Last updated September 7, 2026
Terms of Service
1. Agreement and authority
These terms are between Custavox (“Custavox,” “we,” “us”) and the institution using the service (“you”). By creating an account or using Custavox, you agree to them on behalf of your institution and confirm you have the authority to do that. If you don’t have that authority, don’t create the account. If we have signed a separate agreement with you, that agreement controls where it conflicts with these terms.
2. Who may use the service
Accounts are for your institution’s staff and anyone you invite. Everyone who uses Custavox has their own login, and every login belongs to exactly one institution. There is no shared, anonymous or link-only access to anything that shows your data.
Your administrators choose each person’s role, which decides what they can see and do. You are responsible for everyone you give access to, for the roles you assign them, and for removing access when someone leaves — which you can do yourself, either by deactivating them or by deleting their login.
Your employees answer a questionnaire describing their own role. Anything they submit belongs to your institution and is visible to you.
3. What the service is
Custavox analyzes customer feedback you provide and produces scores, attributions, opportunity cards and recognition drafts. It is a decision-support tool.
It does not make decisions for you, and it is not legal, compliance, regulatory, financial, personnel or investment advice. The judgment about what to act on stays yours.
4. AI-generated output
Parts of the product are written by an AI model, Anthropic’s Claude, working from the feedback you upload. Details of exactly what is sent and what is never sent are in our Privacy Policy.
The model is constrained rather than trusted. It fills a fixed schema and cannot take actions, call tools, browse or send anything to anyone. It never writes a number: every count and dollar figure you see is produced by our code from your data. It may only name a branch, person, system or product that its own evidence points to, and a write-up that breaks either rule is withheld rather than shown to you. Nothing it drafts reaches a person until someone at your institution reviews it and sends it.
Even so, AI output is an inference, not a finding of fact. Attributions can be wrong, patterns can be coincidental, and dollar figures are estimates built on assumptions you can see and change. Review it before you rely on it, and don’t use it as the sole basis for a decision that materially affects a person.
5. Decisions about your employees
Custavox attributes customer feedback to named employees and shows patterns in it. That is a record of what customers said, not a performance evaluation, and it is not designed or validated as one.
You are solely responsible for any employment decision — coaching, discipline, compensation, promotion or termination — and for complying with employment law, your own policies, and any applicable collective agreements. You are responsible for telling your employees that you use Custavox to the extent the law requires it.
6. Your data and your responsibilities
Your data stays yours. You grant us only the permission we need to host and process it in order to provide the service to you, and to keep backups. We don’t sell it, we don’t use it to train AI models, and we don’t use one institution’s data to serve another.
You confirm that you have the right to give us everything you upload, including feedback written by your customers, and that you have given whatever notices and obtained whatever consents the law requires. Those people have no relationship with us; we handle their information on your instructions.
You agree not to upload account numbers, balances, transaction records, Social Security numbers, card or routing numbers, dates of birth, or credentials. The service does not need them, and it is built to keep them out rather than to rely on you: our importer refuses columns whose headers indicate any of that material, and free text is scrubbed of identifier-shaped strings both in your browser and again on our server.
Nonpublic personal information. We understand that you are a financial institution and that we are your service provider. Custavox is designed so that nonpublic personal information does not enter it: there is no connection to your core systems and no place in our database for account numbers, balances or Social Security numbers. To the extent we handle any such information on your behalf, we will use it only to provide the service to you, protect it with the measures described in Section 8, and require the same of the providers listed in Section 10.
7. Acceptable use
- Don’t use Custavox to break the law or infringe anyone’s rights.
- Don’t attempt to access another institution’s data.
- Don’t probe, scrape, overload, or reverse-engineer the service, or use automated means to extract data from it.
- Don’t share credentials or let people outside your institution use your account.
- Don’t upload malware or attempt to interfere with security or availability.
- Don’t resell the service or use it to build a competing product.
We may suspend access immediately if we believe this section has been violated.
8. Accounts and security
You’re responsible for activity under your account and for keeping credentials secure. Tell us promptly if you believe an account has been compromised.
On our side, and in place today: every sign-in requires a password of at least twelve characters that is screened against known breaches, followed by a six-digit code emailed to the account address. Passwords are stored only as salted hashes by our authentication provider and are never visible to us. Every action is authorized against the user’s role on our server rather than merely hidden in the interface, and refused attempts are recorded. Each institution’s data is separated by several independent controls. Everything travels over HTTPS, and our connection to the database is encrypted with the database’s certificate verified on each connection. Sensitive actions are written to a security log your administrators can read in the product.
