Your audio. Your call. Browser capture.
OffBook is operated by OB Labs LLC, a Delaware limited liability company, doing business as OffBook.
How OffBook captures audio
OffBook uses browser APIs (`getDisplayMedia` and `getUserMedia`) to capture user-authorized audio and stream it over encrypted channels for processing. Capture is initiated by the user in the browser and does not rely on a meeting bot participant by default.
What we store
- - Transcripts: stored, encrypted; delete individual calls from the dashboard or delete your entire account from Settings.
- - Audio recordings: not retained as persistent recordings by default.
- - Coaching cues and debriefs: stored for product functionality; removed when you delete your account.
- - Personal Playbook: stored per user and not shared across accounts.
Model and training boundaries
- - OffBook does not train models on your customer audio or transcripts by default.
- - Anthropic API usage is for inference only; per Anthropic API policy, customer content is not used to train Anthropic models by default.
- - In-call prompts are shown to the user only and are not sent to the other call participant.
- - Model context updates are limited to your own workspace context and generalized call-outcome signals.
Compliance
SOC 2 Type II is in progress. OffBook is built with GDPR-aligned data handling practices and requires explicit consent confirmation before each call session starts.
Subprocessors
We maintain this list as our current subprocessors used to deliver OffBook. For legal terms and operational details, refer to each vendor's published privacy and security documentation.
| Vendor | Purpose | Data processed | Region / retention (brief) |
|---|---|---|---|
| Anthropic | Model inference for analysis and debrief generation | Transcript/audio-derived prompt context, generated outputs | US processing; API data not used for model training by default |
| Deepgram | Speech-to-text processing | Live audio stream and transcription text | US processing; retention controlled by provider account settings |
| Vercel | Hosting and edge delivery | Application traffic, logs, deployment artifacts | Global edge network; retention per Vercel account configuration |
| Neon | Managed Postgres database | User account records, transcripts, debrief and profile data | Region set by database project; retained until deleted by customer or policy |
| Firebase | Authentication and identity | Email, auth identifiers, session metadata | Google Cloud regions; retention per authentication and project settings |
| Stripe | Billing and subscription management | Billing profile, subscription status, payment metadata | Global processing; financial records retained per legal and tax obligations |
| PostHog | Product analytics and event instrumentation | Feature usage events, page activity, coarse technical metadata | US/EU hosting options; event retention configured by OffBook workspace settings |
Report a vulnerability
Email [email protected]. We target an initial response within 72 hours.
Your responsibilities
You are responsible for complying with recording, wiretapping, and consent laws in every jurisdiction where you use OffBook, including all-party consent jurisdictions.