← Back to Dais

Privacy Policy

Last updated: [PUBLICATION DATE] · Effective: [PUBLICATION DATE]

Dais records your voice, transcribes it, and has an AI model score how you came across. The recording itself is never stored on our servers — it is transcribed and discarded, and only the text and your scores are kept. This policy explains exactly what happens, who else is involved, how long things are kept, and how to get them back or deleted.

Contents

  1. Who we are
  2. What we collect
  3. Voice recordings and biometric law
  4. How we use it, and our legal basis
  5. AI processing and automated decisions
  6. Third-party service providers
  7. International transfers
  8. How long we keep things
  9. Cookies and analytics
  10. Your rights and how to use them
  11. If you are in the EU, EEA, UK or Switzerland
  12. If you are in California or another US state
  13. Security
  14. Children
  15. Changes
  16. Contact

1. Who we are

Dais LLC, a Wyoming limited liability company ("Dais", "we", "us"), provides an executive-presence and communication coaching service at dais.coach and app.dais.coach. Dais LLC is organized under the laws of the State of Wyoming, United States.

For the purposes of the EU and UK General Data Protection Regulation, where applicable, Dais LLC is the data controller for the personal data described here. Our contact point for all privacy matters is privacy@dais.coach.

This policy covers the marketing website, the Dais application, and our support channels. It does not cover third-party sites we link to, which have their own policies.

2. What we collect

Information you give us

Information generated by using Dais

Information collected automatically

3. Voice recordings and biometric law

We do not store your voice recordings, and we do not use voice to identify anyone. Audio is captured in your browser and sent once to our transcription provider to be turned into text. It is never written to our database or to our file storage, and we keep no copy. Our transcription provider may hold it briefly under its own policy — see below. We do not create, derive, store or compare voiceprints, and we do not use vocal characteristics to identify or authenticate any person. We do not sell, lease, trade or otherwise profit from voice data.

What actually happens to a recording

  1. You start a rep. Your browser asks for microphone permission and records your answer locally.
  2. The audio is sent to our transcription provider, which returns the text of what you said.
  3. We discard the audio. Only the transcript, your scores and the coaching notes are saved to your account.
  4. If you play your answer back on the results screen, that playback comes from a copy held in your browser's memory. It is gone when you close the tab or reload the page.

This means that once you leave the results screen, no copy of your recording exists in our systems or in your browser.

Your transcription provider holds it briefly

To be precise rather than reassuring: the audio does pass through OpenAI, which performs the transcription. OpenAI does not use API data to train its models. It may, however, retain API inputs for a short period for abuse monitoring under its own published policy — currently up to 30 days, after which it is deleted, unless it is legally required to keep it for longer. Retention behaviour can differ by endpoint and by account configuration.

We do not have access to anything OpenAI retains, and we do not receive it back. If you want the current detail, OpenAI publishes it in their enterprise privacy documentation. If you have a question about this specifically, email privacy@dais.coach and we will tell you exactly what our configuration is.

Why we spell this out

Several US states, including Illinois, Texas and Washington, regulate biometric identifiers such as voiceprints, and courts have held that what matters can be whether an entity has the capability to link voice data to an identity, not only whether it does so. Because we retain no voice data, there is nothing on our side for that analysis to attach to, and no ability to link stored audio to an identity. What we analyse is the content of what you said and delivery characteristics such as pace, filler words and clarity, derived from the transcript — not the acoustic properties of your voice, and never for identification.

You control when recording happens. It begins only when you start a rep, and your browser or device asks for microphone permission first. You can revoke that permission at any time in your browser or system settings, though the product cannot function without it.

4. How we use it, and our legal basis

Where the GDPR or UK GDPR applies, we must have a lawful basis for each use. This table sets both out together.

PurposeData usedLegal basis
Transcribe and score your answer, and return coachingRecordings, transcripts, profile answersPerformance of a contract
Tailor questions to your role, level and targetProfile answers, practice recordsPerformance of a contract
Show your history, trajectory and progressTranscripts, scores, practice recordsPerformance of a contract
Create and secure your accountAccount identifiers, device dataPerformance of a contract
Take payment and manage entitlementsBilling records, account identifiersPerformance of a contract; legal obligation for tax records
Respond to support requestsSupport messages, account identifiers, diagnosticsPerformance of a contract; legitimate interests
Keep the service reliable and prevent abuseSecurity logs, device dataLegitimate interests in operating a secure service
Understand how the site is found and usedAnalytics eventsConsent
Send you product emails you asked forAccount identifiersConsent; legitimate interests for service messages
Improve prompts, scoring quality and curriculumAggregated and de-identified usage patternsLegitimate interests
Comply with law and defend legal claimsAs requiredLegal obligation; legitimate interests

Where we rely on legitimate interests, we have considered the impact on you and you can object at any time — see section 10.

What we do not do

5. AI processing and automated decisions

Your transcript is sent to a third-party large language model, which returns dimension scores and written coaching. Those outputs are stored against your account and shown to you.

These scores are a training signal, not an assessment of your ability, employability or worth. They produce no legal or similarly significant effect: they do not determine access to employment, credit, insurance, education or any service, and nothing outside the app depends on them. On that basis, no decision producing legal or similarly significant effects is made solely by automated means within the meaning of Article 22 of the GDPR.

AI output can be wrong or inconsistent. You can report a score you believe is mistaken through in-app support, and you can ask us to delete any individual session.

6. Third-party service providers

We keep our vendor list deliberately small. Each of these providers ("sub-processors") handles personal data only on our documented instructions, under a written data processing agreement, and none of them may use it for their own purposes.

