Privacy Policy
Effective 2026-05-21
This Privacy Policy describes how Meetly.Online ("we", "us", or "Meetly") collects, uses, and shares personal information when you use our meeting-notes service available at https://meetly.online.
1. Who we are
Data controller: Meetly.Online
2. Information we collect
We collect the following categories of personal data:
- Account data: your email address, name (if provided), hashed password, plan tier, and account timestamps. Created when you register.
- Meeting data: Google Meet URLs you provide; the audio recording of each meeting you start; the resulting transcripts and AI-generated summaries. We retain this for as long as your account exists or until you delete the meeting (whichever is sooner).
- Usage data: meeting counts, login timestamps, IP-address-of-record (for security logging), and basic browser/device metadata when you interact with our web app.
- Billing data: handled by our payment processor (Freemius). We receive license metadata, never card numbers.
3. How we use your data
- To provide the meeting capture, transcription, and summary service.
- To authenticate you and protect your account (rate limiting, fraud detection).
- To bill you for paid plans, via Freemius.
- To respond to support inquiries.
- To comply with legal obligations.
Legal basis (GDPR Art. 6): contract performance for service delivery and billing; legitimate interest for security logging; consent for any optional features we may add (e.g. marketing emails).
4. Meeting recording consent
Meetly is designed for consent-based recording. The agent joins as a visible participant and posts a notice in the meeting chat that it is recording. You are responsible for ensuring all participants have consented under your local laws (e.g. all-party consent jurisdictions in the EU, GDPR Art. 5).
5. Third-party processors
We use the following service providers to deliver the service:
| Processor | Purpose | Region |
|---|---|---|
| OpenAI, L.L.C. | Speech-to-text (Whisper) and summarization (GPT models). | United States |
| Anthropic, PBC | Alternative summarization engine (Claude models). | United States |
| Freemius, Ltd. | Billing, checkout, taxation, and license issuance. | Israel / United States |
| Google LLC | Meeting platform (Google Meet) where the agent joins as participant. | United States |
| MongoDB / Self-hosted infrastructure | Storage of transcripts, summaries, and account metadata. | European Union / configured by us |
Where data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) and other appropriate safeguards.
6. Data retention
- Meetings: deleted when you delete them, or after the retention period configured for your plan (default 30 days for free, longer for paid plans).
- Audio recordings: stored only until full-audio transcription completes and you've had a chance to play them back. Auto-deleted after the meeting's retention window.
- Account data: kept while your account is active. On account deletion, data is removed within 30 days (logs may be retained longer for security).
- Audit logs: retained for up to 12 months for security and compliance.
7. Your rights
Under GDPR (and similar laws like CCPA), you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and associated data ("right to erasure").
- Export your transcripts and summaries in machine-readable formats (PDF, Markdown).
- Object to certain processing or withdraw consent.
- Lodge a complaint with your local supervisory authority.
To exercise any of these rights, email privacy@meetly.online. We respond within 30 days.
8. Security
Passwords are stored hashed with bcrypt. Sessions are stored as HttpOnly cookies signed with a server-side secret. Encrypted Google login state is sealed at rest with AES-256-GCM. Communication over TLS in production. Audio files are deleted after retention. We regularly review access controls and audit logs.
9. Cookies
We use only essential cookies (session, theme preference). See our Cookie Policy for details.
10. Children
Meetly is not intended for users under 16 years old. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this policy from time to time. We will notify you of material changes via email or via a prominent notice on the dashboard before they take effect. The "Effective" date at the top reflects the current version.
12. Contact
Questions or complaints? Email privacy@meetly.online.