Descript Review 2026: Privacy, AI Training, and Where the Documents Disagree

Last updated: August 15, 2026

Tier C · Document-first briefing

Future Stack Reviews did not create an account, upload a file, or inspect any setting for this briefing. Every statement comes from eleven documents Descript publishes, read on 15 August 2026. No runtime data route was traced or tested.

Open documentation conflict

Descript’s published documents describe the same data flows in six different ways, covering vendors, human access, account deletion, and AI training. This briefing does not pick a winner among them. It sets out what each document says and identifies the questions that have to be put in writing.

Descript is a cloud audio and video editor. It transcribes uploaded media, lets an editor cut video by deleting transcript words, and runs generative features through models the user can select. This review covers one question: what Descript’s published documents establish about the handling of uploaded material. Editing quality, performance, and pricing are outside its scope.

Descript publishes a dedicated subprocessor page, a security page, a privacy policy, contract terms, help articles, and model documentation. Those sources contain a great deal of detail. They do not reconcile into one account of who handles what.

The verdict in one line: Descript discloses more than most buyers realize, across documents that contradict each other on vendors, human access, and deletion.

Best for

  • Teams deciding whether a specific recording is eligible to upload
  • Agencies handling client or third-party material
  • Reviewers who must keep a processor inventory current
  • Anyone assessing voice cloning or avatars against biometric data rules

Not for

  • Readers looking for a general Descript review. Editing quality, speed, and features are not assessed here
  • Pricing, AI credits, and top-up cost
  • Transcription accuracy or output comparison
  • Anyone seeking a compliance determination. This briefing quotes documents and does not interpret law

At a glance

VendorDescript, Inc.
Evidence tierTier C, document-first, no account access
Documents read11, on 15 August 2026
Dedicated subprocessor pageYes, roughly 48 rows
Data regionUS on every subprocessor row except one reading New York
Biometric data collectedVoiceprints and facial geometry, acknowledged as sensitive
Biometric retentionUp to three years after last account access
Self-serve training controlApp Settings, Profile, Share data with Descript
Prohibited upload classesPHI, financial-institution NPI, content directed to under-16s
Terms last updated25 February 2025
Privacy policy last updated14 April 2025

The document set

A buyer searching for Descript’s data handling usually lands on the security page. That page is written as an explanation. It walks through account data, media files, usage analytics, and voice cloning, naming a vendor for each.

Five other documents cover the same ground from different angles, and each carries information the others omit.

DocumentStructured to answerDoes not carry
Subprocessors pageWhich outside organizations Descript engages, and in which regionNo mapping to features, models, or payload types
Security pageHow selected data classes move through the productNo vendor table, no region column, no retention periods
Privacy policyWhat is collected, for which purposes, and what rights applyNo vendor names for AI processing
Terms of ServiceWhat Descript is permitted to do and who bears which riskNo vendor names
Help centerHow account-level controls behaveNo processing route
Model reference and changelogWhich model family powers a feature, and what changedNo host, router, storage path, or data consequence

Compiled from the six named Descript document types, read 15 August 2026.

The subprocessors page is the fullest vendor inventory and the hardest to reach. At descript.com/subprocessors Descript maintains a table of roughly 48 rows, each with a vendor name, the internal team using it, a link to that vendor’s privacy policy, and a data region. It does not appear in the site footer navigation on any page read for this briefing, including its own. Its copyright line reads 2024 and its footer markup differs from the current site.

Every row on that table states a data region of US, apart from a single row reading New York. The privacy policy states the same thing in prose: Descript is based in the United States and processes and stores information there. Two independent documents agree, so a buyer needing European processing has a clear answer.

Sources: Descript, accessed 15 August 2026 · Descript, accessed 15 August 2026 · Descript Privacy Policy, 14 April 2025

A model name is not a processor

Descript shows model names in two places. The Underlord co-editor has a selector carrying Claude, GPT, and Gemini names. Generative media has a separate reference listing models attributed to Google DeepMind, Black Forest Labs, OpenAI, PixVerse, Kling, and others.

Those labels state which model family Descript says powers a feature. They do not state how Descript serves it.

Descript’s own documentation supplies the counterexample. The security page describes Whisper as an open-source transcription model hosted inside Descript’s infrastructure. OpenAI released Whisper. Naming OpenAI as the processor for a Whisper transcription would be wrong.

The subprocessors page makes the distinction concrete in the other direction. It lists OpenRouter, a routing service that sits between an application and multiple model providers. It lists Baseten and Huggingface, which host models on behalf of customers. It lists Andromeda with a region of New York, and Braintrust, an evaluation and observability platform for language model output.

