ChiefofStaff is built for legal professionals with the highest expectations around privacy, control, and auditability. Every layer of our architecture reflects that commitment.
All data is encrypted using TLS during transmission between your device and our servers.
We never sell personal data, use email content for advertising, or build marketing profiles.
Hosted on secure, access-controlled cloud infrastructure.
Tasks, metadata, voice transcriptions, and account settings are stored securely with strict account isolation. Each user's data is logically separated to prevent cross-account access.
| Data Type | Retention Period | Deletion Trigger |
|---|---|---|
| Voice recordings | Immediately deleted after transcription | Automatic |
| Transcriptions | Up to 30 days | Automatic or account termination |
| Account data | Duration of subscription | Account deletion |
| Task & productivity data | Duration of subscription | Account deletion |
| Integration data | While integration is active | Disconnection or account deletion |
| Security logs | Up to 12 months | System rotation |
Upon account termination, personal data is deleted or anonymized within a commercially reasonable timeframe unless retention is legally required.
ChiefofStaff is built on DONNA, our open-source decision-notarisation engine. Delegated decisions are recorded as Intent Decision Records (IDRs) — each signed and hash-chained to the one before it, so the decision trail is tamper-evident and can be verified independently, without having to rely on us.
DONNA is open source (AGPL-3.0), so the audit mechanism can be inspected or self-hosted. Task activity is also logged for an operational audit trail, and security event logs are retained for up to 12 months.
You are responsible for maintaining the confidentiality of your account credentials and all activity under your account. We recommend:
All data is hosted in the United States. For EU/EEA/UK users, transfers are safeguarded by:
The Service uses AI to process voice commands and summarize information. Important safeguards include:
We may use third-party service providers to host or support the Service. All subprocessors are contractually required to provide appropriate data protection safeguards.
A current list of subprocessors is available upon request at privacy@chiefofstaff.pro
Questions about security or data handling?
Contact us