Legal
Privacy Policy
Last updated: 26 September 2026
This policy explains how Sentriment (“we”, “us”) collects, uses and protects personal data when you visit sentriment.com, create an account, or use the Sentriment service. We wrote it to be read, not skimmed past — it is short because our data practices are simple.
1. Who is responsible (the controller)
Sentriment
Viale Cirene 4, Milan, Italy
Email: hello@sentriment.com
Sentriment acts in two distinct roles, and this policy covers both:
- As a controller for the data of our own users and site visitors — your account, your settings, and how you found us.
- As a processor for the feedback data our customers send into their workspaces. For that data, the customer is the controller and we process it only on their instructions to provide the service.
2. What we collect, and why
Data we control
| Data | Purpose | Legal basis |
|---|---|---|
| Account data — name, email address, password (stored only as a salted hash) | Creating and securing your account; transactional email (verification, password reset) | Contract performance (Art. 6(1)(b)) |
| Onboarding answers — role, company size, goal, referral source (all optional) | Understanding who uses Sentriment and improving the product | Legitimate interest (Art. 6(1)(f)) |
| First-touch attribution — UTM parameters and referrer, stored in a first-party cookie | Knowing which channel brought you here | Legitimate interest (Art. 6(1)(f)) |
| Audit and security logs — actions in your workspace, IP address | Security, abuse prevention, an audit trail for your own workspace | Legitimate interest (Art. 6(1)(f)) |
| Aggregate traffic counts on our public website — page address, referring site, approximate country, browser and device type. No cookie, no persistent identifier. | Knowing how many people reach our site and which pages they read | Legitimate interest (Art. 6(1)(f)) |
Data we process on behalf of customers
Feedback text and optional end-user identifiers that customers send to their workspace via the widget, REST API, connectors or CSV import, and, if a customer connects a meeting notetaker or uploads transcripts, the transcripts of their own calls. Personally identifiable information inside feedback text — emails, names, phone and card numbers — is automatically redacted before storage and replaced with typed placeholders, in two steps: deterministic pattern matching, followed by an AI redaction pass (Anthropic) that removes personal data the patterns miss, such as names or obfuscated emails. Values caught by the pattern pass are never written to our database, and the AI pass runs before the text is analysed, shown in the dashboard or sent to any other provider. Redaction is automated and layered by design; like any automated process it can miss an unusual identifier, so a later analysis step flags anything that slipped through, and if the AI pass is briefly unavailable the pattern-redacted text is kept and that check still applies. Redaction complements, rather than replaces, the customer's own responsibility for the data they collect and choose to send.
Customers are responsible for having a lawful basis to collect this data from their own users, for telling them, in their own privacy notice, that feedback is analysed with the help of service providers such as us, and for what they send. The data processing terms in section 14 of our Terms of Service apply to all of it.
Call transcripts (optional). If a customer connects a meeting notetaker or uploads a transcript, we store the transcript in the customer's workspace and analyse it for what the customer's own customer or prospect said. By default, attendee names are replaced with placeholders and the pattern pass runs before the transcript is stored or sent to Anthropic, and attendees are kept by email address only. A customer may turn this redaction off for a notetaker connection, in which case the transcript, the attendees' names and the signals drawn from the call are stored and analysed as said; transcripts sent through the API or uploaded are always redacted. Anthropic reads each call twice: once to judge whether it is a sales or customer conversation, and once to extract the signals. The customer, as the party who recorded the call, is responsible for any notice or consent the participants are owed.
If a customer connects an analytics destination (such as Mixpanel or Amplitude), Sentriment sends that customer's own user identifiers together with sentiment-derived health properties to that destination — on the customer's instruction and under the customer's configuration. We never send feedback text through this channel, and disconnecting stops the flow immediately. The same holds for any other service a customer connects: we exchange data with it only on the customer's instruction, and that provider's own terms govern what happens to the data once it is there.
