Security & privacy
Clear answers about sensitive speech data.
Security should not require a sales call. This page explains what Articu is designed to collect, why audio is needed, how access is controlled, and when data is deleted. For clinicians, parents, clinic buyers and security reviewers.
At a glance
Design principles first—because verified facts take time.
We publish security facts only when they are implemented and verified. What you see below are the design commitments the product is being built against. Where an operational detail is not yet final, we say so instead of filling the page with reassurance.
Data minimization
Designed to collect only what the practice workflow requires.
Transparent retention
Designed to make clear when raw audio is deleted and when a clinician explicitly chooses to retain it.
Access control
Designed to keep child, caregiver, clinician and organization permissions separate.
Collection
What information Articu is designed to collect—and why audio is needed.
Account data (name, work email, role, organization), practice activity (assignments, attempts, results), and—only when a practice exercise requires it—short speech recordings. Audio exists because evaluating a production at the sound level is the product's purpose; it is never collected for advertising.
Service data vs training data
Data used to operate the service is designed to stay separate from any model-training use. Therapy recordings would never be silently turned into training data—training use would require separate, explicit consent.
Access model
Role-based access is part of the design: child, caregiver, clinician and organization permissions are kept separate. Clinic admins see adoption, not private clinical detail.
Deletion and export
Deletion and export workflows are first-class product requirements, not support-ticket favors.
Data lifecycle
From recording to deletion—one designed flow.
The designed default deletes raw audio after analysis and any required clinician review. Retention beyond that is an explicit clinician choice, never a silent default.
Operational details
Exact numbers, when they are final.
These operational parameters are being finalized. We will publish them on this page—not in a sales deck—before the clinical pilot begins.
- Default raw-audio retention period — will be published here before the clinical pilot begins.
- Data hosting region(s) and residency options — will be published here before the clinical pilot begins.
- Subprocessor list — maintained on the Subprocessors page and completed as the production stack is finalized.
Compliance applicability
No badge theater.
HIPAA applicability depends on the deployment context. COPPA, FERPA and similar regimes apply contextually for child data, schools and covered entities. We describe how requirements shape the product instead of claiming certifications that do not exist.
We do not claim to be “COPPA certified”, “100% HIPAA safe”, or any equivalent. Where regulations apply to a deployment, contractual and technical safeguards are discussed openly during procurement. A BAA will be offered to eligible covered entities only when one actually exists.
Security FAQ
Direct questions, direct answers.
Is raw audio stored?
Is patient audio used to train AI?
Who can access a child's data?
Can a parent delete data?
Does Articu sell personal data?
Where is data hosted?
What happens after account deletion?
How are incidents reported?
Security review for your clinic.
Bring your security questionnaire. We will walk through the data lifecycle, controls and current status honestly.