Privacy Policy
Last updated 4 October 2026
Working draft, pending legal review.
Who we are
Source/Record is a platform for professional post-production teams working with multitrack sound, operated by Source/Record TV Ltd(“we”). This notice explains how we handle personal data.
There are two roles to keep separate. For your account data - your name, email address, role, sign-in times and two-factor settings - we are the data controller. For the material you process- recordings, transcripts, voice prints and everything derived from them - your company is the controller and we act as its processor under a data processing agreement. This notice covers our own handling; your company's own privacy notice governs its use of the material.
What we collect
Account data: the name and email address you sign up with, your role and seat assignments, sign-in timestamps, and - if enabled - your two-factor authentication factors. We use this to run your account, authenticate you and enforce who can see what.
Production material: the audio you upload and everything the pipeline produces from it - per-channel recordings, transcripts, conversation graphs, and voice prints. Voice prints are numerical representations of a voice and are special-category biometric data under UK GDPR Article 9; they are only created after an explicit consent affirmation is recorded for the contributor.
Billing data: where you hold a paid licence, our payments provider processes the payment. We store the resulting invoices and entitlements, not card details.
How your material is processed - and what never happens to it
Every model in the pipeline is open-weight and runs on our own private infrastructure. No transcript, no audio and no voice print is ever sent to a third-party AI service - not to OpenAI, Google, Anthropic or any other model provider. Nobody trains a model on your material. The story assistant answers only from your own production's content, on a model we host ourselves.
Where your data lives
Your database records and stored objects are held in the European Union - our database and authentication run in an EU region, and both storage buckets are held under binding EU jurisdiction. Processing compute runs on ephemeral workers with our compute provider; those workers are not currently pinned to an EU region, so a processing run may execute outside the EU even though the data at rest stays within it. We will state this plainly to any customer for whom processing location is a contractual requirement.
Who else processes data on our behalf
We use a small set of infrastructure sub-processors, each under contract:
- our database and authentication provider (EU region);
- our object-storage provider (EU jurisdiction);
- our ephemeral compute provider (model inference and media processing);
- our hosting and content-delivery provider, which also measures page traffic;
- our payments provider, for licensed customers;
- our email provider, which sends account and support email;
- a bot-detection provider that screens automated abuse of our sign-in forms.
No AI model vendor is a sub-processor. A current list is available on request.
How we keep it safe
Data is encrypted in transit and at rest. Access between one production and another is isolated in the database itself, not merely in application code, and is governed by admin, editor and viewer roles. Two-factor authentication can be required across a company and is enforced at the database. Media is served only through short-lived signed links, and processing runs on workers that are torn down after each job. We hold no ISO 27001 certification and no completed industry security assessment, and we do not claim otherwise.
Cookies and analytics
We set only the essential cookies needed to keep you signed in. We load no advertising or third-party tracking scripts, and there are no non-essential cookies to consent to.
We do measure page traffic, using Vercel Web Analytics. It sets no cookie and builds no profile across sites. Before a page view is sent, the address is reduced to its shape: production, clip and voice identifiers become [id], and the query string and fragment are dropped whole, so a search you typed never leaves your browser. The script is not loaded at all on a share or invitation link, so if you were sent one of those without holding an account here, we do not measure your visit.
How long we keep it
Source recordings are deleted a set number of days after they are processed - seven by default on a new production, and an administrator can lengthen that or switch it off entirely. Other retention is set per production the same way and swept nightly; where no period is set, nothing is auto-deleted. There is no recycle bin - a deletion removes the records and then the underlying objects. When an account or a production is closed, its data is deleted within 30 days.
Your rights
You can access, correct, export, delete, restrict or object to the processing of your personal data, and withdraw consent where processing relies on it. You can download a copy of your own account data at any time from your Account settings. To exercise the other rights, contact us using the details below.
One honest limitation: because contributors' voices bleed across microphones in a multitrack recording, erasing a single person cleanly from a mixed recording is not always possible. Erasure is therefore performed at the level of a clip or a production, not a single person within a shared recording.
Data breaches
Where a personal-data breach is likely to affect you or our customers, we notify the relevant parties within 48 hours of becoming aware of it.
Contact
Source/Record is operated by Source/Record TV Ltd, a company registered in England and Wales (company number 07949435), whose registered office is at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ.
For any data-protection request - to access, correct, erase, export or restrict your data, or to withdraw consent - contact us at privacy@sourcerecord.io.
If you are in the UK or EU and are not satisfied with our response, you have the right to complain to your data-protection supervisory authority - in the UK, the Information Commissioner's Office (ico.org.uk).