The Analyst: questions, chats and reports
Members of a workspace can ask questions about its feedback in the Analyst. What a member types, the chat that follows and any report built from it are stored in the EU with the workspace, and count as that member's personal data. To answer, we send the question, aggregate figures computed by us, excerpts of feedback that were already redacted (see above), and, when a question asks about a segment of users, the label of that segment only where at least five people share it (a plan name, a region; never a value that could identify one person), to Anthropic in the United States; account data — names and email addresses — is not sent. A chat never stores a customer's words: quotations are read live from the feedback record and disappear with it. Chats are private to the member who started them unless that member shares them with the workspace.
3. What we don't do
- We do not sell personal data. To anyone.
- We do not use your data — or your users' feedback — to train shared AI models.
- We do not run third-party advertising or cross-site tracking cookies.
4. Where data lives, and who touches it
Sentriment is hosted in the European Union: our database runs in Frankfurt, Germany, and our application compute — both the dashboard and this website — runs in Frankfurt too. Two exceptions are noted in the table below: anonymous website traffic counts are processed by Vercel in the United States, and — only if you choose to sign in with Google — your name and email address are exchanged with Google in the United States. Your workspace data (your users' feedback) always stays in the EU. We use a small number of subprocessors:
| Subprocessor | Purpose | Region |
|---|---|---|
| Neon (Postgres) | Primary database | Frankfurt, Germany 🇪🇺 |
| Vercel | Web hosting, application serving, and cookieless website traffic measurement | Hosting and application compute: EU (Frankfurt). Website traffic measurement: United States, under Vercel's data processing agreement. |
| Fly.io | Background processing | Frankfurt, Germany 🇪🇺 |
| Resend | Transactional email | EU region |
| Optional “Continue with Google” sign-in. Used only if you choose it: Google confirms your email address and name to us. Your users' feedback is never involved, and signing in with a password avoids Google entirely. | United States † | |
| Mixpanel | Product analytics about how Sentriment's own users use the product (account identifiers and usage events — never your users' feedback content), and, only with your consent, masked session replays | EU data residency 🇪🇺 |
| Anthropic | AI analysis of feedback (themes, sentiment, summaries), a relevance check and one extraction pass per call transcript, and the Analyst (answers and reports to members' questions) | United States * |
| Voyage AI | Text embeddings for clustering and search | United States * |
| Sentry | Error monitoring for the dashboard and our processing service — technical error reports with feedback text, identifiers, addresses and secrets removed before they leave | Frankfurt, Germany 🇪🇺 |
* AI providers receive only feedback text that has already been PII-redacted (see section 2; the one exception is the calls of a notetaker connection on which the customer turned redaction off, which they receive as said) — the AI redaction step itself operates on text already stripped by pattern matching, in order to remove any remainder — under data-processing agreements incorporating Standard Contractual Clauses, and with no retention for model training. Account data — your name and email — never reaches them. Anthropic keeps API inputs and outputs for a limited period under its standard API terms (currently up to 30 days, for abuse monitoring). We intend to ask Anthropic for zero data retention on our account and will update this page when it is in place.
† Google is involved only if you choose “Continue with Google” to sign in. In that case Google confirms your email address and name to us, in the United States, under Standard Contractual Clauses — this is the account you already hold with Google, and it is the only account data that leaves the EU. Signing in with an email address and password avoids Google entirely, and you can add a password to a Google-created account at any time from Account settings.
5. How long we keep data
- Account data — until you delete your account (self-serve, in Account settings).
- Feedback data — for the retention period configured for the workspace (24 months by default), or until the customer deletes it.
- Call transcripts — for the retention period configured for the workspace, like feedback, or until the customer deletes them; an erasure request for a person removes the transcripts of the calls they attended.
- Analyst chats — for 12 months after their last activity, or for the workspace's feedback retention period if that is shorter; a chat's working results for 30 days; saved reports until the customer deletes them.
- Audit logs — for the life of the workspace, as a security record.
