Encrypted everywhere
TLS 1.2+ for every connection. AES-256 encryption for stored recordings and data.
Recordings deleted in 4 days
Audio and transcripts are removed automatically 4 days after upload.
Never used to train AI
Not by BoardBreeze, and not by our AI providers.
Hosted in the United States
Recordings are stored and transcribed in AWS us-east-2 (Ohio).
How your data moves
- 1
Upload
Your recording goes from your browser directly to encrypted storage (Amazon S3, us-east-2) over a short-lived signed link. If you paste a link instead, we fetch that one file on your behalf and store it the same way.
- 2
Transcription
Amazon Transcribe converts the audio to text. Long meetings are split and transcribed in parallel inside our AWS account.
- 3
Minutes
The transcript, and your agenda outline if you upload one, are sent to Anthropic’s Claude API to draft your minutes and answer Minutes Assistant questions.
- 4
Review and export
You review and edit the draft, then export to Word, Google Drive (only files BoardBreeze creates), email, or plain text. Your working draft is saved in your own browser, on your device. We do not keep a copy of your minutes on our servers.
Encryption
- In transit: every connection uses TLS 1.2 or higher, including browser to app, app to storage, and app to our AI and payment providers. The site sends a two-year HSTS header, and the recording bucket rejects any request that is not encrypted.
- At rest: recordings are encrypted with AES-256 in Amazon S3. The account database (Supabase) and the short-lived processing cache (Redis Cloud) are encrypted at rest by their providers.
- Secrets: API keys and credentials are kept in encrypted environment settings, never in source code. GitHub push protection blocks accidental commits of known secret formats.
Retention and deletion
BoardBreeze is a minutes tool, not a records archive. The recording does its job, producing your draft, and then it is deleted. Export approved minutes to your own records system.
| What | When it is deleted |
|---|---|
| Audio and video recordings | Deleted 4 days after upload |
| Transcripts (including the Amazon Transcribe job record) | Deleted 4 days after creation |
| Meeting minutes | Not stored on our servers. Your working draft is saved in your browser on your device |
| Transcription progress (Redis Cloud) | Expires 2 hours after processing starts |
| Agenda files | Never stored. Only the outline (sections, item titles, recommended actions) is kept |
| Results held after a trial ends | Deleted 30 days after upload unless you subscribe |
| Your account and data | Deleted on request within 30 days |
Deletion runs automatically on a schedule. To delete your account and data sooner, email help@appboardbreeze.com.
AI and your content
- No training on your content. BoardBreeze does not train AI models. Anthropic’s commercial API terms do not allow it to train on our customers’ content, and our AWS organization has the AWS AI services opt-out policy applied, so Amazon Transcribe does not keep or use your audio to improve its services.
- Which models: Amazon Transcribe for speech-to-text and Anthropic Claude for drafting minutes, both under commercial terms.
- A person stays in charge. The output is a draft. Your clerk or secretary reviews, edits and approves it before it becomes a record. AI can miss or misattribute a remark, so the draft should always be checked against the meeting.
- Your content stays yours. You own your recordings, transcripts and minutes. We use them only to provide the service to you, and staff do not look at them unless you ask for help with a specific meeting.
Access control
- No passwords to steal. You sign in with a one-time 6-digit code sent to your email, or with Google or Microsoft. Bot protection (Cloudflare Turnstile) guards sign-up.
- Your data is walled off. Database row-level security is enabled on every table, so each account can read only its own records. Billing and plan fields can be changed only by our server, never from a browser.
- Recordings are never public. All public access to the storage bucket is blocked. Uploads use short-lived signed links, and after upload only our own processing services can read the file.
- Staff access is locked down. Multi-factor authentication is required on every administrative account: AWS, GitHub, Supabase, Vercel, Stripe and Redis.
- Abuse limits. Transcription, minutes generation and checkout are rate limited, and transcription and minutes requests are checked for a valid account and an active plan.
Monitoring and development
- AWS CloudTrail records administrative activity in our AWS account, and CloudWatch alarms alert us to unusual processing activity and cost spikes.
- Every upload is recorded in an internal upload log with its size and time.
- Dependencies are monitored with GitHub Dependabot, and security fixes are applied in planned batches.
- Changes are built and tested on a separate preview environment before they reach production.
- The site sends standard security headers, including a Content Security Policy and clickjacking protection.
Incidents and reporting a vulnerability
We keep a written incident response plan. If a security incident affects your data, we will investigate and contain it, and notify affected customers promptly and as required by law.
Found a vulnerability? Email help@appboardbreeze.com. We acknowledge reports within 48 hours. Details are in our vulnerability disclosure policy and security.txt.
Compliance status
We would rather tell you exactly where we stand than overstate it.
- SOC 2: our security, access, change management, incident response and data retention policies and controls are documented against the SOC 2 criteria. We have not yet completed an independent SOC 2 audit, so we do not have a SOC 2 report to share.
- Security questionnaires: we complete HECVAT and vendor security questionnaires on request.
- FedRAMP: BoardBreeze is not FedRAMP authorized.
- Privacy: see our Privacy Policy for your rights under the CCPA and the UK and EU GDPR.
For a questionnaire or a data processing conversation, email help@appboardbreeze.com.
Sub-processors
These providers process data on our instructions to run the service.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Amazon Web Services | Recording storage (S3), transcription (Transcribe), email delivery (SES), processing (Lambda, ECS) | Recordings, transcripts | United States |
| Anthropic | Minutes drafting and the Minutes Assistant (Claude API) | Transcripts, agenda outlines | United States |
| Supabase | Account database and sign-in | Account details; trial preview results held for 30 days | United States |
| Vercel | Website and application hosting | Web requests | United States / global network |
| Stripe | Payments and subscriptions | Billing details (BoardBreeze never stores card numbers) | United States |
| Redis Cloud | Rate limiting and transcription progress | Hashed IP addresses; transcript segments for up to 2 hours while a meeting is processed | United States |
| Sign in with Google; Google Drive export you request; site analytics | Name and email at sign-in; minutes you choose to save | United States | |
| Microsoft | Sign in with Microsoft | Name and email at sign-in | United States |
| Cloudflare | Bot protection at sign-up (Turnstile) | Browser signals, IP address | United States / global network |
| Twilio | Toll-free line for our phone assistant | Caller phone number, call audio | United States |
BoardBreeze is operated by MGE Magneo Solutions LLC.