These are the three everyone asks us. Each answer carries what backs it underneath, and the third is not a "no" — we would rather you decided on the good data.
Do the AIs train on what is said at my event?
No
And where it could be switched on, we switch it off on every single request.
Our speech-to-text provider’s model-improvement programme is decided per request, not in a settings panel. We send the opt-out flag on all of them, without exception — internal tests included — and an automated check fails the build if any file were to open a connection without it. No environment variable can turn it back on: it is a constant, not an option. It is also in writing in the data processing agreement we have signed.
What we will not tell you: that no provider keeps anything at all. The translation and summary providers run their own abuse-monitoring retention periods, and that is in their terms, not in our code. What is ours to decide — not asking for model improvement, never enabling storage, processing in the EU — is done.
Do you store what is said at my event?
No
The live path writes nothing. There are two exceptions and you decide both.
Audio passes through to the provider and back; translation is a round trip that touches no table; and the component that fans captions out to phones has no content storage. What is left of an event is always the same, and it is accounting: duration, billable minutes, microphones, source language, room code, how many devices connected and which languages they asked for. Counts, never text.
The two exceptions, both auto-deleted after 30 days: AI Summary, which stores the transcript only if somebody presses the button; and the questions a moderator puts on screen together with poll results, kept as the record of the event and folded into the minutes. Questions that never reached the screen are not stored at all.
Can anyone else read it?
It depends on the code
Nobody can publish captions into your event or see another account’s data. But the room code is access, not confidentiality.
What is closed: publishing captions requires your account’s token and a session that belongs to you, so nobody can put text into your programme. And nobody reads another account’s transcripts or data: the database isolates by row and the public keys that ship in the browser hold no write permission at all. The links you hand out are signed and open one room only: the room link, for whoever organises the event — its QR, its prepared questions and its results — and the moderation link, narrower, for whoever holds the tablet on the day. Neither reaches billing or the other rooms, and closing the room revokes both. What anyone holding the code CAN do is take part: pick a language, vote, and send a question to the queue. That question passes an automatic content filter, appears in the list the audience can upvote, and only reaches the venue screen if the moderator launches it.
What is not closed, and we say it first: whoever holds the room code can follow the event. An auto code is one in nearly 900 million and we cap failed attempts, but that is friction, not cryptography — and a code you choose to print on the programme is public by definition. For a confidential session: do not project the QR, use the room screen only, and do not press AI Summary. Then nothing of it is written down on any server of ours — the audio still travels to our speech-to-text provider, which is what the product is.
Where a spoken line goes, and where it does not stay
The same path for every line of every event. No box in this chain writes the text to disk.
1
Room microphone
Your sound desk, your cable.
nothing
→
2
Your computer
The caption engine and the video output are local.
nothing
→
3
Our relay
Forwards audio and text. Stateless: processes and forgets.
nothing
→
4
Provider in the EU
Speech-to-text and translation, against European endpoints.
nothing
→
5
Screen and phones
The room and the audience, each in their language.
nothing
All that remains: duration, billable minutes, microphones, language, room code, and how many devices and languages there were. Accounting, not content.
And three places where text usually escapes in other systems
The error log cannot carry speech
It drops by name any field that might hold a sentence — caption, line, question, summary — and summarises nested objects rather than storing them. Filtered on the operator’s machine and again on arrival.
Analytics has no free-text field at all
Only values from a closed list. A sentence cannot land there "for debugging". No email, no IP, no names.
The attendee page loads no analytics
And no session replay. What shows on an audience phone is the event transcript, and no third party gets near it.
Where it is processed
Speech
The provider’s European infrastructure, confirmed in writing. The transfer additionally rides the Standard Contractual Clauses.
Translation
European endpoints, with the region in Ireland. Never the UK.
Data at rest
Frankfurt, inside the European Union.
Sub-processors
Published with name, role and processing location. Signed data processing agreements with both that touch event content.