Those entries describe intermediary layers. Their presence means a request originating from a model name in the picker may reach the named model company directly, may pass through a router, may run on a third-party host, or may run on infrastructure Descript controls. The published documents do not say which, for any specific feature.

The privacy policy adds a third pattern. It states that the software generating voiceprints runs on web hosting infrastructure provided by one of Descript’s vendors, without naming that vendor. So a processing step can be disclosed as existing while the party performing it stays unnamed.

The defensible conclusion is narrower than a count of companies. Descript publishes a vendor inventory and it publishes model names. It does not publish the join between them.

Sources: Descript, accessed 15 August 2026 · Descript, accessed 15 August 2026 · Descript Privacy Policy, 14 April 2025 · Descript Help, accessed 15 August 2026

Where the documents disagree

Six disagreements are visible from published text alone. None of them proves misconduct. Each of them means a reviewer cannot rely on a single document.

Vendors. Neither vendor document contains the other.

VendorSecurity pageSubprocessors pageFunction per the security page
RevNamedNot listedAutomatic transcription
HedraNamedNot listedAvatar generation
Amazon Mechanical TurkNamedNot listedHuman review of voice clone samples
ElevenLabsNot namedListed as 11Labs / Eleven LabsNot stated on either page
Anthropic API, OpenAI API, OpenRouterNot namedListedNot stated on either page
Baseten, Huggingface, Andromeda, BraintrustNot namedListedNot stated on either page
AWS, Google CloudNamedListedStorage

Compiled by comparing Descript’s security page and subprocessors page, both read 15 August 2026.

The transcription row carries the most weight. The security page names Rev, which is absent from the subprocessors page. The changelog states that ElevenLabs Scribe v2 became the default transcription model across supported languages, and ElevenLabs is on the subprocessors page. Two documents describe the transcription vendor differently and neither has been updated to match.

Avatars, described three ways. The security page names Hedra. The changelog states Hedra Character 2 was turned off for all users because Hedra discontinued it, with Kling becoming the default. The privacy policy describes unnamed vendors collecting facial geometry. Neither Hedra nor Kling appears on the subprocessors page.

Human access to Projects. The Terms set out four exceptions to the rule that automatic processing does not involve human access: the user grants permission, the user requests White Glove Service, access is otherwise authorized under the Terms including the generative tools section, or the law requires it. The privacy policy sets out two: the user consents, or the law requires it. The two missing exceptions are the ones a reviewer would most want to see.

Account deletion. The security page states that deleting an account results in <a href=”https://www.descript.com/security” target=”_blank” rel=”noopener”>”all data associated with your account is permanently deleted”</a>. The privacy policy states that some information may be retained where required by law or for legitimate business purposes, and that cached or archived copies may be kept for a period.

Selling and sharing. The security page states that project information is not sold, marketed, or used for advertising. The privacy policy states that advertising activities may result in selling or sharing identifiers, network activity information, and inferences with advertising partners. Those statements cover different data classes and are not contradictory, but a reader of the security page alone would form the wrong impression of the whole.

Privacy contact. The security page directs data subject requests to a data protection officer address. The privacy policy directs the same requests to the general support address.

Sources: Descript, accessed 15 August 2026 · Descript Privacy Policy, 14 April 2025 · Descript Terms of Service, 25 February 2025 · Descript, accessed 15 August 2026 · Descript Changelog, accessed 15 August 2026

Open conflict on AI training

Five documents address whether uploaded material may train a model. They do not describe the same rule.

SourceWhat it statesDirection
Terms of Service, §8.4(e)Descript may use generative tool inputs and outputs to train and develop its models, subject to the user having opted out. Third-party providers are contractually prohibited from training on the same materialOpt-out
Privacy policy, purposes listNames including training our artificial intelligence models among the purposes for information collectedStated purpose
Privacy policy, Projects noteProjects are treated as confidential; users may opt out of Projects being used to improve the service by disabling Share data with DescriptToggle governs Projects
Account data and privacy help articleIn-house training maintains a data sharing opt-in. Production models use no user data. Research models use only data from users who opted inOpt-in
Account data and privacy help articleEnterprise drives have no toggle, and data sharing is disabled by defaultEnterprise has no toggle
Pricing page, Enterprise columnLists opt-out of training and custom retention among Enterprise controlsEnterprise entitlement

Compiled from Descript’s Terms of Service, privacy policy, Account data and privacy help article, and pricing page, read 15 August 2026.

Three things are settled. A self-serve control exists and its location is published. Enterprise drives have data sharing switched off with no toggle, which is the opposite of what a pricing-page reader would conclude. And Descript demonstrates that source-specific carve-outs are possible: the privacy policy states that data obtained through the Google Workspace integration is not used to develop, improve, or train its AI models.

