How we protect your users' data.
Overheard talks to your users on your behalf. Here's how we keep what they tell us private and secure.
Your workspace is isolated
Only your organization can see your data. We enforce this in the database itself with row-level security, so no other customer can reach it.
Participants agree before the interview
Every participant sees a plain-language notice before the interview, including that it's recorded. The interview only starts after they agree.
Recordings and transcripts stay private
We keep them in private storage, never at a public URL. Members of your workspace open them through links that expire quickly. All data is encrypted in transit and at rest.
Interview links only open the interview
A participant's link opens their own interview and nothing else. It can't reach your results, other participants, or your workspace, and it expires.
We use your data only for your studies
We don't sell your data, and we don't train shared models on your interviews. What your users say goes into your readouts and nowhere else.
We delete data on request
Ask us and we'll delete your studies, recordings, and transcripts. Automatic retention controls are on our enterprise roadmap.
The vendors we use
The short list of vendors we run on is public: see Subprocessors.
Enterprise
SSO/SAML, DPAs, and security questionnaires are available for enterprise conversations. Talk to us.
Questions? privacy@withoverheard.com