Image, Video & Voice Generation
Synthesia
Medium riskAI video platform that turns scripts into presenter-led videos with stock or custom avatars, widely used for corporate training.
Is Synthesia safe for confidential data?
Synthesia is enterprise-leaning — consent-verified custom avatars, SOC 2, and corporate terms — but the scripts are the data: training videos encode internal processes, compliance procedures, and product detail, all typed into a third-party platform. Custom avatars add a biometric layer (an employee's face and voice as a reusable asset) that needs consent, ownership, and offboarding answers. Managed correctly it's a low-drama vendor; the exposure is script content and avatar governance, not silent training defaults.
Risk by plan
The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.
Self-serve workspaces outside procurement; internal-process scripts accumulate in personal accounts.
SSO, admin controls, DPA, consent-verified custom avatars, negotiated data terms.
Data handling
Training on inputs
Synthesia states it does not use customer data — inputs or outputs — to pre-train its AI models; fine-tuning on customer data happens only on the customer's written instruction. Custom-avatar models are built from consented enrollment footage.
Retention
Scripts, videos, and avatar assets persist in the workspace under the contract's retention terms.
Residency
EU/U.S. cloud infrastructure; enterprise agreements govern processing commitments.
Compliance
- SOC 2Yes
- GDPR / DPAYes
- HIPAA BAANo
Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.
New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.
Enterprise controls
- SSO / SAML (Enterprise)
- Workspace roles and admin console
- Consent-verified avatar enrollment
- DPA and negotiated retention
Frequently asked questions
What data does Synthesia actually hold?
Your scripts — often step-by-step internal procedures — the rendered videos, and for custom avatars, biometric enrollment footage of real employees. The scripts are usually more sensitive than teams assume.
Who owns an employee's avatar after they leave?
Whatever your contract and consent forms say — which is why both should say something. Enrollment consent, permitted uses, and deletion on offboarding belong in the agreement before the first avatar is made.
Is Synthesia a shadow-AI risk?
Mostly through self-serve accounts: an L&D manager's personal workspace full of internal-process scripts is procurement-invisible. Discovery plus a managed enterprise tenant closes that gap — Sanitized AI surfaces the self-serve usage.
Policy changelog
- Initial entry published from Synthesia's published policies.
Sources
This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.
Synthesia is probably already in your organization.
Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.
More AI tool profiles
Adobe's generative image and design models, standalone and embedded across Creative Cloud, trained on licensed content such as Adobe Stock and public-domain content.
AI design features across Canva — text generation, image generation, and design automation — used broadly by marketing and operations teams.
AI audio and video editor with transcription, overdub voice cloning, and studio-quality enhancement, popular for podcasts and internal recordings.
AI voice platform for text-to-speech and voice cloning, used for narration, dubbing, and conversational voice agents.