One question stays open, and it is now narrow enough to put in a single sentence. The Projects opt-out is described as covering use to improve the Descript Service. The general purposes list separately names training artificial intelligence models. Whether the first phrase covers the second is the whole question, and no published document answers it.

The help article gives the strongest assurance on record, stating that Descript has no plans to use the data of anyone who opted out at any stage of research, development, or production. That is a statement of intent in a help article rather than a term of the contract. A reviewer who needs the assurance to be binding will want it in the agreement.

Sources: Descript Terms of Service, 25 February 2025 · Descript Privacy Policy, 14 April 2025 · Descript Help, accessed 15 August 2026 · Descript, accessed 15 August 2026

Voiceprints, faces, and three years

Two Descript features generate data the privacy policy identifies as sensitive, and both carry retention periods the other documents do not mention.

Voiceprints come first. When a user creates an AI Speaker, Descript generates a voiceprint from the consent statement and from the audio recording being edited, and uses it to authenticate the speaker and prevent fraud. The privacy policy notes that voiceprints may be considered biometric data in some jurisdictions. Retention runs until the purpose is satisfied or up to three years after the account was last accessed, whichever comes first. The software that generates them runs on web hosting infrastructure provided by one of Descript’s vendors, which the policy does not name.

Two details matter for consent design. The voiceprint is derived partly from the working recording, not only from the consent script. And the retention clock runs from last account access rather than from deletion of the clone, so an abandoned account extends the period.

Avatars work differently. When a user creates a Descript avatar, vendors collect facial geometry data from uploaded photos. The privacy policy states that Descript itself does not have access to that data, and that the vendors retain it until the purpose is satisfied or up to three years after last account access. Those vendors are not named in the privacy policy. The security page names Hedra for avatars, and the changelog says Hedra was turned off with Kling replacing it.

The privacy policy acknowledges that voice models and facial geometry are sensitive under applicable US state laws, and states that Descript does not use or disclose sensitive personal information to infer characteristics about a person.

For a buyer, the operational consequence is narrow. Any organization that has a biometric consent or retention policy needs to apply it to these two features specifically, because they are the only parts of Descript that generate biometric data, and they are the only parts with a published retention period.

Sources: Descript Privacy Policy, 14 April 2025 · Descript, accessed 15 August 2026 · Descript Changelog, accessed 15 August 2026

What the standard Terms prohibit

The eligibility question comes before the privacy question, and it is answered in a place most buyers do not look.

Descript’s Terms list categories of content a user may not upload. Three matter to organizational buyers. Content directed to children under 16. Content containing protected health information. Content containing nonpublic personal information from a financial institution.

The restriction follows the content, not the buyer’s industry. A hospital marketing team recording a facility tour is uploading ordinary marketing footage. The same team recording a consultation is uploading a category the standard Terms exclude. The line sits at the data, so the test applies recording by recording rather than once at procurement.

Two further contract terms bear on the same decision. The Terms state that information may be processed, transferred, and stored in the United States and other countries, which matches the privacy policy and the subprocessors table. And the Terms cap aggregate liability at the greater of ten dollars or the amount paid for the service giving rise to the claim, subject to stated exceptions for gross negligence, fraud, intentional misconduct, and matters that cannot be limited by law.

Those provisions do not indicate that Descript is unsafe. They describe where responsibility sits after an incident.

Sources: Descript Terms of Service, 25 February 2025 · Descript Privacy Policy, 14 April 2025

Who may hear a cloned voice

Voice cloning creates a human access path the rest of the product does not.

Descript requires a consent statement. The Terms define a consenting speaker as a person, including the account holder, who has given both the user and Descript permission to train and synthesize their voice. The security page states that speakers must read a Descript-designated script affirming identity and consent. A third-party voice is therefore permitted where that person has authorized both parties, which is wider than a self-cloning-only reading.

The Terms then set out who may listen. Descript employees, vendors, and contractors, naming Amazon Mechanical Turk workers, may listen to samples of training audio and synthesized audio to test quality and monitor for misuse. The same clause permits those workers to use the AI voice to create a series of non-defamatory utterances for internal quality assurance. The security page describes the Mechanical Turk step independently.

The privacy policy covers the same ground with different scope. It refers to employees and contractors listening to samples, and to Descript employees generating the quality assurance utterances. It does not mention vendors, and it does not name Mechanical Turk. Both documents describe human listening; they describe a different set of listeners.

Both also address research use. Training audio may be added to Descript’s research datasets, with the data disassociated from the account before it is added.

