Skip to main content

Security and data handling

How your notes are protected

Drive My Path holds a manager’s working record about the people they manage. This page says, in plain words, what protects it today. It is not a certification and does not claim one: Drive My Path is not SOC 2 audited. Where a control has a limit, the limit is written down here too.


Where your data lives

Your records live in a Postgres database and file store run by Supabase in the United States (us-east-1). Every request travels over TLS and passes through Cloudflare's network; the database provider encrypts data at rest. Google Calendar tokens are encrypted again by Drive My Path itself with AES-256-GCM before they are stored, and the app refuses to store them at all if that key is missing.


Only you can read your records

Every table carries row-level security scoped to the signed-in manager, enforced by the database rather than the application, so no other account can read your data, including your working notes. Working notes are visible only to you inside Drive My Path. Like any record kept about work, they could still be requested in a legal dispute, which is why they are called working notes rather than promised as secret.


What a team member sees

A team member reaches their own page by a link you send them. It shows only the fields marked shareable: the next 1:1, the shared agenda, shared notes, action items and goals. Working notes and personal details are not on it. The link is a long random token, expires after 180 days (90 for a shared review), and can be rotated by you at any time.

Recording

Nobody is recorded without agreeing from their own inbox.

The meeting recorder starts only for a person who has agreed themselves. The manager asks; Drive My Path emails that person a single-use link, open for seven days, to a page that shows the full wording. Nothing changes until they press “I agree to be recorded”. The manager never sees the link, cannot agree on their behalf, and is not told if the person declines.

An agreement lasts twelve months and ends at once if the person withdraws, if the manager changes their email address, if they are archived, or if the wording changes. Before each recorded meeting they get a written notice in their reminder, and each recording opens with an on-screen notice, which is a notice and not consent. Audio is deleted the moment transcription finishes; no one is identified by their voice. A transcript pasted in from another tool does not go through this process, and the manager is responsible for having the right to use it.

Export and deletion

Yours to take, yours to erase

Export. Settings has a full export of everything your account has written, every table, as one JSON file, on every plan. Meeting notes and roll-ups can also be copied out as Markdown.

Deletion. Deleting your account asks you to type DELETE and to re-enter your password. Then, in order: any subscription is cancelled, and if that fails nothing is deleted; your name, email and the names of the people in your records are removed from the audit trail; the account and every record it owns are deleted in one cascade at the database level; stored photos and recordings are swept. Stripe keeps the invoices the law requires and nothing else.

Backups. Backups run nightly and are kept for seven days, so a deleted account is gone from them within a week. We do not run continuous point-in-time backup, which means an incident could lose up to a day of changes made since the last nightly copy.

Retention

How long things are kept

What is kept, for how long, and why.
DataKept forNotes
Your account and everything you wroteWhile the account existsDeleted in one cascade when you delete the account.
Audit log (who did what, with IP address and browser)12 monthsSo a question about an account's history can be answered. Pruned weekly.
Product analytics (which pages and features were used; no content, no names)90 daysAnonymous id in your browser, first-party, no third-party scripts. Pruned weekly.
Recording audioUntil transcription finishes, then deletedOnly the transcript you keep remains. The transcription provider may hold audio up to 30 days for misuse checks.
Unused recording-consent links30 days after they closeA link nobody used is evidence of nothing.
Share links to a team member's page or a review180 days (page), 90 days (review)Then the link stops working; you can issue a new one.
Nightly backups7 daysA deleted account leaves the backups within a week.

Providers

Who else processes your data

Running a cloud service takes infrastructure. These are all of the third parties that can touch your data, what each one sees, and whether it sees anything at all unless you turn a feature on. Each acts only on our instructions. No other third party receives your data, and none receives it for its own purposes. The same list appears in the privacy policy, which we update before any change to it takes effect.

Every provider that processes data, its purpose, what it receives, and whether it is optional.
ProviderPurposeWhat it receivesWhen
SupabaseDatabase, sign-in and file storageEverything you store: your account, team profiles, agendas, working notes, goals, reviews and transcripts.Always
CloudflareHosting, network and TLS; routes mail to our support addressEvery request in transit, server logs, and inbound support email.Always
StripeSubscription billing for the Solo planYour name, email and payment method, on Stripe's own pages. Card numbers never reach our servers, and Stripe never sees 1:1 content.Only if you use it
ResendEmail: the pre-1:1 brief, reminders, roll-ups, a team member's page link, and recording-consent requestsRecipient addresses and whatever the message carries: names, meeting times, agenda and action-item text, and the consent wording with its single-use links.Always
AnthropicAI-polished roll-ups and drafting notes from a transcript (Solo)The roll-up text or transcript being drafted from, when you use the feature. Not used to train models; may be kept up to 30 days for misuse checks.Only if you use it
OpenAITranscribing a recorded meeting (Solo)The audio of a meeting, only for a person who agreed from their own inbox. We delete the audio the moment transcription finishes; OpenAI may keep it up to 30 days for misuse checks, and does not train on it.Only if you use it
GoogleCalendar sync, if you connect a Google CalendarEvent times, titles and attendee emails, to recognise your 1:1s and book new ones. Free/busy times are shown while you schedule and never stored.Only if you use it

Boundaries

What we do not do


  • Sell, rent or trade your data, or share it with anyone for their own use.


  • Show advertising, ours or anyone else's, or run advertising pixels or cross-site trackers.


  • Train any AI model on your content, or let a provider do so.


  • Read your content, except to fix a problem you asked us to fix or where the law requires it.


  • Score, rate, rank or tier a person, or make any automated decision about pay, promotion or continued employment.


  • Record anyone who has not agreed from their own inbox.

Reporting

Found a problem?

Email support@drivemypath.com. The same address is published in our security.txt. We read every report, and a report that describes how to reproduce the problem gets fixed fastest.

Questions

Questions people ask


Is Drive My Path SOC 2 certified?

No, and this page does not claim it. It describes the controls that are in place today: encryption in transit and at rest, row-level isolation enforced by the database, consent-gated recording, full export and deletion, and a short list of providers. We keep internal records against the SOC 2 criteria so that an audit is possible later, but no audit has been performed.


Do you train AI on my notes?

No. Nothing you write is used to train any model, ours or a provider's. When you choose an AI feature (an AI-polished roll-up, or notes drafted from a transcript), the relevant text is sent to Anthropic to produce that one output and is not used for training. The Terms forbid us from reserving training rights.


Can my employer or HR see my working notes through Drive My Path?

Not through Drive My Path. Row-level security means no other account can read your records, and the page a team member sees shows only the fields marked shareable, never working notes. Like any record you keep about work, your notes could still be requested in a legal dispute, which is why the product calls them working notes rather than promising secrecy.


Where is my data stored?

In the United States. The database and file storage run on Supabase in the us-east-1 region; requests pass through Cloudflare's network. Where transfer terms are required, the standard contractual clauses are incorporated by reference in the privacy policy.


What happens to my data if I delete my account?

Deletion asks you to type DELETE and re-enter your password. Billing is cancelled first, then names and email addresses are removed from the audit trail, then the account and every record it owns are deleted in one cascade, then stored photos and recordings are swept. Nightly backups are kept for seven days, so within a week no copy remains.