Your research is your business.
Interview recordings, transcripts, and findings are some of the most sensitive material a team produces. Here is plainly how Voxera handles them.
How we protect your data
The four commitments that apply to every study, every interview, and every account.
Encrypted in transit and at rest
All traffic between your browser, our servers, and participants' devices is encrypted with TLS. Stored data — transcripts, recordings, findings, and account records — is encrypted at rest by our infrastructure providers.
Your data stays yours
We do not use your interviews, transcripts, or findings to train AI models. Our AI providers are accessed through their commercial APIs under terms that exclude customer content from model training.
Access control on every request
Every study belongs to an account. Server-side ownership checks run on every request, so studies, transcripts, and reports are only visible to the account that created them and the collaborators explicitly invited to a project.
Payments handled by Stripe
All payments are processed by Stripe. Your card details go directly to Stripe and are never stored on — or even pass through — Voxera's servers.
The details
Straight answers to the questions security reviewers ask.
Where is my data stored?
Structured data (studies, transcripts, findings, accounts) lives in a managed PostgreSQL database; files such as audio recordings and generated reports live in managed object storage. Both are hosted on SOC 2-audited cloud infrastructure and encrypted at rest.
Who can see my interviews and findings?
Only your account, and any collaborators you explicitly invite to a project. There is no cross-account visibility: participants in one study cannot see other studies, and no other Voxera customer can ever see your data.
How is participant audio handled?
Voice interviews are conducted through our conversational-AI provider over encrypted connections. Recordings and transcripts are stored against your study and are only used to produce your deliverables — the summary, report, article, and clips you see in the product.
Do you use my data to train AI models?
No. Your interviews and findings are processed by AI models only to produce your study's outputs. We access model providers through their commercial APIs, which do not use API content to train their models.
How is my account protected?
Sign-in is via Google OAuth or email and password. Passwords are never stored in plain text — they are hashed with a modern memory-hard algorithm — and new accounts verify their email address before first login.
Can I delete my data?
Yes. You can delete individual projects from the product, and you can delete your entire account from Settings, which removes your studies and associated data from our systems.
Which subprocessors do you use?
Voxera runs on a small set of established providers: Vercel (application hosting and file storage), Neon (PostgreSQL database), ElevenLabs (voice conversations), Anthropic and OpenAI (analysis and synthesis via API), Stripe (payments), and Resend (transactional email).
Are you SOC 2 certified?
Not yet. Voxera is an early-stage product and we have not completed a formal certification program of our own. We build on SOC 2-audited infrastructure providers, and formal compliance work is on our roadmap as the company grows.
How do I report a security issue?
We appreciate responsible disclosure. Reach us through the contact section with details of what you found, and we will respond as quickly as we can. Please give us reasonable time to fix an issue before sharing it publicly.
Have a security question we didn't answer?
Ask us directly — security reviews, questionnaires, and specific data-handling questions welcome.