Summary
- Your meeting audio is streamed to a transcription provider on the default settings. It is relayed through our server, transcribed, and discarded. We do not record or store it.
- You can switch to an on-device engine in settings, and then no audio leaves your machine at all.
- Transcripts are not stored on our servers. Meeting reports are built and kept on your device.
- We never sell personal data, and we do not use your content to train models.
- You can delete your account and everything attached to it from the dashboard, immediately.
Who we are
Meeting Flow (Bangladesh) is the data controller for the personal data described here. You can reach us at privacy@meetingflow.app or through the contact page.
Meeting audio and transcripts
This is the part most people are here for, so it is first and it is specific.
On the default setting, audio is sent to a provider
Meeting Flow ships with live cloud transcription selected, because it is the only engine fast enough to detect that a speaker has finished and start an answer immediately. On that setting, the audio lanes you have enabled — your microphone, the other party’s system audio, or both — are streamed over an authenticated, encrypted relay we operate, and forwarded to Deepgram for transcription.
- The stream is transcribed in real time and is not written to disk by us.
- We do not retain the audio, and we do not retain the resulting transcript on our servers.
- Our relay exists so the provider credential never reaches your computer. It passes audio through; it does not archive it.
- A lane nobody is speaking into disconnects automatically. This is primarily a cost measure, but it also means silence is not transmitted.
You can turn that off
Settings → Speech Recognition offers on-device engines (a local Whisper model, or macOS dictation). With one of those selected, audio is processed in memory on your own hardware and never transmitted. The settings screen labels each engine with whether audio leaves your machine, and the app indicates when a cloud engine is active during a meeting.
Answer generation
To produce an answer, the app sends the relevant transcript text and your context profile to a model provider. It does not send audio, your email, your name, or billing details. If you use screen capture, the image of the window you explicitly selected is sent to a vision model for that single request and is not stored.
What we collect
Account data
- Email address and display name, to sign you in and contact you about your account.
- Email confirmation status. Confirming your address is required before AI features unlock, which is how we keep automated signups from draining the free allowance.
- Country and currency preference, to show and charge the right price.
- A Stripe customer identifier. Card details are held by Stripe, never by us.
Context you provide
- The role, company, job description, résumé text and notes you enter on your context profile. This is the material the assistant reasons from, and you can clear it at any time.
Usage data
- Per-request records: request type, which model answered, token counts, audio duration and credit cost. These enforce your plan limits and power the usage charts in your dashboard. They contain no transcript text.
- Rate-limit counters, so a runaway client cannot exhaust your allowance or degrade the service for others.
- Session records: meeting type, duration, and how many questions were answered. Transcript content is not included.
- Service health events: which provider handled a request, whether it succeeded, and how long it took.
Why we may hold it
For users in the UK, EU and other regions with equivalent law, our legal bases under Article 6 GDPR are:
- Contract — account data, subscription state, usage counters and audio processing during a meeting. Without these we cannot provide the service you signed up for.
- Legitimate interests — rate limiting, abuse prevention, service health monitoring and security logging. We have balanced these against your rights and kept the data minimal and non-content.
- Legal obligation — invoice and tax records retained by our payment processor.
We do not rely on consent for the processing above, and we do not carry out automated decision-making that produces legal or similarly significant effects.
Processors
- Supabase — database, authentication, edge functions and the transcription relay. Holds your account, subscription and usage records. Project region: Singapore (ap-southeast-1).
- Deepgram — live speech-to-text. Receives meeting audio while a cloud engine is selected. Receives no account identifiers.
- Model providers (Google, OpenAI, OpenRouter) — receive transcript text, your context profile, and any screenshot you deliberately capture, in order to generate an answer. They receive no email, name or billing information. Our provider routing is configured to decline data collection for training where the provider offers that control.
- Stripe — payments, invoices and the customer portal. Receives your email and billing details directly.
- Vercel — website hosting and delivery. Receives request metadata and logs. Global edge network.
- Sentry — error reports from the site and app. Contains stack traces and a user id, not transcript content. United States.
Only two of these ever receive meeting audio, and only while a cloud transcription engine is selected: Supabase, whose relay passes it through without storing it, and Deepgram, which transcribes it. Everyone else receives text. Selecting an on-device engine removes both from the path.
Model providers and Deepgram operate primarily in the United States; Stripe in the United States and Ireland. We will update this page before adding a processor that receives personal data.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
International transfers
Our processors operate in several countries, including the United States. Where personal data leaves the UK or EEA, transfers are covered by the processor’s Standard Contractual Clauses or an equivalent approved mechanism, as set out in their own data processing terms.
Retention
- Meeting audio — not retained. Processed in transit and discarded.
- Transcripts — not retained on our servers. Anything kept locally is on your device and under your control.
- Account and subscription records — for as long as the account exists.
- Usage and billing counters — 24 months, for billing accuracy, support and dispute resolution.
- Service health events — 90 days.
- Context profile — until you change or clear it.
- On deletion — everything tied to your user id is removed by cascade. Stripe retains invoice records separately, as tax law requires.
Security
- All traffic to our servers and providers is encrypted in transit (TLS 1.3 for the audio relay).
- Provider API keys are held only in server-side edge functions. They are never delivered to the desktop app, which is why transcription is relayed rather than connected directly.
- Database access is constrained by row-level security, so one account cannot read another’s records.
- Screen capture is limited to the specific window you select; it has no display-level fallback.
No system is perfectly secure, and we do not claim otherwise.
Your rights
Depending on where you live, you may have the right to access, correct, delete, port, restrict or object to our processing of your personal data, and to withdraw consent where we rely on it. California residents have equivalent rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them.
You can view and edit your context profile, usage and account details in the dashboard at any time. Account → Danger zone deletes the account and all associated records immediately and irreversibly. For an export or any other request, email privacy@meetingflow.app and we will respond within 30 days. If you are unhappy with our response, you may complain to your local data protection authority.
Children
Meeting Flow is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.
Cookies
The site sets only what it needs to keep you signed in — session cookies issued by Supabase authentication — and a preference cookie recording your currency selection. There is no advertising or cross-site tracking, which is why you are not being asked to dismiss a consent banner.
Breach notification
If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and tell you directly without undue delay where the risk is high.
Changes to this policy
We may update this page. Material changes — particularly any change to where your audio goes — will be announced by email or in the app before they take effect, and the date at the top of this page will change.
Contact
Questions about this policy, or a request about your data: privacy@meetingflow.app or the contact page.