What we collect, why, and what we never receive.
Effective date: [DATE] Last updated: [DATE]
Tera Inc. ("Tera", "we", "us") builds Fixtureframe, a service for recording, generating and publishing product demonstrations and help content. This policy explains what personal information we collect, why, who we share it with, and the choices you have.
It covers the Fixtureframe web application at app.fixtureframe.ai, the documentation site at docs.fixtureframe.ai, the Fixtureframe command-line tool and browser recorder, and our marketing pages. It does not cover any third-party service you choose to connect, which is governed by that provider's own policy.
Fixtureframe holds two kinds of information, and our responsibilities differ.
Information about you as our customer. Your name, work email, sign-in method, organisation, billing records and usage. Here Tera is the controller (GDPR) / business (CCPA): we decide why and how it is used, and this policy governs it.
Content you put into the service. The flows you author, the recordings and screenshots your runs capture from your applications, the decks you import, the narration you generate, and the voice and presenter profiles you create. If that content contains personal information about anyone — your employees, your own customers, a person whose voice was recorded — you are the controller and Tera is a processor / service provider acting on your instructions.
For that content, our Data Processing Addendum governs what we may do with it, and it takes precedence over this policy where the two differ. Ask us for a copy — we will sign one.
You control what gets captured. Fixtureframe is built to run against fixture and demonstration data, not live production records. A run points a browser at whatever URL you give it and records what appears on screen. If you point it at a live system, real personal data ends up in the screenshots and video, and it is your decision to have done so.
Your name, work email address, and which organisations and workspaces you belong to. If you sign in with Google or Microsoft, we receive a signed identity token from that provider containing your email, name and a stable identifier. We never receive your Google or Microsoft password. We keep a record of which addresses have been verified, and invitations you send or receive.
Flows, steps and their versions; runs and the artifacts they produce (screenshots, video, GIFs, recordings); imported decks (.pptx, .pdf) and the slides extracted from them; narration text, transcripts and pronunciation lexicons; documents and published pages; and share links you create.
See section 6. In short: audio recordings of a person's voice, the synthetic voice built from them, portrait images used to generate a presenter, and the generated video takes.
Your plan, balance, usage records (how much was rendered and what it cost), invoices, and automatic top-up settings. Card details go directly to Stripe and are processed by Stripe under its own terms — Tera never receives or stores your full card number.
If you connect Slack, Microsoft Teams, Jira, Confluence, Zendesk, Intercom, Pylon, HubSpot or Salesforce, we store the access and refresh tokens that integration issues, encrypted at rest. We use them only to perform the actions you asked for. You can disconnect at any time, which deletes the stored credential.
IP address, browser and device information, pages and API endpoints requested, response status and timing, and error diagnostics. Our application logs carry a request identifier, your organisation identifier and your user identifier so we can trace a single request end to end when something goes wrong.
Our logging deliberately redacts credentials. Authorization headers, cookies, tokens, API keys and any value matching a secret this system holds are replaced with [REDACTED] before a line is written.
We use a small number of strictly necessary cookies — principally a session cookie that keeps you signed in. We do not use advertising cookies or third-party trackers in the application. [Confirm what, if anything, the marketing site uses, and add a cookie banner if it uses analytics.]
What we doWhyLegal basis (UK/EU GDPR)Provide the service, run renders, store artifactsYou asked us toContractAuthenticate you and keep sessions secureProtect accountsContract; legitimate interestsBill you and collect paymentGet paidContract; legal obligationSend service, security and billing emailOperate the accountContract; legitimate interestsDiagnose faults, monitor performance, investigate abuseKeep it working and safeLegitimate interestsCreate a synthetic voice or presenterYou explicitly asked, with consentExplicit consent (Art. 9)Improve the product in aggregateBuild a better serviceLegitimate interestsMarketing email to business contactsTell you about the productConsent or legitimate interests; opt out any timeMeet legal, tax and audit obligationsThe lawLegal obligation
We do not use your Content to train our own AI models, and we do not authorise our AI providers to train theirs on it. Product improvement uses aggregated, de-identified operational data — how long renders take, which features are used, what fails — never the substance of your content.
We share personal information with service providers ("subprocessors") who help us run Fixtureframe. Each is bound by contract to use it only on our instructions.
SubprocessorWhat it doesData it seesWhereAmazon Web ServicesHosting, database, object storage, and Amazon Bedrock for model callsAll hosted dataUnited States (us-east-2)AnthropicLanguage models for drafting flows, narration and repairsPrompt content: flow definitions, slide text, step descriptionsUnited StatesElevenLabsSpeech synthesis and voice cloningNarration text; voice recordings and the cloned voiceUnited StatesHeyGenPresenter avatars and generated videoPortrait images, voice, narration text, generated takesUnited StatesStripePaymentsBilling contact, payment details (directly), transactionsUnited StatesMailjetTransactional emailRecipient name and email, message contentEuropean Union
Where we use Amazon Bedrock, model calls stay inside our AWS account and region rather than going to a separate provider.
