Legal

Privacy

The short version: the tools on this site never upload your audio: every check and fix runs in this tab. The optional developer API is a separate surface you would have to sign up for and call yourself, and it keeps what you send no longer than the job needs.

Effective 23 September 2026. Narrator Check (“we”) operates narratorcheck.com and is the data controller for what is described here. Questions: support@narratorcheck.com.

Your audio and manuscripts, in the tools

Audio is read, measured, corrected and encoded inside your browser tab. EPUB, PDF, DOCX and TXT files are unpacked or read there to count words and sections. The tools on this site never upload your audio: every check and fix runs in this tab. No tool page sends a file, a measurement or a verdict anywhere, and no tool page calls the developer API. Outputs stay in browser memory until you download or close them.

That is not only a preference. Unreleased manuscripts are routinely under a non-disclosure agreement with the author, and for those recordings a tool that uploads is not an option at all.

The speech models on three pages

Hear your manuscript, the pronunciation guide and proof-listen use speech models: Kokoro, which reads text aloud, and Whisper, which transcribes a recording. The models are downloaded from this same Narrator Check origin the first time you press the button that needs one, and run on your own device. Your manuscript, your recording, the transcript and the synthesized audio are never sent anywhere: these pages call no server at all, and their security policy lets them connect to nothing but this origin, for the model files, and the cookieless analytics counter described below.

The events these pages record are the same kind as everywhere else — that a read-back started or finished, that a guide or a synthetic MP3 was downloaded, that a proof-listen finished — with no text, no word, no voice and no result attached.

What is stored on your device

Using the tools stores nothing except your browser’s own cache of this site’s files, which includes the speech models once they have been downloaded: no cookie set by us, no saved results, no history of what you checked. The two cookies described under developer accounts exist only if you sign in there.

What is measured

Anonymous, cookieless usage statistics, so we can tell whether anyone is using the tool: which page was visited, roughly where in the world from your IP address (which is not stored), and a small set of events such as “a manuscript estimate completed”, “a batch was checked” or “a fix completed”. These carry no file names, no measurements from your file and no verdict. If your browser sends a Do Not Track signal, nothing is recorded at all.

The shared funnel names are work_started when a supported file begins local analysis, work_completed when that analysis produces a result, and work_refused when a tool declines — because a recording has no quiet passage to learn noise from, say, or a trim range falls outside the file. Like every event here, they carry no properties: no file name, measurement, duration, verdict or reason is attached. Which refusal it was is only recoverable from which page it happened on.

The feedback buttons

After a tool produces a result it asks whether that result was what you needed. Answering records one of feedback_positive or feedback_negative — the thumb, and nothing else.

Saying something went wrong opens a box to describe it. That text is never transmitted by this site. The button below it is an ordinary mailto: link addressed to support, so your own mail client opens with the message and you send it yourself, having read it. Opening that link records feedback_message_opened; whether you then send anything, and what it says, is not something this site can see.

The developer API

The developer API is separate from every tool and opt-in: it processes only the files that key holders send to it, by calling it themselves with a key. If you never create a key, nothing in this section concerns you.

  • What it receives. The audio file or text you upload for a job, and the parameters of that job. The file goes to a private storage bucket in the European Union (Amazon Web Services, Frankfurt, eu-central-1) on a signed URL, and is processed there by the same code the tools run in a tab.
  • How long it is kept. Your upload is deleted when the job finishes, and results expire within 48 hours. An upload that never became a finished job is deleted by storage within 48 hours as well. The job record — its id, kind, state, times, the report and what it cost — is kept for three days, then deleted. Monthly usage counts are kept with your account.
  • No human access. No person listens to or reads what you send. The only exception is a specific job you ask us to investigate, and then only that job. Nothing you send is used to train anything.
  • Your rights to the file. Send only files you have the right to process. The API does not clone, imitate or train on anybody’s voice, and it offers no way to.
  • Synthetic speech is labelled. Text-to-speech output is read by a built-in synthetic voice and carries tags in the file saying it is synthetic and not for ACX. It is for proof-listening, not narration.

Developer accounts and Google sign-in

An account exists only for the API; no tool needs one. You create it by signing in with Google at /account/. We request only the openid, email and profile scopes and receive only:

  • your Google account identifier, which we store only as a one-way hash;
  • your email address and whether Google has verified it, to recognise you when you return and to contact you about the service;
  • your name, to show you who is signed in.

We use this only to operate your account and its API keys. Narrator Check’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: we do not sell Google user data or transfer it to third parties except as needed to provide the service or to comply with the law; we do not use it for advertising or profiling; and we do not allow humans to read it except with your request, for security, or where the law requires. We request no scope that reaches your mail, files, calendar or contacts, and hold no token that lets us act at Google on your behalf.

Cookies. Signing in sets two cookies on this site and nowhere else: __Host-sf-narratorcheck, the signed, HttpOnly session, which expires after 12 hours; and __Host-sf-narratorcheck-hint, which holds only the value 1 and tells the account page that asking who you are is worth a request. Both are strictly necessary for the account, set only when you sign in and cleared when you sign out. There is no consent banner because nothing else is set.

API keys are shown once, when you create them; we keep only a hash, and a revoked key stops working at once.

Deleting your account removes the hashed identifier, the email, the name, every API key and every job record at once from the account page, or within 30 days if you email support. Aggregate counts that carry no identity — how many people chose Pro in a month — are not affected.

Legal bases

For people in the European Economic Area and the United Kingdom, under the GDPR:

  • Legitimate interests (Article 6(1)(f)) for the cookieless usage statistics and for keeping the service secure. Neither involves an identifier.
  • Performance of a contract (Article 6(1)(b)) for operating a developer account you create by signing in, and for processing the jobs you send to the API.
  • Legal obligation (Article 6(1)(c)) where we must retain or disclose information by law.

You may ask what we hold about you, ask for it to be corrected, deleted or exported, object to processing, or complain to your data-protection authority. Email support@narratorcheck.com; a person answers within one month.

What is not here

No advertising, no advertising network, no payment processor, no tracking pixels, and no cross-site identifiers. That is why you were not asked to accept anything when you arrived.

The page loads the cookieless analytics script from analytics.pagefabrica.com. The EPUB/DOCX reader uses fflate and the PDF reader uses Mozilla PDF.js; both libraries are served from this same Narrator Check origin and do not receive your file.

The “Try a sample chapter” buttons fetch a short file this site synthesized, from this same origin, and check it in the tab exactly as they would check yours. Nothing travels the other way, and a sample is not counted as a file you chose.

Contact

Questions about any of this: contact us.