Consent model
Version: 1.0
Last Updated: 2026-03-07
Owner: Privacy & Compliance Team
Classification: Internal — Confidential
Related Docs: Data inventory · Data retention · Subprocessors · Privacy requests
1. Overview
This document defines the consent model for the Perceive8 meeting intelligence platform. It specifies what consent is required for each processing activity, how consent is captured and stored, and how users can withdraw consent. It also addresses special categories of data that require enhanced consent mechanisms.
Regulatory Framework
This consent model is designed to comply with:
- GDPR (EU General Data Protection Regulation) — Arts. 6, 7, 9, 22
- CCPA/CPRA (California Consumer Privacy Act / California Privacy Rights Act)
- BIPA (Illinois Biometric Information Privacy Act)
- PIPEDA (Canada Personal Information Protection and Electronic Documents Act)
- State-level recording consent laws (varies by jurisdiction)
2. Lawful Basis for Processing
2.1 Processing Activities & Lawful Basis
| Processing Activity | Lawful Basis (GDPR) | Consent Type | Required | Granular Opt-Out |
|---|---|---|---|---|
| Account creation & authentication | Contract performance (Art. 6(1)(b)) | Terms of Service acceptance | Yes — mandatory | No |
| Audio file upload & storage | Consent (Art. 6(1)(a)) | Explicit upload action | Yes — mandatory for feature | N/A |
| Transcription (OpenAI Whisper, Replicate) | Consent (Art. 6(1)(a)) | Included in AI processing consent | Yes — mandatory for feature | No (core feature) |
| Speaker diarization (Pyannote.ai, Replicate) | Consent (Art. 6(1)(a)) | Included in AI processing consent | Yes — mandatory for feature | No (core feature) |
| Voiceprint creation & storage | Explicit consent (Art. 9(2)(a)) | Separate biometric consent | Yes — opt-in only | Yes — can disable |
| Emotion/prosody analysis (Hume AI) | Consent (Art. 6(1)(a)) | Included in AI processing consent | Yes — opt-in recommended | Yes — can disable |
| Sentiment/entity analysis (AssemblyAI) | Consent (Art. 6(1)(a)) | Included in AI processing consent | Yes — mandatory for feature | Partial (per-feature) |
| Content moderation (AssemblyAI) | Legitimate interest (Art. 6(1)(f)) | No separate consent needed | N/A | No (safety feature) |
| AI chat / RAG queries (OpenAI) | Contract performance (Art. 6(1)(b)) | Included in service terms | Yes — mandatory for feature | N/A |
| Vector embedding generation (OpenAI) | Contract performance (Art. 6(1)(b)) | Included in service terms | Yes — mandatory for feature | N/A |
| Real-time streaming transcription | Consent (Art. 6(1)(a)) | Explicit stream initiation | Yes — mandatory for feature | N/A |
| Billing & payment processing (Stripe) | Contract performance (Art. 6(1)(b)) | Included in service terms | Yes — mandatory | No |
| Audit logging | Legitimate interest (Art. 6(1)(f)) | No separate consent needed | N/A | No (security) |
| Marketing communications | Consent (Art. 6(1)(a)) | Opt-in checkbox | No — optional | Yes — unsubscribe |
| Analytics & product improvement | Legitimate interest (Art. 6(1)(f)) | Privacy policy notice | N/A | Yes — opt-out available |
2.2 Legitimate Interest Assessments (LIA)
For processing activities based on legitimate interest, a Legitimate Interest Assessment must be documented:
| Activity | Legitimate Interest | Necessity | Balancing Test | Override Risk |
|---|---|---|---|---|
| Content moderation | Platform safety, legal compliance | Essential for preventing harmful content | Low impact on data subjects; high benefit for safety | Low |
| Audit logging | Security, fraud prevention, compliance | Essential for incident response and regulatory compliance | Minimal additional data; high security benefit | Low |
| Analytics | Product improvement, service reliability | Necessary for maintaining service quality | Aggregated/anonymized where possible | Low (with anonymization) |
3. Consent Types & Collection
3.1 Consent Taxonomy
| Consent ID | Name | Category | Granularity | Mandatory |
