalTTS never sees their password. We verify each assertion against the certificate you configured during setup.
  • Access control: Role-based permissions per workspace (owner, admin, teacher, student, member)
  • Audit logging: Conversion jobs and significant account events logged

Subprocessors

NaturalTTS uses the following service providers to deliver our service. We have data processing agreements with each:

SubprocessorPurposeLocation
VercelApplication hostingUS (multi-region)
NeonPostgreSQL databaseUS (multi-region)
Cloudflare R2File storage (audio, uploads)Global edge
OpenAIStandard voice TTS APIUS
ElevenLabsPremium voice TTS APIUS
ResendTransactional emailUS/EU
FastSpringPayment processing (Merchant of Record)US
Google (OAuth)Optional sign-inUS

If you have specific data residency requirements, contact us at contact@naturaltts.org.

Compliance & Standards

  • GDPR:We follow GDPR principles for European users — data minimization, lawful basis, user rights to access/deletion/portability
  • FERPA: We treat institutional content as belonging to the institution. Customers act as data controllers; NaturalTTS acts as data processor.
  • Accessibility: WCAG 2.1 AA conformance target across our platform and outputs, working toward WCAG 2.2 (audit in progress)
  • EAA: European Accessibility Act compliance commitments for our European customers (in force June 2025)

Data Processing Agreement (DPA)

Institutional and enterprise customers can request a Data Processing Agreement reviewed by counsel. Contact contact@naturaltts.org for the current DPA template.

Incident Response

In the event of a security incident affecting customer data:

  • We will notify affected customers within 72 hours of confirmed breach detection
  • We will provide details of what was accessed, what we are doing about it, and what action is required from you
  • We will cooperate fully with any legitimate incident investigation

Report security concerns to: security@naturaltts.org

Contact