Image, Video & Voice Generation

Synthesia

Medium risk

AI video platform that turns scripts into presenter-led videos with stock or custom avatars, widely used for corporate training.

Verified 2026-08-31Synthesiawww.synthesia.io

Is Synthesia safe for confidential data?

Synthesia is enterprise-leaning — consent-verified custom avatars, SOC 2, and corporate terms — but the scripts are the data: training videos encode internal processes, compliance procedures, and product detail, all typed into a third-party platform. Custom avatars add a biometric layer (an employee's face and voice as a reusable asset) that needs consent, ownership, and offboarding answers. Managed correctly it's a low-drama vendor; the exposure is script content and avatar governance, not silent training defaults.

Risk by plan

The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.

Starter / Creator (self-serve)
No training

Self-serve workspaces outside procurement; internal-process scripts accumulate in personal accounts.

Enterprise
No training

SSO, admin controls, DPA, consent-verified custom avatars, negotiated data terms.

Data handling

Training on inputs

Synthesia states it does not use customer data — inputs or outputs — to pre-train its AI models; fine-tuning on customer data happens only on the customer's written instruction. Custom-avatar models are built from consented enrollment footage.

Retention

Scripts, videos, and avatar assets persist in the workspace under the contract's retention terms.

Residency

EU/U.S. cloud infrastructure; enterprise agreements govern processing commitments.

Compliance

  • SOC 2Yes
  • GDPR / DPAYes
  • HIPAA BAANo

Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.

New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.

Enterprise controls

  • SSO / SAML (Enterprise)
  • Workspace roles and admin console
  • Consent-verified avatar enrollment
  • DPA and negotiated retention

Frequently asked questions

What data does Synthesia actually hold?

Your scripts — often step-by-step internal procedures — the rendered videos, and for custom avatars, biometric enrollment footage of real employees. The scripts are usually more sensitive than teams assume.

Who owns an employee's avatar after they leave?

Whatever your contract and consent forms say — which is why both should say something. Enrollment consent, permitted uses, and deletion on offboarding belong in the agreement before the first avatar is made.

Is Synthesia a shadow-AI risk?

Mostly through self-serve accounts: an L&D manager's personal workspace full of internal-process scripts is procurement-invisible. Discovery plus a managed enterprise tenant closes that gap — Sanitized AI surfaces the self-serve usage.

Policy changelog

  • Initial entry published from Synthesia's published policies.

Sources

This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.

Synthesia is probably already in your organization.

Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.

Get a demo

More AI tool profiles