Last updated on July 18th 2026
The model companies work hard to keep their models safe — that's their job. Our job is keeping your life private, from the model companies.
In practice that means three commitments you can check: we tell you exactly which providers touch your conversation and why, we never use your data to train models, and your workspace — the recordings, transcripts, and analyses your meetings produce — belongs to you, until you delete it.
No vague diagrams — this is the actual path of a live meeting:
The complete list of third parties that process customer data, and what each one receives:
| Provider | Purpose | Data processed |
|---|---|---|
| Daily.co | Live call transport (WebRTC rooms) | Call audio and video, for the duration of the call |
| Google Cloud (Vertex AI) | Realtime agent intelligence (Gemini Live) and document retrieval | Live call audio, camera/screen frames when you share them, conversation context, uploaded scenario documents |
| Deepgram | Real-time transcription | Call audio |
| OpenAI | Agent voice (default TTS); optional post-call analysis | The agent's text lines; transcript excerpts when selected for analysis |
| Anthropic | Optional post-call analysis models | Transcript excerpts when selected for analysis |
| ElevenLabs | Optional agent voices (TTS/STT) | The agent's text lines; call audio if selected for transcription |
| Cartesia | Optional agent voices (TTS) | The agent's text lines |
| Microsoft Azure | File storage (uploaded documents, images); optional agent voice | Files you upload; the agent's text lines |
| Amazon Web Services | Recording storage (S3) and playback (CloudFront) | Meeting recordings, when recording is enabled |
| Anam.ai | Opt-in photorealistic avatar for the agent | The agent's synthesized audio |
| PostHog | Product analytics | Usage events and page views — never conversation content |
| Resend | Transactional email | Email addresses, meeting invitations and reports |
| Razorpay | Payments | Billing details |
| Sentry | Crash reporting (desktop app only) | Crash and error reports from the desktop app |
The Waterr desktop app can additionally connect to services you explicitly authorize (email, calendar, and other integrations via OAuth); those connections act on your accounts only with your authorization and are covered in the Transparency & Trust Center.
Your data persists until you delete it. There is no automatic expiration and no silent cleanup — what your meetings produce stays in your workspace, under your control, for as long as you keep it. Third-party model providers in the data path retain API traffic per their own published API terms, which exclude using customer API data for training.
We do not use your conversations, transcripts, recordings, or uploaded documents to train, fine-tune, or improve any model — ours or anyone else's. There is no default data-sharing program to opt out of, because there is nothing to opt out of.
Everything built on Waterr identifies itself. Every agent tells you it's an agent — in its first breath, not in the fine print. Not agents that pass as human; agents worth talking to as agents.
This page is the short, checkable version. The long form — data lifecycle, enterprise controls, vulnerability reporting — lives in our Transparency & Trust Center, alongside our Privacy Policy and Terms of Service.
Questions your security team wants answered directly: [email protected].