Cookie Policy

Ultimo aggiornamento 7 August 2026

You're in control of cookies. Essential cookies keep you signed in; analytics and Meta marketing measurement wait for your consent in some regions and run with an easy opt-out in the rest.

You choose

Accept all, reject non-essential, or pick by category — and change it anytime.

Marketing follows your region

Marketing measurement waits for your consent in most regions, and can be switched off anytime elsewhere.

Privacy-minimizing analytics

Analytics follow your cookie choices and never see your transcripts or recordings.

This Cookie Policy explains how Meeting.ai (Bahasalab Automation Pte. Ltd.) uses cookies and similar technologies (together, "cookies") on the Services. Terms not defined here have the meaning given in our Privacy Policy.

What are cookies?

Cookies are small text files stored on your device when you visit a site. Session cookies last until you close your browser; persistent cookies remain until they expire or you delete them. We also use related browser storage such as localStorage to remember settings and improve performance. Cookies may be first-party (set by us) or third-party (set by a provider we use).

How we use cookies

We use cookies to keep you signed in and secure, remember your preferences (such as language and workspace), understand and improve how the Services perform, and, where the Marketing category is allowed, support marketing. We group them into three categories.

Strictly necessary (always on)

Required for the Services to work — signing you in, keeping your session and workspace, protecting against fraud and abuse, and remembering your cookie choices. You can't turn these off in Cookie preferences, and they do not require consent.

Performance and analytics

Help us understand how the Services are used so we can improve them. We use PostHog for privacy-minimizing, schema-first product analytics; Google Analytics for pageview, campaign, and technical measurement; and Microsoft Clarity for heatmaps and session replay built from page structure and interactions such as clicks, scrolling, and navigation. Meeting.ai explicitly masks the full page before Clarity uploads it, so page text and images — including transcript, chat, file, and meeting contents — are not sent. These tools may process page URLs and browser, device, network, performance, and approximate-location metadata. They run only while the Performance category is allowed under your region's consent model (see Consent by region).

Marketing

Used to attribute visits and conversions and measure and improve Meeting.ai's own advertising campaigns. While the Marketing category is allowed (see Consent by region), we use the Meta Pixel in the browser and the Meta Conversions API on our servers. The Pixel may set marketing cookies and send page-view and attribution data to Meta; the Conversions API sends limited conversion data directly to Meta without setting browser cookies. Neither receives your meeting recordings, transcripts, summaries, notes, files, or chat contents from us.

Where you are determines how the Performance and Marketing categories start:

  • Consent-first regions (such as the European Economic Area (EEA) and the UK): Performance and Marketing cookies stay off until you allow them in the consent notice or Cookie preferences.
  • Opt-out regions (such as the United States): Performance and Marketing cookies run from your first visit and a notice tells you so (when your browser sends an opt-out signal such as Global Privacy Control, we apply it immediately instead and show no notice). You can opt out at any time — through Customize in the notice, Your Privacy Choices in the footer, or a browser opt-out signal such as Global Privacy Control (which turns off Marketing — see Do Not Track and Global Privacy Control).

Not sure which applies to you? Look at the footer of this page: it shows Your Privacy Choices in an opt-out region and Cookie preferences in a consent-first region.

We work out your region from your IP address each time a page is served, and we may use a recently cached copy of that lookup for up to 24 hours. If we can't determine your region, you get the consent-first behavior — the more protective one.

Your choice is stored on your device (see the storage list below) and lasts 182 days. In consent-first regions, we ask again after it expires or after a change that materially affects a category. In opt-out regions, expiry never re-enables a category you refused, and a later change that materially affects a category never turns back on a category you had turned off — a refusal stays effective until you change it yourself. When you are signed in, we also keep an account-linked consent receipt — the enabled categories, how the choice was made, the platform, your region's consent model, and a two-letter country code when available — which server-side measurement reads before sending anything on your behalf.

Cookies and storage we use

Necessary — sign-in and session

  • authorization_v3, refresh_token, local_only_access_token — first-party cookies that sign you in and keep your session secure.
  • otp_pending — first-party cookie that keeps your email sign-in attempt active while you enter the code we sent you; expires in about 10 minutes.
  • mfa_pending — first-party cookie that holds your in-flight two-step verification challenge (passkey or email code) while you complete it; expires in about 5 minutes.

Necessary — your context

  • active_workspace_id — first-party cookie that remembers your active workspace.
  • meetingai_web_device_info_v1 — first-party cookie that records browser, operating system, timezone, and app-version details (including the browser's user-agent string) so your sessions are identifiable in security checks and your device list. Kept up to 1 year.
  • meeting_pin_<meeting-id> — first-party cookie that remembers a PIN you entered for a PIN-protected shared meeting so you don't re-enter it. We use it only to open that meeting. Cleared when your browser closes.

Necessary — your preferences

We set these when you use the matching control — the theme toggle, the sidebar, or a panel resize — and use them only to honor that choice. Your timezone is the exception: we detect it automatically so meeting times display correctly. Each lasts up to 400 days.

