Security

Security, privacy and encryption. Your recordings stay yours.

You are handing us meetings, interviews and things people said out loud. That deserves a straight answer rather than a page of badges — so here is what we do with it, in the order you would ask.

The first question everyone asks

Business content is never training data.

Content in team and enterprise workspaces is not used to train models, unless your organisation explicitly agrees. On newly created individual accounts, de-identified content may help improve our speech models — one switch in Settings turns it off; existing accounts are opted out automatically.

Sharing

Nobody sees it until you decide they should.

A project opens at Restricted access, which means you and no one else. Turning on a view link is a deliberate act, and turning it back off ends it — the link you sent stops working the moment you flip the switch.

Deleting

You can take it back at any time.

Delete a project and it is out of your workspace the moment you confirm. Permanent removal from our systems happens when you delete your account, or at any time on written request. We ask you to type your email first, because we would rather slow you down for a moment than let a mis-click take your work. The Privacy Policy sets out what we keep, and why.

A worked example

Follow one file.

The clearest way to answer “what happens to my data” is to watch it happen. This is a 102-minute board recording, from the moment it leaves your laptop to the moment it stops existing.

  1. 01

    You upload it

    It travels over TLS 1.2 or newer, and it lands in your projects and nowhere else — at rest in AWS Singapore storage, encrypted with AES-256. Nobody is notified, no link exists yet, and there is no shared folder it quietly appears in.

  2. 02

    We transcribe it

    Our AI and cloud providers do the processing. They return the transcript; they do not keep your audio to learn from, and neither do we.

    Also in the roomAI and cloud infrastructure

  3. 03

    You fix the two names it got wrong

    Still just you. Editing is single-player today — the person who owns the project is the only person who can change it.

  4. 04

    You send it to one colleague

    You switch on a view link. They can read it; they cannot edit it. Someone without an account sees roughly the first minute, badged Preview, and cannot copy the text.

  5. 05

    You ask us why one export looks wrong

    To answer that, someone here opens your project — and that opening is written into the log with your conversation number against it. It is the only reason we ever look. Staff access to production systems needs two-factor login and is reviewed on a schedule.

    Also in the roomSubanana support · Intercom

  6. 06

    You delete it

    When you delete a project, it leaves your workspace immediately. Permanent removal from our systems happens when you delete your account, or on written request. Eligible paid plans retain projects until you delete them. Projects and data on the Free plan are subject to expiry after 90 consecutive days without a successful sign-in, followed by a 14-day grace period.

Everyone who was in the room

The full list, with what each one receives, lives at one address: subanana.com/legal/subprocessors. If it changes, that page changes first.

AI and cloud infrastructure
Transcribes, translates and hosts
Stripe
Takes the payment — your card never reaches us
Intercom
Carries what you write to support
PostHog
Product analytics, hosted in the EU, deleted after 90 days
Google · Microsoft
Signs you in, and reads your calendar if you connect it

Three things we won’t pretend.

We don’t have a SOC 2 report yet.

We follow SOC 2-aligned practices and are working toward the report. When it exists we will say so here — until then we won’t borrow the badge.

Standard plans run in the cloud.

A file has to reach our infrastructure to be transcribed, and our providers work across regions, so processing can happen outside Hong Kong. If it has to stay inside a boundary you draw, that is a private deployment, and we scope those one at a time.

Sharing is a window, not a workspace.

Two people can’t edit the same project yet — the owner edits, everyone else reads. It keeps the permissions simple and it is the honest state of the product today, not a security posture we are claiming credit for.

If anything here is unclear, ask.

A real person answers, and we would much rather have the conversation before you upload something than after. Nothing on this list needs a sales call first — say which one and it comes back written down.

hello@subanana.comA person replies — usually the same day. Privacy requests: privacy@subanana.com, answered within 7 days; verified deletions completed within 30.
Our security questionnaire
Answered in writing, signed by someone here
The sub-processor list
Published at subanana.com/legal/subprocessors
A data processing agreement
Self-serve at subanana.com/legal/dpa — countersign and send it back
A copy of your data
Everything we have on you, as a file
Deletion
Of one project, or of everything

We operate under Hong Kong’s Personal Data (Privacy) Ordinance, and the rights it gives you are yours to use at any time — you do not need a reason and we will not ask for one.

Written by the people who build Subanana.