Trust isn't a page. But here's where it's written down.
Recalla works with one of the most sensitive things there is — a person's voice. So we've tried to be explicit, not vague, about how we treat it. The essentials first; the detailed policies are linked throughout.
Six commitments, each with the detail behind it.
Privacy
What we collect, why, the legal bases, and your rights — including GDPR and US state privacy rights.
Privacy PolicyConsent
Voice and health-related data are processed only under explicit, revocable consent, for a stated purpose.
How consent worksSecurity
The technical and organisational measures we use to protect data — described honestly for our stage.
Security practicesResponsible AI
Explainable by design, non-diagnostic, and built to keep a qualified human in control of every decision.
Our approachData governance
Minimisation, purpose limitation, special-category handling, and ethics review for any study.
Governance & ethicsTransparency
We publish our limitations, not just our hopes — separating external science from our own unproven work.
Evidence HubWhat we do — and, honestly, what we haven't yet.
We'd rather tell you exactly where we are than imply a maturity we haven't reached. Both lists below are true today.
Measures in place
- Encryption of data in transit (HTTPS/TLS).
- Least-privilege access and limited data collection.
- Reputable infrastructure and service providers under contract.
- Synthetic-only public demo; on-device processing for live features.
- A responsible-disclosure channel for security reports.
Not yet in place
- No formal certifications yet (e.g. SOC 2, ISO 27001).
- Not a HIPAA-covered entity; not operating under a BAA today.
- No independent penetration test or audit completed yet.
- Formal compliance will be pursued as we handle real clinical data.
Where we are today
Recalla is a research-stage prototype, not a medical device, and has not been validated for clinical use. Our public materials use synthetic, illustrative examples. This Trust Center describes real commitments and practices for our current stage — and it will grow more formal as the product does. We'll update it in public rather than overstate it.
Found a security or privacy issue?
We welcome good-faith reports. Please email us with details and avoid accessing or altering others' data. We'll acknowledge your report and work with you on a fix.
Need something specific for a review?
Clinical, enterprise, or research partners often need particular details on privacy, consent, or data handling. Ask us — we'll give you a straight answer.
Contact us