Data handling & security

Where your data lives, who can see it, how long it’s kept, and what processes it. No marketing language — this is the same page we’d walk your InfoSec or audit team through.

Where your data lives

Mayetik runs on Railway’s managed infrastructure, backed by a dedicated PostgreSQL database — not a shared multi-vendor stack. All traffic to and from Mayetik is encrypted in transit (TLS). Data at rest sits on encrypted infrastructure-provider storage. We don’t currently hold a formal certification (SOC 2, ISO 27001) for this infrastructure — we’ll say that plainly rather than imply otherwise, and formal certification is on our roadmap as we grow.

Who can see it

Access is role-based and enforced on every request, not just in the UI:

  • Project-level roles (owner, admin, participant) scope who can view responses, briefs, and synthesis for a given project — participants see only what they’re explicitly granted.
  • Organization-level roles scope cross-project visibility — a project admin in one business unit cannot see another business unit’s data unless separately granted access.
  • There is no default cross-tenant visibility. Every query is scoped to the organization and project the requester belongs to.

Audit trail

Every meaningful action — session created, invitation sent, brief generated, role changed, knowledge queried or exported — is written to an append-only log with who, what, and when. Nothing in that log can be edited or deleted through the product. Org and project admins can view their own scoped history at any time.

What processes your data

Responses are sent to OpenAI’s API to generate briefs, transcribe voice input, and build search embeddings. Per OpenAI’s API data usage policy, data submitted through the API is not used to train their models by default. Email delivery (invitations, magic links, notifications) is handled by our transactional email provider. Those are the only third parties that process respondent data — we don’t sell, share, or otherwise use it beyond delivering the product. A full sub-processor list is available on request.

Retention & deletion

Responses, briefs, and audit history are retained for the life of your organization’s account — we don’t auto-delete data on a fixed schedule today. An org owner can request deletion of a specific project, interview, or the entire account at any time by contacting hello@mayetik.com.

Getting your data out

Responses, briefs, and syntheses export as CSV, JSON, or Markdown at any time — nothing is locked in. This matters for evidence packs, legal or IC review, and simply not being dependent on us to hold your own records.

Questions about a specific control, retention window, or a data processing agreement for your organization?