AudioClerkUpload a recording

AudioClerk

Retention, deletion and acceptable use

Specific enough to publish and true enough to survive an audit. If any row here is wrong, the product is wrong — tell us and we will fix the product.

What we hold, and for how long

WhatWhere it livesDefault lifeYou can change it
Upload in flightTLS 1.3 straight to our host, no third-party CDNSecondsNo
Audio at ingestEncrypted volume on the web tier, until the worker collects itMinutes — deleted on collectionNo. Attested routes upload straight to the worker, skipping this step
Original audioEncrypted volume on the worker, per-job directory, mode 70024 h after the job completesYes — immediate, 7 d, 30 d, or keep
Decoded audio, alignment temp filesWorker scratch, tmpfs — never a diskEnd of jobNo — never configurable
Voice embeddings from diarizationProcess memory onlyEnd of jobNo — never written to disk
Transcript and derived documentsEncrypted volume90 daysYes — 30 d, 1 y, or until deleted
Job metadata: id, duration, costPostgres7 years (tax)No — contains no content
LogsWorker and web host14 days, job ids only, never filenamesNo
Deletion logAppend-only2 yearsNo — this is the evidence

The thing that would make this a lie

Nightly backups are how a deletion promise usually turns out to be false. If audio sat in the backup set with a retention policy measured in weeks, “deleted after 24 hours” would be wrong by about thirty days — and wrong in a way nobody would notice until a subject-access request or a breach.

So the audio and transcript volumes are excluded from backup entirely. We back up the metadata database and nothing else. A lost disk means lost recordings. That is the correct trade for this product, and we would rather say it here than have you discover it.

What else is true

  • Deleted means unrecoverable.

    We unlink the file on an encrypted volume. We do not claim a secure wipe on hardware we do not physically own, because that would not be honest.

  • Nothing trains anything.

    The models run locally and self-hosted weights do not learn. No recording has ever been used to train anything, and none will be.

  • Sovereignty is not a tier.

    Every recording, on every package, is processed on hardware we own by a container with no network interface. There is no upgrade that makes your audio more private, because there is no version of this service that sends it anywhere.

  • Isolation is per job.

    A fresh container per recording, destroyed at the end. Separate directories, no shared scratch, no network egress at all.

Acceptable use

Recording law is not uniform — one party's consent is enough in Canada and much of the United States, two parties are required in a dozen states, and the EU and UK need a lawful basis regardless. We do not do the recording and cannot police it, so you attest at upload that you had the right to record. We will not knowingly process covert recordings.

We cannot moderate content we delete within 24 hours, and we do not pretend to. There is a takedown contact and a right to terminate. Liability is capped at fees paid, and no output is warranted for decisions of consequence.

Subprocessors

No vendor processes your audio, on any package. Every recording is transcribed on GPU hardware we own, in a container with no network interface. The only third party that touches audio at all is the host of our upload server, which holds an encrypted file for the minutes before our worker collects it — and with Attested, upload goes straight to the worker, so even that does not happen.

If we ever route a package to a hosted transcription vendor, that vendor will be named here before a single byte reaches it, it will be opt-in, and it will be on a zero-retention, no-training tier.

Questions, a DPA request, or a suspected breach: clerk@audioclerk.aitech.ca