Local by default. Consent by design.
The character renderer runs in the visitor's browser. What leaves the page — and when — is a deliberate, visible choice. This page describes how data is handled in the current release.
Consent & likeness
Permission is a gate, not a checkbox theater
Photo upload requires confirming you own the image or have the person's permission. Uploads without that confirmation don't proceed.
No identification
Alive builds a stylized character from visual features. It does not attempt to identify who is in a photo, and it isn't a face-recognition service.
Source images aren't kept
Source photos are not stored by default; metadata (EXIF, location) is stripped where practical before any processing.
Delete means delete
Every likeness profile has visible delete and reset controls. Deleting removes the profile and its derived features from your workspace.
Safety controls
- Microphone: requested only on explicit action, indicated while active, stopped with one tap. Never on page load.
- Audio: no autoplayed speech, anywhere. Sound starts only after a user gesture.
- Minors: guardian controls for experiences aimed at or involving minors — including likeness restrictions and locked wardrobes.
- Published characters: business workspaces support review-before-publish workflows for anything customer-facing.
- Analytics: event names and coarse UI metadata only — never uploaded photos, transcripts, or conversation content.
Responsible disclosure
Found something? Write to ai@netshow.ai. We acknowledge reports and credit researchers who wish to be named.
Enterprise documentation
Security review packets, DPAs, and deployment architecture docs are available through the enterprise team.