Last updated: [PUBLICATION DATE] · Effective: [PUBLICATION DATE]
Dais records your voice, transcribes it, and has an AI model score how you came across. The recording itself is never stored on our servers — it is transcribed and discarded, and only the text and your scores are kept. This policy explains exactly what happens, who else is involved, how long things are kept, and how to get them back or deleted.
Dais LLC, a Wyoming limited liability company ("Dais", "we", "us"), provides an executive-presence and communication coaching service at dais.coach and app.dais.coach. Dais LLC is organized under the laws of the State of Wyoming, United States.
For the purposes of the EU and UK General Data Protection Regulation, where applicable, Dais LLC is the data controller for the personal data described here. Our contact point for all privacy matters is privacy@dais.coach.
This policy covers the marketing website, the Dais application, and our support channels. It does not cover third-party sites we link to, which have their own policies.
We do not store your voice recordings, and we do not use voice to identify anyone. Audio is captured in your browser and sent once to our transcription provider to be turned into text. It is never written to our database or to our file storage, and we keep no copy. Our transcription provider may hold it briefly under its own policy — see below. We do not create, derive, store or compare voiceprints, and we do not use vocal characteristics to identify or authenticate any person. We do not sell, lease, trade or otherwise profit from voice data.
This means that once you leave the results screen, no copy of your recording exists in our systems or in your browser.
To be precise rather than reassuring: the audio does pass through OpenAI, which performs the transcription. OpenAI does not use API data to train its models. It may, however, retain API inputs for a short period for abuse monitoring under its own published policy — currently up to 30 days, after which it is deleted, unless it is legally required to keep it for longer. Retention behaviour can differ by endpoint and by account configuration.
We do not have access to anything OpenAI retains, and we do not receive it back. If you want the current detail, OpenAI publishes it in their enterprise privacy documentation. If you have a question about this specifically, email privacy@dais.coach and we will tell you exactly what our configuration is.
Several US states, including Illinois, Texas and Washington, regulate biometric identifiers such as voiceprints, and courts have held that what matters can be whether an entity has the capability to link voice data to an identity, not only whether it does so. Because we retain no voice data, there is nothing on our side for that analysis to attach to, and no ability to link stored audio to an identity. What we analyse is the content of what you said and delivery characteristics such as pace, filler words and clarity, derived from the transcript — not the acoustic properties of your voice, and never for identification.
You control when recording happens. It begins only when you start a rep, and your browser or device asks for microphone permission first. You can revoke that permission at any time in your browser or system settings, though the product cannot function without it.
Where the GDPR or UK GDPR applies, we must have a lawful basis for each use. This table sets both out together.
| Purpose | Data used | Legal basis |
|---|---|---|
| Transcribe and score your answer, and return coaching | Recordings, transcripts, profile answers | Performance of a contract |
| Tailor questions to your role, level and target | Profile answers, practice records | Performance of a contract |
| Show your history, trajectory and progress | Transcripts, scores, practice records | Performance of a contract |
| Create and secure your account | Account identifiers, device data | Performance of a contract |
| Take payment and manage entitlements | Billing records, account identifiers | Performance of a contract; legal obligation for tax records |
| Respond to support requests | Support messages, account identifiers, diagnostics | Performance of a contract; legitimate interests |
| Keep the service reliable and prevent abuse | Security logs, device data | Legitimate interests in operating a secure service |
| Understand how the site is found and used | Analytics events | Consent |
| Send you product emails you asked for | Account identifiers | Consent; legitimate interests for service messages |
| Improve prompts, scoring quality and curriculum | Aggregated and de-identified usage patterns | Legitimate interests |
| Comply with law and defend legal claims | As required | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have considered the impact on you and you can object at any time — see section 10.
Your transcript is sent to a third-party large language model, which returns dimension scores and written coaching. Those outputs are stored against your account and shown to you.
These scores are a training signal, not an assessment of your ability, employability or worth. They produce no legal or similarly significant effect: they do not determine access to employment, credit, insurance, education or any service, and nothing outside the app depends on them. On that basis, no decision producing legal or similarly significant effects is made solely by automated means within the meaning of Article 22 of the GDPR.
AI output can be wrong or inconsistent. You can report a score you believe is mistaken through in-app support, and you can ask us to delete any individual session.
We keep our vendor list deliberately small. Each of these providers ("sub-processors") handles personal data only on our documented instructions, under a written data processing agreement, and none of them may use it for their own purposes.
| Provider | Category of service | Location |
|---|---|---|
| Supabase | Database and authentication | United States |
| Vercel | Hosting and infrastructure | United States / global edge |
| Anthropic | AI processing | United States |
| OpenAI | Speech processing | United States |
| Sign-in and, with your consent, analytics | United States / global | |
| Stripe | Payments | United States / global |
Audio is not stored by us. Our speech-to-text provider may retain it briefly for abuse monitoring under its own policy, as described in section 3.
