Privacy Policy - Polygraph Reports

Effective Date: July 20, 2026

Polygraph Reports, Inc ("Polygraph Reports," "we," "our," or "us") provides AI-assisted report creation and related services through our websites, applications, and software, including polygraphreports.com and reportwiz.ai (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information.

Our customers often use the Service to process highly sensitive interview and investigation materials. We designed our practices to minimize retention, preserve customer control, and protect confidentiality. Please read this Policy together with our Terms of Use.

1. Scope, Roles, and Direct Agreements

This Policy applies to personal information we process through the Service, our websites, account administration, sales, support, and business operations. It does not apply to third-party products or websites that operate under their own privacy policies.

For account, billing, website, sales, and support information, Polygraph Reports generally determines why and how the information is processed. For files, recordings, transcripts, report content, and other information a customer submits to the Service ("Customer Content"), the customer determines the purpose of processing and Polygraph Reports processes the information on the customer's behalf and instructions. Individuals whose information appears in Customer Content should direct privacy requests to the customer that submitted it.

If we have a signed order form, data processing addendum, business associate agreement, government contract, or other written agreement with a customer (a "Direct Agreement"), that agreement controls over this Policy to the extent of any conflict. This is particularly important for government and regulated customers whose legal requirements may differ from this generally published Policy.

2. Information We Collect

  • Customer Content: audio and video recordings, transcripts, prompts, interview information, PDFs, forms, supporting documents, report text, templates, and related metadata. This may include names, contact information, government identifiers, criminal justice or investigation information, employment information, health information, biometric-related information, and other sensitive personal information selected by the customer.
  • Account and organization information: name, organization, job title, email address, telephone number, account role, authentication details, settings, and administrator relationships.
  • Transaction information: subscription, credit, invoice, and payment status. Payment card details may be collected directly by our payment processor rather than stored by us.
  • Usage, device, and audit information: IP address, browser and device details, login events, feature usage, report and document events, administrative activity, diagnostics, security events, and timestamps.
  • Communications: information included in sales inquiries, support requests, demonstrations, surveys, and other communications with us.
  • Cookies and similar technologies: session, authentication, security, preference, and operational information needed to run the websites and Service.

3. Sources of Information

We receive information directly from users and customers; automatically from browsers, devices, and use of the Service; from a customer's administrators and authorized users; from service providers that support our operations; and from business partners or public sources when someone requests information about the Service.

4. How We Use Information

We process information to:

  • provide transcription, AI-assisted report drafting, document processing, exports, storage, account administration, and other requested features;
  • follow customer instructions and apply the customer's selected retention settings;
  • authenticate users, manage permissions, maintain audit trails, secure the Service, prevent misuse, and investigate incidents;
  • process payments, administer subscriptions and credits, and maintain business and tax records;
  • provide support, respond to requests, communicate service and security notices, and manage our customer relationship;
  • maintain, troubleshoot, and improve the reliability, usability, and performance of the Service;
  • comply with law, enforce agreements, establish or defend legal claims, and protect rights, safety, and property; and
  • create aggregated or de-identified information that cannot reasonably identify a customer or individual.

We do not use Customer Content to train our own or third-party AI models. We do not sell personal information or Customer Content. We do not share personal information for cross-context behavioral advertising or targeted advertising.

5. OpenAI Zero Data Retention

The Service currently uses OpenAI's API to process Customer Content for transcription and report generation. We have been approved for OpenAI's Zero Data Retention program and use approved Zero Data Retention eligible endpoints and features for Customer Content submitted to OpenAI.

For those requests:

  • Customer Content is used only to process and return the requested result;
  • prompts and responses are excluded from OpenAI's abuse-monitoring logs;
  • OpenAI does not retain Customer Content after processing the request; and
  • Customer Content is not used to train or improve OpenAI models.

Zero Data Retention at OpenAI is separate from the retention setting selected for the Polygraph Reports Service. If a future feature or provider cannot support the handling described above, we will not represent that feature as Zero Data Retention and will disclose materially different handling before applying it to Customer Content. More information about OpenAI API data controls is available in OpenAI's data controls documentation.

6. When We Disclose Information

We disclose information only as needed for the following purposes:

  • Service providers: vendors that provide cloud infrastructure, AI processing, communications, monitoring, support, authentication, and payment services. They may process information only to provide contracted services and are subject to confidentiality and data protection obligations.
  • Customer administrators and authorized users: according to the customer's account configuration, roles, sharing choices, and instructions.
  • Legal and safety purposes: when we reasonably believe disclosure is required by law or valid legal process, or necessary to protect rights, safety, security, and the integrity of the Service. When legally permitted and appropriate, we will notify the affected customer before disclosing Customer Content and will seek to limit overbroad requests.
  • Business transactions: in connection with a financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections and applicable law.
  • At the customer's direction: when a customer enables an integration, requests disclosure, exports information, or otherwise instructs us to share it.
  • Professional advisers: auditors, insurers, attorneys, and other advisers bound by confidentiality duties.

