Trust & data

Your calls train your team. Never our models.

Your client recordings and transcripts are never used to train models — ours or any vendor's — and never sold or monetized as data. This is contractual, not a settings toggle. A DPA is available on request.

How data flows

Four steps, every one under no-training terms.

AI providers in the production chain are Anthropic and OpenAI, both under enterprise no-training API terms. The sub-processor list below is the exhaustive source.

01

Encrypted ingestion

Calls arrive via Zoom OAuth, a signed partner API, or direct upload — encrypted in transit.

02

Stored in the US

Recordings and transcripts live in the United States (Supabase on AWS, us-west-2), encrypted at rest and isolated per organization.

03

Transcribed & audited

Vetted processors under enterprise no-training terms: Deepgram for transcription, Anthropic and OpenAI for the audit.

04

Delivered to your team

Results reach the right roles. Magic-link reports are read-only and expire in 7 days.

Sub-processors

Who touches your data, and where.

Each provider processes only the minimum required for its function. We update this page before adding a processor.

ProcessorPurposeRegion
ZoomCall source (OAuth)US
DeepgramTranscriptionUS
AnthropicAI audit — no-training termsUS
OpenAIAI audit failover — no-training termsUS
SupabaseDatabase · auth · storageUS · AWS us-west-2
VercelApplication hostingUS
StripeBillingUS
ResendDelivers coaching email — sees the agent's address and the note, which quotes the transcriptUS
SentryError telemetry — PII disabled, payloads scrubbed before sendUS
PostHogProduct analytics — anonymized usage events only, no call contentUS
UpstashRate limiting — request counters keyed by organization, no call contentUS

The table above is the complete list. Our Privacy Policy covers the terms under which each one processes data.

Access & tenancy

Isolation enforced at the database, not the UI.

  • Organization-scoped row-level security — no cross-tenant access, enforced at the database, not just the UI.
  • Role-based dashboards: admins, supervisors, and agents each see only what their role permits.
  • Caller-identity sanitization for managed engagements — voices are separated without exposing PII.
  • Audit log on every administrative action.
  • Magic-link reports are read-only and expire after 7 days.
Retention & deletion

Your plan sets how long we keep your data — and you can delete it anytime.

The periods below are what your plan guarantees we retain. Deletion runs on request and is verified: we re-count every table and your recording storage afterwards, and the job reports itself as unclean if anything survives. Scheduled expiry at the end of each period is on our roadmap — we would rather tell you that than imply it already runs. Life-insurance workflows involve PII, not PHI; if your use case touches health data, talk to us first.

Starter

90 days

Team

13 months

Pro

2 years

Agency

10 years

Enterprise

Custom

Vulnerability disclosure

Found something? Tell us — we would rather hear it from you.

We do not run a paid bug bounty, and we would rather say that plainly than imply one exists. What we do offer: we read every report, we reply, and we will credit you publicly if you want the credit.

Safe harbour. If you follow this policy in good faith, we will not pursue legal action against you, and we will work with you if a third party does. Machine-readable contact details: /.well-known/security.txt.

We audit ourselves on a schedule. A full internal security review runs every 60 days, and each one is written up with its findings and their fixes rather than a pass mark. The most recent closed on 29 July 2026 with six findings resolved; the next is due 29 August 2026. Between reviews, every pull request is gated on a dependency audit that fails the build on any high-severity CVE, and on a secret scan of the full repository.

What we do not have. No SOC 2 report, no ISO 27001, no third-party penetration test, no paid bug bounty. We are a small team and we would rather show you the controls we actually run than a badge we have not earned. Ask us for anything specific and we will answer it straight.

Proof a prospect can verify before buying.

Every Compliance Certificate carries a public, cryptographic verifier — the one place anyone can confirm an audit is genuine without an account.