Waterr AI Logo

Trust

Last updated on July 18th 2026

The model companies work hard to keep their models safe — that's their job. Our job is keeping your life private, from the model companies.

In practice that means three commitments you can check: we tell you exactly which providers touch your conversation and why, we never use your data to train models, and your workspace — the recordings, transcripts, and analyses your meetings produce — belongs to you, until you delete it.

The short version

  • A Waterr call is one human and one agent. Every agent introduces itself as an agent — honestly artificial, always.
  • We do not use your conversations, transcripts, or recordings to train or fine-tune any model.
  • Recording is off unless the meeting enables it, and scenarios can require explicit participant consent before anyone joins.
  • Everything a meeting produces lands in your workspace. It stays until you delete it — there is no silent expiration, and deletion is yours to trigger.
  • Sensitive fields — participant names, transcripts, memory, consent messages — are encrypted at the column level (AES-256-GCM) in our database, on top of TLS in transit.
  • Every provider in the data path is listed on this page, with what flows to it. No unlisted processors touch your conversation.

Where your conversation goes

No vague diagrams — this is the actual path of a live meeting:

  • The call itself runs over Daily.co's WebRTC network.
  • The agent's realtime intelligence is Google's Gemini Live, running on Vertex AI. Call audio — and camera or screen frames, if you share them — stream to it for the duration of the call. Ori Realtime, our own interaction model running on infrastructure we operate, is available as an opt-in realtime backend.
  • The live transcript is produced by Deepgram from the call audio.
  • The agent's voice is synthesized by the voice vendor your scenario selects — OpenAI by default; ElevenLabs, Cartesia, Azure, or Deepgram optionally. Only the agent's own lines are sent for synthesis.
  • Recordings — only when enabled — are written to our AWS S3 bucket and played back through signed CloudFront URLs.
  • Transcripts and analyses are stored in our database with content encrypted at the column level.
  • Post-call analysis routes through our model gateway to the model you select (Google, Anthropic, or OpenAI). The gateway passes conversation content through; it does not store it.
  • Billing meters token and character counts — numbers, never content.

Subprocessors

The complete list of third parties that process customer data, and what each one receives:

ProviderPurposeData processed
Daily.coLive call transport (WebRTC rooms)Call audio and video, for the duration of the call
Google Cloud (Vertex AI)Realtime agent intelligence (Gemini Live) and document retrievalLive call audio, camera/screen frames when you share them, conversation context, uploaded scenario documents
DeepgramReal-time transcriptionCall audio
OpenAIAgent voice (default TTS); optional post-call analysisThe agent's text lines; transcript excerpts when selected for analysis
AnthropicOptional post-call analysis modelsTranscript excerpts when selected for analysis
ElevenLabsOptional agent voices (TTS/STT)The agent's text lines; call audio if selected for transcription
CartesiaOptional agent voices (TTS)The agent's text lines
Microsoft AzureFile storage (uploaded documents, images); optional agent voiceFiles you upload; the agent's text lines
Amazon Web ServicesRecording storage (S3) and playback (CloudFront)Meeting recordings, when recording is enabled
Anam.aiOpt-in photorealistic avatar for the agentThe agent's synthesized audio
PostHogProduct analyticsUsage events and page views — never conversation content
ResendTransactional emailEmail addresses, meeting invitations and reports
RazorpayPaymentsBilling details
SentryCrash reporting (desktop app only)Crash and error reports from the desktop app

The Waterr desktop app can additionally connect to services you explicitly authorize (email, calendar, and other integrations via OAuth); those connections act on your accounts only with your authorization and are covered in the Transparency & Trust Center.

Retention

Your data persists until you delete it. There is no automatic expiration and no silent cleanup — what your meetings produce stays in your workspace, under your control, for as long as you keep it. Third-party model providers in the data path retain API traffic per their own published API terms, which exclude using customer API data for training.

Deletion

  • Meetings, transcripts, and recordings can be deleted directly from your workspace or via the API.
  • Uploaded scenario documents can be removed from their scenarios at any time.
  • For complete removal of an account and everything attached to it — including storage copies of recordings — email [email protected] from your account address and we will purge it.

Training

We do not use your conversations, transcripts, recordings, or uploaded documents to train, fine-tune, or improve any model — ours or anyone else's. There is no default data-sharing program to opt out of, because there is nothing to opt out of.

Security

  • All traffic is encrypted in transit with TLS.
  • Sensitive database fields — participant names, transcript content, agent memory, consent messages, webhook and redirect URLs — are encrypted at the column level with AES-256-GCM.
  • Recordings and files live in cloud object storage (AWS S3, Azure Blob) with provider-managed encryption at rest.
  • API access uses scoped keys; account access uses token-based authentication.
  • Account-level actions — key creation and revocation, plan changes, organization changes — are written to an append-only audit log.

Honestly artificial. Always.

Everything built on Waterr identifies itself. Every agent tells you it's an agent — in its first breath, not in the fine print. Not agents that pass as human; agents worth talking to as agents.

The full document

This page is the short, checkable version. The long form — data lifecycle, enterprise controls, vulnerability reporting — lives in our Transparency & Trust Center, alongside our Privacy Policy and Terms of Service.

Questions your security team wants answered directly: [email protected].