|---|---|---|---|---|
C-TOS |
Terms of Service | Contract | Account-level | Yes |
C-PP |
Privacy Policy | Notice | Account-level | Yes |
C-AUDIO |
Audio Processing | Feature consent | Per-upload | Yes (for feature) |
C-AI |
AI Provider Processing | Data sharing | Account-level | Yes (for feature) |
C-VOICE |
Voiceprint Biometric | Special category | Per-profile | No (opt-in) |
C-EMOTION |
Emotion Analysis | Feature consent | Account-level | No (opt-in recommended) |
C-STREAM |
Real-Time Streaming | Feature consent | Per-session | Yes (for feature) |
C-MARKETING |
Marketing Communications | Marketing | Account-level | No (opt-in) |
C-THIRDPARTY |
Third-Party Recording | Recording consent | Per-upload | Conditional |
3.2 How Consent Is Captured
Account Creation (C-TOS, C-PP)
┌─────────────────────────────────────────────────┐
│ Create Your Account │
│ │
│ Email: [________________________] │
│ Password: [________________________] │
│ │
│ ☑ I agree to the Terms of Service │
│ ☑ I have read and accept the Privacy Policy │
│ │
│ [ Create Account ] │
│ │
│ By creating an account, you agree that your │
│ uploaded audio will be processed by AI │
│ providers as described in our Privacy Policy. │
└─────────────────────────────────────────────────┘
Storage: Consent timestamp stored in Supabase Auth metadata
Implementation Status: ⚠️ Partial — ToS acceptance exists; no granular consent tracking
Audio Upload (C-AUDIO, C-AI)
┌─────────────────────────────────────────────────┐
│ Upload Audio File │
│ │
│ ┌─────────────────────────────────┐ │
│ │ Drag & drop audio file │ │
│ │ or click to browse │ │
│ └─────────────────────────────────┘ │
│ │
│ ⓘ Your audio will be processed by: │
│ • OpenAI Whisper (transcription) │
│ • Pyannote.ai (speaker identification) │
│ • Replicate (diarization) │
│ • Hume AI (emotion analysis) │
│ • AssemblyAI (content intelligence) │
│ │
│ ☐ I confirm all participants in this recording │
│ have consented to being recorded and analyzed │
│ │
│ [ Upload & Analyze ] │
└─────────────────────────────────────────────────┘
Storage: Consent flag stored per audio_files record
Implementation Status: ❌ Not Implemented — no consent confirmation at upload time
Voiceprint Consent (C-VOICE)
┌─────────────────────────────────────────────────┐
│ Enable Speaker Recognition │
│ │
│ Perceive8 can create a voiceprint profile to │
│ automatically identify speakers across your │
│ recordings. │
│ │
│ ⚠️ This involves processing biometric data │
│ (voice characteristics). This data is: │
│ │
│ • Stored securely in our database │
│ • NOT shared with third parties after creation │
│ • Deletable at any time from your settings │
│ • Subject to a maximum 3-year retention period │
│ │
│ ☐ I consent to the creation and storage of │
│ voiceprint profiles for speaker recognition │
│ │
│ ☐ I understand this involves biometric data │
│ processing and I can withdraw consent at │
│ any time │
│ │
│ [ Enable Voiceprints ] [ Cancel ] │
└─────────────────────────────────────────────────┘
Storage: Dedicated consent record with timestamp, version, and withdrawal capability
Implementation Status: ❌ Not Implemented — voiceprints are created without explicit biometric consent
Emotion Analysis Opt-In (C-EMOTION)
┌─────────────────────────────────────────────────┐
│ Emotion Analysis Settings │
│ │
│ Perceive8 can analyze emotional tone and │
│ prosody in your recordings using Hume AI. │
│ │
│ This analysis detects: │
│ • Emotional states (joy, anger, sadness, etc.) │
│ • Vocal characteristics and tone │
│ • Non-speech vocalizations │
│ │
│ ⓘ Emotion data is linked to identified │
│ speakers and stored with your analysis. │
│ │
│ Emotion Analysis: [ ON | OFF ] │
│ │
│ [ Save Preferences ] │
└─────────────────────────────────────────────────┘
Storage: User preference in account settings
Implementation Status: ❌ Not Implemented — emotion analysis runs by default on all uploads
4. Consent Storage Schema
4.1 Proposed user_consents Table
❌ Not Yet Implemented — This table needs to be created.
