AI Vendor Directory · Image, video & audio generation
Does ElevenLabs train on your data?
Depends — varies by plan or setting. Vendor-stated default: configurable. Enterprise: no by default — help center states "By default, we don't train on any data from our Enterprise customers, other than as may be necessary to provide services." All other tiers (Free through Business, including API use on those plans): yes by default — "ElevenLabs uses certain data you provide to us to improve the quality of our audio models"; opt out in-app via profile > Terms and privacy > Data use > disable "Improve the models for everyone" (applies prospectively only, per the privacy policy). Enterprise can also enable Zero Retention Mode so audio inputs/outputs are not stored after processing. Note: non-US data residency is an Enterprise-exclusive feature; self-serve tiers are US-hosted.
By the Shieldra Compliance Team · Last updated 2026-07-29
What is ElevenLabs?
Text-to-speech, voice cloning, and conversational-audio platform with self-serve and API tiers plus an Enterprise plan. SMBs use it for voiceovers, IVR/agents, and audio content.
Key facts
- Vendor: ElevenLabs, Inc. — https://elevenlabs.io
- Trains on customer data by default: configurable
- Source for the training answer: https://elevenlabs.io/docs/help-center/legal/is-my-data-used-to-improve-eleven-labs-ai-models
- Data residency: US (default, all tiers); EU (Enterprise only); IN (Enterprise only); SG (Enterprise only)
- Last verified: 2026-07-29
What certifications does ElevenLabs hold?
- SOC 2 Type II
- ISO 27001
- PCI DSS Level 1
- CSA STAR Level 1
- HIPAA (per vendor)
Security, DPA, and subprocessor links
- Security / trust page: https://compliance.elevenlabs.io/
- Data processing agreement (DPA): https://elevenlabs.io/dpa
What is your EU AI Act role when you build on ElevenLabs?
Customers are typically deployers; Article 50 requires disclosure when synthetic/cloned voice audio could be mistaken for a real person (deepfake-type content). Building a voice product on the API can make you the provider of that downstream system.
What to record in your AI registry
- Provider: ElevenLabs, Inc.
- Model type: third party api
- Data typically flowing to the vendor: voice recordings/voiceprints (treat as biometric-adjacent), scripts and prompts, generated audio
Sources
- https://elevenlabs.io/privacy-policy
- https://elevenlabs.io/enterprise
- https://elevenlabs.io/docs/help-center/legal/is-my-data-used-to-improve-eleven-labs-ai-models
- https://compliance.elevenlabs.io/
- https://elevenlabs.io/dpa
Disclaimer
Curated from vendor-published pages on the date above. Vendor terms change - verify against the cited sources before relying on a profile for a procurement decision. Last verified 2026-07-29.
Frequently asked questions
Does ElevenLabs train AI models on your data?
Depends — varies by plan or setting. Vendor-stated default: configurable. Enterprise: no by default — help center states "By default, we don't train on any data from our Enterprise customers, other than as may be necessary to provide services." All other tiers (Free through Business, including API use on those plans): yes by default — "ElevenLabs uses certain data you provide to us to improve the quality of our audio models"; opt out in-app via profile > Terms and privacy > Data use > disable "Improve the models for everyone" (applies prospectively only, per the privacy policy). Enterprise can also enable Zero Retention Mode so audio inputs/outputs are not stored after processing. Note: non-US data residency is an Enterprise-exclusive feature; self-serve tiers are US-hosted.
What certifications does ElevenLabs hold?
Per the vendor's published pages as of 2026-07-29: SOC 2 Type II; ISO 27001; PCI DSS Level 1; CSA STAR Level 1; HIPAA (per vendor).
Where does ElevenLabs store your data?
Vendor-listed data residency options as of 2026-07-29: US (default, all tiers); EU (Enterprise only); IN (Enterprise only); SG (Enterprise only).
What is your EU AI Act role when you build on ElevenLabs?
Customers are typically deployers; Article 50 requires disclosure when synthetic/cloned voice audio could be mistaken for a real person (deepfake-type content). Building a voice product on the API can make you the provider of that downstream system.