Back to Home
ChiefofStaff security shield

Security & Data Handling

Written for people who have to answer for what their tools did: partners, founders, and whoever runs the security review. It says what is true today, including the parts that are still in build.

Encrypted in Transit

All data is encrypted using TLS during transmission between your device and our servers.

No Data Selling

We never sell personal data, use email content for advertising, or build marketing profiles.

Secure Hosting

Hosted on secure, access-controlled cloud infrastructure.

Data Storage & Isolation

Tasks, metadata, voice transcriptions, and account settings are stored securely with strict account isolation. Each user's data is logically separated to prevent cross-account access.

  • Voice notes are transcribed and are not used for anything else; automatic deletion of the audio immediately after transcription is being built and is not in place yet
  • Transcriptions retained up to 30 days or until account termination
  • The Service does not access or import device phone contacts
  • Integration data (Google/Microsoft) used exclusively for core functionality

Data Retention

Data TypeRetention PeriodDeletion Trigger
Voice recordingsRetained in processing logs; immediate deletion in buildAccount termination
TranscriptionsUp to 30 daysAutomatic or account termination
Account dataDuration of subscriptionAccount deletion
Task & productivity dataDuration of subscriptionAccount deletion
Integration dataWhile integration is activeDisconnection or account deletion
Security logsUp to 12 monthsSystem rotation

Upon account termination, personal data is deleted or anonymized within a commercially reasonable timeframe unless retention is legally required.

Auditable Activity Trail

Every delegated action is logged end to end for an operational audit trail, so what was asked, what was done and by whom can always be reconstructed. Security event logs are retained for up to 12 months.

Security Measures

  • Encryption in transit (TLS)
  • Role-based access control
  • Limited internal access to production data
  • System of record in the EU (Frankfurt); model and transcription providers currently US-hosted
  • Contractual subprocessor safeguards
  • OAuth 2.0 for Google and Microsoft integrations (we never see your passwords)

Access Control

You are responsible for maintaining the confidentiality of your account credentials and all activity under your account. We recommend:

  • Using strong, unique passwords
  • Notifying us immediately of any unauthorized access
  • Revoking third-party integration access if no longer needed

International Data Transfers

The system of record (tasks, time entries, account data) is hosted in the European Union, in Supabase's eu-central-1 region in Frankfurt. Some processing leaves the EU: speech to text and the language models we call are US-hosted providers, so the content of an instruction passes through the United States even though the record of it does not. Transfers are safeguarded by:

  • Standard Contractual Clauses (EU 2021/914)
  • UK International Data Transfer Addendum (where applicable)
  • Technical and organizational security measures
  • Contractual safeguards with subprocessors

AI & Automated Processing

The Service uses AI to process voice commands and summarize information. Important safeguards include:

  • No decisions producing legal or similarly significant effects without human involvement
  • Users retain full control over actions taken based on AI-generated outputs
  • During early access, selected tasks may be reviewed internally to improve accuracy -- no data is shared externally

Subprocessors

We may use third-party service providers to host or support the Service. All subprocessors are contractually required to provide appropriate data protection safeguards.

A current list of subprocessors is available upon request at privacy@chiefofstaff.pro

Questions about security or data handling?

Contact us