CREATE TABLE user_consents (
id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
user_id UUID NOT NULL, -- References users.external_id
consent_type VARCHAR(50) NOT NULL, -- e.g., 'C-TOS', 'C-VOICE', 'C-EMOTION'
consent_version VARCHAR(20) NOT NULL, -- Version of the consent text shown
granted_at TIMESTAMPTZ NOT NULL DEFAULT NOW(),
withdrawn_at TIMESTAMPTZ, -- NULL if consent is active
ip_address INET, -- IP at time of consent
user_agent TEXT, -- Browser/client at time of consent
consent_text_hash VARCHAR(64), -- SHA-256 of the consent text shown
metadata JSONB, -- Additional context (e.g., upload_id for per-upload consent)
created_at TIMESTAMPTZ NOT NULL DEFAULT NOW(),
updated_at TIMESTAMPTZ NOT NULL DEFAULT NOW()
);
CREATE INDEX idx_user_consents_user_id ON user_consents(user_id);
CREATE INDEX idx_user_consents_type ON user_consents(consent_type);
CREATE INDEX idx_user_consents_active ON user_consents(user_id, consent_type) WHERE withdrawn_at IS NULL;
4.2 Consent Record Requirements
Each consent record must capture:
- Who — User ID
- What — Consent type and version
- When — Timestamp of grant/withdrawal
- How — IP address, user agent, UI element
- Which version — Hash of the consent text displayed
- Context — Any relevant metadata (e.g., which upload triggered the consent)
5. Consent Withdrawal
5.1 Withdrawal Mechanisms
| Consent Type | Withdrawal Method | Effect | Timeline |
|---|---|---|---|
C-TOS |
Account deletion | Full account and data deletion | 30 days (GDPR) |
C-PP |
Account deletion | Full account and data deletion | 30 days (GDPR) |
C-AUDIO |
Delete individual analysis | Removes specific audio and derived data | Immediate |
C-AI |
Account settings toggle | Stops future AI processing; existing data retained | Immediate (prospective) |
C-VOICE |
Account settings → Delete voiceprints | Deletes all voiceprint profiles and embeddings | Immediate |
C-EMOTION |
Account settings toggle | Disables emotion analysis for future uploads | Immediate (prospective) |
C-STREAM |
End streaming session | Stops real-time processing | Immediate |
C-MARKETING |
Unsubscribe link / account settings | Stops marketing communications | Immediate |
C-THIRDPARTY |
N/A (per-upload) | Cannot retroactively withdraw (data already processed) | N/A |
5.2 Withdrawal Flow
User requests consent withdrawal
│
▼
┌─────────────────────┐
│ Validate request │
│ (auth + consent ID) │
└─────────┬───────────┘
│
▼
┌─────────────────────┐ ┌──────────────────────┐
│ Update consent │────▶│ Trigger side effects │
│ record │ │ (data deletion, etc.) │
│ (set withdrawn_at) │ └──────────┬───────────┘
└─────────────────────┘ │
▼
┌──────────────────────┐
│ Send confirmation │
│ email to user │
└──────────────────────┘
5.3 Implementation Status
| Withdrawal Feature | Status | Notes |
|---|---|---|
| Account deletion (full withdrawal) | ❌ Not Implemented | See Deletion & Export Workflow |
| Per-analysis deletion | ⚠️ Partial | API exists but no cascade to all derived data |
| Voiceprint deletion | ❌ Not Implemented | No ChromaDB deletion mechanism |
| Emotion analysis toggle | ❌ Not Implemented | No per-user feature flags |
| Marketing unsubscribe | ❌ Not Implemented | No marketing system exists yet |
| Consent record storage | ❌ Not Implemented | user_consents table not created |
6. Special Categories of Data
6.1 Biometric Data (Voiceprints)
Applicable Regulations:
- GDPR Art. 9 — Special categories of personal data
- BIPA (Illinois) — Biometric Information Privacy Act
- CCPA/CPRA — Sensitive personal information
- Texas CUBI — Capture or Use of Biometric Identifier Act
- Washington State Biometric Privacy Law
Requirements:
| Requirement | GDPR | BIPA | Status |
|---|---|---|---|
| Explicit, informed consent before collection | ✅ Required | ✅ Required | ❌ Not Implemented |
| Written policy on retention and destruction | ✅ Required | ✅ Required | ⚠️ This document (partial) |