7. Data Retention and Deletion Options

Customers control how long report content remains available, subject to their selected retention option, administrator actions, legal requirements, and any Direct Agreement.

Standard Retention

Report content remains in the Service until an authorized customer administrator deletes it, the customer requests deletion, the account is terminated and deletion occurs under our offboarding process, or a Direct Agreement sets another period. Deleting a report removes its uploaded source files, generated transcripts, and report body from active systems. File data becomes unavailable from active storage promptly after deletion. Deleted database content may remain in encrypted disaster-recovery backups for up to 30 days, after which it is no longer recoverable through our ordinary processes.

Document Zero Data Retention

After a report is created, the Service automatically deletes uploaded source files and transcripts generated from those files. The completed report remains available to the customer until an authorized administrator deletes it or another applicable retention event occurs.

Report Zero Data Retention

This includes Document Zero Data Retention. In addition, after the first successful download of a completed report, the Service automatically deletes the report content. The customer must securely preserve the downloaded copy if needed because Polygraph Reports cannot recover or recreate the deleted content.

Metadata Retained After ZDR

We retain limited metadata needed for audit, security, account administration, and billing, such as report name, report template name, creation date, deletion date, and creator. This metadata does not include the report body, transcripts, or uploaded source files. Account, billing, security, and audit records may be retained for legitimate business and legal purposes even after content deletion.

Deletion may be delayed or limited when preservation is required by law, legal hold, a binding government request, security investigation, or Direct Agreement. We will isolate retained information from ordinary use and delete it when the obligation ends. Customers can contact their account manager to enable a Zero Data Retention option.

8. Security and Confidentiality

We maintain administrative, technical, and physical safeguards designed to protect information. Our production servers operate in AWS GovCloud (US), and uploaded files are stored in private Amazon S3 buckets with encryption in transit and at rest. Controls include least-privilege access, role-based access, pre-signed URLs, multi-factor authentication for privileged credentials, logging, monitoring, and restricted personnel access based on business need.

Polygraph Reports has completed a SOC 2 Type II examination, which independently assesses the design and operating effectiveness of in-scope controls over a defined review period. AWS GovCloud is designed to support sensitive and regulated workloads, but use of AWS GovCloud or our SOC 2 report does not by itself make every customer workload compliant with a particular legal or regulatory framework. Any specific compliance commitment must appear in a Direct Agreement.

No transmission or storage system can be guaranteed completely secure. Customers are responsible for managing their Users, permissions, endpoints, exported files, and credentials. If we discover a security incident affecting personal information, we will investigate and provide notice as required by applicable law and any Direct Agreement.

9. Customer Responsibilities and Sensitive Information

Customers determine what Customer Content to submit and are responsible for providing legally required notices, obtaining consents, establishing a lawful basis, configuring retention, responding to individuals, and complying with recordkeeping and disclosure requirements. Customers should not submit protected health information, criminal justice information, controlled unclassified information, or other regulated data unless their use is lawful and any required Direct Agreement or compliance configuration is in place.

10. Privacy Rights and Choices

Depending on where you live and subject to legal exceptions, you may have rights to request access, correction, deletion, or a copy of personal information; to restrict or object to certain processing; or to appeal our response. We do not discriminate against anyone for exercising a privacy right.

To submit a request concerning account, website, sales, or support information, contact us using Section 15. We may verify identity and authority before acting. An authorized agent may submit a request where permitted by law. If the request concerns Customer Content, contact the customer organization that collected or submitted the information. We will assist that customer as required by law or a Direct Agreement.

Users may manage account settings through the Service and may opt out of non-transactional marketing email using the unsubscribe link. Service, security, billing, and legal notices are not marketing communications. Browser settings can control cookies, but disabling essential cookies may prevent the Service from functioning.

11. Children

The Service is intended for authorized professionals and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13 for their own use of the Service. Customer Content may concern minors when lawfully submitted by an authorized customer for a professional purpose. In that situation, the customer is responsible for legal authority, notices, consents, and appropriate safeguards.

12. United States Processing

Polygraph Reports is based in the United States, and the Service is operated using United States infrastructure. Information may be processed in the United States, where privacy laws may differ from those in another jurisdiction. Customers must not use the Service where prohibited by applicable law and are responsible for any required cross-border transfer mechanism.

13. De-Identified Information

We may use and disclose information that has been aggregated or de-identified so that it cannot reasonably identify a customer or individual, including for security, analytics, capacity planning, and Service improvement. We will not attempt to re-identify de-identified information except to test whether de-identification controls are effective or as permitted by law.

14. Changes to This Policy

We may update this Policy to reflect changes in the Service, law, or our practices. We will post the revised Policy and effective date and provide reasonable notice of material changes through the Service, by email, or by another appropriate method. A Direct Agreement may require a different notice or approval process.

15. Contact Us

For privacy questions or requests, email support@polygraphreports.com or contact:

Polygraph Reports, Inc
Attn: Privacy
4409 Samantha Drive
Raleigh, NC 27613
United States
Back to Login / Dashboard