On watermarking, the pages read for this briefing are silent. Descript’s ethics page describes verbal consent verification and membership of the Content Authenticity Initiative. Neither that page, nor the Terms, nor the privacy policy, nor the security page, nor the voice cloning product page contains a provision stating that generated audio carries a watermark or provenance signal. Third-party writeups assert one exists. Five pages is a narrow search, so this is recorded as unresolved rather than absent.

Sources: Descript Terms of Service, 25 February 2025 · Descript Privacy Policy, 14 April 2025 · Descript, accessed 15 August 2026 · Descript, accessed 15 August 2026 · Descript, accessed 15 August 2026

What to request in writing

The published documents answer more than most buyers expect. These six cannot be closed from public text.

Ask Descript for these in writing

  1. Which listed subprocessor, router, or host serves each selectable model, per feature.
  2. Whether disabling Share data with Descript withdraws the AI model training purpose named in the privacy policy, or only use to improve the service.
  3. Which of the Terms’ four exceptions to no-human-access apply in practice, and how often the generative tools authorization is exercised.
  4. What is retained after account deletion, given that the security page and the privacy policy describe this differently.
  5. The identity of the vendors that generate voiceprints and collect facial geometry, and their retention and deletion mechanics.
  6. The notification process when the model route or the subprocessor set changes.

Derived from gaps between Descript’s subprocessors page, security page, privacy policy, Terms, help center, and pricing page, read 15 August 2026.

Alongside those, a reviewer will want the standard artifacts. The security page links a trust portal where requirements can be searched and further detail requested, which is the route to the SOC 2 Type II report. The privacy policy contains a European Economic Area section setting out legal bases for processing, data subject rights, and the route to a supervisory authority complaint, though it names no specific transfer mechanism. The Terms specify a written notice address for the arbitration opt-out, which has a 30-day window; that address should be taken from the Terms rather than the site footer, because the two differ.

Sources: Descript, accessed 15 August 2026 · Descript Privacy Policy, 14 April 2025 · Descript Terms of Service, 25 February 2025

FAQ

Does Descript train its AI on my uploads?

The documents differ. The help center states that in-house training requires a data sharing opt-in and that production models use no user data. The Terms permit Descript to use generative tool inputs and outputs for model development unless the user opts out. A self-serve toggle exists in App Settings under Profile. Status: OPEN CONFLICT.

Is ElevenLabs a Descript subprocessor?

Yes. ElevenLabs appears on Descript’s subprocessors page, listed under Engineering with a US data region. It does not appear in the security page’s description of transcription, which still names Rev. Status: OFFICIAL CLAIM, with a documentation mismatch.

Which companies process Descript projects?

The subprocessors page lists roughly 48 vendors, including OpenRouter, Anthropic API, OpenAI API, ElevenLabs, Baseten, Huggingface, AWS, and Google Cloud. It does not map any vendor to a specific feature or model, so which one handles a given action is not established. Status: OFFICIAL CLAIM, feature mapping NOT PUBLISHED.

Can Descript store data in the EU?

No European region appears in Descript’s published material. The privacy policy states that Descript is US-based and processes and stores information in the United States. Every subprocessor row states a US region apart from one reading New York. No self-serve regional selector was located. Status: OFFICIAL CLAIM.

How long does Descript keep a voice clone or avatar?

The privacy policy gives one period for both. Voiceprints and facial geometry data are retained until the purpose of collection is satisfied, or up to three years after the account was last accessed, whichever comes first. The clock runs from last account access rather than from deletion of the clone. Status: OFFICIAL CLAIM.

Does Descript collect biometric data?

The privacy policy states that voiceprints may be considered biometric data in some jurisdictions and that voice models and facial geometry are sensitive under applicable US state laws. Voiceprints are generated from the consent statement and the audio being edited. Facial geometry is collected by vendors for avatars. Status: OFFICIAL CLAIM.

What happens when I delete my Descript account?

Two documents differ. The security page states that all data associated with the account is permanently deleted. The privacy policy states that some information may be retained where required by law or for legitimate business purposes, and that cached or archived copies may be kept for a period. Status: OPEN CONFLICT.

Can Descript process protected health information?

The standard Terms prohibit uploading content that contains protected health information. They also prohibit nonpublic personal information from a financial institution and material directed to children under 16. The restriction attaches to the content, not to the buyer’s industry. Status: OFFICIAL CLAIM.

Who can listen to a Descript voice clone?

The Terms state that Descript employees, vendors, and contractors, including Amazon Mechanical Turk workers, may listen to training and synthesized audio for quality testing and misuse monitoring, and may generate non-defamatory sample utterances for internal quality assurance. The privacy policy describes the same practice but refers only to employees and contractors. Status: OFFICIAL CLAIM, with a scope mismatch.

Can a user clone another person’s voice?

The Terms permit it where that person qualifies as a consenting speaker, meaning they have given both the user and Descript permission and have read the designated consent statement. Submitting a third party’s unauthorized recordings or a deceptive consent statement is expressly prohibited. Status: OFFICIAL CLAIM.

What does Enterprise add to the training opt-out?

Not established. The pricing page lists opt-out of training among Enterprise controls, while the help center states that Enterprise drives have no data sharing toggle because it is disabled by default. Whether the Enterprise entitlement is contractual, administrative, or the same control described differently is not explained publicly. Status: NOT PUBLISHED.

Methodology and source ledger

This is a Tier C briefing. Future Stack Reviews did not create an account, upload a file, run a feature, or inspect a setting. No claim here describes measured behavior or an observed data route.

Eleven Descript-published documents were read on 15 August 2026.

  1. Data Subprocessors, descript.com/subprocessors
  2. Security and privacy, descript.com/security
  3. Privacy Policy, descript.com/privacy, last updated 14 April 2025
  4. Terms of Service, descript.com/terms, last updated 25 February 2025
  5. Account data and privacy, help center article 10255866490125
  6. Ethics statement, descript.com/ethics
  7. AI voice cloning, descript.com/tools/voice-cloning
  8. Pricing, descript.com/pricing
  9. Underlord co-editor, help center article 36803785502221
  10. Generative image and video models, help center article 39869916772621
  11. Changelog, feedback.descript.com/changelog

Four limits bound every statement above.

Page state cannot be asserted for a specific moment. Retrieval tools return cached versions in practice. The claim is that this content existed at these URLs as read, not that any page displayed the same on another date.

Account-gated material was not inspected. The Share data with Descript setting, the usage screen, checkout, and billing sit behind a login. The default position of that toggle for a new self-serve account is not established here.

Absence is recorded as unresolved. Where a provision was not located, that reflects a search across the eleven named documents. It does not establish that Descript has not published it elsewhere. The SecurityPal trust portal, any data processing addendum, and any Enterprise order form were not opened.

Provider attributions in the model reference were not verified against each model vendor’s own sources. That work is separate and is not reported here.

Sources rechecked: 15 August 2026. Contract versions checked: Terms 25 February 2025, Privacy Policy 14 April 2025. Product pages and the changelog change without notice and require a fresh check before any revision.

Verdict

Do not approve Descript by reading one privacy page.

Descript discloses a great deal. It publishes a subprocessor inventory with region labels, names biometric data as biometric, gives a retention period for it, states that Mechanical Turk workers may hear voice clone samples, and provides a self-serve control for data sharing with a published path. Most vendors of its size disclose less than this.

The problem is that no two of those documents agree on the same thing. The security page and the subprocessors page name different vendors for transcription, avatars, and human voice review. The Terms allow four exceptions to no-human-access; the privacy policy allows two. The security page says account deletion is permanent; the privacy policy says some information may be retained. Five documents describe the training rule in five ways.

The decision therefore turns on the recording rather than on the tool. Owned material containing no restricted data class, on a self-serve plan, is a decision the published documents can support once the sharing setting has been checked. Anything involving a third party’s voice or face brings biometric data and a three-year clock into scope. Client footage, confidential interviews, or anything touching a prohibited class should wait for written answers to the six questions above.

The finding is not that Descript hides its processors. The finding is that its disclosures were written at different times for different purposes, and reading any single one of them will give a buyer a picture the others contradict.

Need the same audit for another vendor?

Future Stack Reviews reconstructs vendor data paths from published documents: subprocessor inventories, training defaults, retention and region claims, biometric handling, prohibited data classes, and the gaps between them. Tell us the vendor and the question your review has to answer.

Corrections are equally welcome. If a statement here is wrong, send the document and the exact URL. Every correction is numbered, logged, and published.

Contact Future Stack Reviews

Related FSR briefings

Tier B = hands-on tested. Tier C = document-first, no hands-on testing.

This is a Tier C briefing. Future Stack Reviews did not create an account, upload a file, or inspect any setting. All statements are drawn from eleven documents published by Descript and read on 15 August 2026. Vendor documentation changes without notice; confirm current terms against the vendor’s own pages before relying on anything here.

Nothing in this briefing is legal, regulatory, or compliance advice. Compliance determinations belong to the data controller and its advisers. Where a provision could not be located, that is recorded as unresolved rather than as absent.

Future Stack Reviews received no compensation, product access, or editorial input from Descript. This article contains no affiliate links.