| Maximum retention period | Not specified (purpose limitation) | 3 years or when purpose fulfilled | ❌ Not Enforced |
| Right to deletion | ✅ Required | ✅ Required | ❌ Not Implemented |
| No sale or profit from biometric data | N/A | ✅ Required | ✅ Compliant (not sold) |
| Reasonable security measures | ✅ Required | ✅ Required | ⚠️ Partial (encrypted at rest) |
| Private right of action for violations | N/A | ✅ Yes ($1,000–$5,000 per violation) | ⚠️ High risk |
Required Actions:
- Implement explicit biometric consent flow (
C-VOICE) - Create biometric data retention policy (max 3 years)
- Implement voiceprint deletion from PostgreSQL and ChromaDB
- Add biometric consent to
user_consentstable - Display BIPA-compliant notice before voiceprint creation
- Allow users to opt out of voiceprint creation entirely
🔴 Critical Risk: Processing voiceprints without BIPA-compliant consent exposes the platform to statutory damages of $1,000–$5,000 per violation. This must be resolved before any Illinois users create voiceprint profiles.
6.2 Healthcare Recordings
Scenario: Users upload recordings of medical consultations, therapy sessions, or health-related meetings.
Applicable Regulations:
- HIPAA (US) — Health Insurance Portability and Accountability Act
- GDPR Art. 9 — Health data as special category
Risk Assessment:
| Risk | Severity | Mitigation |
|---|---|---|
| Transcripts contain PHI (Protected Health Information) | 🔴 High | Perceive8 is NOT a HIPAA-covered entity or business associate by default |
| Emotion analysis on therapy sessions | 🔴 High | Sensitive mental health inferences |
| AI providers process health data | 🔴 High | No BAAs (Business Associate Agreements) with AI providers |
Current Position:
- Perceive8 does not position itself as HIPAA-compliant
- Terms of Service should prohibit uploading PHI without a BAA in place
- No BAAs exist with any AI provider
Required Actions:
- Add Terms of Service clause prohibiting PHI uploads without BAA
- Implement content warning when healthcare-related content is detected
- Evaluate BAA availability with each AI provider for future healthcare tier
- Consider PII/PHI detection and redaction feature
6.3 Legal Conversations
Scenario: Users upload recordings of legal consultations, depositions, or privileged communications.
Risk Assessment:
| Risk | Severity | Mitigation |
|---|---|---|
| Attorney-client privilege may be waived by third-party processing | 🔴 High | User responsibility; warn in ToS |
| Legal discovery implications | 🟡 Medium | Retention schedule must be defensible |
| Confidential legal strategy exposed to AI providers | 🔴 High | No confidentiality agreements with AI providers |
Required Actions:
- Add Terms of Service warning about legal privilege implications
- Consider "legal hold" feature to prevent auto-deletion during litigation
- Document that AI provider processing may affect privilege claims
6.4 Children's Voices
Applicable Regulations:
- COPPA (US) — Children's Online Privacy Protection Act (under 13)
- GDPR Art. 8 — Conditions for child's consent (under 16 in most EU states)
- UK Age Appropriate Design Code
Current Position:
- Perceive8 Terms of Service require users to be 18+
- However, uploaded recordings may contain children's voices as participants
Risk Assessment:
| Risk | Severity | Mitigation |
|---|---|---|
| Voiceprints of minors | 🔴 High | Must not create voiceprint profiles for minors |
| Emotion analysis of children | 🟡 Medium | Ethical concerns; no specific legal prohibition |
| Transcription of children's speech | 🟢 Low | Incidental; user responsibility |
Required Actions:
- Add Terms of Service clause requiring users to ensure no minors' data is processed for voiceprints
- Consider age detection/warning for voiceprint creation
- Document that platform is not designed for processing children's data
6.5 Employee Monitoring
Scenario: Employers upload recordings of employee meetings, performance reviews, or workplace conversations.
