Last updated September 7, 2026

Privacy Policy

The short version

  • We never connect to your core banking system.
  • We only receive the feedback data you choose to give us, and our importer refuses the columns a bank shouldn’t be sending us in the first place.
  • We don’t sell data, and we never use one institution’s data to serve another.
  • Feedback text goes to an AI provider to write up opportunities and draft recognition emails. It is not used to train anyone’s models.
  • You can export everything yourself, and delete your institution yourself.

Who this policy covers

Custavox is sold to institutions, not to individuals, so there are three different groups of people involved and they aren’t treated the same way.

  • The institution and its administrators. The bank or credit union that subscribes, and the people there who run it.
  • The institution’s employees. People who are named in customer feedback, and people who answer a questionnaire describing their own role. They each have their own login.
  • The institution’s customers. The people whose reviews, survey responses, complaints and exit interviews are uploaded. They have no relationship with Custavox at all.

For the second and third groups we act as a service provider processing data on the institution’s behalf and under its instructions. If you are an employee or a customer of an institution that uses Custavox, that institution controls the data and your request should go to them first — though you can always call us and we will help route it.

What we collect

Account information. Everyone who uses Custavox has a login: a work email address and a password. The password is stored by our authentication provider as a salted bcrypt hash and is never visible to Custavox. Signing in also requires a six-digit code we email you; we store only a hash of that code, and those rows are deleted after a day. If you contact us or book a demo, we collect what you send us — typically a name, work email, phone number and institution.

Employee questionnaire answers. Employees of a customer institution describe their own role: their title, which locations and teams they belong to, who they report to, the systems and products they work with, when they started, and the handoffs they are part of. It is visible to their employer, because their employer is the one asking.

The feedback you upload. Reviews, survey responses, complaints, exit-interview notes and similar records. These frequently contain personal information about third parties — a reviewer’s display name, the words they wrote, and often the name of an employee they dealt with. You control what is in those files, and our importer refuses a great deal of it outright (see below).

Your org structure. The branches, departments, people, systems, products and touchpoints you set up, so findings can be attributed to the right part of your institution.

A security log. For each sensitive action — a role change, an invitation, a deletion, an import, an export, a refused attempt to do something a role isn’t allowed to do — we record who did it, their role at the time, what they did it to, the IP address, the browser user-agent and the time. Your administrators can read this in the product under Settings, and so can we.

Usage and technical data. Standard logs — pages loaded, requests made, browser and device information — used to operate, secure and troubleshoot the service. We also record every AI request (what triggered it, whether it succeeded, how long it took) and every notification decision (what was emailed to whom, or deliberately not, and why).

Support and in-product feedback. If you use the feedback button inside the product, we receive your message along with your name, email, the page you were on and your browser details, so we can reproduce what you saw.

What our importer refuses

Custavox is built for feedback, not for account data, and it enforces that rather than just asking. When you upload a file we read its column headers and refusethe ones that indicate Social Security or tax identifiers, account, member, loan, card or policy numbers, routing or IBAN numbers, card detail, balances and transaction detail, dates of birth, phone numbers, email addresses, home addresses, credentials, or record identifiers. Those columns are never mapped, never offered to you in a picker, and never reach our servers.

Free text is scrubbed as well — in your browser before upload, and again on our server, because we don’t trust the browser to have done it. Anything shaped like a Social Security number, a card number, a long run of digits or a phone number becomes [removed], and the sentence around it survives so the finding does. The same scrubbing applies to free text employees type into the questionnaire.

Please still keep that material out of the files you send us. If something slips through, call us and we will delete it.

What we never collect

We do not integrate with, read from, or write to your core banking system, and we have no access to account balances, transactions or customer financial records. Nothing about Custavox requires that access. All data reaches us because someone at your institution uploaded it or typed it in.

We use no analytics, advertising or tracking scripts of any kind. Your browser is told, by our own Content-Security-Policy, to refuse connections to anywhere except Custavox and its database service.