ProviderCategory of serviceLocation
SupabaseDatabase and authenticationUnited States
VercelHosting and infrastructureUnited States / global edge
AnthropicAI processingUnited States
OpenAISpeech processingUnited States
GoogleSign-in and, with your consent, analyticsUnited States / global
StripePaymentsUnited States / global

Audio is not stored by us. Our speech-to-text provider may retain it briefly for abuse monitoring under its own policy, as described in section 3.

We may also disclose personal data where we are legally required to — for example in response to a valid legal request — or in connection with a merger, acquisition or sale of assets, in which case we will notify you before your data becomes subject to a different privacy policy.

We will update this list before adding a new provider that handles your content. To be notified when it changes, email privacy@dais.coach and we will add you to the list.

7. International transfers

Dais operates from the United States and our providers are primarily US-based. If you use Dais from the EEA, UK or Switzerland, your personal data is transferred to the United States, which has not received a general adequacy decision.

Where required, these transfers rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), and where a provider participates, the EU-US Data Privacy Framework and its UK and Swiss extensions. You can request a copy of the relevant transfer mechanism from privacy@dais.coach.

8. How long we keep things

DataRetention
Account and profileFor as long as your account exists
Voice recordingsNot retained by us. Discarded after transcription; browser playback is held in memory only and ends when you close the tab. Our transcription provider may hold it up to 30 days for abuse monitoring under its own policy
Transcripts, scores and practice recordsFor as long as your account exists — your trajectory over time is the product
Billing and tax recordsUp to 7 years, as required by tax and accounting law, after which they are deleted
Support correspondenceUp to 3 years from the last message
Security and request logsTypically up to 30 days, unless needed for an active investigation
Analytics eventsUp to 14 months, per our Google Analytics configuration

When you delete your account, we delete or irreversibly anonymise your personal data within 30 days, except where we must keep specific records to meet a legal obligation or to establish or defend a legal claim. Backups are purged on their normal rotation, typically within 90 days.

9. Cookies and analytics

We use two kinds of browser storage.

TypeWhat it doesConsent
Strictly necessaryKeeps you signed in, remembers your consent choice, holds basic app stateNot required — the service cannot work without it
AnalyticsGoogle Analytics 4 — how the site is found, which pages are used, whether visitors start a repRequired. Off until you press Accept

Analytics is denied by default using Google Consent Mode v2. Nothing analytics-related is set or transmitted before you accept. If you decline, analytics stays off. You can change your choice at any time via Cookie settings in the site footer. IP addresses are anonymised. We do not use advertising cookies, and advertising and personalisation signals are set to denied.

We honour the Global Privacy Control (GPC) signal where your browser sends one.

10. Your rights and how to use them

Regardless of where you live, you can ask us to:

Making a request (DSAR)

  1. Email privacy@dais.coach with the subject line "Data request". Tell us which right you are exercising.
  2. We will acknowledge within 5 business days.
  3. We verify identity before acting, normally by confirming you control the email on the account. For deletion or export we may ask for one additional confirmation. We only use what you send us for verification and then discard it.
  4. We respond substantively within 30 days. If a request is complex we may extend by a further 60 days and will tell you why within the first 30.
  5. There is no charge. We will not degrade your service or charge you differently for exercising a right. If we cannot act on a request, we will explain why and how to challenge it.

An authorised agent may submit a request on your behalf with written proof of authorisation.

11. If you are in the EU, EEA, UK or Switzerland

You have the rights in section 10 under the GDPR or UK GDPR, and additionally the right to lodge a complaint with a supervisory authority. In the EEA that is the authority in your country of residence, work, or where the issue occurred; in the UK it is the Information Commissioner's Office; in Switzerland the Federal Data Protection and Information Commissioner. We would appreciate the chance to address it first.

Providing your profile answers and recordings is necessary to use Dais. If you do not provide them, we cannot deliver the service. We do not currently require an EU or UK representative under Article 27; if that changes we will name one here.

12. If you are in California or another US state

This section applies if you are a resident of California, and the substance applies equally under the comprehensive privacy laws of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with similar statutes.

Categories of personal information we collect, using the CCPA's categories: identifiers (email, name, IP address, account ID); commercial information (purchases and plan history); internet or network activity (usage of the site and app); audio information (your recordings); professional or employment information (role, seniority, industry, target level); and inferences drawn from the above (your scores and readiness number).

Sensitive personal information. Audio recordings may be treated as sensitive personal information in some states. We use them only to provide the service you requested — transcription and scoring — and for no purpose that would require offering a right to limit use under the CPRA. We do not use them to infer characteristics about you.

We do not sell your personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA. We have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of anyone under 16.

Your rights are to know, access, correct, delete, obtain a portable copy, opt out of sale or sharing (not applicable, as we do neither), limit use of sensitive personal information, and not be discriminated against for exercising any of them. Submit a request as described in section 10. If we deny a request, California residents may appeal by replying to our decision; we will respond to an appeal within 45 days.

13. Security

We protect your data with encryption in transit (TLS) and at rest, database-level access rules that restrict rows to the account that owns them, access limited to what is needed to run and support the service, multi-factor authentication on administrative accounts, and vendors selected for their own security posture.

No system is perfectly secure. If a breach affects your personal data, we will notify affected users and any required regulator without undue delay and, where the law requires it, within 72 hours of becoming aware.

14. Children

Dais is for adults. It is not directed to anyone under 18 and we do not knowingly collect personal data from them. If you believe a minor has given us data, email privacy@dais.coach and we will delete it.

15. Changes

We will update this policy as Dais changes and revise the date at the top. If a change materially affects how your personal data is used, we will notify you by email or in-app before it takes effect, and where the law requires it, ask for fresh consent. Previous versions are available on request.

16. Contact

Privacy questions, data requests and complaints: privacy@dais.coach
General: hello@dais.coach · Support: support@dais.coach · Billing: billing@dais.coach

Terms of Service