Applicable Regulations:
- GDPR Art. 88 — Processing in the context of employment
- Various state/national employment privacy laws
- Works council / union consultation requirements (EU)
Risk Assessment:
| Risk | Severity | Mitigation |
|---|---|---|
| Emotion analysis used for employee evaluation | 🔴 High | Potential discrimination; EU AI Act implications |
| Surveillance without employee consent | 🔴 High | Varies by jurisdiction |
| Automated decision-making about employees | 🟡 Medium | GDPR Art. 22 right to human review |
Required Actions:
- Add enterprise agreement template with employee monitoring provisions
- Implement "employer use" flag that triggers additional consent requirements
- Consider restricting emotion analysis for identified employee monitoring use cases
- Document EU AI Act implications for emotion recognition in workplace settings
7. Consent Flow Diagrams
7.1 New User Registration Flow
┌──────────────┐
│ User visits │
│ signup page │
└──────┬───────┘
│
▼
┌──────────────┐
│ Display ToS │
│ + Privacy │
│ Policy │
└──────┬───────┘
│
┌──────┴───────┐
│ User accepts │──── No ───▶ Cannot create account
│ ToS + PP? │
└──────┬───────┘
│ Yes
▼
┌──────────────┐
│ Store C-TOS │
│ + C-PP │
│ consent │
└──────┬───────┘
│
▼
┌──────────────┐
│ Account │
│ created │
└──────┬───────┘
│
▼
┌──────────────┐
│ Optional: │
│ Marketing │
│ opt-in │
└──────────────┘
7.2 Audio Upload Flow
┌──────────────┐
│ User selects │
│ audio file │
└──────┬───────┘
│
▼
┌──────────────────┐
│ Display AI │
│ processing info │
│ + provider list │
└──────┬───────────┘
│
┌──────┴───────────┐
│ Third-party │
│ recording │──── No ───▶ Skip C-THIRDPARTY
│ consent needed? │
└──────┬───────────┘
│ Yes
▼
┌──────────────────┐
│ Confirm all │
│ participants │──── No ───▶ Block upload
│ consented? │
└──────┬───────────┘
│ Yes
▼
┌──────────────────┐
│ Store C-AUDIO │
│ + C-AI consent │
│ (if first time) │
└──────┬───────────┘
│
▼
┌──────────────────┐
│ Check voiceprint │
│ consent status │
└──────┬───────────┘
│
┌────────────┴────────────┐
│ │
C-VOICE granted C-VOICE not granted
│ │
▼ ▼
┌────────────────┐ ┌────────────────┐
│ Process with │ │ Process without│
│ voiceprints │ │ voiceprints │
└────────────────┘ └────────────────┘
│ │
└────────────┬────────────┘
│
▼
┌──────────────────┐
│ Check emotion │
│ consent status │
└──────┬───────────┘
│
┌────────────┴────────────┐
│ │
C-EMOTION granted C-EMOTION not granted
│ │
▼ ▼
┌────────────────┐ ┌────────────────┐
│ Include Hume │ │ Skip Hume AI │
│ AI analysis │ │ analysis │
└────────────────┘ └────────────────┘
│ │
└────────────┬────────────┘
│
▼
┌──────────────────┐
│ Begin analysis │
│ pipeline │
└──────────────────┘
7.3 Voiceprint Enrollment Flow
┌──────────────┐
│ User enables │
│ voiceprints │
└──────┬───────┘
│
▼
┌──────────────────┐
│ Display BIPA │
│ notice + │
│ biometric info │
└──────┬───────────┘
│
┌──────┴───────────┐
│ User provides │
│ explicit consent │──── No ───▶ Feature disabled
│ (two checkboxes) │
└──────┬───────────┘
│ Yes
▼
┌──────────────────┐
│ Store C-VOICE │
│ consent with: │
│ - Timestamp │
│ - IP address │
│ - Consent text │
│ version hash │
└──────┬───────────┘
│
▼
┌──────────────────┐
│ Enable voiceprint│
│ processing for │
│ future uploads │
└──────────────────┘
8. Recording Consent (Multi-Party)
8.1 The Recording Consent Problem
Perceive8 processes audio recordings that may contain multiple speakers. The uploader consents to processing, but other participants in the recording may not have consented.
