---
url: https://tingvar.com/trust/your-data
title: "Your data · Tingvar"
updated: 2026-09-09
---

# Your data

A Tingvar session produces a transcript. That transcript is a record of your company's unresolved strategic weaknesses, spoken aloud and attributed. Read this before you run one.

Version 1.0.0 Effective 2026-08-24 Last updated 2026-08-24

In short

Applies to: Every buyer, before their first session

- A session transcript is a record of your unresolved strategic weaknesses.
- This page states where it goes, who can reach it and how to destroy it.
- Read it before your first session rather than after it.

## What a session actually produces

This is the inventory a reviewer builds for themselves during due diligence. Publishing it first is both honest and faster for everybody.

| Artefact | What it contains | Where it is created | Sensitivity |
| --- | --- | --- | --- |
| Your microphone audio | Your voice, saying your company's problems out loud, and anything else audible in your room | Your browser, the media server, then the model vendor | High |
| The transcript of what you said | The text of everything you said in the room | The speech vendor, in the United States | High |
| The brief | The proposal you want attacked. It becomes part of every persona's instructions | Typed on this site, then sent to the model vendor with every turn | Highest |
| Persona audio | Synthetic speech, generated from your brief and what you said | The model vendor, the media server, then your browser | Medium |
| The attributed transcript | Who said what, which assumption was attacked, and where the personas disagreed | Our systems | Highest |
| Session metadata | Duration, which personas were in the room, floor share, interruption counts, cost | Our systems | Low |
| Derived quality measures | How often the personas agreed with you, how often they disagreed with each other | Our systems | Low |
| The answer to the closing question | What you now believe that you did not believe an hour ago | Our systems | Medium |

Everything one session creates, and where it is created

Scroll to see the rest

## How long each piece is kept

Every row carries a number. An unbounded retention statement is banned from this site by our own commitment C20, and the build fails on the phrase it usually hides behind.

| Item | How long | How to delete it |
| --- | --- | --- |
| Session audio, yours and the personas' | Not retained. Processed while the room is live | Nothing to delete, because nothing is written |
| Transcripts and the brief | Kept until you delete them, then gone within 30 days including backups | Delete a session yourself, or delete the account |
| Session metadata, such as duration and floor share | 24 months, then aggregated | Aggregated records carry no identifier |
| The one question a session ends on | Destroyed with the session, so within 30 days of you deleting it | Deleted with the session |
| Server logs | 90 days | Purged automatically |
| Backups | Purged within 30 days of the source being deleted | Automatic, and this is the number questionnaires ask for |
| Billing records | 7 years | Tax law requires them, so they survive a deletion request |
| Consent records | 6 years after the consent is withdrawn | Kept to evidence that the choice was honoured |

The retention schedule, with a number on every row

Scroll to see the rest

## Where it is processed

Your session audio and your transcripts are processed in the United States, in Google Cloud's us-central1 region. There is no EU only processing region for this configuration. For customers in the UK and the EEA that is a transfer out of your region, and we rely on Standard Contractual Clauses and the safeguards in our data processing agreement.

Caution If your procurement requires EU residency

Today the honest answer is that we cannot meet it. We would rather you knew that before you bought than after. When the position changes we will publish it here with a date, and we will not promise one in advance.

Not yet produced

A figure showing where your words go and where they stop. It has to match the sub processor list exactly, and that list is not final, so drawing it now would publish a boundary we might move.

Blocked on the sub processor list being final 2026-08-26

## What is not built

The compliance layer is not built. That is the second half of the honest answer about your data, and a reviewer should read it here rather than find it three weeks into a procurement. Named plainly, this is what is absent today, in the same words the capability table on the enterprise page uses.

- No single sign on.
- No directory provisioning.
- No audit log and no audit export.
- No tenancy isolation. Sessions are isolated per account, not per tenant.
- No retention override. Retention is the published default for every account.
- No role model beyond one role. Every account holder can do everything their own account can do.
- No service level agreement. Not planned. There is no operating history to write one from.

