Skip to main content

Your data

A Tingvar session produces a transcript. That transcript is a record of your company's unresolved strategic weaknesses, spoken aloud and attributed. Read this before you run one.

Version 1.0.0 Effective 2026-08-24 Last updated 2026-08-24

In short

Applies to: Every buyer, before their first session

  • A session transcript is a record of your unresolved strategic weaknesses.
  • This page states where it goes, who can reach it and how to destroy it.
  • Read it before your first session rather than after it.

What a session actually produces

This is the inventory a reviewer builds for themselves during due diligence. Publishing it first is both honest and faster for everybody.

Everything one session creates, and where it is created
ArtefactWhat it containsWhere it is createdSensitivity
Your microphone audioYour voice, saying your company's problems out loud, and anything else audible in your roomYour browser, the media server, then the model vendorHigh
The transcript of what you saidThe text of everything you said in the roomThe speech vendor, in the United StatesHigh
The briefThe proposal you want attacked. It becomes part of every persona's instructionsTyped on this site, then sent to the model vendor with every turnHighest
Persona audioSynthetic speech, generated from your brief and what you saidThe model vendor, the media server, then your browserMedium
The attributed transcriptWho said what, which assumption was attacked, and where the personas disagreedOur systemsHighest
Session metadataDuration, which personas were in the room, floor share, interruption counts, costOur systemsLow
Derived quality measuresHow often the personas agreed with you, how often they disagreed with each otherOur systemsLow
The answer to the closing questionWhat you now believe that you did not believe an hour agoOur systemsMedium

How long each piece is kept

Every row carries a number. An unbounded retention statement is banned from this site by our own commitment C20, and the build fails on the phrase it usually hides behind.

The retention schedule, with a number on every row
ItemHow longHow to delete it
Session audio, yours and the personas'Not retained. Processed while the room is liveNothing to delete, because nothing is written
Transcripts and the briefKept until you delete them, then gone within 30 days including backupsDelete a session yourself, or delete the account
Session metadata, such as duration and floor share24 months, then aggregatedAggregated records carry no identifier
The one question a session ends onDestroyed with the session, so within 30 days of you deleting itDeleted with the session
Server logs90 daysPurged automatically
BackupsPurged within 30 days of the source being deletedAutomatic, and this is the number questionnaires ask for
Billing records7 yearsTax law requires them, so they survive a deletion request
Consent records6 years after the consent is withdrawnKept to evidence that the choice was honoured

Where it is processed

Your session audio and your transcripts are processed in the United States, in Google Cloud's us-central1 region. There is no EU only processing region for this configuration. For customers in the UK and the EEA that is a transfer out of your region, and we rely on Standard Contractual Clauses and the safeguards in our data processing agreement.

Not yet produced

A figure showing where your words go and where they stop. It has to match the sub processor list exactly, and that list is not final, so drawing it now would publish a boundary we might move.

Blocked on the sub processor list being final 2026-08-26

What is not built

The compliance layer is not built. That is the second half of the honest answer about your data, and a reviewer should read it here rather than find it three weeks into a procurement. Named plainly, this is what is absent today, in the same words the capability table on the enterprise page uses.

  • No single sign on.
  • No directory provisioning.
  • No audit log and no audit export.
  • No tenancy isolation. Sessions are isolated per account, not per tenant.
  • No retention override. Retention is the published default for every account.
  • No role model beyond one role. Every account holder can do everything their own account can do.
  • No service level agreement. Not planned. There is no operating history to write one from.

Each of these is stated as not built, not as coming. Where an item sits on the roadmap it sits there in the future tense, with the state it is in and no delivery date, because a date we cannot keep is worth less to you than the word no. If one of them is a hard requirement, the honest answer today is that we cannot meet it.

The evidence is published in two tables rather than asserted here. The capability table on the enterprise page carries a yes or a no on every row, and the known gaps on the security page name what we do not have and why.

Who touches it

Every vendor that touches customer data is named, including the model vendor, which is the row most vendor lists leave out. The list carries the data category each one receives and the jurisdiction it operates in.

The full sub-processor list

The questions this page exists to answer

What happens to my recording?

Tingvar does not store your session audio: it is processed while the room is live and no recording of it is kept. What persists is the transcript, the text of what you said and what each persona said, attributed line by line. Only the account that ran the session can read that transcript, and nobody at Tingvar reads one without your written request on a support case. You can delete any session yourself, and deletions are purged from backups within 30 days. The retention schedule is published at tingvar.com/trust/your-data.

Who can hear my strategic weaknesses?

Nobody else joins a Tingvar room: the participants are you and the AI personas, and the audio is not stored for anyone to play back later. The transcript is the part that persists, and it reaches our model vendor as part of the personas' context. Every vendor that touches customer data is named on the sub-processors page, including the model vendor. Who at Tingvar can read a transcript, and in what circumstances, is stated at tingvar.com/trust/your-data.

Is my data used to train AI models?

No, Tingvar does not use your brief, your transcript or your audio to train models. Google, which runs the model, states that customer data submitted to Vertex AI is not used to train or fine-tune its models without permission, that cached content is held for up to 24 hours in the data centre serving the request, and that prompts may be logged for abuse detection unless an exception is agreed. It is linked from our sub-processors page so you can check it.

Where is my data stored?

Your Tingvar session audio and transcripts are processed in the United States, in Google Cloud's us-central1 region, and we do not currently offer an EU-only processing region. For customers in the UK and the EEA, that means a transfer out of your region. We rely on Standard Contractual Clauses and the safeguards in our DPA. If your procurement requires EU data residency, the honest answer today is that we cannot meet it, and we would rather you knew that before you bought than after.

How do I delete a session?

You delete a Tingvar session yourself from the session list, and deleting your account destroys every session in it. Deletion is self-service and does not go through support. Anything you delete is purged from backups within 30 days, and we publish that number because an unbounded backup window is what fails a security questionnaire. Billing records survive deletion for seven years, because tax law requires it, and we say so rather than implying everything vanishes.

I am going to describe things about my company that are not public. Should I?

A Tingvar session is a spoken record of what is wrong with your plan, which makes it one of the most sensitive artefacts your company could produce. So the honest advice is to read our data page before your first session rather than after it. What we control is where it goes, who can reach it and how fast you can destroy it, and all three are published. Names, unreleased figures and anything under an agreement with somebody else are worth redacting from the brief.

Do you have SOC 2 or ISO 27001?

No, Tingvar holds no SOC 2 report and no ISO 27001 certificate, and we will not claim a stage of either one that we have not reached. No product in the set we crawled on 23 August 2026 publishes one either. What we do have is published: the controls on the security page, a pre-signed DPA you can read in full without a form, and every sub-processor named including the model vendor. We answer a security questionnaire in five business days.

What we would redact if it were our plan

Names of individuals, unreleased figures, and anything held under an agreement with somebody else. The personas argue about the shape of a plan, and a shape survives redaction better than most people expect.