legal

Counsel brief — voice-cloning consent for a facilitated eldercare legacy product

Not legal advice — this is founder homework to hand to an attorney. It states the product, the specific mechanics that create legal risk, and seven questions we need answered before writing code. Statute references are our lay understanding, flagged for your verification. Ideal reviewer: someone spanning elder law + right of publicity + biometric-privacy (BIPA-class).

Companion design doc (internal): docs/product/LEGACY_CHANNEL_CONSENT_MODEL.md. GTM context: docs/product/LEGACY_CHANNEL_ELDERCARE.md.


1. What the product does

We operate a consumer app (HiveJournal / Lovio). A planned feature — the "Legacy Channel" — lets a family capture an elderly person's life stories in that person's own voice, and deliver those recordings to family members, including on a delay or after the person has died.

The mechanics that matter legally:

  • A voice clone is created. Clean audio samples of the elderly person ("the subject") are sent to a third-party vendor (ElevenLabs) which returns a synthetic voice model ("voiceprint"). We store the source audio + the consent recording; the vendor stores the voice model.
  • The capture is facilitated by a family member ("the operator") — typically an adult child who has just moved a parent into assisted living / memory care. The operator holds the account and runs the recording sessions. The subject is usually not an account holder.
  • Consent is captured as a recording of the subject reading a consent statement aloud (our proposed proof artifact — see §3), not merely a checkbox.
  • Delivery includes posthumous delivery: recordings/"capsules" can be sealed to unlock at a future date or after the subject's death, delivered to named family recipients (sometimes minors, e.g. "for my granddaughter's 18th birthday").
  • Read-only by default: we play back what the person actually recorded. We do not generate new speech in the subject's voice. (A generative mode is explicitly out of scope for this launch.)
  • The family pays; facilities only refer. We intend the contracting party to always be the family member, never the care facility or a health plan.

2. The core tension

The subject is often elderly and may have diminishing cognitive capacity (industry data: ~44–69% of nursing-home residents have impaired decision-making capacity). We want to capture consent while the subject still has capacity (early / pre-placement). But some families will arrive after that window, wanting to record a parent who can no longer validly consent — which raises whether a surrogate (POA / guardian / healthcare proxy / next-of-kin) can authorize cloning on the subject's behalf. Separately, because a synthetic voice is created and used after death, both right-of-publicity/likeness law and biometric-privacy law are implicated.

3. What we've already designed (so you can react to a concrete proposal)

  • Consent artifact: the subject reads aloud a plain-language statement while being recorded. Draft text: "My name is [name]. I understand that HiveJournal will make a recording — a clone — of my voice, and use it to read back stories and messages that I record, in my own voice. I am giving this permission freely. I understand these recordings may be shared with my family, including after I am gone, and I want that. I can change my mind and stop this at any time."
  • Heir-durability approach: rather than seek estate/heir sign-off after death, we obtain living, voice-specific, explicitly-posthumous consent from the subject themselves while alive.
  • Data: we intend a published retention + destruction schedule for the source audio and the vendor voiceprint, and revocation (subject-initiated is paramount) as a first-class action that deletes/retires the clone.
  • Scope structure: consent is recorded as granular opt-ins (capture / clone / deliver-now / deliver-after-death).

We want to know whether this design is sufficient, and where it fails.

4. The seven questions

Q1 — Consent sufficiency / form. Is a recorded-aloud consent (audio of the subject reading the statement) legally sufficient to authorize creating and using a voice clone of a person? Or do we need written and/or witnessed/notarized consent, especially for an elderly/vulnerable adult? What must the statement say to be valid and informed?

Q2 — Surrogate authority (go/no-go on a whole feature). When the subject lacks capacity, can a financial POA, healthcare proxy, court-appointed guardian, or next-of-kin authorize creating a voice clone of the subject? Our understanding is that voice/likeness (right of publicity) generally passes through the estate, not through a POA or healthcare proxy — meaning a surrogate likely cannot authorize this. Please confirm. If surrogates cannot, we will simply exclude diminished-capacity subjects and require the subject's own consent — we need a clear go/no-go.

Q3 — Posthumous use / heir-durability. Does living, informed, voice-specific, explicitly-posthumous consent from the subject (per §3) validly authorize using their cloned voice after death, or is separate estate/heir authorization also required? Relevant statutes we're aware of: Tennessee ELVIS Act (2024) (explicitly protects voice against AI cloning), California AB 1836 (eff. Jan 2025) (bars unauthorized digital replicas of deceased persons), and the proposed federal NO FAKES Act. Post-mortem right-of-publicity duration also varies by state (e.g., CA 70 yrs, NY 40, TN indefinite). How should our consent + our launch geography account for this?

Q4 — Biometric privacy (likely our biggest exposure). A voiceprint is, as we understand it, a biometric identifier under Illinois BIPA (requiring a written release, a published retention/destruction schedule, a bar on profiting from biometric data, and carrying a private right of action with statutory damages), and similar regimes exist under Texas CUBI and Washington (incl. the My Health My Data Act). What written-consent language, retention/destruction schedule, and operational controls do we need to be compliant — and should we geo-exclude any states at launch? Does the third-party vendor (ElevenLabs) holding the voice model change our obligations or theirs?

Q5 — Capacity threshold + attester. For the subject-consents path, what is a defensible standard for "has capacity to consent to this," and who may attest it — the family operator, or must it be a clinician? Should we require re-affirmation on more than one occasion (we've seen clinical-consent guidance suggesting ≥2)?

Q6 — Data handling / regulatory scope. Does keeping the family (not a facility or health plan) as the sole contracting party reliably keep us outside HIPAA? What are our obligations for this sensitive/vulnerable-adult data (retention, access, breach, deletion) under general and state consumer-health-data law?

Q7 — Minor recipients. Capsules may be delivered to minor grandchildren (e.g., released at age 18). Any COPPA or other consent interplay on the recipient side we must handle?

5. What we need back from counsel (deliverables)

  1. Go/no-go on the surrogate path (Q2) — this determines whether we build a whole workflow or exclude diminished-capacity subjects.
  2. Required consent-form language (Q1, Q3, Q4) — the exact statement + any written/witnessed requirement.
  3. A BIPA-class retention/destruction schedule + written-release requirements (Q4) we can implement from day one.
  4. A launch-geography recommendation (Q3, Q4) — any states to exclude at v1.
  5. The HIPAA-scope confirmation (Q6) — is family-as-contracting-party sufficient.

We will not write or ship any of this feature until these are answered.

LEGACY VOICE CONSENT COUNSEL BRIEF — Docs | HiveJournal