Legal
Privacy Policy
Last updated: June 30, 2026
1. Introduction
MeetBase (operated by [Legal Entity Name], [Registered Address]) provides an AI-powered personal assistant that joins your meetings, transcribes them, and syncs your Google Calendar. This Privacy Policy describes how we collect, use, and protect information when you use our services. If you do not agree, please do not use MeetBase. Effective date: June 30, 2026.
2. Information We Collect
(a) Account & identity — When you sign in with Google, we receive your name, email address, and profile picture via Google Sign-In (OAuth 2.0).
(b) Google Calendar data — With your authorisation, MeetBase accesses your Google Calendar via the Google Calendar API using a read-only OAuth scope. We store your OAuth refresh token to sync your calendar on your behalf. We access event titles, dates and times, attendee lists, and conference/Google Meet links.
(c) Meeting content — When you opt a specific meeting in, our bot joins as a named, visible participant. We capture the meeting audio and use it to generate transcripts, summaries, decisions, and action items. We store these outputs linked to your account.
(d) Usage and technical data — We collect standard server logs, device/browser information, IP addresses, and in-product usage events to operate and improve the service.
(e) Cookies — We use strictly necessary cookies to keep you signed in and to secure your session. For details on the cookies we use and how to manage them, see our Cookie Policy.
3. How We Use Your Information
We use your information to: provide and operate the MeetBase service; generate, store, and display transcripts, summaries, decisions, and action items; authenticate you and secure your account; detect abuse, debug issues, and improve the service; communicate with you about the service. We do not use your data for advertising or sell it to third parties.
4. Meeting Recording & Consent (Important)
Our meeting bot joins as a named, visible participant — it does not record covertly or impersonate a human. The bot's display name makes its presence apparent to all participants. You are responsible for ensuring all meeting participants are informed and that you have the legal right to record, prior to enabling the MeetBase bot for any meeting.
Recording consent laws vary significantly by jurisdiction. Many jurisdictions — including several US states (e.g., California, Illinois) and EU member states under the GDPR — require all-party consent before a conversation may be recorded. It is your obligation to comply with applicable law. MeetBase provides tooling to support compliance: the bot is always visible, and you can remove it from any meeting at any time to stop recording.
5. How We Share Information / Sub-processors
We do not sell your personal data. We share information only with service providers (“sub-processors”) that help us operate the service, under appropriate data processing agreements.
| Provider | Purpose | Data shared |
|---|---|---|
| Google LLC | Sign-in (OAuth), Google Calendar API, AI summarization (Gemini API) | Identity data, calendar data, transcript text |
| Supabase, Inc. | Database, authentication, file storage | Account data, calendar data, transcripts, summaries, OAuth tokens |
| Deepgram, Inc. | Speech-to-text transcription (where cloud speech services are used) | Meeting audio, transcript text |
| Vercel Inc. | Web application hosting | Technical and usage data |
| Hetzner Online GmbH (Germany, EU) | Backend processing and meeting-bot infrastructure | Meeting audio and transcript text during processing |
This list reflects our current architecture and may be updated. Contact us at [privacy@...] for the current list.
6. AI Processing & Training
We do not use your meeting content, transcripts, summaries, or other personal data to train our own AI models or any third-party foundation models. Our AI sub-processors (including Google Gemini) are contractually restricted from training on your data when accessed via their API.
7. Data Retention & Deletion
We retain your data for as long as your account is active. You may delete individual meetings and their transcripts/summaries from within the app at any time, or delete your account entirely which removes all associated personal data. Account deletion can be initiated in app settings or by contacting us at [privacy@...].
8. Security
We protect your data with: encryption in transit (TLS/HTTPS) and at rest; row-level security for per-user data isolation; restricted and logged internal access. For more detail, see our Trust & Security page.
9. Your Privacy Rights
GDPR (EU/EEA): you have the right to access, rectify, erase, and port your personal data; to restrict or object to processing; and to withdraw consent.
CCPA (California): you have the right to know what data we collect, to request deletion, and to opt out of sale of personal data — we do not sell personal data.
Contact [privacy@...] to exercise any rights.
10. Google API Limited Use Disclosure
MeetBase's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve the features visible to the user within MeetBase; we do not use it for serving ads, for unauthorized data sharing, or for purposes unrelated to the service.
11. International Data Transfers
Your data may be processed in the United States and the European Union. Where data is transferred from the EEA, we rely on appropriate legal mechanisms such as Standard Contractual Clauses.
12. Children
MeetBase is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, contact us at [privacy@...] and we will delete it promptly.
13. Changes to This Policy
We may update this policy from time to time. When we do, we will post the revised policy with an updated effective date. Material changes will be communicated via email or in-app notice.
14. Contact
For privacy-related questions or to exercise your rights: [privacy@...], [Legal Entity Name], [Registered Address].