Security and privacy

Security and privacy, by architecture

The most dependable way to protect a conversation is to keep it where it happens. bitHuman avatars can render on the device, on your own servers or completely offline, so you decide what — if anything — reaches us. This page sets out what we receive in each mode.

When the avatar renders on your hardware and the conversation runs on your own services, bitHuman receives usage metering only — never audio, video or conversation text.

What reaches bitHuman

In each deployment mode. Compare the modes in full →

bitHuman cloud

The avatar renders
On bitHuman's servers, in the US
The conversation runs
bitHuman's voice service, or your own provider keys
What reaches bitHuman
The session's audio and conversation, to run it. Transcripts are kept with your agent; deleting the agent deletes them.

Your servers

The avatar renders
On your own Mac or Linux machines, on-premises or in your cloud account; a standard Linux PC needs no GPU
The conversation runs
Your choice: the CLI's local conversation brain, your own speech and language services, or bitHuman's
What reaches bitHuman
A credential check when a session starts, the avatar download, and usage reports with no audio, video or conversation text

On the device

The avatar renders
On the iPhone, iPad, Mac or Android device in front of the user, or in a WebGPU browser tab
The conversation runs
Your app's choice; with the web embed, on bitHuman's servers
What reaches bitHuman
With your own voice and language services, usage metering only — never audio, video or conversation text

Fully offline

The avatar renders
On your Linux PCs and terminals
The conversation runs
Agreed with sales for your site
What reaches bitHuman
Nothing while it runs: usage is metered on the machine, and no reconnection is required

Usage metering

Self-hosted and on-device sessions check your credential when they start and report usage while they run, so your credits can be metered.

Usage reports contain no audio, video, images or conversation text. Self-hosted and on-device sessions store no transcript at bitHuman.

Conversations

An avatar animates from audio. Where that audio comes from — and where speech recognition, the language model and the voice run — is your choice: the CLI's local conversation brain on macOS and Linux, which keeps all three on the machine; your own speech services and any OpenAI-compatible model endpoint, including one inside your network; or bitHuman's cloud voice service.

Only bitHuman's cloud voice service sends conversation audio and text to bitHuman and its service providers. With the web embed, the conversation runs on bitHuman's servers, even when the avatar renders in the tab.

Creating an avatar

Creating an avatar from a portrait happens in the bitHuman cloud; the portrait is uploaded for that step, in every mode. The finished avatar model then downloads to your devices and runs there.

Encryption in transit

Connections to bitHuman use HTTPS (TLS). Real-time media travels over WebRTC, which encrypts audio and video in transit (DTLS-SRTP). Provider keys you connect are encrypted at rest.

Access control

Organization roles (owner, admin, member); an audit-log API; API-secret rotation that revokes the old secret immediately; and scoped runtime and embed tokens, so browsers never hold your secret.

The Apple and Android SDKs hold an API secret on the device: give each app or device fleet its own secret that you can rotate or revoke.

Retention and deletion

Sessions that render on your hardware store no transcript at bitHuman. Conversations in the bitHuman cloud are stored with your agent so you can review them.

Deleting an agent deletes its records, including transcripts, and its model files.

Your content and our models

From our privacy policy:

“We do not use your content to train our AI models unless you explicitly opt in.”
“We do not sell your personal information to third parties.”

Read the privacy policy

Compliance starts with where the data goes

HIPAA, GDPR and CCPA obligations follow the data, so we start with architecture.

In on-device, self-hosted and offline deployments, patient and customer conversations stay in systems you already govern, and your existing programs apply.

Healthcare and financial-services deployments are set up under an enterprise agreement and review. We are glad to complete security questionnaires and walk your team through each data flow.

Common questions

Does customer audio or video leave our network?

When the avatar renders on your hardware, its audio and video stay there. The conversation runs where you choose: the CLI's local conversation brain, your own speech and language services, or bitHuman's cloud voice service. With the first two, bitHuman receives usage metering only — never audio, video or conversation text. In the bitHuman cloud, and with the web embed, audio and conversation are processed by bitHuman and its service providers to run the session.

Is bitHuman HIPAA compliant?

HIPAA compliance is a property of your program and deployment, not of a single software component. bitHuman can be deployed so that no protected health information reaches bitHuman — on the device, on your own servers with speech and language services you control, or fully offline — and sessions that render on your hardware store no transcript with us. Healthcare deployments are set up under an enterprise agreement and review; contact us to walk through your data flows.

How does bitHuman help with GDPR and CCPA?

With on-device, self-hosted or offline deployment, your customers' conversations stay in the systems and regions you choose, and bitHuman receives usage metering only. Creating an avatar from a portrait happens in the bitHuman cloud. We do not sell your personal information, and we do not use your content to train our AI models unless you explicitly opt in.

Does bitHuman train on our data?

No. We do not use your content to train our AI models unless you explicitly opt in.

Where does the bitHuman cloud run?

Avatars in the bitHuman cloud render in the US. If the avatar must render somewhere else, render it on the device or on your own servers.

Start a security review

Tell us your devices, your network and what your security team needs to see. We'll complete your questionnaire and walk your team through each data flow.