We have not yet commissioned an independent penetration test, and Custavox does not hold its own SOC 2 report; we say so rather than implying otherwise. Our fuller security document is available on request.
If we become aware of a breach affecting your data, we will notify you without undue delay and within 72 hours of confirming it, with what we know and what we are doing.
9. Confidentiality
Each of us may learn confidential information about the other. We will each protect it with at least reasonable care, use it only to perform under these terms, and not disclose it except to people who need it and are bound to keep it confidential, or where the law requires disclosure. Your data is your confidential information.
10. Service providers
We use a small number of providers to run the service. They process your data only to provide their service to us, are bound by contract, and may not use it for their own purposes. We remain responsible for their performance.
- Vercel — application hosting, in the United States.
- Supabase — database and authentication, running on Amazon Web Services in Oregon (us-west-2), United States.
- Resend — email delivery, in the United States.
- Anthropic — the AI described in Section 4, in the United States.
- Have I Been Pwned — breached-password screening, which receives five characters of a hash and no account or personal data.
Call us if you want notice when this list changes, or a copy of our security document for your vendor review. If your review requires a data-processing agreement, tell us and we will work through it with you.
11. Fees
Paid plans are billed as described in the order or quote you agree to. Free or trial access, where offered, may be changed or discontinued. We’ll give you notice before a price change affects a term you’ve already paid for.
12. Availability and changes
We work to keep Custavox available and improve it continuously, which means features change. We’ll give reasonable notice before removing something you depend on. We don’t promise uninterrupted service unless we’ve agreed to a specific service level with you in writing.
13. Termination and getting your data back
You can stop using Custavox at any time. An administrator can export your entire institution as a single file, and delete the institution outright, from Settings — you don’t need us for either, and you can do both before you leave. We may suspend or terminate access if these terms are breached, or if required by law.
For 30 days after termination you can also ask us for an export. After that we delete your data as described in the Privacy Policy, which also explains the two things that deliberately survive a deletion: individual logins, because they belong to people, and the security log, because a log that the subject can erase is not a log.
14. Intellectual property
The service — its software, design, and the methods behind the analysis — belongs to us, and nothing here transfers ownership of it to you. Your data, and the output generated from your data, belong to you.
If you send us ideas or suggestions about the product, we may use them without obligation to you. We may also use aggregated, de-identified statistics that cannot identify you, your employees or your customers to operate and improve the service — for example, how often a feature is used, or how long a scan takes. For the avoidance of doubt, this does not permit us to train AI models on your data, which Section 6 prohibits outright.
15. Publicity
We won’t use your name or logo publicly as a customer without your written permission.
16. Disclaimers
Custavox analyzes text and surfaces patterns. Its output is an estimate, not a certainty. Except as expressly stated in these terms, the service is provided “as is” and “as available,” and to the maximum extent permitted by law we disclaim all warranties, express or implied, including merchantability, fitness for a particular purpose, accuracy and non-infringement.
17. Limitation of liability
To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue, data or goodwill. Our total liability for all claims is limited to the amounts you paid us in the twelve months before the event giving rise to the claim.
These limits do not apply to your obligations under Section 18, or to either party’s breach of Section 9.
18. Indemnification
You agree to defend and indemnify us against third-party claims arising from your use of the service, the data you upload, your violation of these terms, or your violation of law or a third party’s rights — including claims by your employees or your customers relating to data you provided to us.
19. Dispute resolution
Please read this carefully; it affects your legal rights. Except for small-claims matters and claims for injunctive relief to protect intellectual property or confidential information, you and Custavox agree to resolve disputes through binding individual arbitration rather than in court, and to bring claims only on an individual basis and not as part of a class or representative proceeding.
20. Governing law
These terms are governed by the laws of the State of Iowa, United States, without regard to conflict-of-law rules. Where arbitration does not apply, the state and federal courts located in Iowa have exclusive jurisdiction.
21. General
Neither party is liable for delays caused by events outside its reasonable control. You may not assign these terms without our consent; we may assign them to a successor in a merger or sale of assets. If a provision is unenforceable, the rest stays in force. These terms, together with any agreement we’ve signed with you, are the entire agreement between us. Sections that by their nature should survive termination — including 6, 9, 14, 16, 17, 18, 19 and 20 — do.
22. Changes to these terms
If we update these terms we’ll change the date at the top of this page and tell you directly if the change is significant. Continuing to use Custavox after that means you accept the update.
23. Contact
Questions about these terms, a copy of our security document, or notice when our provider list changes: call us at (515) 460-4911.