Last updated: 18 August 2026
Mara is where senior people rehearse the conversations that matter, which means it hears things they would not say anywhere else. That places a duty on us. This page sets out how the product actually handles data, in plain terms, including the parts we have not built yet.
The principle behind the design: keep the points of learning, not the conversation.
In the Practise and Coaching rooms your camera and microphone are read and analysed inside your own browser. Posture, gaze, pace, pauses, pitch and energy are measured there. Your speech is turned into text by a speech model that runs in the browser itself, so the audio is never sent anywhere to be transcribed. Only the text and the measured signals reach us, and only so that Mara can coach you on them.
Where a browser cannot run that model, Mara falls back to the speech recognition built into the browser. In Chrome that service is operated by Google and receives your own microphone audio for that purpose.
Where an organisation buys Mara for its people, that organisation sees engagement and the shape of progress. It does not see the content of anyone's coaching, and it does not see an individual's scores. Reporting to an employer is aggregate only, and is withheld entirely below a minimum cohort size, because a small group average identifies the person in it.
Mara is not used to make, inform or support employment decisions about an individual, and we contract on that basis.
| What | How it is handled |
|---|---|
| Coaching and Practise | The working transcript is discarded once your summary and scores are written. We keep the summary and the scores. |
| Off the Record | Not recorded. It is processed only to produce Mara's reply in the moment. Shredding clears it. |
| Saved takes | Held in your private Vault, encrypted, reached only through links that expire, deletable by you at any time, and removed automatically after ninety days. |
| Meeting recordings | Never uploaded. Where the Observer records a meeting, the file is written to your own computer. There is no route in the Mara service that accepts a meeting recording. |
| Meeting transcripts | Kept for a maximum of ninety days, then cleared automatically. Your coaching debrief is kept, the transcript beneath it is not. |
| Account data | Kept while your account is active. Deleted within thirty days of closure, or on request. |
Deletion runs on a schedule and every run is logged, so retention is something we can evidence rather than simply assert.
| Provider | Purpose | Data |
|---|---|---|
| Anthropic | Generates Mara's coaching and analysis | Session text |
| OpenAI | Converts meeting audio to text in Mara Teams | Audio, then text |
| Browser speech recognition, where the in browser model is unavailable | Your own microphone audio | |
| Supabase | Database, authentication and file storage | Account and session data |
| Render | Application hosting | Requests and delivery |
| Zoom | Meeting capture for the Observer, by consent | Meeting audio |
| Stripe | Subscriptions and payments | Billing and contact details |
| Brevo | Transactional and programme email | Name and email |
Every provider is contracted on terms prohibiting the use of our customers' data to train their models. This list is maintained under change notice: business customers are told before it changes.
In the Observer you can enrol your own voice, so Mara can tell your contributions apart from other voices in the room. A voiceprint is biometric data, so we are precise about it: it is created on your device, held for your own sessions, used only to work out which words were yours, never matched against any outside database, never used to identify anyone else, and deleted on request. It is optional and Mara works without it.
We would rather you read this here than discover it in a questionnaire.
None of that stops us answering your security questionnaire in full, and we would rather do that than imply a maturity we have not reached.
Security and procurement teams can request our full Security and Privacy Overview, which covers architecture, controls, residency, sub processor terms and the commitments we make in contract. It is shared under NDA. Email security@thesessionlab.com.
If you believe you have found a security issue, email security@thesessionlab.com with enough detail to reproduce it. We will acknowledge you within two working days, keep you updated while we fix it, and we will not pursue anyone who reports in good faith and does not access or alter other people's data.
Mara is built by Session Care Ltd, trading as Session, registered in England and Wales, company number 14261673. Registered office provided on request and stated in the Data Processing Agreement. For anything on this page, contact privacy@thesessionlab.com.