8.2 Responsibility Model
| Party | Responsibility |
|---|---|
| Perceive8 (Data Processor) | Provide tools and notices to help users comply with recording consent laws |
| User (Data Controller) | Ensure all recording participants have consented to recording and AI analysis |
| Recording Participants (Data Subjects) | Have the right to be informed and to object |
8.3 Jurisdictional Requirements
| Jurisdiction | Consent Standard | Requirement |
|---|---|---|
| US — Federal | One-party consent | Uploader's consent sufficient |
| US — California, Illinois, others | Two-party / all-party consent | All participants must consent |
| EU / UK | Informed consent | All participants must be informed of recording and AI processing |
| Canada | One-party (federal) / varies by province | At least one party must consent |
8.4 Platform Safeguards
Current:
- ❌ No recording consent verification at upload
- ❌ No participant notification mechanism
- ❌ No jurisdiction detection
Proposed:
- Add upload-time confirmation: "All participants consented to recording and AI analysis"
- Provide shareable consent notice template for users to send to participants
- Implement participant notification feature (email notice with opt-out)
- Add jurisdiction selector to help users understand their obligations
- Create "participant rights" page where recording subjects can request data access/deletion
9. Consent for AI Provider Data Sharing
9.1 Transparency Requirements
Users must be clearly informed that their audio data is sent to third-party AI providers for processing. This includes:
| Information | Where Disclosed | Status |
|---|---|---|
| List of AI providers | Privacy Policy, Upload UI | ❌ Not in upload UI |
| What data is sent to each provider | Privacy Policy | ⚠️ Partial (in Privacy Policy) |
| Provider data locations (countries) | Privacy Policy | ❌ Not disclosed |
| Provider retention policies | Privacy Policy | ❌ Not disclosed |
| Provider DPA status | Internal only | ❌ Not disclosed to users |
9.2 Required Disclosures
Before first audio upload, users must be shown:
- Which providers will process their data
- What data is sent to each provider
- Where the data is processed (country)
- How long providers retain the data
- Their rights regarding provider-held data
See Subprocessors for the full provider registry.
10. Implementation Status Summary
Consent Infrastructure
| Component | Status | Priority |
|---|---|---|
user_consents database table |
❌ Not Implemented | 🔴 Critical |
| Consent capture at registration | ⚠️ Partial (ToS only) | 🔴 Critical |
| Consent capture at upload | ❌ Not Implemented | 🔴 Critical |
| Biometric consent flow (voiceprints) | ❌ Not Implemented | 🔴 Critical |
| Emotion analysis opt-in/opt-out | ❌ Not Implemented | 🟡 High |
| Consent withdrawal mechanism | ❌ Not Implemented | 🔴 Critical |
| Consent version tracking | ❌ Not Implemented | 🟡 High |
| Marketing consent (opt-in) | ❌ Not Implemented | 🟢 Standard |
| Recording consent verification | ❌ Not Implemented | 🟡 High |
| Provider disclosure in upload UI | ❌ Not Implemented | 🟡 High |
| Participant notification system | ❌ Not Implemented | 🟢 Standard |
Implementation Roadmap
Phase 1 — Critical (Before EU/BIPA exposure):
- Create
user_consentstable - Implement biometric consent flow for voiceprints
- Add consent withdrawal mechanism
- Add upload-time consent confirmation
Phase 2 — High Priority (Enterprise readiness): 5. Implement emotion analysis opt-in toggle 6. Add provider disclosure to upload UI 7. Implement consent version tracking 8. Add recording consent verification
Phase 3 — Standard (Full compliance): 9. Build participant notification system 10. Implement marketing consent 11. Add jurisdiction-aware consent flows 12. Create consent audit dashboard
11. Revision History
| Version | Date | Author | Changes |
|---|---|---|---|
| 1.0 | 2026-03-07 | Privacy & Compliance Team | Initial consent model |