Trust and security

How BoardBreeze protects your meetings

Board recordings can include closed session discussion, personnel matters and public comment. This page explains, in plain terms, where that content goes, who can see it, and when it is deleted. It is written for the IT, privacy and procurement reviewers at agencies, districts, colleges and associations.

Last updated October 3, 2026

Encrypted everywhere

TLS 1.2+ for every connection. AES-256 encryption for stored recordings and data.

Recordings deleted in 4 days

Audio and transcripts are removed automatically 4 days after upload.

Never used to train AI

Not by BoardBreeze, and not by our AI providers.

Hosted in the United States

Recordings are stored and transcribed in AWS us-east-2 (Ohio).

How your data moves

  1. 1

    Upload

    Your recording goes from your browser directly to encrypted storage (Amazon S3, us-east-2) over a short-lived signed link. If you paste a link instead, we fetch that one file on your behalf and store it the same way.

  2. 2

    Transcription

    Amazon Transcribe converts the audio to text. Long meetings are split and transcribed in parallel inside our AWS account.

  3. 3

    Minutes

    The transcript, and your agenda outline if you upload one, are sent to Anthropic’s Claude API to draft your minutes and answer Minutes Assistant questions.

  4. 4

    Review and export

    You review and edit the draft, then export to Word, Google Drive (only files BoardBreeze creates), email, or plain text. Your working draft is saved in your own browser, on your device. We do not keep a copy of your minutes on our servers.

Encryption

  • In transit: every connection uses TLS 1.2 or higher, including browser to app, app to storage, and app to our AI and payment providers. The site sends a two-year HSTS header, and the recording bucket rejects any request that is not encrypted.
  • At rest: recordings are encrypted with AES-256 in Amazon S3. The account database (Supabase) and the short-lived processing cache (Redis Cloud) are encrypted at rest by their providers.
  • Secrets: API keys and credentials are kept in encrypted environment settings, never in source code. GitHub push protection blocks accidental commits of known secret formats.

Retention and deletion

BoardBreeze is a minutes tool, not a records archive. The recording does its job, producing your draft, and then it is deleted. Export approved minutes to your own records system.

WhatWhen it is deleted
Audio and video recordingsDeleted 4 days after upload
Transcripts (including the Amazon Transcribe job record)Deleted 4 days after creation
Meeting minutesNot stored on our servers. Your working draft is saved in your browser on your device
Transcription progress (Redis Cloud)Expires 2 hours after processing starts
Agenda filesNever stored. Only the outline (sections, item titles, recommended actions) is kept
Results held after a trial endsDeleted 30 days after upload unless you subscribe
Your account and dataDeleted on request within 30 days

Deletion runs automatically on a schedule. To delete your account and data sooner, email help@appboardbreeze.com.

AI and your content

  • No training on your content. BoardBreeze does not train AI models. Anthropic’s commercial API terms do not allow it to train on our customers’ content, and our AWS organization has the AWS AI services opt-out policy applied, so Amazon Transcribe does not keep or use your audio to improve its services.
  • Which models: Amazon Transcribe for speech-to-text and Anthropic Claude for drafting minutes, both under commercial terms.
  • A person stays in charge. The output is a draft. Your clerk or secretary reviews, edits and approves it before it becomes a record. AI can miss or misattribute a remark, so the draft should always be checked against the meeting.
  • Your content stays yours. You own your recordings, transcripts and minutes. We use them only to provide the service to you, and staff do not look at them unless you ask for help with a specific meeting.

Access control

  • No passwords to steal. You sign in with a one-time 6-digit code sent to your email, or with Google or Microsoft. Bot protection (Cloudflare Turnstile) guards sign-up.
  • Your data is walled off. Database row-level security is enabled on every table, so each account can read only its own records. Billing and plan fields can be changed only by our server, never from a browser.
  • Recordings are never public. All public access to the storage bucket is blocked. Uploads use short-lived signed links, and after upload only our own processing services can read the file.
  • Staff access is locked down. Multi-factor authentication is required on every administrative account: AWS, GitHub, Supabase, Vercel, Stripe and Redis.
  • Abuse limits. Transcription, minutes generation and checkout are rate limited, and transcription and minutes requests are checked for a valid account and an active plan.

Monitoring and development

  • AWS CloudTrail records administrative activity in our AWS account, and CloudWatch alarms alert us to unusual processing activity and cost spikes.
  • Every upload is recorded in an internal upload log with its size and time.
  • Dependencies are monitored with GitHub Dependabot, and security fixes are applied in planned batches.
  • Changes are built and tested on a separate preview environment before they reach production.
  • The site sends standard security headers, including a Content Security Policy and clickjacking protection.

Incidents and reporting a vulnerability

We keep a written incident response plan. If a security incident affects your data, we will investigate and contain it, and notify affected customers promptly and as required by law.

Found a vulnerability? Email help@appboardbreeze.com. We acknowledge reports within 48 hours. Details are in our vulnerability disclosure policy and security.txt.

Compliance status

We would rather tell you exactly where we stand than overstate it.

  • SOC 2: our security, access, change management, incident response and data retention policies and controls are documented against the SOC 2 criteria. We have not yet completed an independent SOC 2 audit, so we do not have a SOC 2 report to share.
  • Security questionnaires: we complete HECVAT and vendor security questionnaires on request.
  • FedRAMP: BoardBreeze is not FedRAMP authorized.
  • Privacy: see our Privacy Policy for your rights under the CCPA and the UK and EU GDPR.

For a questionnaire or a data processing conversation, email help@appboardbreeze.com.

Sub-processors

These providers process data on our instructions to run the service.

ProviderPurposeDataLocation
Amazon Web ServicesRecording storage (S3), transcription (Transcribe), email delivery (SES), processing (Lambda, ECS)Recordings, transcriptsUnited States
AnthropicMinutes drafting and the Minutes Assistant (Claude API)Transcripts, agenda outlinesUnited States
SupabaseAccount database and sign-inAccount details; trial preview results held for 30 daysUnited States
VercelWebsite and application hostingWeb requestsUnited States / global network
StripePayments and subscriptionsBilling details (BoardBreeze never stores card numbers)United States
Redis CloudRate limiting and transcription progressHashed IP addresses; transcript segments for up to 2 hours while a meeting is processedUnited States
GoogleSign in with Google; Google Drive export you request; site analyticsName and email at sign-in; minutes you choose to saveUnited States
MicrosoftSign in with MicrosoftName and email at sign-inUnited States
CloudflareBot protection at sign-up (Turnstile)Browser signals, IP addressUnited States / global network
TwilioToll-free line for our phone assistantCaller phone number, call audioUnited States

BoardBreeze is operated by MGE Magneo Solutions LLC.