Security & privacy

Clear answers about sensitive speech data.

Security should not require a sales call. This page explains what Articu is designed to collect, why audio is needed, how access is controlled, and when data is deleted. For clinicians, parents, clinic buyers and security reviewers.

At a glance

Design principles first—because verified facts take time.

We publish security facts only when they are implemented and verified. What you see below are the design commitments the product is being built against. Where an operational detail is not yet final, we say so instead of filling the page with reassurance.

Data minimization

Designed to collect only what the practice workflow requires.

Transparent retention

Designed to make clear when raw audio is deleted and when a clinician explicitly chooses to retain it.

Access control

Designed to keep child, caregiver, clinician and organization permissions separate.

Collection

What information Articu is designed to collect—and why audio is needed.

Account data (name, work email, role, organization), practice activity (assignments, attempts, results), and—only when a practice exercise requires it—short speech recordings. Audio exists because evaluating a production at the sound level is the product's purpose; it is never collected for advertising.

Service data vs training data

Data used to operate the service is designed to stay separate from any model-training use. Therapy recordings would never be silently turned into training data—training use would require separate, explicit consent.

Access model

Role-based access is part of the design: child, caregiver, clinician and organization permissions are kept separate. Clinic admins see adoption, not private clinical detail.

Deletion and export

Deletion and export workflows are first-class product requirements, not support-ticket favors.

Data lifecycle

From recording to deletion—one designed flow.

The designed default deletes raw audio after analysis and any required clinician review. Retention beyond that is an explicit clinician choice, never a silent default.

Operational details

Exact numbers, when they are final.

These operational parameters are being finalized. We will publish them on this page—not in a sales deck—before the clinical pilot begins.

Compliance applicability

No badge theater.

HIPAA applicability depends on the deployment context. COPPA, FERPA and similar regimes apply contextually for child data, schools and covered entities. We describe how requirements shape the product instead of claiming certifications that do not exist.

Security FAQ

Direct questions, direct answers.

Is raw audio stored?
The designed default deletes raw audio after analysis and any required clinician review. Retention is an explicit clinician choice when enabled. Exact default retention periods will be published on this page before the clinical pilot begins.
Is patient audio used to train AI?
The product is designed so that service operation and model training stay separate, and therapy recordings are designed not to be used for model training by default. Any training use would require separate, explicit consent with opt-out.
Who can access a child's data?
Access is designed to be role-based: the treating clinician, the linked caregiver where applicable, and clinic roles enabled by permission settings. Organization admins see adoption—not private clinical detail.
Can a parent delete data?
Caregiver-initiated deletion workflows are a first-class product requirement, subject to the clinic's data-control configuration.
Does Articu sell personal data?
No. Articu does not sell personal data and does not use therapy recordings for advertising.
Where is data hosted?
Hosting regions and residency options are being finalized and will be published on this page before the clinical pilot begins.
What happens after account deletion?
Account and service data are designed to be deleted according to the retention policy described in the privacy policy; applicable statutory retention obligations are described there as well.
How are incidents reported?
Contact privacy@articu.tech. Incident response will be documented publicly as the security program matures.

Security review for your clinic.

Bring your security questionnaire. We will walk through the data lifecycle, controls and current status honestly.