Privacy policy
Last updated: 30 July 2026
StaffVoice is operated from the United Kingdom. This policy explains what personal data we handle, why, who helps us process it, and what rights you have under UK data protection law (UK GDPR and the Data Protection Act 2018). We've written it to match what the product actually does — nothing here is boilerplate.
The two hats we wear
For account holders (managers and organizations who sign up) and visitors to this website, StaffVoice is the data controller: we decide how sign-in, billing, and product data is used.
For feedback written by your team, the organization that runs the pulse is the controller and StaffVoice is their data processor: we process responses only to deliver the service, under our Data Processing Addendum.
What we collect, and why
Account data. Your email address, name, and — if you sign in with Google or Microsoft — the basic profile those providers share. If you enable two-factor authentication we store your TOTP secret and hashed recovery codes. Used to sign you in and run your account.
Organization data.Your organization's name and industry, team rosters and invite emails you add, and — if you connect them — a Slack bot token or Microsoft Teams webhook for delivering pulse invitations. Used to send invitations and reminders.
Respondent data.When someone responds to a pulse, we store their written notes and, only if they explicitly tick the box, the name they chose to sign with. Invitation emails and responses are stored with no link between them — our database schema has no join between who was invited and what was written. Anonymous means a respondent's name isn't attached; a manager may still recognize details a respondent includes, and we tell respondents this plainly on the response page.
Billing data. Payments are handled by Stripe. We store your Stripe customer and subscription IDs, never card numbers.
Usage data.First-party product events (for example "a respondent visited this pulse") with no third-party analytics, no advertising trackers, and no user-level tracking of respondents. See our cookie notice — we use only strictly necessary cookies, so there is no consent banner to click.
AI processing
Responses are rewritten and organized into reports by Claude, an AI model from Anthropic. Raw notes are sent to Anthropic's API for this purpose only. Anthropic does not use API data to train its models. Managers never see raw notes — only the AI-rewritten responses and the report.
How long we keep things
- Raw respondent notes are deleted at most 30 days after a pulse closes (organizations can shorten this, never lengthen it). Only the AI-rewritten version remains.
- Account and organization data is kept while your account is active and deleted on request (see your rights below).
- Sign-in links expire after 15 minutes; session cookies expire when you sign out or they lapse.
Who processes data for us
We use a small number of service providers (sub-processors), each only for the purpose listed:
- Anthropic (US) — AI rewriting and report generation.
- Resend (US) — transactional email: sign-in links, invitations, reminders, digests.
- Stripe (US/UK) — payments and billing.
- Vercel (US) — application hosting.
- Neon (US) — database hosting.
- Slack and Microsoft — only if your organization connects them, to deliver invitations where your team already works.
Where these providers process data outside the UK, transfers rely on the UK International Data Transfer Agreement or Addendum, or the UK extension to the EU–US Data Privacy Framework, as applicable to each provider.
Your rights
Under UK GDPR you can ask us for access to, correction of, deletion of, or a portable copy of your personal data, and you can object to or ask us to restrict processing. Email us and we'll respond within one month.
One honest caveat for respondents: because responses are stored with no link to who wrote them, we cannot find or delete "your" response after it is submitted — we have no way of knowing which one is yours. That unlinkability is the point of the design; it cuts both ways.
If you're unhappy with how we've handled your data, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
Contact
Questions about this policy or your data: [email protected]. We'll update this page when our practices change and note the date above.