Nonpublic personal information and GLBA

Our customers are financial institutions, so we know the question behind the question. Custavox is designed so that nonpublic personal information never enters it: there is no connection to your core, no column in our database for an account number, a balance, a Social Security number or a date of birth, and the importer refuses those fields by name. What we hold is what a customer chose to say in public or in a survey, plus your own org structure.

Where we do handle information on your behalf, we act as your service provider, use it only to provide the service, and protect it with the measures described below. If your vendor-management review needs this in a specific contractual form, call us and we will work through it with you.

How we use it

  • To analyze the feedback you upload and produce the scores, attributions, opportunity cards and recognition drafts that are the product.
  • To create and maintain your account and let your colleagues collaborate in it.
  • To respond to you, provide support, and run a demo if you ask for one.
  • To keep the service secure, reliable and working, and to investigate misuse.
  • To meet our legal obligations.

We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not use one institution’s data to serve another, and we do not use your data to train AI models.

How AI is used

Custavox uses Anthropic’s Claude for two jobs: naming and writing up the opportunities on your board, and drafting the recognition emails you send your staff. Everything that decides whether an opportunity exists at all — the grouping, the thresholds, the routing, the deduplication and every dollar figure — runs in our own code, not in the model.

What is sent: the feedback text itself, after the scrubbing described above, so the model only ever reads what we already store; the themes, ratings and dates on those records; the branch, team, system, product or touchpoint each one was attributed to; the names and job titles of your staff, so it can pick a plausible owner from a shortlist we compute; descriptions of your products, systems and touchpoints from our catalogs; and counts we calculated.

What is never sent: reviewer names; anything the importer refused; login credentials, email addresses or session data; and data from any other institution — every request is about one bank.

The model fills a fixed schema. It cannot take actions, call tools, browse the web, or send anything to anyone. It never writes a number: every count and dollar figure you see is rendered from your data by our code, and a write-up containing a digit is held back rather than shown. Nothing it drafts is sent to a person until someone at your institution reads it and presses send. What the model originally proposed is frozen and kept alongside every human edit, so you can always see the difference.

Under our agreement with Anthropic, what we send is not used to train their models. Anthropic retains API inputs and outputs for a limited period for abuse monitoring, thirty days by default; zero-retention handling can be arranged for an institution that requires it. The AI produces analysis and suggestions; it does not make decisions, and everything it produces is visible to you in the product.

Emails we send, and what is in them

All email a bank sees comes from Custavox, at no-reply@mail.custavox.com, never from a third party’s domain. There are five kinds:

  • Invitations — the bank’s name, who invited you, and a single-use link.
  • Sign-in codes — a six-digit code and nothing else. No link, and never your password.
  • Password resets — a single-use link.
  • Notifications — a card was assigned to you, feedback was imported, a scan finished. A title, a count and a link back into the app. Never customer comment text.
  • Recognition emails, or shoutouts — these do contain verbatim customer quotes praising the recipient, with the source, branch and month of each, sent to the employee being praised with their manager copied. They never contain reviewer names, ratings or account data, and one is only ever sent after a person at your institution reviews it and presses send. Nothing sends itself.

Which notifications reach whom is set by the institution, per role and per kind, and an administrator can override it per person. Every decision to send or to skip is recorded so a bank can see exactly what went out.

Who can see your data

Your own team. People at your institution who have been given access, and only as much as their role allows: an administrator sees the institution, a manager sees the part of it they manage, and an employee sees only their own profile. You control who those people are and what role each one has.

A small number of Custavox staff. Some of our people can access customer accounts to provide support, investigate problems, and tune the analysis. Access is a named list, every grant and removal is logged, and anything our staff do to your data is recorded in the same security log your administrators read.

Our service providers. These process data solely to provide their service to us, are bound by contract, and may not use it for their own purposes:

  • Vercel — application hosting, TLS and the request logs that come with it. United States.
  • Supabase — the PostgreSQL database and the authentication service that holds login emails and password hashes. Runs on Amazon Web Services in Oregon (us-west-2), United States.
  • Resend — delivery of the emails described above, on Amazon SES. United States.
  • Anthropic — the AI described above. United States.
  • Have I Been Pwned — checks a new password against known breaches. It receives the first five characters of a hash of the password and nothing else; the password itself never leaves our server, and the service cannot tell which password was asked about.