We will publish material changes to this list at [[SUBPROCESSOR_PAGE_URL]]([SUBPROCESSOR_PAGE_URL]) and, for customers with a signed DPA, give advance notice as that DPA requires.
We also disclose information when:
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months.
This is the most sensitive material Fixtureframe handles, and it has its own rules.
Depending on where you live, a voiceprint or a facial template may be biometric information under laws such as the Illinois Biometric Information Privacy Act, Texas CUBI, Washington's My Health My Data Act, and GDPR Article 9. We treat it that way everywhere, for everyone.
Consent is recorded, not assumed. Creating a voice profile requires the speaker to record themselves saying, in their own voice:
"I am recording this so Fixtureframe can create a synthetic version of my voice. This is my own voice, and I am authorised to use it for my organisation's demos and help content. I understand the recording is sent to voice providers to build the model, and that I can have it deleted at any time."
We store that recording, the exact wording consented to, the time, and which user account performed it. That record is the authorisation, and it is retrievable on request.
What we do with it. The recording is sent to our voice and presenter providers to build the synthetic voice or avatar. It is used to generate narration and video for your organisation's demos, and for nothing else.
What we never do.
Deletion is real and it propagates. Deleting a voice or presenter profile deletes the stored recording, the consent record and our database row, and issues a delete to the provider that holds the cloned voice. Cloned voices are deleted at the provider; voices selected from a provider's public library are not, because they were never yours to delete and removing one would take it from every other customer.
If your voice or face is in Fixtureframe and you are not the account holder — for example, you recorded a sample for an employer — you can contact us directly at [PRIVACY_EMAIL] to ask what is held and to have it deleted. We will act on that request and inform the account holder. You do not need to go through them.
Fixtureframe is hosted in the United States (AWS us-east-2, Ohio). Our email provider operates in the European Union. If you are in the UK, EEA or another jurisdiction with transfer restrictions, your information will be transferred to and processed in the United States.
For those transfers we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the technical and organisational measures described in section 9. A copy of the clauses we use is available on request. [Confirm with counsel whether Tera will also certify under the EU–US Data Privacy Framework.]
CategoryRetentionAccount recordsFor the life of the account, then [30] days after closureContent, flows, runs and artifactsUntil you delete them, or [30] days after account closureVoice recordings, consent records, cloned voices, avatarsUntil the profile is deleted; then removed from our systems and the providerBilling and tax records[7] years, as tax and accounting law requiresApplication logs[30] daysBackups[35] days, after which deleted data ages out
Deletion from live systems is immediate. Deletion from backups happens as backups expire on the schedule above — during that window your data is retained but not used.
We protect information with, among other measures: encryption in transit (TLS 1.2+) and at rest; encryption of third-party credentials at the application layer; least-privilege access controls with scoped, revocable API keys; organisation-level isolation enforced in the data layer; automatic redaction of credentials from logs; private networking for the database, reachable only through an audited session; and separate staging and production environments.
No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulator as the law requires, and without undue delay.
Report a vulnerability to [SECURITY_EMAIL]. We will not pursue legal action against good-faith security research that follows our disclosure policy.
Everyone. You can ask us to give you a copy of your information, correct it, delete it, restrict or object to how we use it, or export it in a portable format. Most of this you can do yourself in Studio; for the rest, email [PRIVACY_EMAIL].
UK and EEA. You additionally have the right to withdraw consent at any time (without affecting what was done before), and to lodge a complaint with your supervisory authority — in the UK, the Information Commissioner's Office.
California (CCPA/CPRA). You have the right to know, delete, correct, and to opt out of sale or sharing — we do neither. Voice and biometric data is "sensitive personal information"; we use it only to provide the service you asked for, which does not trigger a right to limit. We will not discriminate against you for exercising any right. You may use an authorised agent.
Other US states (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others as they take effect) have comparable rights, including appeal of a refused request. To appeal, reply to our decision and we will escalate it to someone who was not involved the first time.
Verification. We will verify your identity before acting, usually by confirming control of the account email. We respond within 30 days (45 in California, extendable once with notice). There is no charge unless a request is manifestly unfounded or excessive.
If you are an end user of one of our customers — your data reached us because that customer put it here. Send your request to them; we will help them answer it. The exception is section 6: a person whose voice or likeness is held may come to us directly.
Fixtureframe is a business tool, not for children. We do not knowingly collect personal information from anyone under 16. If we learn that we have, we delete it. Contact [PRIVACY_EMAIL] if you believe a child has given us information.
Fixtureframe uses AI models to draft flows, write narration and generate media. These produce drafts that a person reviews and approves — they do not make decisions with legal or similarly significant effects about anyone. We do not carry out profiling of that kind.
We will update this policy as the product changes. For material changes we will give notice in the application or by email at least [30] days before they take effect, and update the date at the top. Continued use after that means you accept the revised policy.
Tera Inc. [REGISTERED_ADDRESS]