Security and Data Protection at Cuckoo

  • We do not train on your data. Customer content is not used to develop, train, or improve our AI or machine-learning models, including third-party components used to provide the service.
  • Delete your data whenever you want. You can delete your content directly or ask us to delete it. For sensitive meetings and events, immediate deletion can be selected so meeting content is removed from our database when the session ends.
  • Your data belongs to you. You retain all rights, title, and interest in your content. Cuckoo processes it only as needed to provide and maintain the service.
  • Your data is encrypted. We use TLS 1.2 or later for data in transit and AES-256 encryption for data at rest.
  • Access is restricted. Access to customer data is limited through least-privilege controls and multi-factor authentication.

Your data remains yours

Customers retain ownership of the audio, transcripts, translations, terminology, and other content they provide to Cuckoo.

Cuckoo receives only the limited rights needed to process that content and deliver the requested transcription, translation, and related services.

We do not train on customer data

Customer content is not used to develop, train, or enhance artificial-intelligence or machine-learning models that are part of Cuckoo's service.

This restriction also applies to third-party AI components used by Cuckoo to provide the service.

You control retention and deletion

Customers can delete their content through the product or request deletion at any time.

For meetings or events requiring additional confidentiality, Cuckoo provides an immediate-deletion setting. Meeting content must be processed and temporarily stored while the live translation is being delivered, but when this setting is enabled, the content is deleted from the database when the session ends.

Retention and deletion are governed by:

  • The security and retention settings selected by the customer
  • Explicit deletion requests from the customer
  • The applicable customer agreement or data-processing agreement

When a customer agreement ends, customers may request that their content be deleted or returned. Under our standard Cloud Service Agreement, this is completed within 30 days, and written confirmation of deletion can be provided upon request.

Encryption and infrastructure

Cuckoo applies the following protections to customer content:

  • TLS 1.2 or later for data transmitted between users, Cuckoo, and our service providers
  • AES-256 encryption for data stored within our systems
  • Hosting and processing within the United States
  • Access controls designed according to the principle of least privilege
  • Multi-factor authentication for authorized personnel
  • Access permitted only when required for legitimate business, support, security, or legal purposes

Cuckoo applies these security measures to customer content regardless of its legal classification.

Legal and security documentation

Cuckoo can provide the following materials for a customer's internal review:

  • Cloud Service Agreement
  • Data Processing Agreement
  • Subprocessor information
  • Security questionnaires
  • NDA or additional customer security documentation, when required

For security or privacy questions, contact legal@cuckoo.so.