• No passwordsSign-in is an emailed one-time link plus a 6-digit code.
  • No AI trainingNo AI provider trains on your data, and we never opt in to data sharing.
  • Your retention periodWorkspaces choose how long transcripts are kept. Older ones are deleted automatically.
  • US hostingData is stored in the United States on Render, a SOC 2 Type II audited host.

Data we store

Talkthrough keeps account details, practice transcripts, voice recordings and results in one database. Voice audio streams from the device to the voice model during a round, and the call is also recorded and stored in the same database, with no new vendor. The learner and their coach can play it back.

DataStored?
Name, email, optional phone numberYes, in our database
Practice transcriptsYes, until the workspace's retention period ends or the data is deleted
Scores, feedback, coach notes and session ratingsYes. Written feedback, notes and rating comments follow the retention period. Scores are kept for progress over time.
Coach methodology documentsThe text is extracted and stored. The original file isn't kept.
Voice recordingsYes, in our database. The learner and their coach can play them back. Kept with no time limit until deleted; a workspace's retention period doesn't remove them.
PasswordsNone exist
Sign-in links and codesOnly as a one-way hash. They work once and expire after 30 minutes.

Who can see what

  • Learners see their own practice.
  • A learner's coach sees their practice in full. Coaches see only their own learners, and managers only the cohorts they lead.
  • Owners, admins and cohort leads see progress only: names, practice, scores and criteria met. They don't see what was said, so no transcripts, quotes, written feedback, recordings, coach notes or rating comments, unless they are that learner's coach. Changing a learner's coach is written to the audit log.
  • Access checks run on every request, and every API request is validated before it's handled.

AI providers

Practice runs on AI models from OpenAI and Anthropic, used through their business APIs.

  • No training. Neither provider trains on API data by default, and we don't take part in any data-sharing program.
  • No stored conversations. Our code never asks a provider to store a conversation. The scoring call sends store: false, and voice sessions leave storage and tracing off.
  • Short-term safety copies. OpenAI keeps abuse-monitoring logs for up to 30 days. Anthropic deletes API data within 30 days and keeps content flagged for policy violations for up to 2 years.
  • Zero data retention. Both providers offer it with their approval. We'll apply when a customer needs it.
  • The AI doesn't decide. Scores and feedback are practice aids that a coach reviews. They aren't meant for hiring, promotion or performance decisions.

Subprocessors

These companies process customer data for us. All are based in the United States, and none may use it to train AI models.

CompanyWhat forData it receives
RenderHosting for the app and its databaseAll stored account and practice data
OpenAILive voice conversation, speech, conversation direction, scoringPractice audio and transcripts during a round; scenario and methodology text
AnthropicScenario characters, the Scenario Builder, feedback, typed practiceScenario text and transcripts
PostHogProduct analyticsUsage events keyed by an internal ID. No names, emails, IP addresses or conversation content; page text and form inputs are masked.
ResendEmail delivery: sign-in links and codes, and practice notices once they launchEmail addresses and the content of those emails
CloudflareDNS, website hosting, email forwarding for our addresses, and access control for our internal staff consoleNetwork traffic and email to our addresses, in transit only; nothing stored
AppleiPhone practice reminders, once they launch, if a learner allows notificationsA device token, removed on sign-out, and generic reminder text. No practice content.

We'll update this list before adding a subprocessor.

Controls in place

  • Encryption in transit: TLS on every connection. The database is encrypted at rest by the hosting provider.
  • Sign-in: passwordless one-time links and codes. A link locks after 5 wrong codes, and the same response is given whether or not an email has an account.
  • Rate limits on sign-in emails, code guesses and AI usage.
  • Session cookies are HttpOnly, Secure and SameSite=Lax, and expire after 30 days.
  • Roles: owner, admin, manager, coach and learner, scoped to each workspace.
  • Security headers: HSTS, a nonce-based Content Security Policy, frame blocking, and strict referrer and permissions policies.
  • Live sessions: browsers can connect to a practice round only from our own site.
  • Automatic retention: transcripts and written feedback older than a workspace's retention period are deleted every hour, and each purge is logged.
  • Audit log of admin actions, workspace changes and retention purges.
  • Change control: type checks, unit tests, a build and a smoke test on every change. Production deploys only from code that has passed CI and already runs on our test server, with automatic rollback if a health check fails.
  • Dependency scanning against the GitHub Advisory Database on every dependency change and weekly. High or critical findings fail the build.
  • Separate production keys for AI providers, kept only in the hosting provider. Two-factor sign-in is required on the hosting account.

Roadmap

ItemStatus
Daily database backups with a tested restoreBefore the first customer
Data Processing Agreement (DPA)In preparation
SOC 2 Type 1 (Security), then Type 2Planned
Single sign-on (SAML or OIDC)Planned
Self-serve data export and deletionPlanned. Until then, we export or delete on request.
A workspace setting to delete recordings automatically after a set timePlanned. Until then, recordings stay until they're deleted.
Pull request approval before every production deployPlanned

Report a security issue

If you think you've found a vulnerability, please email security@talkthrough.studio. We'll confirm we received it and keep you updated while we fix it. Please don't access other people's data or disrupt the service while testing.

For a security questionnaire or a copy of our security overview, write to hello@talkthrough.studio.

See also our privacy policy and terms.