6. Your rights
Under the GDPR you can access, rectify, export, delete and restrict the processing of your personal data, and object to processing based on legitimate interest. Most of this is self-serve:
- Rectify / update — change your name, email and password in Account settings.
- Export — download your account data from Account settings; workspace feedback exports as JSON from each project.
- Delete — delete your account (and workspaces where you are the only member) from Account settings, with email confirmation. Customers can erase an individual end-user's data via the deletion API.
For anything else, email hello@sentriment.com — we respond within 30 days. You also have the right to lodge a complaint with a supervisory authority; ours is the Italian Garante per la Protezione dei Dati Personali (gpdp.it), and you may also contact the authority of your own country.
7. Cookies, analytics and session replays
Strictly necessary — a session cookie that keeps you signed in, a first-party cookie that remembers which campaign or referrer first brought you here, and a first-party cookie storing your consent choice. These require no consent and are always on.
Product analytics — we measure how Sentriment itself is used (which features, how often) with events sent from our own servers to Mixpanel (EU). These events contain account identifiers, feature usage, and approximate location (country and region, derived from your IP address at request time — the IP address itself is not sent to the analytics processor), along with browser and device type — never the feedback content in your workspace, and never identifiers of your own users. This stream sets no cookie and uses no third-party script. We do not run advertising or cross-site tracking of any kind.
Traffic measurement (no cookie, always on) — on our public website only, we count page views using Vercel Web Analytics. This is deliberately not behind the consent banner, because it stores nothing on your device: there is no cookie and no persistent identifier, visitors are counted using a hash derived from the incoming request which is discarded within 24 hours, and the data cannot be used to follow you across sites or to single you out. What it records is the page address, the referring site, approximate country, and browser and device type, plus, with no identifier, how often the cookie banner is shown and which button is chosen. We use it for two things: knowing how many people actually reach the site, which the consented analytics below cannot tell us, because everyone who declines is invisible to it, and knowing how often the banner is answered either way. The signed-in dashboard is deliberately excluded — this counting does not run there at all. Inside the product the only third-party code we ever load is the opt-in session replay described below; decline that and no third-party script runs on your workspace pages. Note that, unlike the rest of our infrastructure, this one measurement is processed outside the EU (see section 4). Our lawful basis is legitimate interest (Art. 6(1)(f)).
Website analytics (cookie — opt-in only) — on sentriment.com, if, and only if, you accept the cookie banner, we set one first-party cookie holding a random identifier so we can count returning visits and see which pages lead people to sign up. The events (page path, campaign parameters, referring site, approximate country, browser family) are forwarded by our own server to Mixpanel (EU). If you later create an account, that random identifier is linked to it so we know which pages preceded the signup. Decline and the cookie is never set, nothing is linked to you, and the site works identically — only the cookieless traffic count described above continues. The choice is shared across sentriment.com and its subdomains and expires after 180 days. You can change it at any time from Cookie settings, at the bottom of every page.
Session replays (opt-in only) — if, and only if, you accept the in-app prompt, we record masked replays of your Sentriment sessions to understand where the product is confusing. Masking happens in your browser before anything is transmitted: all text is replaced with blanks and images are blocked, so neither your data nor your users' feedback is ever readable in a recording — we see clicks, movement and page structure only. Declining changes nothing about how Sentriment works, and you can withdraw at any time in Account settings, which stops recording immediately. Replays are processed by Mixpanel under EU data residency.
8. Security
Data is encrypted in transit and at rest. Passwords are stored only as salted scrypt hashes. Secret API keys are stored only as SHA-256 hashes. Stored integration credentials are encrypted with AES-256-GCM. And — the measure we're proudest of — PII in feedback is redacted before it is ever written to disk (for call transcripts, unless the customer turns redaction off for a notetaker connection).
9. Changes
Sentriment is in open beta and the product evolves quickly; this page describes the service as it is today and is updated in step with it. If we materially change this policy we will update this page and, for significant changes affecting account holders, notify you by email. The “last updated” date at the top always reflects the current version.