Security and privacy

Livrable processes business meetings, often technical and confidential. This page describes precisely what we do with your data, what is in place today and what is not yet.

1. How your data flows

  1. 01

    Your browser

    You record the meeting or import a file. The audio is converted in your browser before it is sent.

  2. 02

    Temporary audio storage

    Supabase, Frankfurt (European Union).

  3. 03

    Transcription

    Gladia, in the European Union (France). As soon as the transcript is saved, the audio is deleted from our storage and the copy at Gladia is deleted.

  4. 04

    Writing the deliverables

    Anthropic (Claude), in the United States. Only the text is sent, never the audio.

  5. 05

    Your results

    Transcripts, deliverables and actions are kept in your workspace, on Supabase, in Frankfurt (European Union). Email reminders are sent via Resend.

The application runs on Cloudflare infrastructure (via Lovable), in the data centre closest to the user.

2. What we keep, and what we do not keep

  • ·We keep: transcripts, deliverables, follow-up actions and the details of each meeting (date, client, participants).
  • ·We do not keep the audio: it is deleted as soon as the transcript is saved. If transcription fails, it is kept for up to 24 hours so you can retry, then deleted automatically. An automated task checks every hour that no audio file exceeds this limit.

3. Where your data is processed

The database is hosted in Germany. Transcription takes place in France. Deliverables are written in the United States, under the European Commission's standard contractual clauses. The full list, with each provider's role and location, is on the Subprocessors page.

4. AI model training

Gladia and Anthropic may not use your content to train their models: this is set out in their contractual terms. Livrable does not train any model with your data.

5. Access protection

  • ·Each account is isolated at database level: a user technically cannot access another user's meetings.
  • ·Passwords of at least 10 characters; passwords that have appeared in known data breaches are rejected.
  • ·Two-factor authentication available in "My account": once enabled, access to your meetings, transcripts and deliverables requires the second factor, including at database level.
  • ·Access to the service is by invitation during the current phase.
  • ·Administrator access to the database is limited to the publisher, for maintenance.

6. Encryption and access keys

  • ·All communications are encrypted (TLS).
  • ·Data is encrypted at rest by the database host.
  • ·The access keys for the transcription and writing services stay on the server and are never exposed to the browser.

7. Backups

The database is backed up every day, in the European Union. Backups are kept for 7 days, then deleted. Audio is never included in backups.

8. Deleting your data

You can delete a meeting at any time from the application: its transcript, deliverables and actions are deleted. To delete your account and all your data, write to contact@livrable.app: deletion is carried out within 30 days. Deleted data disappears from backups within 7 days at most.

9. Security incidents

Livrable has a documented incident management procedure. If an incident affects your data, we will inform you as soon as possible, and within 72 hours at the latest.

10. Accuracy of meeting reports

When a term in the recording is uncertain, Livrable flags it explicitly ("uncertain term") instead of inventing a value. You remain in control to approve each document before sending.

11. Available documents

  • ·List of subprocessors: public page
  • ·Data processing agreement (GDPR Article 28): being finalised, available on request.
  • ·Incident management procedure: available on request.

12. What we do not have yet

Livrable is in private beta and we prefer to say so clearly:

  • ·Livrable is not ISO 27001 or SOC 2 certified at this time.
  • ·No external penetration test has been carried out yet; an automated security scan is run with each significant change.
  • ·Team accounts (single sign-on SSO, role management, audit logs) are not available yet.

A security question or a documentation request: contact@livrable.app