Vercel, Supabase, Resend and Anthropic each hold a SOC 2 Type II attestation. Custavox does not hold one of its own today, and we don’t claim theirs as ours. If your vendor review wants our full security document, or notice when this list changes, call us at (515) 460-4911.

Nobody else. We do not share your data with other institutions, advertisers, or data brokers. We may disclose information if we are legally required to, or to protect rights and safety, and we will tell you unless we are prohibited from doing so.

Where your data is stored

Your data is stored in the United States, in Amazon Web Services’ Oregon region. It is encrypted in transit and at rest, and every record is scoped to your institution.

Security

The measures below are in place today, not planned:

  • Every user signs in with a password of at least twelve characters that is checked against known breaches, then enters a six-digit code we email them.
  • Accounts are invite-only, bound to a specific email address, and one login belongs to exactly one institution.
  • Every action is checked against the user’s role on the server, not just hidden in the interface, and refused attempts are logged.
  • Each institution’s data is separated by several independent controls, and an automated check fails our build if any new code is added without the guard that enforces it.
  • Everything travels over HTTPS, and our own connection to the database is encrypted with the database’s certificate verified on every connection.
  • Uploaded files are parsed in your browser and never written to disk on our servers.

No system is perfectly secure, and we have not yet commissioned an independent penetration test — we say so plainly rather than implying otherwise. But we treat this data as what it is: your customers’ words about your institution.

If personal information is compromised, we will notify affected institutions without undue delay and within 72 hours of confirming it, and give you what you need for your own regulatory obligations.

Retention and deletion

We keep your data for as long as your account is active. You can delete individual records in the product at any time, and an administrator can export the entire institution as a single file or delete the institution outright, both from Settings, without asking us. Deleting it removes every row your institution owns in one cascading delete.

Two things deliberately survive that delete. Logins survive, because they belong to people rather than to the institution, and can be deleted separately. The security log survives, detached from the deleted institution but still recording who did what — a log that can be erased by the person it incriminates is not a log. We also keep anything we are required to keep for legal, accounting or fraud-prevention reasons.

Sign-in codes are deleted after a day. Rate-limiting counters are deleted after a day. Deleted data is gone from the live database immediately and ages out of encrypted backups on our provider’s backup schedule.

Employees named in feedback

Customer feedback often names the employee who served them, and Custavox attributes that feedback to the person. This is an accurate reflection of what customers said, not a performance rating, and the analysis can be wrong — a name can be misheard, a complaint can be about a policy rather than the person who explained it.

Decisions about employees belong to the employer. If you are an employee at an institution that uses Custavox and you want to know what has been attributed to you, or you think something is wrong, ask your employer — they can see it, correct it, and are responsible for how it is used.

Your rights and choices

You can access, correct, export or delete data in the product, and you can call us for help with any of it. Depending on where you live you may have additional rights under state or other privacy laws — including the right to know what personal information is collected and why, to request correction or deletion, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are used in the California Consumer Privacy Act.

If you are a customer or employee of an institution that uses Custavox, send your request to that institution. They control the data; we will assist them in responding.

Cookies and similar technologies

We use cookies that are necessary for the product to work: one that keeps you signed in, and one that records that you passed the six-digit code check, which is tied to that single session and unreadable by page scripts. We store a few interface preferences in your browser, like which columns you chose and which items you flagged. Your light or dark mode preference is saved to your login rather than your browser, so it follows you and doesn’t leak between people sharing a computer.

We do not use advertising cookies or third-party tracking pixels. Blocking essential cookies will prevent sign-in from working.

Business transfers

If Custavox is involved in a merger, acquisition, financing or sale of assets, data may be part of that transaction. We will tell you before your data becomes subject to a different privacy policy.

Children

Custavox is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 13.

Changes

If we change this policy we’ll update the date at the top of this page, and we’ll tell you directly if the change is significant.

Contact

Questions, requests, or concerns — including access, correction and deletion requests, our full security document, or notice when our provider list changes — call us at (515) 460-4911.