  • theme — your light, dark, or system appearance choice.
  • tz — your timezone.
  • sidebar:status — whether the sidebar is expanded or collapsed.
  • agent_work_rail_open, agent_work_rail_width, chat_preview_rail_width — your chat panel layout choices.

Necessary — other

  • meetingai:cookie-consent (localStorage) — stores your cookie preferences on this device.
  • meetingai.locale (first-party cookie and localStorage) — remembers your language choice; the cookie lets the server respond in your language.
  • meetingai.web-device-id.v1 (localStorage) — a stable browser identifier for your device list and security records; kept until you clear site data.
  • meetingai.fingerprint (localStorage) — a pseudonymous browser identifier used to de-duplicate anonymous views of shared meetings; kept until you clear site data.
  • auth_pending_email (sessionStorage) — the email address of an in-progress sign-in, removed when the sign-in completes or the tab closes.
  • meetingai:optout-bar-ack, meetingai:consent-revoke-pending (localStorage) — remember that you dismissed the opt-out notice, and that a consent withdrawal still needs to reach our server.
  • Other meetingai:* / meeting-ai:* keys (localStorage) — remember your interface state (drafts, view modes, dismissed notices, read state).
  • Google reCAPTCHA (_GRECAPTCHA and related) — third-party, set by Google to prevent bots and fraud on sign-in, verification, and redemption flows.
  • Sign-in provider cookies (Google, Microsoft, Apple, Zoom) — third-party, set only during sign-in or when you connect an account.

Performance (set only while the category is allowed)

  • PostHog cookies and storage (such as ph_*) — pseudonymous, schema-first product analytics. When you are signed in, analytics are linked to internal account and workspace identifiers, not your name or email.
  • Google Analytics cookies (such as _ga and _ga_<measurement-id>) — first-party cookies used by Google as our analytics provider, for pageview and campaign measurement and automatically collected technical events such as session, first-visit, and user-engagement events.
  • Microsoft Clarity cookies (_clck and _clsk, with related Microsoft-domain cookies where supported) — connect allowed page views into masked session replays and heatmaps. Microsoft currently keeps playback data for 30 days and heatmap and aggregate click data for up to 9 months. Meeting.ai does not send Clarity account identifiers through its Identify API.

Marketing

  • Meta Pixel cookies and identifiers (such as _fbp, and _fbc when a Meta click identifier is present) — used for campaign attribution, conversion measurement, and advertising. The Meta Pixel loads only while the Marketing category is allowed. When you opt out, it receives no further events from us and is not loaded again on your next page visit; Meta cookies already set remain until they expire or you delete site data.
  • attr_anon_id (first-party cookie, also stored as meetingai:attr_anon_id in localStorage) — a random identifier set only while the Marketing category is allowed, to link campaign attribution and conversions for Meta measurement. The cookie is kept up to 2 years; the localStorage copy remains until you clear your site data.

We update this list when our cookies change.

Managing your cookies

You can open Cookie preferences — from the page footer, or from Customize in the consent notice shown on your first visit — to choose Accept all, Reject non-essential, or pick by category, and you can change your choice at any time. In opt-out regions the footer link is titled Your Privacy Choices and opens the same controls, and Got it on the notice only dismisses it — it does not change what runs; to turn Performance or Marketing off, use the controls above. Declining the Performance category turns off PostHog, Google Analytics, and Microsoft Clarity in the app and removes Clarity's first-party cookies; declining Marketing stops new Meta measurement from the app. Most browsers also let you block or delete cookies in their settings; blocking necessary cookies may break parts of the Services.

Deleting cookies does not remove data already collected, and disabling a category stops the tools listed under it.

Basic visit counting (not a cookie category). When a page first opens, your browser sends the landing URL and referrer to our own server, without cookies or account credentials; the request carries ordinary connection data such as your IP address, which the server uses transiently for coarse geolocation. The server removes query values and advertising click identifiers before storing the sanitized visit record for aggregate counting. This runs regardless of your cookie choices. The record is linked to a pseudonymous attribution identifier only if the Marketing category is allowed during that visit.

Do Not Track and Global Privacy Control

Some browsers send a "Do Not Track" signal, but there is no single industry standard for responding to it, so we do not respond to that signal. We do honor the Global Privacy Control signal: in opt-out regions it opts you out of the Marketing category, and in consent-first regions it declines all non-essential cookies. Whichever is most recent wins: turning the signal on overrides any choice you saved earlier, and saving a new choice in Cookie preferences while the signal is on overrides the signal — the dialog tells you when a signal has been applied.

Changes

We may update this Cookie Policy as our use of cookies changes. We will update the "Last updated" date and, where appropriate, notify you. Continued use after changes take effect means you accept the update; where a change materially affects a cookie category, we ask again before the affected non-essential cookies are used under the new terms.

Contact

Questions: legal@meeting.ai — Bahasalab Automation Pte. Ltd., 171 Tras Street, #04-175 Union Building, Singapore 079025.