Each of these is stated as not built, not as coming. Where an item sits on the roadmap it sits there in the future tense, with the state it is in and no delivery date, because a date we cannot keep is worth less to you than the word no. If one of them is a hard requirement, the honest answer today is that we cannot meet it.

The evidence is published in two tables rather than asserted here. The [capability table on the enterprise page](/enterprise) carries a yes or a no on every row, and the [known gaps on the security page](/security) name what we do not have and why.

## Who touches it

Every vendor that touches customer data is named, including the model vendor, which is the row most vendor lists leave out. The list carries the data category each one receives and the jurisdiction it operates in.

[The full sub-processor list](/subprocessors)

## The questions this page exists to answer

### What happens to my recording?

Tingvar does not store your session audio: it is processed while the room is live and no recording of it is kept. What persists is the transcript, the text of what you said and what each persona said, attributed line by line. Only the account that ran the session can read that transcript, and nobody at Tingvar reads one without your written request on a support case. You can delete any session yourself, and deletions are purged from backups within 30 days. The retention schedule is published at tingvar.com/trust/your-data.

### Who can hear my strategic weaknesses?

Nobody else joins a Tingvar room: the participants are you and the AI personas, and the audio is not stored for anyone to play back later. The transcript is the part that persists, and it reaches our model vendor as part of the personas' context. Every vendor that touches customer data is named on the sub-processors page, including the model vendor. Who at Tingvar can read a transcript, and in what circumstances, is stated at tingvar.com/trust/your-data.

### Is my data used to train AI models?

No, Tingvar does not use your brief, your transcript or your audio to train models. Google, which runs the model, states that customer data submitted to Vertex AI is not used to train or fine-tune its models without permission, that cached content is held for up to 24 hours in the data centre serving the request, and that prompts may be logged for abuse detection unless an exception is agreed. It is linked from our sub-processors page so you can check it.

### Where is my data stored?

Your Tingvar session audio and transcripts are processed in the United States, in Google Cloud's us-central1 region, and we do not currently offer an EU-only processing region. For customers in the UK and the EEA, that means a transfer out of your region. We rely on Standard Contractual Clauses and the safeguards in our DPA. If your procurement requires EU data residency, the honest answer today is that we cannot meet it, and we would rather you knew that before you bought than after.

### How do I delete a session?

You delete a Tingvar session yourself from the session list, and deleting your account destroys every session in it. Deletion is self-service and does not go through support. Anything you delete is purged from backups within 30 days, and we publish that number because an unbounded backup window is what fails a security questionnaire. Billing records survive deletion for seven years, because tax law requires it, and we say so rather than implying everything vanishes.

### I am going to describe things about my company that are not public. Should I?

A Tingvar session is a spoken record of what is wrong with your plan, which makes it one of the most sensitive artefacts your company could produce. So the honest advice is to read our data page before your first session rather than after it. What we control is where it goes, who can reach it and how fast you can destroy it, and all three are published. Names, unreleased figures and anything under an agreement with somebody else are worth redacting from the brief.

### Do you have SOC 2 or ISO 27001?

No, Tingvar holds no SOC 2 report and no ISO 27001 certificate, and we will not claim a stage of either one that we have not reached. No product in the set we crawled on 23 August 2026 publishes one either. What we do have is published: the controls on the security page, a pre-signed DPA you can read in full without a form, and every sub-processor named including the model vendor. We answer a security questionnaire in five business days.

## What we would redact if it were our plan

Names of individuals, unreleased figures, and anything held under an agreement with somebody else. The personas argue about the shape of a plan, and a shape survives redaction better than most people expect.

Related documents

- [Privacy notice](/privacy)
- [Sub-processors](/subprocessors)
- [Security](/security)
- [Data processing agreement](/dpa)
