Memorial Voice Sites (crosstalk §16) — shaping
Status: SHAPING ONLY. No build — HJ or QS — until (a) the counsel gate in LEGACY_CHANNEL_CONSENT_MODEL.md §10 clears and (b) the owner explicitly signs off on this surface + the funeral-home channel. Shaped 2026-07-17 in response to the QuickSites session's §16.
What this is (and what it is NOT new)
A memorial / tribute website where you hear the person — their own recorded stories, in their own voice — not just text + a photo. "Hear Grandma tell how she met Grandpa." Distributed through funeral homes as a QuickSites white-label they resell to every family (reseller + commission rails).
This is not a new ethics regime. It is a new surface (a website) and a new channel (funeral homes) for the already-designed Living Voice Track B ("Lovio Presence" — the voice that outlives the person) and Track C ("The Legacy Channel") in LIVING_VOICE_ROADMAP.md. It inherits — wholesale, unchanged — the consent architecture in LEGACY_CHANNEL_CONSENT_MODEL.md and the custody/GTM posture in LEGACY_CHANNEL_ELDERCARE.md. If anything here conflicts with those, THOSE win.
The bright line (binding — restated from the consent model)
- A voice clone is created ONLY from consent recorded while the person is
living — versioned, informed, voice-specific, and (for this use)
explicitly posthumous-aware (
scope.deliver_posthumous,scope.heir_durable— consent model §5/§8). Never posthumous cloning from found audio. - Read-only for the dead. After
deceased_at, the voice entersposthumous_custody: it may PLAY BACK what the person actually recorded / pre-authorized, and it must never generate new speech they never said. No AI fabricating "grandma narrating a wedding she didn't live to see." - Family stewardship of delivery, not authorship. After death, a designated legacy contact controls who may hear (reuse the JQ Bridge hear-ACL, consent model §6) and when — never a right to make the voice say new things.
- Done right, a memorial site is therefore mostly the person's REAL recordings in their REAL voice — always ethical, and the point.
What's ethically CLEAN and could build first (still owner-gated, but no new ethics)
"Legacy stories" — a living person records + a site plays their own real audio. This is playback of consented, real recordings of a living person telling their own stories. It touches none of the posthumous machinery:
- Capture: extend the existing lovio consent + capture flow into a "record a story" surface (prompted: "how did you meet?", "advice for your grandkids"). Real voice, real recording, living consent.
- Site: a QuickSites
memorial/tributeblock plays those recordings (audio_url playback — the same permanent-public-MP3 model as About That renditions + Voice Welcome). No generation, no clone-TTS required at all. - This is buildable on shipped rails and is the honest MVP: you hear the real person. It becomes "memorial" only when the delivery/custody layer (below) is added — and that layer is the gated part.
What stays GATED (counsel §10 + owner)
- Posthumous delivery + custody mechanics (
deceased_at→posthumous_custody, legacy-contact custody, JQ Bridge hear-ACL for after-death playback) — consent model §6/§11 (phase C1). Do not build ahead of counsel. - Any clone-TTS generating NEW memorial narration in a deceased person's voice — the read-only rule largely forbids this; treat any exception as a hard no absent explicit, specific, living, counsel-cleared authorization.
- Funeral-home reseller GTM — a white-label channel selling voice-of-the-deceased at the moment of grief is high-trust, high-scrutiny; needs the owner + counsel on positioning, pricing, and the consent UX shown to grieving families.
Mesh split (when/if cleared)
- HJ owns: the voice, the capture surface, the consent record
(
voice_consents), the render-once TTS / real-recording storage (permanent public MP3s), and the posthumous-custody + hear-ACL enforcement. The bright line lives here and is non-delegable. - QuickSites owns: the memorial-site UI + the
memorialindustry scaffold- the funeral-home reseller org (existing white-label/commission rails), and
a
memorial_voiceblock that PLAYS HJ-provided consented audio_urls (same block shape asvoice_welcome/daily_artifact— it renders audio it's handed, it never generates). QS holds no consent authority and no generation.
- the funeral-home reseller org (existing white-label/commission rails), and
a
GTM note (funeral homes vs the existing nursing-home wedge)
Track C's existing wedge is nursing homes ("record while you still can"). Funeral homes are the downstream moment (at need). Both are valid; the nursing-home/at-leisure capture is ethically easier (the person records themselves, unhurried, clearly consenting) than an at-need funeral-home flow (grief, time pressure, the subject may already be gone → only pre-existing consented recordings are usable, never new capture). Prefer the ahead-of- need capture; the funeral-home surface mostly PRESENTS what was already recorded + consented. If nothing was recorded in life, the honest answer is a beautiful text+photo memorial — not a fabricated voice.
The gate (do not remove)
No code — HJ or QS — until the owner signs off AND counsel clears LEGACY_CHANNEL_CONSENT_MODEL.md §10. The clean "living person records + plays their own stories" MVP is the only part that could move earlier, and even that waits on the owner's explicit go. This doc shapes; it does not authorize.