ekinox Pronunciation

What we do with your data

For the Ekinox Pronunciation API, sold through AWS Marketplace. It describes what this service actually does, and is kept in step with it.

What we collect

From AWS, when you subscribe. The licence and agreement identifiers for your subscription, your AWS account number, and the product code. We take these from AWS rather than from you, because AWS is the only source that can be trusted to say who has bought what.

From you. One email address, given when you set up your account and changeable at any time from your subscription page. It is the only thing we ask you for.

From your API calls. The audio you send and the text you expect it to match, for as long as it takes to answer the request. A recording made in the demo in your browser is treated exactly the same way.

Produced by use. How many seconds of audio you submitted in each hour, a one-way hash of each API key, and the hour each key was last used. We never hold an API key itself — it is shown to you once and stored only as a hash, which is why we cannot show it to you again.

Recorded automatically. The IP address of requests, in security logs. Requests our firewall blocks are logged with their headers, with any API key removed before the log is written.

Where we store it

All of it inside AWS, and nowhere else. Your subscription records, usage figures and key hashes are in DynamoDB in Europe (Ireland); security logs are in CloudWatch Logs and Amazon S3, partly in the United States because that is where the content delivery network and firewall in front of this service run. Everything is encrypted at rest.

Your connection to us is encrypted. These pages contact no other server: even the typefaces are served by us, so opening a page or a link we gave you tells nobody else that you did.

What we use it for

Six things, and nothing else:

We do not use your audio to train or improve models. It is not kept, so there would be nothing to train on.

Who we share it with

AWS Marketplace. We report how many seconds of audio your account used, so that AWS can bill you. AWS already knows who you are; this tells them how much. It is how the product is sold and cannot be opted out of.

AWS, as the provider of the infrastructure this runs on.

Nobody else. No analytics, no advertising, no error reporting service, no data broker, no sale of anything to anyone. There is no third party in this system to share anything with.

How long we keep it

WhatHow long
The audio you submitNot kept. Written to temporary storage for one request and deleted as the answer is returned. It never reaches a database or a bucket.
Your email addressWhile your subscription is live, and 3 years after it ends. Then deleted.
Your subscription record — licence, AWS account number, dates, status10 years, the period accounting rules require for the records behind an invoice.
How many seconds you used, per hour400 days — long enough to settle a disputed invoice.
Hashes of your API keysWith the subscription record. They are not keys and cannot be turned back into one.
Security logs, including IP addresses1 year.
Console sessions, and links you shareA console session lasts 30 minutes. A link you share lasts as long as you chose when you made it, up to 24 hours — and its record is deleted within about two days of that, which is how quickly the automatic sweep runs.

Your subscription record outlives your email address because the two are kept for different reasons: one is how we reach you, the other is what substantiates what you were charged, which accounting rules require us to keep.

Backups

Your subscription, key and usage records are covered by point-in-time recovery, which lets us restore them to any moment in the preceding 35 days. The security archive is kept in a form that cannot be altered or deleted before its year is up, which is the point of it.

There are no copies outside AWS, and none on anybody's laptop. When something is deleted it leaves the recovery window within 35 days.

Your audio is not backed up, because it is never stored.

Asking us about it

Write to pronunciation-assessment@ekinox.io to ask what we hold about you, to correct it, or to have it deleted.

We will delete what we are free to delete. The subscription and usage records behind your invoices we have to keep for the accounting period described above; we will say exactly what was kept and why.