- Home
- Security
How we protect your data
Security is how we build from day one, not something we bolt on later.
We process sensitive professional data — contacts, conversations, business relationships. We take that seriously. Every architectural decision we make starts with the question: how does this protect the people who trust us with their data?
We're an early-stage company, but we've made deliberate infrastructure choices to protect your data now, and we keep building our security posture as we scale.
What we process
Contact capture
Photos of business cards, badges, notes, and voice recordings — we extract contact information.
Enrichment
We match contacts against public professional data like LinkedIn profiles and company info.
Follow-up drafts
AI generates personalised follow-up messages based on the context you captured.
Contact storage
Structured profiles in a secure dashboard, exportable to your CRM.
How we protect it
EU-first infrastructure
Railway (EU) for hosting, Supabase (EU) for database. Your data lives in Europe by default.
Encryption everywhere
Everything encrypted in transit (TLS) and at rest — uploads, API calls, database records.
Authentication & access control
Secure session management via enterprise-grade identity infrastructure. Data is scoped per user — you only see your own contacts.
AI processing controls
Our AI runs through OpenAI's API under their enterprise data processing terms, which prohibit using your data for model training. We've also disabled API call logging for an additional layer of privacy.
International transfers
Where we use US-based processors (OpenAI, Google Cloud, Twilio), Standard Contractual Clauses govern the transfer.
What we will never do
- ✕Sell your data to third parties
- ✕Use your contacts for our own marketing
- ✕Share your data with other users
- ✕Use your data to train AI models
- ✕Access your contacts without your explicit action
If something goes wrong
If we ever discover a data breach affecting your information, we will notify you within 72 hours as required under GDPR. We'll tell you what happened, what data was affected, and what we're doing about it. No hiding, no delay.
Book a security call
Questions about security? It's our top priority, ask all your questions to our technical team by booking a slot below.
Your rights
You have full GDPR rights: access, correct, export, and delete your data at any time.
To delete your account or request an export of your data, email info@speaksoon.app. We'll confirm in writing.