Data Handling Record

Privacy Policy

This policy describes how DebriefCore handles your information. We may update it as the product evolves.

About this policy

This is a good-faith description of our current data practices. We review and update it as the product evolves.

What we collect

Account data: your email address, organization name and type, and basic membership/role information needed to run your workspace.

Capture content: the debrief answers, notes, and generated drafts you create in the app, scoped to your organization.

Usage events: limited records (for example, generation counts) used for rate limiting and basic operation.

Voice input: if you use voice capture, the audio you record is sent to our transcription provider to convert it to text. We do not store the audio recording; only the resulting transcript becomes part of your capture content, and you can review, edit, or remove it before saving (see Voice capture and transcription below).

Reference photos:images you attach to a capture to give human reviewers visual context. Reference photos are stored in your organization's private storage and are not sent to any AI model.

How we use AI — content sent to OpenAI

When you generate a draft, the relevant capture content is sent to OpenAI to produce that draft. AI outputs are drafts only and require qualified human review before they are treated as official.

Please do not enter regulated records, secrets, credentials, or highly sensitive personal data — use realistic but non-sensitive examples.

Voice capture and transcription

DebriefCore offers an optional voice capture feature. When you record audio with this feature, the audio is transmitted to OpenAI for the sole purpose of converting your speech to text (transcription). Voice capture is available to signed-in users only; we do not transcribe audio for anonymous visitors.

We do not store the audio. The recording is sent for transcription and is not retained on our systems. Only the resulting text is returned to you and saved as part of your capture, where you can review, edit, or remove it before saving.

Audio you submit for transcription is processed by OpenAI under OpenAI's own API terms and privacy practices. Under OpenAI's current API policy, content submitted through its API is not used to train its models. We do not control, and are not responsible for, OpenAI's independent practices. Please do not speak regulated records, secrets, credentials, or highly sensitive personal data into voice capture.

Reference photos

You may attach reference photos to a capture to give human reviewers visual context. Reference photos are not sent to OpenAI or any other AI model and are not used to generate drafts.

Reference photos are stored in your organization's private, access-controlled storage and are accessible only to authenticated members of your organization. Please do not upload faces, identity documents, or other sensitive personal information unless you have the rights and permissions to do so.

Boardroom — saved sessions and transcripts

Boardroom is an interactive voice or text briefing feature with Nova. When you use Boardroom, your questions and Nova's answers are automatically saved as text in a session record scoped to your organization, so you can review, export (PDF/Word), or continue past sessions. As with regular voice capture, we do not store Boardroom audio — only the transcribed text.

For security, quality, and abuse prevention, we log operational metadata about Boardroom questions in our internal audit log (for example, question length, language, and which knowledge sources were used). This audit log does not store your full question text — only the saved session record does, and only within your organization.

Voice Profile (Beta)

Voice Profile is an optional, Beta-stage feature that creates a voice-similarity fingerprint so Nova can personalize how it addresses you. It requires your explicit consent before enrollment. It is not biometric authentication and is never the sole basis for verifying your identity or approving content. It is never used to sign in.

You can delete your Voice Profile at any time from Settings. Deleting it permanently removes the record from our database — it is not merely disabled.

Translation and localization

DebriefCore's interface is available in English and Spanish. This interface translation uses fixed, pre-written text built into the app — no capture content or personal data is sent anywhere to translate the interface.

Automated translation of your capture content (for example, translating a draft into natural Mexican Spanish) is planned but not currently active. If and when we enable content translation through a third-party provider (such as HablaFlow), we will update this policy to identify the provider and the data involved, and we will require your organization's consent before any of your content is sent to that provider. Until then, your capture content is not transmitted to any translation service.

Service providers

We rely on third-party providers to operate the service, including Supabase (authentication, database, and file storage), Vercel (hosting), OpenAI (AI draft generation and voice transcription), Stripe (subscription payment processing), and Resend (transactional email). Each processes data on our behalf to provide their part of the service.

Payment card details are entered directly with Stripe and are not collected, seen, or stored by DebriefCore. A translation provider (HablaFlow) is planned for future content localization but is not active and receives no data today.

Data separation & security

Each organization's data is isolated using database row-level security so one workspace cannot access another's captures, outputs, knowledge articles, or Context Packs. We keep secret keys server-side and require authentication for real (non-demo) actions.

Retention, export & deletion

We retain your organization's data — captures, drafts, approved knowledge, saved Boardroom sessions, and audit records — for as long as your account or organization remains active. We do not currently apply automatic time-based deletion to these categories; data remains available as your organizational record until you request export or deletion.

You can export your organization's approved knowledge at any time from Settings → Data Export. Account-level export and deletion requests are handled on request — contact us at hello@debriefcore.com and we will handle it. Your Voice Profile is the exception: you can delete it yourself at any time from Settings, and that deletion is immediate and permanent (see Voice Profile (Beta) above).

What we do not claim

DebriefCore is being designed toward recognized security and privacy best practices, but it is not certified or audited against any standard. We make no SOC 2, ISO, GDPR, or FAA compliance/approval claims.

Access & visibility labels

Access is controlled by organization membership. The Internal / External / Restricted visibility labels shown on captures and outputs are not yet enforced — they do not control who can see, share, or filter content, and should not be relied on as a confidentiality or access boundary.

Contact

Questions about privacy? Email hello@debriefcore.com. Please do not send passwords or secrets by email.

See also our Terms of Use and Security & Trust page.