Privacy Policy
MeetViz sends a bot into your meeting, turns what is said into a live wall of notes, and hands you a written record afterwards. That means it handles what people say in meetings — the most sensitive thing a tool like this can touch. This page says exactly what is collected, who else sees it, how long it is kept, and how to get rid of it. No dark corners.
1. Who is responsible
MeetViz (“the Service”) is operated by MeetViz, the controller of the personal data described here. You can reach us at privacy@meetviz.com for any privacy question, including a request to access or delete your data.
If you use MeetViz inside an organisation that runs its own deployment, that organisation is the controller for the meetings it records, and this policy describes what its deployment does on its behalf.
2. What we collect
Account data (Google sign-in)
Signing in uses Google with the scopes openid, email
and profile — nothing more. From your Google profile we receive
and use your Google account identifier, email address, display name
and profile picture URL. We do not request, and cannot read, your
Gmail, your Drive, your contacts or your Google Calendar.
Your identity is kept in a signed, HttpOnly session cookie
(mv_session, 30 days) and stored alongside each wall you create,
so that only you can edit, end, deliver or delete it.
Meeting content
When you send the bot into a meeting, our transcription provider joins that meeting as a visible participant with a name and a video feed, converts speech to text in real time, and sends us that text with speaker labels. MeetViz stores the transcript text, the successive versions of the wall built from it, and your corrections. MeetViz does not store meeting audio or video; the recording that produces the transcript is held by the provider named in section 5 under its own retention rules.
The wall the bot broadcasts back into the meeting as its camera is a public view of that meeting’s own notes — it shows nothing from any other meeting.
Transcripts you upload
If you paste or upload a transcript (.vtt, .srt,
.txt, .json or plain prose), its contents are
processed and stored exactly like a live transcript, including any names,
personal details or confidential material inside it.
Microphone mode
In microphone mode, speech recognition is performed by your browser through the Web Speech API, not by us. In Chrome and other Chromium browsers this means your audio is sent to Google’s speech service for recognition under Google’s privacy policy. MeetViz receives only the resulting text. Your browser will ask for microphone permission first; declining it simply means no notes are produced.
Calendar (optional, off by default)
A deployment can be configured with a secret iCalendar (.ics)
feed URL so the bot joins scheduled meetings by itself. When that is on, we
read event titles, times and meeting links from that feed.
This uses a URL the operator supplies — it is not an OAuth connection, and it
gives us no access to your Google Calendar account.
Technical data
Our servers keep ordinary operational records: IP address, request time, page or endpoint requested, browser user-agent, and error diagnostics. We use no advertising or analytics trackers, and set no cookies other than the sign-in cookie described above.
3. Google user data and Limited Use
MeetViz’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, the data we receive from Google sign-in is used only to:
- identify you when you sign in and keep you signed in;
- mark you as the owner of the walls you create, so only you can change them;
- show your name, email and picture back to you in the interface;
- check your address against the deployment’s allowlist, where one is set.
We do not sell it, do not use it for advertising or profiling, do not transfer it to third parties except as needed to run the Service or where the law requires it, and do not use it to train any machine-learning model. You can revoke MeetViz’s access at any time at myaccount.google.com/permissions.
4. Why we may process it (legal bases)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Running the Service you asked for — transcribing, drawing the wall, producing the record | Performance of a contract (Art. 6(1)(b)) |
| Sign-in, ownership and access control | Performance of a contract (Art. 6(1)(b)) |
| Microphone capture in your browser | Consent, given through the browser permission prompt (Art. 6(1)(a)) |
| Keeping the Service secure, debugging failures, preventing abuse of model spend | Legitimate interests (Art. 6(1)(f)) |
| Delivering the record to the channels the operator configured | Performance of a contract (Art. 6(1)(b)) |
A meeting transcript can contain special categories of data (health, opinions, and so on) if participants happen to discuss them. MeetViz does not seek such data; the person who invites the bot is responsible for whether a given meeting should be transcribed at all — see section 8.
