Protecting journalistic sources in the AI era — a practical guide
June 4, 2026 · 5 min read · Privacy
Every journalist who has used an AI tool has wondered: where does my audio go? Who has access to what my source said? Could this be used against them?
They're legitimate questions. And they deserve specific answers, not generic privacy policies.
The fear: "where does my audio stay?"
Most AI transcription services process audio on external servers, store it for days or weeks, and use it — sometimes — to improve their models. For a journalist working with sensitive sources, that's unacceptable.
How Tangara handles your audio
The process is simple and verifiable:
- You upload the audio to Tangara's servers.
- The SHA-256 hash of the original file is calculated (for the Seal of Authenticity).
- The audio is sent to Groq for transcription via Whisper Large v3.
- The resulting text is saved in your account.
- The original audio is permanently deleted — from Tangara's servers and from Groq.
There are no backups. There is no copy in cold storage. There's no way to recover the audio once the transcription is complete.
Colombian Law 1581 — what it means in practice
Law 1581 of 2012 is Colombia's personal data protection law. Tangara complies with it in three specific ways:
- Informed consent: you accept the privacy policy before registering. The policy is in plain Spanish.
- ARCO rights: you can Access, Rectify, Cancel or Object to your data at any time by writing to hola@tangara.rumbi.io.
- Data in Colombia: the servers that process and store your data are hosted on Colombian infrastructure.
External technical verifications
Tangara doesn't just promise security — it demonstrates it:
- Mozilla Observatory: A+ (110/100) — the highest possible score. 9/9 OWASP security controls active.
- SSL Labs: A+ — perfect encryption on both servers (IPv4 and IPv6).
- TrustedSite: active security certification, verified weekly.
Your data is not used to train models
Tangara uses Groq's Whisper API, which, according to Groq's privacy policy, does not use requests to train models. Your transcription doesn't improve anyone's AI. It's yours, and it stays that way.