Effective Date: July 20, 2026
Polygraph Reports, Inc ("Polygraph Reports," "we," "our," or "us") provides AI-assisted report creation and related services through our websites, applications, and software, including polygraphreports.com and reportwiz.ai (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information.
Our customers often use the Service to process highly sensitive interview and investigation materials. We designed our practices to minimize retention, preserve customer control, and protect confidentiality. Please read this Policy together with our Terms of Use.
This Policy applies to personal information we process through the Service, our websites, account administration, sales, support, and business operations. It does not apply to third-party products or websites that operate under their own privacy policies.
For account, billing, website, sales, and support information, Polygraph Reports generally determines why and how the information is processed. For files, recordings, transcripts, report content, and other information a customer submits to the Service ("Customer Content"), the customer determines the purpose of processing and Polygraph Reports processes the information on the customer's behalf and instructions. Individuals whose information appears in Customer Content should direct privacy requests to the customer that submitted it.
If we have a signed order form, data processing addendum, business associate agreement, government contract, or other written agreement with a customer (a "Direct Agreement"), that agreement controls over this Policy to the extent of any conflict. This is particularly important for government and regulated customers whose legal requirements may differ from this generally published Policy.
We receive information directly from users and customers; automatically from browsers, devices, and use of the Service; from a customer's administrators and authorized users; from service providers that support our operations; and from business partners or public sources when someone requests information about the Service.
We process information to:
We do not use Customer Content to train our own or third-party AI models. We do not sell personal information or Customer Content. We do not share personal information for cross-context behavioral advertising or targeted advertising.
The Service currently uses OpenAI's API to process Customer Content for transcription and report generation. We have been approved for OpenAI's Zero Data Retention program and use approved Zero Data Retention eligible endpoints and features for Customer Content submitted to OpenAI.
For those requests:
Zero Data Retention at OpenAI is separate from the retention setting selected for the Polygraph Reports Service. If a future feature or provider cannot support the handling described above, we will not represent that feature as Zero Data Retention and will disclose materially different handling before applying it to Customer Content. More information about OpenAI API data controls is available in OpenAI's data controls documentation.
We disclose information only as needed for the following purposes:
Customers control how long report content remains available, subject to their selected retention option, administrator actions, legal requirements, and any Direct Agreement.
Report content remains in the Service until an authorized customer administrator deletes it, the customer requests deletion, the account is terminated and deletion occurs under our offboarding process, or a Direct Agreement sets another period. Deleting a report removes its uploaded source files, generated transcripts, and report body from active systems. File data becomes unavailable from active storage promptly after deletion. Deleted database content may remain in encrypted disaster-recovery backups for up to 30 days, after which it is no longer recoverable through our ordinary processes.
After a report is created, the Service automatically deletes uploaded source files and transcripts generated from those files. The completed report remains available to the customer until an authorized administrator deletes it or another applicable retention event occurs.
This includes Document Zero Data Retention. In addition, after the first successful download of a completed report, the Service automatically deletes the report content. The customer must securely preserve the downloaded copy if needed because Polygraph Reports cannot recover or recreate the deleted content.
We retain limited metadata needed for audit, security, account administration, and billing, such as report name, report template name, creation date, deletion date, and creator. This metadata does not include the report body, transcripts, or uploaded source files. Account, billing, security, and audit records may be retained for legitimate business and legal purposes even after content deletion.
Deletion may be delayed or limited when preservation is required by law, legal hold, a binding government request, security investigation, or Direct Agreement. We will isolate retained information from ordinary use and delete it when the obligation ends. Customers can contact their account manager to enable a Zero Data Retention option.
We maintain administrative, technical, and physical safeguards designed to protect information. Our production servers operate in AWS GovCloud (US), and uploaded files are stored in private Amazon S3 buckets with encryption in transit and at rest. Controls include least-privilege access, role-based access, pre-signed URLs, multi-factor authentication for privileged credentials, logging, monitoring, and restricted personnel access based on business need.
Polygraph Reports has completed a SOC 2 Type II examination, which independently assesses the design and operating effectiveness of in-scope controls over a defined review period. AWS GovCloud is designed to support sensitive and regulated workloads, but use of AWS GovCloud or our SOC 2 report does not by itself make every customer workload compliant with a particular legal or regulatory framework. Any specific compliance commitment must appear in a Direct Agreement.
No transmission or storage system can be guaranteed completely secure. Customers are responsible for managing their Users, permissions, endpoints, exported files, and credentials. If we discover a security incident affecting personal information, we will investigate and provide notice as required by applicable law and any Direct Agreement.
Customers determine what Customer Content to submit and are responsible for providing legally required notices, obtaining consents, establishing a lawful basis, configuring retention, responding to individuals, and complying with recordkeeping and disclosure requirements. Customers should not submit protected health information, criminal justice information, controlled unclassified information, or other regulated data unless their use is lawful and any required Direct Agreement or compliance configuration is in place.
Depending on where you live and subject to legal exceptions, you may have rights to request access, correction, deletion, or a copy of personal information; to restrict or object to certain processing; or to appeal our response. We do not discriminate against anyone for exercising a privacy right.
To submit a request concerning account, website, sales, or support information, contact us using Section 15. We may verify identity and authority before acting. An authorized agent may submit a request where permitted by law. If the request concerns Customer Content, contact the customer organization that collected or submitted the information. We will assist that customer as required by law or a Direct Agreement.
Users may manage account settings through the Service and may opt out of non-transactional marketing email using the unsubscribe link. Service, security, billing, and legal notices are not marketing communications. Browser settings can control cookies, but disabling essential cookies may prevent the Service from functioning.
The Service is intended for authorized professionals and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13 for their own use of the Service. Customer Content may concern minors when lawfully submitted by an authorized customer for a professional purpose. In that situation, the customer is responsible for legal authority, notices, consents, and appropriate safeguards.
Polygraph Reports is based in the United States, and the Service is operated using United States infrastructure. Information may be processed in the United States, where privacy laws may differ from those in another jurisdiction. Customers must not use the Service where prohibited by applicable law and are responsible for any required cross-border transfer mechanism.
We may use and disclose information that has been aggregated or de-identified so that it cannot reasonably identify a customer or individual, including for security, analytics, capacity planning, and Service improvement. We will not attempt to re-identify de-identified information except to test whether de-identification controls are effective or as permitted by law.
We may update this Policy to reflect changes in the Service, law, or our practices. We will post the revised Policy and effective date and provide reasonable notice of material changes through the Service, by email, or by another appropriate method. A Direct Agreement may require a different notice or approval process.
For privacy questions or requests, email support@polygraphreports.com or contact: