Data inventory
Version: 1.0
Last Updated: 2026-03-07
Owner: Privacy & Compliance Team
Classification: Internal — Confidential
Related Docs: Data retention · Consent model · Subprocessors · Privacy requests
1. Overview
This document provides a comprehensive inventory of all personal and sensitive data collected, processed, and stored by the Perceive8 meeting intelligence platform. It is organized by feature area and includes data classification, storage location, processing parties, and cross-border transfer implications.
Data Classification Levels
| Level | Label | Description |
|---|---|---|
| L1 | Public | Non-sensitive, publicly available information |
| L2 | Internal | Internal operational data, low sensitivity |
| L3 | Confidential | Business-sensitive data, PII, requires access controls |
| L4 | Restricted | Highly sensitive data — biometrics, health data, legal recordings |
2. Data Inventory by Feature Area
2.1 Authentication & User Management
| Data Element | Purpose / Lawful Basis | Storage Location | Processor | Classification | PII | Cross-Border |
|---|---|---|---|---|---|---|
external_id (Supabase auth UUID) |
Account identification — Contract performance | PostgreSQL (Supabase) | Supabase (internal) | L3 — Confidential | Yes (pseudonymous identifier) | Supabase cloud region (US) |
| Email address | Authentication, account recovery — Contract performance | Supabase Auth | Supabase | L3 — Confidential | Yes | Supabase cloud region (US) |
| Password hash | Authentication — Contract performance | Supabase Auth | Supabase | L4 — Restricted | No (derived) | Supabase cloud region (US) |
| Session tokens / JWTs | Session management — Contract performance | In-memory / client-side | Internal | L3 — Confidential | Yes (linked to user) | Client device location |
users table:
- Stores
external_idlinking to Supabase Auth - Minimal PII stored in application database by design
- Auth metadata (email, password) managed by Supabase Auth service
2.2 Audio Processing
| Data Element | Purpose / Lawful Basis | Storage Location | Processor | Classification | PII | Cross-Border |
|---|---|---|---|---|---|---|
| Raw audio files | Meeting analysis — Consent | MinIO (S3-compatible object storage) | Internal | L4 — Restricted | Yes (voice recordings) | Self-hosted / deployment region |
| Enhanced audio files | Improved transcription quality — Consent | MinIO (S3-compatible object storage) | Internal | L4 — Restricted | Yes (voice recordings) | Self-hosted / deployment region |
original_path |
File reference — Contract performance | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes (linked to audio) | Supabase cloud region |
enhanced_path |
File reference — Contract performance | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes (linked to audio) | Supabase cloud region |
| Audio metadata (duration, format, sample rate) | Processing optimization — Legitimate interest | PostgreSQL (Supabase) | Internal | L2 — Internal | No | Supabase cloud region |
audio_files table:
- Contains paths to raw and enhanced audio in object storage
- Audio files are the most sensitive data class — contain voice biometrics and spoken content
- Linked to
analysesvia foreign key
2.3 Transcription
| Data Element | Purpose / Lawful Basis | Storage Location | Processor | Classification | PII | Cross-Border |
|---|---|---|---|---|---|---|
| Audio sent to OpenAI Whisper | Speech-to-text transcription — Consent | Transient (API call) | OpenAI (third-party) | L4 — Restricted | Yes | US (OpenAI servers) |
| Audio sent to Replicate | Diarized transcription — Consent | Transient (API call) | Replicate (third-party) | L4 — Restricted | Yes | US (Replicate servers) |
Transcript text (text) |
Core product feature — Contract performance | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes (verbatim speech) | Supabase cloud region |
speaker_label |
Speaker attribution — Contract performance | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes (identifies individuals) | Supabase cloud region |
language |
Transcription configuration — Contract performance | PostgreSQL (Supabase) | Internal | L2 — Internal | No | Supabase cloud region |
transcript_segments table:
- Contains verbatim speech content with timestamps
- Speaker labels link to
speakerstable - Text may contain any PII spoken during the meeting (names, addresses, financial data, health information)
⚠️ Special Note: Transcript text is unpredictable in content. It may contain special category data (health, legal, financial) depending on the meeting subject matter. This must be treated as L4 — Restricted by default.
2.4 Speaker Analysis & Diarization
| Data Element | Purpose / Lawful Basis | Storage Location | Processor | Classification | PII | Cross-Border |
|---|---|---|---|---|---|---|
| Audio sent to Pyannote.ai | Speaker diarization & voiceprint — Consent | Transient (API call) | Pyannote.ai (third-party) | L4 — Restricted | Yes (biometric) | EU (Pyannote servers) |
Speaker name (name) |
Speaker identification — Consent | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes | Supabase cloud region |
| Diarization segments | Speaker turn tracking — Contract performance | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes (speaker identification) | Supabase cloud region |
| Voiceprint embeddings | Speaker re-identification — Explicit consent | PostgreSQL (Supabase) | Internal | L4 — Restricted | Yes (biometric data) | Supabase cloud region |
| Speaker voice embeddings (vector) | Similarity matching — Explicit consent | ChromaDB | Internal | L4 — Restricted | Yes (biometric data) | Self-hosted / deployment region |
speakers table:
- Real names of meeting participants
- Linked to voiceprint profiles for re-identification
voiceprint_profiles table:
- Contains voice embeddings — classified as biometric data under GDPR Art. 9
- Requires explicit consent for processing
- Subject to enhanced protection requirements
diarization_segments table:
- Speaker turn boundaries and identification data
- Links audio segments to identified speakers
🔴 Biometric Data Warning: Voiceprint profiles constitute biometric data under GDPR, BIPA (Illinois), and similar regulations. Processing requires explicit consent and enhanced safeguards. See Consent Model.
2.5 Emotion & Prosody Analysis
| Data Element | Purpose / Lawful Basis | Storage Location | Processor | Classification | PII | Cross-Border |
|---|---|---|---|---|---|---|
| Audio sent to Hume AI | Emotion/prosody analysis — Consent | Transient (API call) | Hume AI (third-party) | L4 — Restricted | Yes | US (Hume AI servers) |
prosody_emotions |
Emotional tone analysis — Consent | PostgreSQL (Supabase) | Internal | L4 — Restricted | Yes (emotional state) | Supabase cloud region |
vocal_burst |
Non-speech vocal analysis — Consent | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes (behavioral data) | Supabase cloud region |
audio_intelligence_segments table (emotion fields):
- Prosody emotions reveal emotional states of identified speakers
- May constitute "inferences" about individuals under CCPA
- Combined with speaker identification, this is highly sensitive profiling data
⚠️ Sensitive Processing: Emotion analysis combined with speaker identification constitutes profiling under GDPR Art. 22. Users must be clearly informed and given the right to object.
2.6 Content Intelligence (Sentiment, Entities, Topics, Moderation)
| Data Element | Purpose / Lawful Basis | Storage Location | Processor | Classification | PII | Cross-Border |
|---|---|---|---|---|---|---|
| Audio sent to AssemblyAI | Multi-modal analysis — Consent | Transient (API call) | AssemblyAI (third-party) | L4 — Restricted | Yes | US (AssemblyAI servers) |
sentiment_label |
Sentiment analysis — Consent | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes (opinion attribution) | Supabase cloud region |
entities |
Named entity recognition — Consent | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes (names, orgs, locations) | Supabase cloud region |
content_moderation |
Safety/compliance flagging — Legitimate interest | PostgreSQL (Supabase) | Internal | L3 — Confidential | Potentially | Supabase cloud region |
contextual_analysis |
Topic/context extraction — Consent | PostgreSQL (Supabase) | Internal | L3 — Confidential | Potentially | Supabase cloud region |
audio_intelligence_segments table (content fields):
- Entities may include PII extracted from speech (person names, organizations, locations, dates)
- Content moderation flags may indicate sensitive topics discussed
- Contextual analysis provides topic categorization
2.7 Conversations & Chat (RAG)
| Data Element | Purpose / Lawful Basis | Storage Location | Processor | Classification | PII | Cross-Border |
|---|---|---|---|---|---|---|
Chat messages (content) |
AI-assisted meeting analysis — Contract performance | PostgreSQL (Supabase) | Internal | L3 — Confidential | Potentially (user queries) | Supabase cloud region |
| Chat messages sent to OpenAI | RAG query processing — Consent | Transient (API call) | OpenAI (third-party) | L3 — Confidential | Potentially | US (OpenAI servers) |
tool_calls |
Function call metadata — Contract performance | PostgreSQL (Supabase) | Internal | L2 — Internal | No | Supabase cloud region |
artifacts |
Generated analysis artifacts — Contract performance | PostgreSQL (Supabase) | Internal | L3 — Confidential | Potentially | Supabase cloud region |
| Vector embeddings | Semantic search — Contract performance | ChromaDB | Internal + OpenAI (embedding generation) | L3 — Confidential | Yes (derived from transcripts) | Self-hosted (ChromaDB) / US (OpenAI API) |
conversations table:
- Links chat sessions to users
- Contains conversation metadata
conversation_messages table:
- Full chat history including user queries and AI responses
- Tool calls may reference analysis data
- Artifacts may contain generated summaries with PII
2.8 Scenarios & Reports
| Data Element | Purpose / Lawful Basis | Storage Location | Processor | Classification | PII | Cross-Border |
|---|---|---|---|---|---|---|
| Scenario definitions | Analysis templates — Contract performance | PostgreSQL (Supabase) | Internal | L2 — Internal | No | Supabase cloud region |
scenario_questions |
Analysis prompts — Contract performance | PostgreSQL (Supabase) | Internal | L2 — Internal | No | Supabase cloud region |
executive_summary |
Report output — Contract performance | PostgreSQL (Supabase) | Internal | L3 — Confidential | Potentially | Supabase cloud region |
answer / evidence |
Report findings — Contract performance | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes (derived from transcripts) | Supabase cloud region |
reports / report_findings tables:
- Generated analysis reports containing summaries and evidence
- Evidence text is extracted from transcripts and may contain PII
- Reports may be shared or exported by users
2.9 Billing & Subscriptions
| Data Element | Purpose / Lawful Basis | Storage Location | Processor | Classification | PII | Cross-Border |
|---|---|---|---|---|---|---|
stripe_customer_id |
Payment processing — Contract performance | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes (linked to user) | Supabase cloud region |
stripe_subscription_id |
Subscription management — Contract performance | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes (linked to user) | Supabase cloud region |
stripe_payment_id |
Payment tracking — Contract performance | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes (linked to user) | Supabase cloud region |
| Payment card details | Payment processing — Contract performance | Stripe only (not stored locally) | Stripe (third-party) | L4 — Restricted | Yes | US/EU (Stripe servers) |
| Usage minutes | Billing calculation — Contract performance | PostgreSQL (Supabase) | Internal | L2 — Internal | Yes (linked to user) | Supabase cloud region |
subscriptions / usage_records / minute_packs tables:
- Only Stripe reference IDs stored locally — no PCI data
- Usage records track minutes consumed per analysis
- Stripe handles all payment card data (PCI DSS compliant)
2.10 Real-Time Streaming
| Data Element | Purpose / Lawful Basis | Storage Location | Processor | Classification | PII | Cross-Border |
|---|---|---|---|---|---|---|
| Real-time audio stream | Live transcription — Consent | Transient (WebSocket) | Internal + AI providers | L4 — Restricted | Yes (voice recordings) | Deployment region + provider regions |
| Stream session metadata | Session management — Contract performance | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes (linked to user) | Supabase cloud region |
Stream alerts (message, evidence_text, speaker_name) |
Real-time notifications — Contract performance | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes | Supabase cloud region |
stream_sessions table:
- Tracks active and historical streaming sessions
- Links to user identity
stream_alerts table:
- Contains alert messages with evidence text from live transcription
- Speaker names directly identify individuals
2.11 API Access & Security
| Data Element | Purpose / Lawful Basis | Storage Location | Processor | Classification | PII | Cross-Border |
|---|---|---|---|---|---|---|
key_prefix / key_hash |
API authentication — Contract performance | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes (linked to user) | Supabase cloud region |
| API key scopes | Authorization — Contract performance | PostgreSQL (Supabase) | Internal | L2 — Internal | No | Supabase cloud region |
client_id / client_secret_hash |
OAuth authentication — Contract performance | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes (linked to user) | Supabase cloud region |
| Webhook URLs / secrets | Event delivery — Contract performance | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes (linked to user) | Supabase cloud region |
api_keys / oauth_clients / webhooks tables:
- API keys stored as hashes only (prefix retained for identification)
- OAuth client secrets stored as hashes
- Webhook secrets used for payload signing
2.12 Audit & Compliance
| Data Element | Purpose / Lawful Basis | Storage Location | Processor | Classification | PII | Cross-Border |
|---|---|---|---|---|---|---|
user_id |
Audit attribution — Legitimate interest / Legal obligation | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes | Supabase cloud region |
action |
Activity tracking — Legitimate interest | PostgreSQL (Supabase) | Internal | L2 — Internal | No | Supabase cloud region |
ip_address |
Security monitoring — Legitimate interest | PostgreSQL (Supabase) | Internal | L3 — Confidential | Yes | Supabase cloud region |
| Timestamp | Audit trail — Legal obligation | PostgreSQL (Supabase) | Internal | L2 — Internal | No | Supabase cloud region |
audit_log table:
- Immutable audit trail for compliance
- IP addresses are PII under GDPR
- Retention governed by legal/regulatory requirements
3. Cross-Border Data Transfer Summary
| Destination | Provider(s) | Data Types | Transfer Mechanism | Status |
|---|---|---|---|---|
| United States | OpenAI, Replicate, Hume AI, AssemblyAI, Stripe | Audio, transcripts, embeddings, payment refs | Standard Contractual Clauses (SCCs) required | ❌ SCCs not yet executed |
| European Union | Pyannote.ai | Audio, diarization data | Adequate (if EU-to-EU) | ⚠️ Depends on deployment region |
| United States | Supabase | All database records | SCCs required (if users in EU) | ❌ SCCs not yet executed |
⚠️ Gap: No Standard Contractual Clauses (SCCs) or Transfer Impact Assessments (TIAs) have been executed with any AI provider. This is a prerequisite for processing EU personal data. See Subprocessors for DPA status.
4. Data Flow Diagram (Text)
User Device
│
├── Audio Upload ──────────────────────┐
│ ▼
│ ┌─────────────────┐
│ │ MinIO (S3) │
│ │ Audio Storage │
│ └────────┬────────┘
│ │
│ ▼
│ ┌─────────────────┐
│ │ Perceive8 API │
│ │ (Processing) │
│ └────────┬────────┘
│ │
│ ┌────────────────────────┼────────────────────────┐
│ │ │ │ │ │
│ ▼ ▼ ▼ ▼ ▼
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌────────┐ ┌──────────┐
│ │ OpenAI │ │Pyannote │ │Replicate │ │Hume AI │ │AssemblyAI│
│ │ Whisper │ │ .ai │ │ │ │ │ │ │
│ └─────┬─────┘ └────┬─────┘ └────┬─────┘ └───┬────┘ └────┬─────┘
│ │ │ │ │ │
│ └────────────┴───────────┴───────────┴────────────┘
│ │
│ ▼
│ ┌─────────────────┐
│ │ PostgreSQL │
│ │ (Supabase) │
│ └────────┬────────┘
│ │
│ ▼
│ ┌─────────────────┐
│ Chat / RAG ───────────────▶│ ChromaDB │
│ │ │ (Embeddings) │
│ │ └─────────────────┘
│ │
│ └──── OpenAI (Chat/Embeddings API)
│
└── Billing ──── Stripe (Payment Processing)
5. Implementation Status
| Area | Status | Notes |
|---|---|---|
| Data inventory documentation | ✅ Complete | This document |
| Data classification labels in code | ❌ Not Implemented | No field-level classification metadata in database |
| Automated data discovery | ❌ Not Implemented | Manual inventory only |
| Data flow monitoring | ❌ Not Implemented | No runtime data flow tracking |
| Cross-border transfer safeguards | ❌ Not Implemented | SCCs/TIAs needed for all US providers |
| PII detection in transcripts | ❌ Not Implemented | No automated PII scanning of transcript content |
| Data minimization review | ⚠️ Partial | Minimal user data stored; transcript content unbounded |
6. Revision History
| Version | Date | Author | Changes |
|---|---|---|---|
| 1.0 | 2026-03-07 | Privacy & Compliance Team | Initial data inventory |