Privacy Policy
Last updated: 11 October 2026
This Privacy Policy explains how Meeti ("we", "us") collects, uses and protects your personal data when you use our web, iPhone and Android apps. It should be read with our Terms of Service and AI Policy.
1. Who we are
Meeti is operated by [SET: legal entity name], [SET: registration number], [SET: registered address]. Data protection contact: [SET: privacy email, e.g. privacy@meeti.org.uk].
2. Data we collect
- Account data: email address and password (stored as a bcrypt hash), and your name/profile details.
- Meeting content: audio recordings you upload or capture, and the transcripts, summaries, notes, decisions and action items generated from them.
- Usage data: meeting metadata such as titles, dates, language and status.
- Device/connection data: information needed to deliver and secure the service.
- Analytics: [SET: list any analytics tools you actually use, or state "we do not use third-party analytics"].
3. How we use your data and legal basis
- To provide transcription, AI summaries, task tracking and exports — performance of a contract.
- To authenticate you and secure your account — legitimate interest / contract.
- To send service notices (e.g. reminders you enable) — contract / consent.
- To comply with law and prevent abuse — legal obligation / legitimate interest.
4. Who we share your data with
- OpenAI — transcription (Whisper) and analysis/translation (GPT‑4). See our AI Policy.
- Amazon Web Services (AWS) — hosting, the PostgreSQL database and S3 storage for recordings (US East region).
- Upstash — managed Redis for background job queues.
- Google (Drive, Gmail, Calendar) and Slack — only if you connect them and choose to export.
- Payment processor: [SET: name (e.g. Stripe) once billing is enabled, or state "we do not currently process payments"].
- We do not sell your personal data.
5. International transfers
Your data is processed in the United States (AWS and OpenAI). Where transfers rely on safeguards, we use our providers' standard contractual measures. [SET: confirm additional safeguards if you serve UK/EU users].
6. Retention
- We keep your recordings and notes until you delete them or delete your account.
- You can delete an individual meeting in the app at any time.
- To delete all data, delete your account or email us at [SET: privacy email].
- We may retain limited data where the law requires it.
7. Your rights
Subject to applicable law, you can request access, correction, deletion, objection, data portability, and withdrawal of consent. Contact [SET: privacy email]. You also have the right to complain to a data protection authority — see section 10.
8. Security
- All traffic between your device and our servers uses HTTPS/TLS.
- Passwords are hashed with bcrypt; access uses short-lived signed tokens (JWT).
- Storage and database are protected by provider-side access controls and encryption at rest.
- No method of transmission or storage is perfectly secure.
9. Children
Meeti is not directed at children under [SET: age limit, e.g. 18 / 16]. We do not knowingly collect their data.
10. Complaints and regulator
You may complain to the data protection authority in your country. For users in Uganda this is the Personal Data Protection Office; for UK users, the Information Commissioner's Office (ICO). [SET: confirm which regulators apply to you and whether you are registered].
11. Changes
We may update this policy. Material changes will be noticed in the app or by email to [SET: support email].