Mara Trust and Security

Trust and Security

Last updated: 18 August 2026

Mara is where senior people rehearse the conversations that matter, which means it hears things they would not say anywhere else. That places a duty on us. This page sets out how the product actually handles data, in plain terms, including the parts we have not built yet.

The principle behind the design: keep the points of learning, not the conversation.

What happens on your device, and what reaches us

In the Practise and Coaching rooms your camera and microphone are read and analysed inside your own browser. Posture, gaze, pace, pauses, pitch and energy are measured there. Your speech is turned into text by a speech model that runs in the browser itself, so the audio is never sent anywhere to be transcribed. Only the text and the measured signals reach us, and only so that Mara can coach you on them.

Where a browser cannot run that model, Mara falls back to the speech recognition built into the browser. In Chrome that service is operated by Google and receives your own microphone audio for that purpose.

The boundary that matters

Where an organisation buys Mara for its people, that organisation sees engagement and the shape of progress. It does not see the content of anyone's coaching, and it does not see an individual's scores. Reporting to an employer is aggregate only, and is withheld entirely below a minimum cohort size, because a small group average identifies the person in it.

Mara is not used to make, inform or support employment decisions about an individual, and we contract on that basis.

What we keep, and for how long

WhatHow it is handled
Coaching and PractiseThe working transcript is discarded once your summary and scores are written. We keep the summary and the scores.
Off the RecordNot recorded. It is processed only to produce Mara's reply in the moment. Shredding clears it.
Saved takesHeld in your private Vault, encrypted, reached only through links that expire, deletable by you at any time, and removed automatically after ninety days.
Meeting recordingsNever uploaded. Where the Observer records a meeting, the file is written to your own computer. There is no route in the Mara service that accepts a meeting recording.
Meeting transcriptsKept for a maximum of ninety days, then cleared automatically. Your coaching debrief is kept, the transcript beneath it is not.
Account dataKept while your account is active. Deleted within thirty days of closure, or on request.

Deletion runs on a schedule and every run is logged, so retention is something we can evidence rather than simply assert.

Who processes data on our behalf

ProviderPurposeData
AnthropicGenerates Mara's coaching and analysisSession text
OpenAIConverts meeting audio to text in Mara TeamsAudio, then text
GoogleBrowser speech recognition, where the in browser model is unavailableYour own microphone audio
SupabaseDatabase, authentication and file storageAccount and session data
RenderApplication hostingRequests and delivery
ZoomMeeting capture for the Observer, by consentMeeting audio
StripeSubscriptions and paymentsBilling and contact details
BrevoTransactional and programme emailName and email

Every provider is contracted on terms prohibiting the use of our customers' data to train their models. This list is maintained under change notice: business customers are told before it changes.

Where data is held

Voice attribution in the Observer

In the Observer you can enrol your own voice, so Mara can tell your contributions apart from other voices in the room. A voiceprint is biometric data, so we are precise about it: it is created on your device, held for your own sessions, used only to work out which words were yours, never matched against any outside database, never used to identify anyone else, and deleted on request. It is optional and Mara works without it.

How the platform is protected

What we do not have yet

We would rather you read this here than discover it in a questionnaire.

None of that stops us answering your security questionnaire in full, and we would rather do that than imply a maturity we have not reached.

The documents

Security and procurement teams can request our full Security and Privacy Overview, which covers architecture, controls, residency, sub processor terms and the commitments we make in contract. It is shared under NDA. Email security@thesessionlab.com.

Reporting a vulnerability

If you believe you have found a security issue, email security@thesessionlab.com with enough detail to reproduce it. We will acknowledge you within two working days, keep you updated while we fix it, and we will not pursue anyone who reports in good faith and does not access or alter other people's data.

Who we are

Mara is built by Session Care Ltd, trading as Session, registered in England and Wales, company number 14261673. Registered office provided on request and stated in the Data Processing Agreement. For anything on this page, contact privacy@thesessionlab.com.