Resonant IQ Help & Docs
Concepts QA Insights Open Resonant IQ
Help / Data & privacy
Help

Data & privacy

Your customer conversations are the most sensitive data you have. This page is the plain-English version of how Resonant IQ treats them — what it reads, how it's protected, and the controls you hold. The Privacy Policy and Security pages are the authoritative source.

7 min read
For admins & security reviewers
Admin Security reviewer CS Leader

Three commitments shape everything below. They're worth holding in mind as you read the specifics.

Read-only
Resonant IQ reads from your connected tools. It never writes, edits, or deletes records in them.
Never trained on
Your data is never used to train models — ours or our providers'. It's a contractual commitment, not just a policy.
Evidence over inference
Every signal ties back to the specific conversations and timestamps it came from. Nothing is asserted without a source.

What Resonant IQ reads

Only what you connect, and only what the product uses. Through the read-only OAuth access you grant, Resonant IQ imports the two streams — conversation transcripts and their metadata, plus account activity like notes, tasks, calls, and meetings — along with the contact and company identifiers needed to associate a conversation with an account.

We read this data. We never write back.
Resonant IQ holds a strict read-only stance toward HubSpot, Intercom, Zendesk, and every other connected source. It does not pull payment details, full customer profiles, or unrelated contact history.

Whose data it is

For the conversation data you connect, your organization is the data controller — you own it, and Resonant IQ processes it only on your instructions to deliver the service, under a Data Processing Agreement. For your own account and billing data, Resonant IQ is the controller.

Each tenant's data is isolated from every other's — enforced at the application boundary and again by Postgres row-level security as an independent second layer, with a cross-tenant isolation test suite running in CI. One tenant cannot reach another's data.

AI and your data

Resonant IQ uses large language models to score conversations and detect signals. Two providers see conversation text as part of that work, both under enterprise data-handling terms, and neither retains your data for training:

  • Anthropic — conversation scoring. Transcripts are sent to Anthropic's API to return scores and explanations. Anthropic retains API inputs for up to 30 days for trust and safety, then deletes them; details at trust.anthropic.com.
  • Voyage AI — semantic search. Transcripts are sent to return vector embeddings used only for search and evidence retrieval.

Scores are advisory only. Your organization retains sole responsibility for any employment, coaching, or operational decisions made using them — Resonant IQ output is an input to human judgment, not a binding determination.

How it's protected

The controls below are built and running today — not planned. The full detail lives on the Security page.

Encryption
TLS for all data in transit; AES-256 at rest. Integration credentials are additionally encrypted at the application layer before storage.
Access control
Role-based within each tenant. Support access is read-only and audited — the team can see what you see to help, but cannot modify your data. Platform admin requires phishing-resistant passkeys.
Audit logging
Every platform-admin action is logged with actor, tenant, and timestamp. The log is append-only and immutable — enforced by a database trigger. Human score corrections are audited with before/after values.
Operations
Personally identifiable information is stripped from server logs by design. Automated daily backups with 7-day retention (recovery point ≤ 24 hours).

On compliance: Resonant IQ is pre-launch and does not yet hold a SOC 2 report, but runs an internal controls program mapped to SOC 2 Trust Services Criteria, with a formal audit planned once there are production customers. GDPR data-subject obligations — export and deletion — are supported today.

Where it's processed

Resonant IQ runs on a small, deliberate set of US-based providers, each bound by a data processing agreement. The key ones that touch conversation data:

Provider
Role
Location
Anthropic
AI conversation scoring
United States
Voyage AI
Embeddings (semantic search)
United States
Supabase
Database (Postgres on AWS us-east-1)
United States
Vercel
Application hosting & CDN
United States
Stripe
Billing (no card details stored)
United States

The full subprocessor list — and the EU-to-US transfer mechanisms (Standard Contractual Clauses) — is in Privacy Policy §7. You'll get at least 30 days' notice before a new subprocessor handling your data is added.

How long it's kept

Data is retained for as long as your account is active, with these windows after closure or deletion:

Data type
Retention
Conversation data
Account lifetime + 90 days after closure (to allow export)
Account information
Account lifetime + 3 years
Billing records
7 years (tax compliance)
Server & access logs
90 days, rolling

Disconnect an integration and its sourced data is purged within 60 days. Close your account or request deletion and Customer Data is deleted within 90 days, with confirmation; backups are purged on the same schedule after their normal cycle.

Controls you hold

  • Disconnect any integration from Settings at any time — it revokes OAuth access immediately.
  • Export your data in a structured, machine-readable format, or request deletion of specific records or your whole tenant.
  • Data-subject rights (access, rectification, erasure, portability, and more) are available per the Privacy Policy. Requests from your end customers are administered by your organization as the controller; if you forward a valid one, Resonant IQ acts on it promptly.

Questions & requests

General & data requests
Data questions, exports, and deletion requests.
help@resonantiq.app
Security
Vulnerability reports and security questionnaires.
security@resonantiq.app

For the full legal detail, see the Privacy Policy, Security, and Terms. A copy of the Data Processing Agreement is available on request.

← Previous
Troubleshooting & FAQ
Back to
Docs home →