Security & Trust
Last updated: June 2026
Overview
UpSight is built for teams who handle sensitive customer conversations. We take data protection seriously — your recordings, transcripts, and customer information are isolated, encrypted, and never used to train AI models. This page describes our security controls, the third-party providers we rely on, and how to exercise your data rights.
Security questions or concerns? Contact us at [email protected].
Encryption
- In transit: All data transmitted between your browser or app and UpSight uses TLS 1.3. Connections that attempt to use older protocols are rejected.
- At rest: Database records are encrypted at rest using AES-256 by our database provider (Supabase). Media files (recordings, uploads) stored in Cloudflare R2 are encrypted at rest by default.
- Backups: Database backups are encrypted with the same AES-256 standard and stored in geographically redundant locations.
Access Controls & Data Isolation
- Row-level security: Every database query is scoped to your account and project at the database layer — not just in application code. A misconfigured query cannot return another customer's data.
- Authentication: User sessions are managed through Supabase Auth with short-lived JWTs. We support single sign-on (SSO) via OAuth providers.
- Role-based access: Within an account, access to projects and data is controlled by membership and role. Team members only see data within their assigned projects.
- Internal access: DeepLight employees access production data only when necessary to provide support, and only with explicit account holder consent. We log administrative access.
Infrastructure
UpSight's application is hosted on infrastructure maintained by providers who hold SOC 2 Type II certification. We do not operate our own data centers.
- Application servers are located in the United States.
- Database and media storage are provided by Supabase and Cloudflare R2 respectively, both operating in U.S. regions by default.
- EU customers: contact us to discuss data residency options as our infrastructure roadmap develops.
Meeting Recordings & Consent
When you use UpSight to record meetings, a named bot participant joins on your behalf via Recall.ai. The bot's display name is configurable and visible to all participants — it is not hidden.
Your responsibility: Recording laws vary by jurisdiction. Many U.S. states and most countries outside the U.S. require the consent of all parties before a conversation can be recorded. You are responsible for ensuring you have obtained appropriate consent before recording any meeting. UpSight provides disclosure templates and configurable bot naming to help you meet this obligation.
UpSight does not make recordings available to anyone outside your account. Recordings are stored encrypted in Cloudflare R2 and are accessible only to members of your team with appropriate permissions.
Data Retention
- Recordings and transcripts: Retained for the life of your account, or 3 years from creation — whichever comes first. Shorter retention periods are available on request.
- Survey responses: Retained for the life of the survey project.
- Account data: Retained while your account is active and for up to 90 days after closure, after which it is permanently deleted.
- Deleted items: Moved to trash and permanently deleted after 30 days.
- Billing records: Retained for 7 years as required by applicable law.
Your Data Rights
You can request any of the following by emailing [email protected] with the subject line "Data Request". We respond within 30 days.
- Export (portability): Receive a machine-readable export of your account data — transcripts, survey responses, contacts, and analysis — in JSON or CSV format.
- Deletion: Permanently delete your account and all associated data. This is irreversible and includes all recordings, transcripts, contacts, and survey responses.
- Correction: Correct inaccurate information we hold about you.
- Access: Receive a summary of what personal data we hold about you.
Note: For B2B customers, your end users' data rights requests should be directed to you as the account holder. We will support you in fulfilling those requests.
Subprocessors
We rely on the following third-party providers to deliver the Service. Each processes personal data on our behalf and is bound by a Data Processing Agreement (DPA).
| Provider | Country | Purpose | Certifications |
|---|---|---|---|
| Supabase | United States | Database and authentication | SOC 2 Type II |
| Cloudflare R2 | United States | Media file storage (recordings, uploads) | SOC 2 Type II, ISO 27001 |
| Anthropic | United States | AI transcription and analysis | SOC 2 Type II |
| Recall.ai | United States | Meeting recording bot infrastructure | SOC 2 Type II |
| LiveKit | United States | Real-time voice and video | SOC 2 Type II |
| Trigger.dev | United States / European Union | Background task processing | SOC 2 Type II |
| Fly.io | United States | Application hosting and deployment | SOC 2 Type II |
| Stripe | United States | Payment processing | PCI DSS Level 1, SOC 2 Type II |
We will notify account holders of material changes to our subprocessor list at least 30 days in advance via email.
AI Processing & Your Data
We do not use your content to train AI models. Your recordings, transcripts, survey responses, and customer data are processed solely to provide the Service to you. We have zero-data retention agreements with our AI providers where available, and we do not share your content with third parties for their own model training.
AI processing (transcription, analysis, summarization) is performed by Anthropic's Claude API. Inputs sent to Anthropic are governed by their API data handling policy, which prohibits training on API inputs by default.
HIPAA & Healthcare
UpSight is not currently HIPAA-certified. If your use case involves Protected Health Information (PHI), we recommend keeping patient identifiers out of meeting recordings and survey responses until we complete our HIPAA compliance program.
Healthcare teams with specific compliance requirements should contact us at [email protected] to discuss your needs. We are actively working toward BAA availability with our key subprocessors.
Incident Response
In the event of a data breach that affects your account, we will notify affected customers within 72 hours of becoming aware of the incident — or sooner if required by applicable law. Notification will include the nature of the breach, data categories affected, and steps we are taking to remediate.
Vulnerability Disclosure
If you discover a security vulnerability in UpSight, please report it responsibly to [email protected]. We ask that you give us reasonable time to investigate and remediate before public disclosure. We do not pursue legal action against researchers who follow this policy.
Contact
DeepLight (UpSight)
General: [email protected]
Security & vulnerability reports: [email protected]
Data requests: [email protected] — subject line: "Data Request"