Security & privacy

Anonymous by design, not by promise.

Most "anonymous" channels ask you to trust that no one will look. We built Proper Feedback so there's nothing to look at. Caller identities aren't protected behind a permission — they're never stored in a form anyone could retrieve. Here's exactly how that works.

What happens to a call

1

The number is hashed on the way in

Before a caller's phone number ever touches our database, it's run through a one-way hash with a secret key stored outside the database. We keep the hash, never the number.

2

The voice is masked before storage

The caller chooses how they want to sound — their own voice, a pitch shift, or a different voice entirely. Masking is applied before the audio is written to disk. The original recording is discarded.

3

It's transcribed and screened

The masked audio is transcribed and auto-screened for threats, doxxing, hate speech, and CSAM. Clear cases are blocked; borderline ones are held for a human moderator.

4

It lands in your inbox — without an identity

You receive the transcript, the tags, and the masked audio. You do not receive, and cannot request, a caller's identity. There is no admin setting that reveals it.

There is no setting in your admin panel that exposes caller identities, because the data doesn't exist anywhere to expose.
The privacy model, in one sentence

Why the hash, not the number

We keep the hash for one reason only: rate-limiting spam. If the same caller floods a line, we can throttle the hash without ever knowing who they are. The hash can't be reversed to a phone number, and the secret that produces it lives outside the database — so even a full database breach reveals no caller identities. We use the hash for nothing else.

How your data is protected

Encrypted in transit & at rest

All traffic runs over TLS. Stored audio and transcripts are encrypted at rest. Access is scoped to your organization.

Screened in both directions

Callers stay anonymous; recipients stay safe. Abuse is caught before it lands, with a moderation threshold you control.

Data minimization

We collect what's needed to run the line and nothing more. No caller identities, no original recordings, no ad trackers.

Audit logs & SSO

SAML SSO, SCIM provisioning, and admin audit logs on Enterprise — so you control who on your side can see what.

Retention you control

Set how long transcripts and audio are kept, then auto-deleted. Export anytime; delete on demand.

Compliance packages

HIPAA, SOX, and FERPA packages, plus data-processing agreements, available for Enterprise deployments.

What we never do

Disclosure & legal requests

Because caller identities aren't stored, we can't produce them — not for you, not in response to a subpoena. We can provide the masked audio and transcript that exist; we cannot provide an identity that was never collected. The full legal detail lives in our Privacy Policy and Terms.

Have a security question?

Reviewing us for a procurement or security assessment? We're happy to walk through the architecture and share documentation.

Contact security → Or walk the live dashboard to see the no-identity model in action.