Privacy

Where your data lives, and how we checked

Everyone says your data is safe. Almost nobody says how they know. This is what we measured, what came back, and the three things we can’t prove to you from here.

“Your data is safe” is the cheapest sentence you can write on a website. It costs nothing, it can’t be checked from outside, and everyone writes it.

So instead of repeating it, here is what we went to look at, what came back, and where we ran out of things we can prove.

01Where they are, literally

In the European Union, in Ireland. And not “mostly”: we counted the pieces one by one —the databases, the file stores, the programs that answer when you talk to Saelyx— and every one of them is there. Not a single stray one on another continent.

We checked it that way on purpose. It is easy to put the bulk in Europe and leave one piece outside without noticing, because nothing breaks when it happens: it keeps working exactly the same. The only way to know is to count.

The exception, said here and not buried: the Apple Watch. Its microphone connects directly to another provider and that audio does not pass through our servers. It is spelled out, with names, in the privacy policy.

02Encrypted, and what that actually means

Your memory is encrypted in transit and at rest. The second one with our own key, which rotates by itself, not the one that comes switched on by default. The difference matters: a key of your own can be disabled —and then nothing decrypts again—, it leaves a trace of every use, and it renews without anyone remembering to do it.

And now the part almost nobody tells you. Having your own key does not mean few people can decrypt. That is decided by who has permission, which is a separate thing handled separately. Saying “encrypted” and letting it sound like “nobody can see it” is the most common sleight of hand in this industry. We say them apart because they are two separate questions.

03What deletes itself

  • The raw transcript of a meeting: 30 days.
  • Videos and their transcripts: 30 days.
  • The exports you generate: 30 days.
  • What you import: 7 days.

That is what is configured. But a deletion rule that is set and a deletion rule that is working are two different things, and we have learned that by running into the gap. So we went to look at the oldest file still alive. It was 36 days old, against a rule of 35. That extra day is not a fault: deletion runs in batches, not the second the deadline passes. What it proves is the thing that matters: the rule isn’t declared, it is deleting, and that is why nothing older is left.

We write the exact number instead of rounding to “exactly the age it should be” because the first version of this paragraph said that, and it was wrong by a day. A figure rounded towards the picture that suits you stops being a figure.

04What does not delete itself, on purpose

Your memory. The facts you decide Saelyx should remember do not expire, and that is a decision, not an oversight: a memory that evaporates on its own is worth nothing.

The consequence has to be said in full, even though it sounds worse: if you stop using Saelyx and don’t delete your account, your things are still there. The cleaning up is yours. That is why the memory is a list you can open, read, edit and empty —and the account can be deleted whole, cascading—. We cover it at length in your memory in Saelyx.

The same goes for the documents you attach: they don’t expire. Checked —the oldest one still there is over two months old— and it matches what the policy says, which keeps them while your account is active. If you showed it a contract in June, that contract is still there.

05Our favourite proof: what doesn’t fit

We say audio and screen are processed on the fly and not stored in our systems. You can check that by reading configurations… or you can check it by counting.

A conversation session takes up under 300 bytes on average in our databases. For scale: 300 bytes is about fifty words of this article. Identifiers and timestamps fit in there. One second of audio does not. Not one frame.

We give a ceiling rather than an exact figure, and it is worth explaining why. The first version of this paragraph said “262 bytes”. Measuring it again a few hours later gave 268: the size the database reports is an estimate that refreshes itself every few hours, so the exact figure expires without warning. “Under 300” is still true tomorrow. Three exact digits sound more rigorous and are less true.

We like this proof more than the others because it doesn’t depend on anyone having configured anything correctly. A retention rule can be set wrong. A setting can be changed tomorrow. But bytes are bytes: the audio isn’t there because it wouldn’t fit even if we wanted to keep it.

06Three things we can’t prove to you from here

This section is what makes the rest worth anything.

  • That the voice engine provider holds up their end. We configure what can be configured and we name them in the policy. But what happens inside their house is guaranteed by their contract, not by our word.
  • That deletion takes absolutely everything. The buttons exist and they work. That the cascade doesn’t miss a corner can only be shown by deleting a real account and going to look for the leftovers. It is a check that needs doing, not one we can show you yet.
  • None of the above, if you don’t believe us. All of this is claims about servers you have no access to. You can believe them or not; you cannot verify them from outside. That is why we prefer them specific and falsifiable —dates, figures, exceptions— rather than reassuring.

07Frequently asked questions

Is everything in Europe?

Saelyx infrastructure is, in Ireland, checked piece by piece. The exception is the Apple Watch, whose audio goes straight to the provider without passing through our servers, plus some external providers that may process data outside the European Economic Area. Both cases are in the policy.

What does “encrypted” mean exactly?

In transit and at rest, with our own key that rotates by itself. It does not mean that few people can decrypt it: that depends on permissions, which is a different thing.

Is my audio stored?

Not in our systems. And it isn’t just that we don’t store it: there would be nowhere to. A session takes under 300 bytes.

What if I stop using it?

Your memories are still there. They don’t expire, on purpose. You can empty them one by one or delete the whole account.

When does meeting data get deleted?

The raw transcript after 30 days, on its own. The summary stays until you delete it or close your account.