NEWS
Verax AI Risk Assessment is live. See what's exposed
RephraseAI
RephraseAI
 
Risk Overview
Significant Risk
5.7
/10
Video Generation
·
Avatar Generation
·
Top Risks

Biometric/likeness data from AI-avatar video product (face + voice required for personalized spokesperson videos) with no explicit consent or deletion process documented for sunset platform; Adobe acquisition creates data lineage uncertainty; limited transparency on what happened to trained likeness models; no SOC 2 or ISO certification on standalone product.

Mitigations

Product is now sunset and folded into Adobe Firefly—users should ensure no residual data remains. New users interacting with Adobe's platform benefit from Adobe's enterprise security posture (SOC 2 Type II, ISO 27001). Request explicit data deletion from Adobe for any legacy Rephrase.ai account data.

Get started
Is your team using 
RephraseAI
 
safely?

Highest Risk Categories

The highest-scoring risk categories identified in this assessment.

Training Use

Rephrase.ai was a digital-avatar/synthetic-video platform that required training AI models on users' likenesses and voice to produce personalized spokesperson videos. The standalone service has been sunset following Adobe acquisition (Dec 2023); active users effectively transitioned to Adobe. Legacy ToS granted a broad license to use uploaded content to 'provide and improve the service.' No explicit opt-out from AI-model training was offered for avatar/likeness data. The rephraseai.com paraphrase tool (a different product at the same domain) claims it only uses data to provide/improve the service, but the original AI-video product's biometric data handling was never clearly explained. Data practices now governed by Adobe—rated elevated due to likeness/biometric sensitivity.
7
/10

Data Retention

The rephraseai.com paraphrase product retains rephrased text for 90 days post-use and account data as long as account is active. For the original AI-video product (now sunset), there is no clearly communicated deletion timeline for likenesses/voice models created within the platform. Adobe's broader data retention policies likely apply to any data transitioned. No zero-data-retention commitment found.
6
/10

Output/IP Ownership

The core risk for the original product: users uploaded their face and voice to create AI avatars—the platform's core IP was built on processing biometric data. The paraphrase tool ToS states users retain all rights and grants only a limited service license. For the AI-video product, the company needed a broad license to likenesses to generate synthetic videos. Likeness/voice models created on the platform—unclear if these were deleted post-sunset. No clear statement that generated avatar outputs are fully owned by users with commercial rights.
6
/10

Unlock the complete assessment

Run a free assessment to access the full AI tool risk analysis.
Start Free Assessment
Updated July 2026 • AI-assisted research • Reviewed by Verax • Report an issue

Reference Documentation

Official documentation and policies referenced as part of this assessment.