Your data, after you have used it
Updated 25 August 2026 Applies to: Web app · iOS · Android · Windows · Browser extension · MCP server
Export is self serve on every plan. Deletion is self serve, permanent, and it says exactly what goes before you confirm. A single session can be destroyed on its own without touching the account. None of the three needs a support ticket.
The thing this page is really about
A session is a recording of you saying what is wrong with your company. The assumption you are least sure of, the cost you cannot defend, the failure you think is most likely: you said all of it out loud, and the transcript has your name on the turns where you conceded a point.
That is not an unfortunate side effect. It is what makes the product work, and it is the reason a session is worth running at all. It is also the single most sensitive document your account will ever hold, and pretending otherwise would be the first thing we asked you not to trust us about.
So the answer is not that the risk is small. The answer is that you can see the whole inventory, take it out, and destroy any part of it without asking anybody.
What one session created
This is the whole inventory. It is the same list the trust centre publishes for a reviewer, because there is no version of it that is softer for a user.
| Artefact | What it contains | Where it is created | Sensitivity |
|---|---|---|---|
| Your microphone audio | Your voice, saying your company's problems out loud, and anything else audible in your room | Your browser, the media server, then the model vendor | High |
| The transcript of what you said | The text of everything you said in the room | The speech vendor, in the United States | High |
| The brief | The proposal you want attacked. It becomes part of every persona's instructions | Typed on this site, then sent to the model vendor with every turn | Highest |
| Persona audio | Synthetic speech, generated from your brief and what you said | The model vendor, the media server, then your browser | Medium |
| The attributed transcript | Who said what, which assumption was attacked, and where the personas disagreed | Our systems | Highest |
| Session metadata | Duration, which personas were in the room, floor share, interruption counts, cost | Our systems | Low |
| Derived quality measures | How often the personas agreed with you, how often they disagreed with each other | Our systems | Low |
| The answer to the closing question | What you now believe that you did not believe an hour ago | Our systems | Medium |
Who can reach each piece of it
| Name | Data it receives | Why |
|---|---|---|
| You, signed in | Everything the account holds: every transcript, every summary, every brief, and the account history. | No other route on this list reads a transcript as a document. |
| Anybody you send it to | Whatever you exported and sent. An exported transcript is an ordinary file once it leaves here. | We cannot recall it, and nothing on our side knows it left. |
| The model vendor | The brief and the session speech, while the room is running, in order to answer it. | Named on the sub-processor list with the region it operates in. |
| People who work here | Account records, and session content only where you have asked us to look at a specific session. | Reading a transcript to answer a support question you did not ask about is not something we do. |
| A law enforcement or regulatory demand | Whatever a valid, binding order compels, which is not nothing and we will not pretend otherwise. | We tell you unless the order forbids it, and the privacy notice states the rest. |
Taking it out
The export holds the transcripts, the summaries, the briefs and the account history, in formats that open somewhere else. It is included on every plan, and it does not go through support.
Exporting before deleting is the order we recommend and the order the pages are in. Without an export, a person who wants one session gone chooses between keeping everything and losing everything, and that is not a choice we are willing to hand anybody.
Delete your account and everything in it
Deletion is permanent and support cannot undo it. Export first if you want any of it, then delete the single session or the whole account. The deletion page names what is destroyed, what is anonymised and what survives, before you confirm rather than after.
01
Export first, if you want any of it
Deletion is permanent and support cannot restore it. The export page is deliberately ahead of the deletion page for exactly this reason.
What you should see. A file on your own machine before anything is destroyed.
02
Delete a single session, if that is all you want gone
One bad session does not need the whole account destroyed. A session is deletable on its own, and it takes the summary and the brief with it.
What you should see. That session gone from the list, and the rest still there.
03
Open the deletion page for the whole account
It is reachable signed out as well as signed in, because the person who most wants it may no longer be able to sign in.
What you should see. A page that names what is destroyed, what is anonymised and what is kept, before you confirm.
04
Read the scope before you confirm
Billing records survive a deletion because tax law requires them. Everything you said in a room does not.
What you should see. A list, not a paragraph. If it reads as a paragraph, do not confirm it.
05
Confirm, and keep the receipt
The confirmation is what you show somebody who asks whether it was actually done.
What you should see. A confirmation naming what was destroyed and when.
What a deletion actually reaches
Three outcomes and no fourth. This is the same list the deletion page itself shows before you confirm, read from one source, so the page you research on and the page you act on cannot disagree.
| Item | What happens | When |
|---|---|---|
| Your account and sign in | Destroyed | When the deletion runs. |
| Every brief you wrote | Destroyed | When the deletion runs. |
| Every session transcript | Destroyed | When the deletion runs. |
| Every session summary | Destroyed | When the deletion runs. |
| Session audio, where any is retained | Destroyed | When the deletion runs. |
| Persona configuration you changed | Destroyed | When the deletion runs. |
| Copies in backups | Destroyed | Purged within 30 days of the deletion. |
| Aggregate product measurements | Anonymised | Kept only in a form that cannot be tied back to you or your company. |
| Billing and payment records | Retained | Seven years, because tax and accounting law requires it. |
The last row is the one people ask about. Billing records survive because tax law requires them, and a company that told you otherwise would either be lying or be planning to break the law on your behalf.
If you cannot sign in to delete it
The deletion page is reachable signed out, and a person who has lost access to the mailbox on the account can still make the request. Write to privacy@tingvar.com rather than to support, because it is a privacy request rather than a support question and it carries a statutory clock.
A reply comes within 5 business days. The requests page states what we do with each kind of request and how long each one takes.
Still stuck
Write to support@tingvar.com. A person replies within 2 business days, Monday to Friday. Do not send us the transcript you are asking about. The session date is enough and it is all we want.