One page for your legal, information security and HR teams — what is collected, who sees what, where it is stored, and what the organization never receives. No marketing and no vague wording; every line here is what the software actually does.
The service runs on Telegram and WhatsApp. Joining is by personal invitation code, and on first entry the participant is shown a notice setting out what is stored and for what purpose, and must give explicit consent. That consent is recorded — the time, the version of the policy shown, and the wording of the answer.
| Type | What it is |
|---|---|
| Conversation content | The participant's messages and the system's replies |
| The personal map | A summary of the participant's working patterns, built from the conversations and confirmed by them as it goes |
| Memory log | Accumulated insights that give continuity between conversations |
| Technical identifier | The Telegram account identifier or WhatsApp phone number, and the name the participant chose |
| Usage data | When conversations happened and how long they ran, for operations and billing |
What is not collected: identity documents, addresses, card details, location, contacts, or access to email or calendar. Payments are processed by an external payment provider and card details never reach the system.
No voice recordings are kept. A WhatsApp voice message is transcribed to text and stored as text only. The audio file is not retained — a deliberate decision, so that the system holds no biometric data.
This is the question that actually gets asked, so it gets an explicit answer. Three levels of access, and no more.
The safety exception, and it is the only one. If the system detects acute distress it sends the operator an alert containing the participant's identity alone — not one word of the conversation — so that human help can be offered. The alert is not sent to the organization.
An organization commissioning a pilot wants to know whether anything happened. It receives a patterns report — deliberately designed so that no individual can be extracted from it.
| The rule | What it means |
|---|---|
| A threshold of 15 | A theme enters the report only if it came up for at least 15 participants. In a pilot cohort of 15–25 people this is a very high bar, and that is the intent. |
| Zero quotations | The report contains not one sentence spoken by a participant, not even paraphrased. |
| Zero segmentation | No breakdown by department, seniority, tenure, age or gender — each one narrows the group until a person becomes identifiable. |
| Participants see it first | The report is shown to the participants before it reaches the organization. |
| The report does not travel upward | When the pilot runs in a particular manager's territory, the report stays with them. Not to HR, not to the VP, not to the CEO. |
The fifth rule came out of a question a real manager asked: "Am I supposed to fund, out of my own budget, a process whose first measurable output is a document explaining to the CEO that the problem is me?" In a cohort that all reports to one person, the sentence "people don't say things upward" is a proper noun. So the report does not travel upward.
These are not settings that can be changed by agreement, for an additional fee, or on special request. They are the condition without which there is no product.
Precise status: the cohort report is a contractual commitment at this stage — the rules are settled and binding, and the mechanism that produces it has not yet been built in software. No report will be produced before it is built to these rules.
The list of sub-processors, in full. If another provider is added, this list is updated and subscribers are notified in advance.
| Party | What it does | Location |
|---|---|---|
| Google Cloud | Server hosting. The data processing addendum has been accepted. | USA |
| Anthropic | Generating the replies (the Claude model). Its commercial terms do not permit the content to be used to train models. | USA |
| OpenAI | Transcribing WhatsApp voice messages to text, and nothing else. | USA |
| Telegram / WhatsApp | The messaging channel. Each is subject to its own privacy policy, which the organization is invited to review separately. | Per platform |
| Payment provider | Payments only. Card details never reach the system. | External |
International transfer. The data sits in the United States. The basis for transfer: processing agreements with the cloud provider and the model provider, explicit disclosure in the privacy policy, and explicit consent that is recorded at entry. An organization with a European data residency requirement — that is a point to discuss before signing, not after.
The three substantive rights are implemented in software and work inside the conversation, without asking anyone's permission and without a human intermediary.
| The right | How | Status |
|---|---|---|
| Access and portability | A command in the conversation immediately sends the map, the memory log and every transcript — decrypted and readable. | Working |
| Rectification | The system asks the participant to confirm the map as it goes, and a mechanism verifies that a promised correction was actually made. | Working |
| Erasure | A command in the conversation, after explicit confirmation, moves every file to quarantine. Final deletion within 14 days. | Working |
| Control of access | The participant decides whether the operator may read their conversations, and can change that decision at any moment. | Working |
The 14 days include the backups. Files awaiting deletion are never included in backups at all, and the backup copies themselves are kept for 14 days and then rotated out. This is the point at which deletion promises usually break, which is why it was checked and fixed.
Leaving the organization does not transfer ownership. The map and the conversations belong to the participant, not to the employer. An employee who leaves takes them along, and the organization cannot request them — neither during employment nor after it.
| Control | Detail |
|---|---|
| Encryption at rest | All content files are encrypted on disk. Legacy files were converted in August 2026 with per-file verification. |
| Encryption in transit | TLS across all communication channels. |
| No key, no service | If the encryption key is missing, the system does not start. Previously it printed a warning and carried on writing in the clear; that was fixed, because a safeguard that only writes to a log dies quietly. |
| Key custody | The key is deliberately held outside the backup, in two separate custodies. Documented as a procedure. |
| Access restriction | Server access is restricted and encrypted. The admin interface sits behind a login, and content a participant has marked confidential is blocked there too. |
| Security incident procedure | Exists in writing: detection, containment, assessment, notification. Notice of a material incident is given without delay. |
| Backup | Daily, two-layer. The encryption key is deliberately excluded from it. |
Database classification. The personal map describes a person's behavioural patterns, so our assumption — taken strictly — is that it falls within the definition of "information of particular sensitivity" under Amendment 13 to Israel's Protection of Privacy Law, and that the database is classified at the medium security level. The high level applies only to a database of 100,000 records or more, or with 100 or more authorized users; both conditions are a long way off.
This is not a privacy question, but it comes from the same legal department in the same meeting, so it is here.
The service is a leadership coaching tool. It is not therapy, not diagnosis, and not a crisis service. The participant is told at first entry that this is a computer system and not a person. When a moment is bigger than the limits of the tool, the system says so explicitly and points to real professional human help — a referral that may not be shortened or softened.
The system never invents an emergency number. In acute distress it also sends an alert to the operator, containing identity alone.
SECTION 08A facts sheet that lists only what exists is not worth reading. This is what is missing, as of today, so that you can weigh it up front rather than discover it in a questionnaire.
| What | Status | Note |
|---|---|---|
| SOC 2 / ISO 27001 | None | Not obtained and not in progress. If your procurement threshold requires it, let's discuss that before either of us invests time. |
| External penetration test | None | Not yet carried out by an external party. |
| External legal opinion | In progress | A full self-assessment against Amendment 13 has been completed and is being passed to a privacy lawyer for review. The assessment is available to you. |
| Data protection officer | None | At current scale the assumption is that the obligation does not apply. To be reassessed with an enterprise engagement. |
| Cohort report generation | Rules settled | See section 03. The mechanism has not been built. |
| European data residency | None | The data sits in the USA. An organization with such a requirement — a point for early discussion. |
Why this is written here. We are a product in pilot, and a product in pilot that presents itself as a regulated enterprise is the real risk. What exists is built, working, and open to inspection. What does not exist is written down.
Questions on privacy and information security, and requests for the source documents — the Amendment 13 assessment, the security incident procedure, and the processing agreements — directly to me: hello@talktosaul.ai