Trust & Security
You certify the record, so you carry the confidentiality duty — and any tool you run case audio through carries it with you. This page states plainly how Stenobox protects your work. Every claim here is specific on purpose: no vague badges, no marketing language, and nothing we haven't verified.
Only you can see your work
Your transcripts, audio, and review data are tied to your account by security rules enforced at the database and storage layer. A request from any other user's account is refused by the infrastructure itself — this is not an access policy an employee follows; it is a rule the system cannot be asked to ignore. Ownership of every uploaded file is established server-side, never trusted from the uploading device.
What happens to your audio
- Source uploads are deleted within one day. The file you upload is removed automatically after processing — a storage lifecycle rule, not a manual step.
- Review copies auto-delete after 30 days. The audio copy that powers listen-along review is removed after 30 days by default. You can choose Keep until I delete for a job or for future uploads.
- Recordings you make in Stenobox stay until you delete them. Your capture may be your only copy, so it is never auto-deleted.
- Deleting a transcript deletes its audio. Removing a job removes the review audio and any original recording with it.
Never used to train anything
Your recordings and transcripts are never sold, never shared for advertising, and never reused to build or improve any other product. That includes the outside speech and language services our pipeline uses to produce your draft: none of them use audio or text processed for Stenobox to train or improve their systems — a commitment we have confirmed in each provider's written commercial terms or in our account's data-control settings. Where a provider offered a data-sharing program, we opted out; where exclusion required a per-request setting, it is written into our code with a note that it must never be removed.
Where your data lives
Storage and processing run on Google Cloud, with your files stored in the US-East region and encrypted in transit and at rest. One transcription step runs on a provider's global infrastructure, which may route processing outside the United States. We say that because it is true — a page that told you "everything stays in the US" would be overclaiming, and in legal work an honest gap beats a polished overstatement.
Certifications — attributed honestly
Google Cloud, the infrastructure Stenobox runs on, holds SOC 2 and ISO 27001 certifications, among others. Those are Google's certifications, not ours — Stenobox is a small company and does not claim them directly. If you ever see a transcription product wearing a compliance badge, it is worth checking whose certification it actually is.
HIPAA, stated plainly
Stenobox does not claim HIPAA compliance and does not offer Business Associate Agreements today. Court reporting generally sits outside HIPAA's chain of covered entities — the confidentiality duties on deposition and hearing records come from court rules and protective orders, which is exactly the work Stenobox is built around. If your situation genuinely requires a BAA, tell us at hello@stenobox.com — we would rather hear the requirement than have you assume a compliance we haven't claimed.
Payments
Checkout and billing are handled by Stripe. Your card number goes to Stripe directly; Stenobox never sees or stores it.
Built by someone with the same license on the line
Stenobox is built and run by a working, Michigan-certified electronic recorder who processes his own case audio through the same pipeline his customers use — under the same confidentiality obligations you carry. That is not a security control, but it is the reason the controls above exist: this product was built by someone whose own name goes on the certificate.
Questions
Anything on this page you want evidence for, ask: hello@stenobox.com. The full legal detail lives in the Privacy Policy and Terms of Use.