BenchVoice Data Security
Last reviewed: May 27, 2026
What data BenchVoice handles
- Voice recordings from researchers
- Transcribed text from those recordings
- Structured experimental data extracted from transcripts (protocols, reagents, conditions, observations)
- User account information (email, name)
Where data lives
- Audio files: Supabase Storage, private bucket with Row Level Security, encrypted at rest. Signed URLs expire in 7 days.
- Transcripts and structured data: Supabase Postgres database, encrypted at rest, accessible only to the user who created the entry via Row Level Security policies.
- User accounts: Supabase Auth.
Third-party AI services
BenchVoice uses leading commercial AI providers to process user audio: OpenAI for speech transcription and Anthropic for language understanding. Both providers' privacy policies are linked below for verification.
OpenAI (speech transcription)
- Data retention: DISABLED. OpenAI does not log or retain BenchVoice audio after transcription.
- Training: NO. OpenAI does not train on API customer data.
- Privacy policy: https://openai.com/policies/privacy-policy
Anthropic (language understanding)
- Data retention: 30 days. Anthropic retains inputs and outputs for 30 days for abuse monitoring, then deletes.
- Training: NO. Anthropic does not train on API customer data.
- BenchVoice has not enabled any optional feedback or training programs in our Anthropic account.
- Privacy policy: https://www.anthropic.com/legal/privacy
What BenchVoice does NOT do
- Does not sell user data to third parties
- Does not use user data to train AI models
- Does not share data between user accounts
- Does not allow staff access to individual entries except for user-requested support
User rights
- Users can view all their own data through the BenchVoice interface
- Users can delete entries at any time. Soft-deleted entries are automatically purged from the database after 30 days.
- Users can export their data
- Users can request full account deletion via benchvoice@benchvoice.ai
Compliance posture
- HIPAA: BenchVoice is currently evaluating HIPAA compliance. Until certification is in place, BenchVoice should not be used to store Protected Health Information.
- SOC 2: Not currently SOC 2 certified. On roadmap for future when scaling to institutional customers.
- FERPA: Applies if BenchVoice is used in academic instruction. Users at academic institutions should consult their institution's policy.
Verification
Researchers who want to verify these claims can:
- Read Anthropic's privacy policy at https://www.anthropic.com/legal/privacy
- Read OpenAI's privacy policy at https://openai.com/policies/privacy-policy
- Read Supabase's security documentation at https://supabase.com/security
- Email benchvoice@benchvoice.ai with specific questions
This document describes BenchVoice's data handling practices as of the last reviewed date. This document is not legal advice.