Privacy Policy
Last updated: July 27, 2026
📜 MeetingVault Privacy Policy (V1)
Last Updated: February 27, 2026
MeetingVault (“MeetingVault”, “we”, “our”, or “us”) is a device-native, privacy-first meeting intelligence platform that converts meeting recordings and transcripts into structured project documentation.
This Privacy Policy explains how we collect, use, disclose, and protect your information when you use:
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
-
Name
-
Email address
-
Authentication credentials (managed via Supabase Auth)
-
OAuth data (if signing in via Google)
-
Profile metadata (avatar, timestamps)
Email verification is required before access to protected features.
1.2 Meeting Content
When you use MeetingVault, we collect:
-
Audio recordings you upload or record
-
Transcripts generated from recordings
-
Pasted transcript text
-
AI-generated meeting minutes (MOM)
-
Extracted action items, decisions, risks
-
Status reports
-
Transcript Q&A queries and AI responses
-
Translations and humanized variants
-
AI-generated audio recap files
Audio files and recap files are stored in a secured storage bucket.
1.3 Anonymous Usage Data
If you use “Try It Now” without signing up:
-
Device fingerprint (browser characteristics)
-
IP address
-
Usage counts (transcriptions, MOM generations)
-
Conversion tracking if you later register
This is used strictly for rate limiting and abuse prevention.
1.4 Usage & Analytics Data
We collect limited technical data for:
-
Performance monitoring
-
Error tracking
-
Feature usage analytics
-
Security monitoring
Tools used:
-
PostHog (product analytics)
-
Vercel Analytics (web performance)
-
Sentry (error tracking)
Analytics do not intentionally capture transcript content.
1.5 Billing Information
If you subscribe:
-
Subscription status
-
Plan type
-
Payment provider references
Payments are processed via third-party payment provider DoDo Payments. MeetingVault does not store full card details.
1.6 Admin & Security Logs
We maintain:
-
Audit logs of administrative actions
-
Security alerts
-
Rate limit enforcement logs
-
Blocked IP records
Admin impersonation sessions are logged and audited.
2. How We Use Your Information
We use your information to:
-
Authenticate users
-
Enforce feature entitlements and rate limits
-
Transcribe audio
-
Generate AI summaries and structured outputs
-
Provide transcript Q&A
-
Generate audio recaps
-
Deliver translations and humanized variants
-
Provide project analytics and reports
-
Monitor system health
-
Prevent abuse and fraud
-
Comply with legal obligations
We do not sell your personal data.
3. AI Processing Disclosure
MeetingVault uses third-party AI providers to process meeting content, including:
-
AI transcription
-
AI summarization
-
AI extraction
-
AI translation
-
AI chat
-
AI audio recap generation
AI requests are routed through an AI provider infrastructure.
Meeting content is transmitted securely over HTTPS.
AI outputs may contain inaccuracies. Users are responsible for reviewing generated content before relying on it.
4. Data Storage & Security
4.1 Infrastructure
MeetingVault uses:
-
Supabase (PostgreSQL, Auth, Edge Functions, Storage)
-
Secure HTTPS communication
-
Encrypted token storage on desktop (Stronghold vault)
-
Signed URLs for file access
4.2 Desktop Upload Queue
The desktop application may temporarily store audio uploads locally in a SQLite queue to ensure reliability across restarts. These files are uploaded securely and processed once connected.
4.3 Access Controls
-
Role-based access control
-
Admin action audit trails
-
Email verification requirements
-
Rate limiting and abuse detection
5. Data Retention
We retain:
-
Account data until account deletion
-
Meeting content until deleted by user
-
Billing records as required for accounting/legal purposes
-
Audit logs for security purposes
Users may delete their account via the account deletion workflow. Deletion cascades to associated projects and meeting content.
6. Your Rights
Depending on your jurisdiction, you may have rights to:
-
Access your data
-
Correct inaccuracies
-
Delete your data
-
Export your data
-
Restrict processing
MeetingVault provides:
-
Data export functionality
-
Account deletion workflow
To exercise rights, contact: support@meetingvault.ai (placeholder)
7. International Data Transfers
Your data may be processed in jurisdictions outside your country. By using the service, you consent to such transfers.
8. Recording Consent
MeetingVault records audio only when explicitly initiated by the user.
You are solely responsible for complying with all applicable recording and consent laws in your jurisdiction.
9. Children’s Privacy
MeetingVault is not directed to children under 13. We do not knowingly collect personal data from children.
10. Changes to This Policy
We may update this Privacy Policy. Continued use constitutes acceptance of updates.
11. Contact
For privacy inquiries:
Sub-processors
We use the following sub-processors to operate the Service. Your meeting audio and transcripts are transmitted over the internet to AI providers for transcription and structured-output generation — they are not processed solely on your device.
- Supabase — database, authentication, and file storage (all user data and files).
- Google (OAuth) — authentication, if you sign in with Google.
- OpenRouter and fallback AI gateways — routing of audio/transcripts to AI models.
- Third-party AI model providers (e.g., Google Gemini), accessed via the gateways above — transcription, summarization, Q&A, and text-to-speech.
- Brevo — transactional and lifecycle email delivery (email address, name).
- Sentry — error monitoring and diagnostics.
- PostHog (if enabled) — product analytics.
- Vercel — web hosting and analytics (IP address, request metadata).
- FingerprintJS — device identification for abuse prevention.
- DoDo Payments (if enabled) — payment processing.
Audio Retention
Raw recording audio is automatically deleted from cloud storage approximately 30 days after the meeting is created. Your transcript, minutes, decisions, action items, and AI audio recaps are retained until you delete them or close your account — only the raw voice recording is removed on the rolling 30-day schedule. This minimizes how long your voice data is stored while preserving the meeting outputs you rely on.
Analytics in the Desktop & Mobile Apps
On the web, product analytics load only after you accept analytics in our cookie banner. In the desktop and mobile apps, first-party product analytics (PostHog) run under our legitimate interest in understanding usage and improving the Service — they are not advertising and never capture your recordings, transcripts, or meeting content. You can turn them off at any time in your profile's Privacy settings (the “Share usage analytics” toggle). On iOS, analytics are additionally gated by the system App Tracking Transparency prompt.
Your Data Export (Access & Portability)
You can download a complete, machine-readable copy of all your account data as a JSON file from Subscription & Usage → “Download a copy of all your data.” The export covers your profile, projects, meetings, transcripts (including sentence-level segments and speaker labels), AI summaries, action items, decisions, risks, usage history, subscription and billing history, feedback, and bug reports. Your raw recording audio is included as time-limited secure download links (valid for 7 days). This supports your right of access and data portability (e.g. GDPR Articles 15 and 20).
Web Analytics
On our website, after you accept analytics in the cookie banner, we load Microsoft Clarity (session analytics and heatmaps) and Google Analytics (aggregate usage analytics), alongside Vercel Analytics for privacy-friendly traffic measurement. These tools never capture your recordings, transcripts, or meeting content. If you choose “Essential only,” none of them load. See our Cookie Policy for details.