Skip to content

Security and privacy

Anonymity the database enforces.

No table maps a person to what they said, so no query, and no administrator, can produce one.

An insight belongs to a cohort, never a person.

  1. One way in

    Capture enters through a single ingest that swaps the identity for a derived code and writes only the code.

  2. Names stripped before storage

    Personal identifiers come out of every transcript, Perspective and written answer before anything is stored.

  3. Two stores, no bridge

    Names and capture share no key finer than the date, and tests against the live database prove it.

  4. Small cohorts withheld at read

    A cohort too small to stay anonymous is withheld from every reader, explained without saying how small.

In the conversation itself two people see and hear each other. The guarantee begins where their words enter the analysis.

What gets in the way of doing your best work here?

  1. Meetings crowd out focused time

    Strong58%
  2. Decisions wait on people who are not in the room

    Moderate31%
  3. Tools differ from one team to the next

    Weak12%

What a reviewer will find.

Each of these is a property of the product rather than a promise about it.

Questions, answered.

Is it really anonymous?

For the analysis and every report, yes, and by construction rather than by policy: capture is written against a derived code and never an identity, and no table maps one to the other. In the conversation itself, two people see and hear each other.

What data is collected?

Accounts and memberships on one side of the store; transcripts, written Perspectives, survey answers and ratings on the other, redacted of personal identifiers before they are stored. The two sides share no key finer than the date.

What does the AI see?

Only the de-identified corpus of one generation, assembled after the cohorts a reader may never see have been suppressed. Nothing sent to or returned by the model survives beyond the report itself.

Can a person's data be deleted?

A person is erased in full — account, memberships, consent records and any identified material — after which their code can never be derived again. Anonymous capture is untouched: it names no one, and no mechanism exists that could find one person's records.

How is access secured?

Sign-in is delegated to an identity authority — Google, Microsoft or company SSO, a magic link or a one-time code — so the product holds no password, and two-factor can be required. Inside, every operation tests the privilege it requires and every administrative act is audited.

Is anything installed in our environment?

No. Everyone uses a browser, nothing runs on a device or inside your network, and no integration into your own systems is required or offered.

What happens to recordings?

Where an Event permits one, a recording is an identified artefact served at its own address under its own privilege. It never enters the analysis, is never read by generation, and appears in no report.

Security questions and data-processing-agreement requests go to support@trylinguini.com.

See Linguini in action.

In 30 minutes, we'll show you how to capture every voice in your organisation and turn what they said into decisions, the same day.

Request a demo