5. Who else processes your data
MeetViz is a thin layer over a small number of specialist services. Each acts as our processor under a data-processing agreement.
| Provider | What it does | What it sees |
|---|---|---|
| Recall.ai | Joins the meeting as a bot, transcribes speech, renders the wall as the bot’s camera | Meeting audio and video, transcript, participant names |
| Anthropic (Claude), directly or through AWS Bedrock | Turns transcript text into the notes on the wall and the written record | Transcript text and your corrections |
| Amazon Web Services | Hosts the application and its stored data (US East region) | Everything stored by the Service |
| Sign-in; and, in microphone mode, browser speech recognition | Your account identity; microphone audio in that mode only | |
| Delivery channels (only if configured) | Sends the finished record to Slack, a webhook, or an email address | The record and its transcript excerpts |
Your content is not used to train AI models. Anthropic does not train its models on inputs submitted through its API, and the same holds for model calls made through AWS Bedrock.
These providers are established in the United States, so running the Service involves transferring data outside the European Economic Area. Those transfers rely on the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
6. Who can see a wall
- You, as the person who created it.
- Anyone holding the share link, which carries a secret view token. That link is read-only, it cannot be guessed, and it is also what the meeting bot uses — because a bot cannot sign in. Treat it like a password: anyone you send it to can read the wall and the transcript. A link without the token is refused.
- The recipients of the delivered record, where the operator has configured Slack, email or webhook delivery.
We do not publish walls, sell data to anyone, or share it with third parties beyond the processors in section 5 — except where we are legally compelled to, or where it is necessary to establish or defend a legal claim.
7. How long we keep it
- Walls, transcripts and records are kept until you delete them. Deleting a wall removes its transcript, its version history and its notes from our storage, permanently and immediately.
- Version history is capped, so a long session keeps a sample of its earlier states rather than every one.
- The sign-in cookie expires after 30 days, or immediately when you sign out.
- Server logs are kept for a short operational period and then rotated away.
- Recordings held by the transcription provider are subject to that provider’s retention policy, not ours.
8. Recording other people
Whoever invites the bot is responsible for the recording being lawful. In many countries, and in several US states, everyone in a conversation must be told it is being recorded, and sometimes must consent. Do not send the bot into a meeting you are not entitled to have transcribed.
MeetViz is deliberately not a hidden recorder: the bot appears as a named participant in the participant list and shows a live wall as its camera, so the room can see it is there. That helps, but it does not replace telling people — and where consent is required, obtaining it.
If you took part in a meeting recorded through MeetViz and want your data removed, write to privacy@meetviz.com. We will pass the request to the person who owns that wall and help carry it out.
9. Your rights
Under the GDPR and comparable laws you may request access to your personal data, correction of it, erasure of it, restriction of or objection to its processing, and a portable copy of it; where processing rests on consent, you may withdraw that consent at any time. Most of this you can do yourself: a wall’s export gives you a copy, and deleting the wall erases it. For anything else, write to privacy@meetviz.com and we will respond within 30 days.
You also have the right to lodge a complaint with your local data protection supervisory authority.
10. Security
- All traffic is served over HTTPS.
- The sign-in cookie is
HttpOnly,SameSite=Lax, cryptographically signed, and markedSecurein production, so page scripts cannot read it and it cannot be forged. - Walls are readable only by their owner or by a holder of the secret view token, and writable only by their owner.
- A deployment can restrict sign-in to named addresses or a single email domain.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to privacy@meetviz.com rather than disclosing it publicly.
11. Children
The Service is intended for use at work and is not directed at children under 16. We do not knowingly collect their data; if you believe we have, contact us and we will delete it.
12. Changes to this policy
We will update this page when the Service changes, and move the date at the top. Material changes to how we handle your data will be announced in the application before they take effect.
13. Contact
MeetViz — privacy@meetviz.com