We may also disclose personal data where we are legally required to — for example in response to a valid legal request — or in connection with a merger, acquisition or sale of assets, in which case we will notify you before your data becomes subject to a different privacy policy.
We will update this list before adding a new provider that handles your content. To be notified when it changes, email privacy@dais.coach and we will add you to the list.
Dais operates from the United States and our providers are primarily US-based. If you use Dais from the EEA, UK or Switzerland, your personal data is transferred to the United States, which has not received a general adequacy decision.
Where required, these transfers rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), and where a provider participates, the EU-US Data Privacy Framework and its UK and Swiss extensions. You can request a copy of the relevant transfer mechanism from privacy@dais.coach.
| Data | Retention |
|---|---|
| Account and profile | For as long as your account exists |
| Voice recordings | Not retained by us. Discarded after transcription; browser playback is held in memory only and ends when you close the tab. Our transcription provider may hold it up to 30 days for abuse monitoring under its own policy |
| Transcripts, scores and practice records | For as long as your account exists — your trajectory over time is the product |
| Billing and tax records | Up to 7 years, as required by tax and accounting law, after which they are deleted |
| Support correspondence | Up to 3 years from the last message |
| Security and request logs | Typically up to 30 days, unless needed for an active investigation |
| Analytics events | Up to 14 months, per our Google Analytics configuration |
When you delete your account, we delete or irreversibly anonymise your personal data within 30 days, except where we must keep specific records to meet a legal obligation or to establish or defend a legal claim. Backups are purged on their normal rotation, typically within 90 days.
We use two kinds of browser storage.
| Type | What it does | Consent |
|---|---|---|
| Strictly necessary | Keeps you signed in, remembers your consent choice, holds basic app state | Not required — the service cannot work without it |
| Analytics | Google Analytics 4 — how the site is found, which pages are used, whether visitors start a rep | Required. Off until you press Accept |
Analytics is denied by default using Google Consent Mode v2. Nothing analytics-related is set or transmitted before you accept. If you decline, analytics stays off. You can change your choice at any time via Cookie settings in the site footer. IP addresses are anonymised. We do not use advertising cookies, and advertising and personalisation signals are set to denied.
We honour the Global Privacy Control (GPC) signal where your browser sends one.
Regardless of where you live, you can ask us to:
An authorised agent may submit a request on your behalf with written proof of authorisation.
You have the rights in section 10 under the GDPR or UK GDPR, and additionally the right to lodge a complaint with a supervisory authority. In the EEA that is the authority in your country of residence, work, or where the issue occurred; in the UK it is the Information Commissioner's Office; in Switzerland the Federal Data Protection and Information Commissioner. We would appreciate the chance to address it first.
Providing your profile answers and recordings is necessary to use Dais. If you do not provide them, we cannot deliver the service. We do not currently require an EU or UK representative under Article 27; if that changes we will name one here.
This section applies if you are a resident of California, and the substance applies equally under the comprehensive privacy laws of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with similar statutes.
Categories of personal information we collect, using the CCPA's categories: identifiers (email, name, IP address, account ID); commercial information (purchases and plan history); internet or network activity (usage of the site and app); audio information (your recordings); professional or employment information (role, seniority, industry, target level); and inferences drawn from the above (your scores and readiness number).
Sensitive personal information. Audio recordings may be treated as sensitive personal information in some states. We use them only to provide the service you requested — transcription and scoring — and for no purpose that would require offering a right to limit use under the CPRA. We do not use them to infer characteristics about you.
We do not sell your personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA. We have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of anyone under 16.
Your rights are to know, access, correct, delete, obtain a portable copy, opt out of sale or sharing (not applicable, as we do neither), limit use of sensitive personal information, and not be discriminated against for exercising any of them. Submit a request as described in section 10. If we deny a request, California residents may appeal by replying to our decision; we will respond to an appeal within 45 days.
We protect your data with encryption in transit (TLS) and at rest, database-level access rules that restrict rows to the account that owns them, access limited to what is needed to run and support the service, multi-factor authentication on administrative accounts, and vendors selected for their own security posture.
No system is perfectly secure. If a breach affects your personal data, we will notify affected users and any required regulator without undue delay and, where the law requires it, within 72 hours of becoming aware.
Dais is for adults. It is not directed to anyone under 18 and we do not knowingly collect personal data from them. If you believe a minor has given us data, email privacy@dais.coach and we will delete it.
We will update this policy as Dais changes and revise the date at the top. If a change materially affects how your personal data is used, we will notify you by email or in-app before it takes effect, and where the law requires it, ask for fresh consent. Previous versions are available on request.
Privacy questions, data requests and complaints: privacy@dais.coach
General: hello@dais.coach · Support: support@dais.coach · Billing: billing@dais.coach