Security & privacy
How we look after
your recordings.
What protects your files, which providers process them, and what we don't have yet. Every line on this page is checked against how DOVEV actually works.
HTTPS on every connection
The site, the app and the API are served only over HTTPS, with TLS 1.2 or newer. Plain HTTP is redirected or refused.
AES-256 at rest
Media is stored on Cloudflare R2 and data in Supabase Postgres. Both encrypt everything they hold with AES-256.
Scoped to your account
Row-level security ties every file, transcript and translation to its owner. Media is only ever served through signed links that expire.
Not used to train AI
DOVEV never uses your recordings or transcripts to train or fine-tune a model, and never sells them.
Deleted when you say
A deleted file waits in Trash for 7 days, then it and everything made from it are purged from DOVEV's storage and database. Empty Trash to purge it at once.
You decide who sees it
Nothing is shared until you share it, one person at a time, with view, comment or edit access. Revoke a share whenever you like.
What happens to your file
From upload to deletion,
step by step.
Upload
Your file travels over HTTPS to encrypted storage, and its first bytes are checked to confirm it really is audio or video.
Transcribe
Our worker keeps a temporary copy while the job runs and sends the audio over HTTPS to the transcription engine: AssemblyAI on paid plans; Groq on Free, and on paid plans when AssemblyAI is unavailable, with OpenAI as the last fallback. The copy is deleted when the job ends.
Translate and summarise
Translations go to Google Cloud Translation, and AI summaries and questions to OpenAI. Only transcript text is sent for these, never the audio.
Store and delete
Results are stored encrypted, and deleting a file removes it from DOVEV. Once DOVEV has a finished transcript, it deletes AssemblyAI's copy, audio included (for jobs from 22 September 2026). If a job fails there, AssemblyAI removes the audio within 48 hours and the transcript after 30 days. Other providers follow their own retention policies.
In the product
Safeguards you
can check.
Each of these is a feature you can see working in the app or the API, not a policy statement.
What we don't have yet
DOVEV is not SOC 2 audited. DOVEV is not HIPAA compliant and does not sign BAAs, so please don't upload protected health information. If your organisation needs a compliance or data-processing answer, ask us and we'll tell you exactly where things stand.
Start transcribing.
Your first 30 minutes are free. See what each action costs before you run it. You never pay for work you didn’t ask for.
No credit card required · Cancel anytime