Security and privacy
Anonymity the database enforces.
No table maps a person to what they said, so no query, and no administrator, can produce one.
An insight belongs to a cohort, never a person.
One way in
Capture enters through a single ingest that swaps the identity for a derived code and writes only the code.
Names stripped before storage
Personal identifiers come out of every transcript, Perspective and written answer before anything is stored.
Two stores, no bridge
Names and capture share no key finer than the date, and tests against the live database prove it.
Small cohorts withheld at read
A cohort too small to stay anonymous is withheld from every reader, explained without saying how small.
In the conversation itself two people see and hear each other. The guarantee begins where their words enter the analysis.
What gets in the way of doing your best work here?
Meetings crowd out focused time
Strong58%Decisions wait on people who are not in the room
Moderate31%Tools differ from one team to the next
Weak12%
What a reviewer will find.
Consent on the record
Each consent is recorded naming the document and its version; re-acceptance is a new record, never an edit.
Sign-in you already run
Delegated to an identity authority, with no password held by the product and two-factor enforceable.
Every act audited
Every administrative act is written to an audit record naming the action, its tenant and its actor.
Erasure in full
A person is removed from everything that names them; what they contributed anonymously was never personal data.
Recordings stay out of it
Where an Event permits a recording, it is served under its own privilege and never enters the analysis.
What the model sees
The language model receives only de-identified text for one generation, and nothing it sees is kept.
Questions, answered.
Is it really anonymous?
For the analysis and every report, yes, and by construction rather than by policy: capture is written against a derived code and never an identity, and no table maps one to the other. In the conversation itself, two people see and hear each other.
What data is collected?
Accounts and memberships on one side of the store; transcripts, written Perspectives, survey answers and ratings on the other, redacted of personal identifiers before they are stored. The two sides share no key finer than the date.
Do participants consent?
Every surface that captures what a person says states how it is treated, and the statement is never suppressed. Each consent is recorded naming the document and its version, so what was in force at the time is recoverable.
What does the AI see?
Only the de-identified corpus of one generation, assembled after the cohorts a reader may never see have been suppressed. Nothing sent to or returned by the model survives beyond the report itself.
Can a person's data be deleted?
A person is erased in full — account, memberships, consent records and any identified material — after which their code can never be derived again. Anonymous capture is untouched: it names no one, and no mechanism exists that could find one person's records.
How is access secured?
Sign-in is delegated to an identity authority — Google, Microsoft or company SSO, a magic link or a one-time code — so the product holds no password, and two-factor can be required. Inside, every operation tests the privilege it requires and every administrative act is audited.
Is anything installed in our environment?
No. Everyone uses a browser, nothing runs on a device or inside your network, and no integration into your own systems is required or offered.
What happens to recordings?
Where an Event permits one, a recording is an identified artefact served at its own address under its own privilege. It never enters the analysis, is never read by generation, and appears in no report.
Security questions and data-processing-agreement requests go to support@trylinguini.com.
See Linguini in action.
In 30 minutes, we'll show you how to capture every voice in your organisation and turn what they said into decisions, the same day.
Request a demo