RegaLabs · Legal & Compliance

Privacy Policy

Last updated 2026-10-03Questions?
Contents
01

Personally Identifiable Information & AES-256-GCM Encryption

We collect account email addresses, display names, IP addresses, and — for voice cloning users — a 20–30 second verbal consent recording. All personal identifying data is encrypted at rest using AES-256-GCM before writing to PostgreSQL disks. Passwords are cryptographically hashed using scrypt. User data is never sold or shared with commercial data brokers.

02

Cloud Infrastructure & Model Privacy Guarantee

RegaLabs operates out of Erbil, Kurdistan Region of Iraq. High-performance GPU neural inference (Rega Voice, Rega Transcribe, and the Agent language model) and object storage are hosted on secure, access-controlled enterprise cloud infrastructure located inside and outside Iraq. Private voice clone weights, uploaded audio recordings, and enterprise business states are never used to train public open-source foundation models.

03

Judicial Disclosures & Law Enforcement Protocol

RegaLabs maintains a strict zero-warrantless-disclosure policy. No customer data, telephony call recordings, or voice assets are disclosed to any third party, government agency, or law enforcement entity without a formal, binding judicial warrant or subpoena issued by an investigative judge (قاضي التحقيق / فەرمانی دادوەری) having competent jurisdiction in the Kurdistan Region of Iraq or Federal Iraq.

04

Account Deletion vs. Statutory Audit Invariant

You may permanently delete your account at any time via Settings → Privacy & Data, which automatically purges your credentials, private voice clone weights, and uploaded media. However, in compliance with Central Bank of Iraq financial regulations (AML Law No. 39 of 2015) and our documented audit-retention policy, anonymized transaction ledgers and cryptographic provenance hashes are retained in our immutable audit archive for a statutory period of 5 years.

05

Data Subject Rights & Regulatory Compliance

Your privacy rights are protected under the Constitution of Iraq (Articles 17 and 40) and the Iraqi E-Commerce Regulation No. 4 of 2025. You may export a complete JSON archive of your account preferences, API keys, and workspace metadata at any time from Settings. RegaLabs maintains proactive alignment with Iraq's draft Personal Data Protection Law.

06

Third-Party Subprocessors (Named)

RegaLabs shares the minimum necessary personal data with the following named subprocessors, and with no one else: Cloudflare, Inc. (edge delivery, DNS, bot protection via Turnstile, and object storage — receives IP addresses, request metadata, and stored media); Resend (Plus Five, Inc.) (transactional and announcement email — receives your email address, display name, and message contents); Neon, Inc. (managed PostgreSQL hosting — holds the encrypted application database); Wayl (payment gateway, settling through First Iraqi Bank, FastPay, ZainCash, and QiCard — receives your name, email, purchase amount, and payment instrument details, which RegaLabs itself never stores); Functional Software, Inc. d/b/a Sentry (error and performance monitoring — receives IP addresses, account identifiers, and technical diagnostics, with message and audio content redacted before transmission); Google LLC (only if you choose Google Sign-In — receives the sign-in request and returns your verified email address and display name). Real-time call audio is carried by a LiveKit server that RegaLabs operates itself (livekit.regalabs.dev); it is not a third-party service. Speech synthesis (Rega Voice), speech recognition (Rega Transcribe), and the agent language model run on RegaLabs-controlled GPU infrastructure: your audio, transcripts, and agent prompts are not sent to OpenAI, Anthropic, Google, ElevenLabs, or any other external model vendor. Image and video generation is the one exception — where your workspace selects an external generation provider, the prompt and any supplied image are sent to that provider, which is named on the provider selector before you generate. This list is updated before any new subprocessor begins processing.

07

Cookies & Analytics

RegaLabs sets a strictly necessary session cookie (rega_session) to keep you signed in, a language preference cookie (rega_lang), and a consent-record cookie (rega_consent) that remembers your cookie choice. None of these require consent under the ePrivacy Directive because the service cannot be delivered without them. Analytics and any other non-essential cookie are loaded only after you accept them in the cookie banner, and your choice can be changed at any time from the banner's preferences link or from Settings. We do not use advertising cookies, cross-site trackers, or data brokers.

08

Children & Minimum Age

RegaLabs is not intended for children. You must be at least 16 years old to create an account, which is above the 13-year floor set by the U.S. Children's Online Privacy Protection Act (COPPA, 16 CFR Part 312) and at or above the threshold set by every member state under Article 8 of the GDPR. We ask for a date of birth at signup and, for accounts created through Google Sign-In, at first use. We do not operate a verifiable parental-consent process, so an account that declares an age below the minimum is refused outright and no account data is retained. If you believe a child has created an account, email support@regalabs.dev and we will erase it.