Privacy Policy

Последнее обновление 7 August 2026

The short version: you control your data, we don't train public AI models on your meetings unless you ask us to, and we never sell your personal information for money. The details are below.

Yours to control

You can access, export, and delete your content — see Your rights and choices.

No training on your meetings

We don't train public, general-purpose AI models on your meetings unless you ask us to.

Never sold for money

We don't sell your personal information for money.

Privacy-minimizing analytics

Our analytics never see your transcripts or recordings.

This Privacy Policy explains how Bahasalab Automation Pte. Ltd., doing business as Meeting.ai ("Meeting.ai", "we", "us", "our"), collects, uses, shares, and protects personal information when you use our websites, apps, and services (the "Services"). We are the controller of your personal information. If you do not agree with this Policy, please do not use the Services.

You can reach us at legal@meeting.ai or by post at Bahasalab Automation Pte. Ltd., 171 Tras Street, #04-175 Union Building, Singapore 079025.

Information we collect

Information you provide. Account and profile details — your name, email address, and profile photo — obtained when you register with email (a one-time code, or a password where you have configured one) or sign in with Google, Microsoft, Apple, or Zoom. We also collect your workspace and team identifiers and role, your language and timezone preferences, and any messages or feedback you send us.

Meeting and product content. Meeting recordings and audio, and the transcripts, summaries, notes, and Visual Notes generated from them; your chat threads and agent interactions (prompts, responses, and the context the agent uses); files you upload; calendar data from connected Google or Microsoft accounts (events, times, attendees); and contacts derived from your calendar and meetings.

Information collected automatically. Usage and log data (actions taken, feature usage, timestamps, and diagnostic information), device and connection data (IP address, browser and device type, operating system, language), and approximate location inferred from your IP address (for language, regional offers, consent handling, and security). We do not collect precise GPS location. See our Cookie Policy for cookies and similar technologies.

Payment information. We do not collect or store full payment card numbers. Payments are processed by Stripe, Xendit, the Apple App Store, and Google Play under their own privacy policies; we receive limited transaction data such as status, plan, and billing country.

How we use information

We process personal information to:

  • provide, operate, and secure the Services and your account;
  • capture, transcribe, summarize, and otherwise process meetings, and run the AI agent and skills you use;
  • connect the third-party tools you authorize;
  • process payments and manage subscriptions and credits;
  • provide support;
  • maintain security and prevent fraud and abuse;
  • analyze and improve the Services and build new features;
  • send marketing communications where permitted (you can opt out anytime); and
  • comply with legal obligations.

AI processing. Your content is processed by automated systems and AI models, including third-party AI providers acting as our processors, to deliver features such as transcription, summaries, and the agent. We treat the identifiable contents of your meetings as confidential, do not sell them, and do not use them to train publicly available, general-purpose AI models except with your consent or as permitted by law. We may create and use aggregated, de-identified data (which does not identify you) to operate and improve the Services.

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Services you request); legitimate interests (to secure, analyze, and improve the Services, prevent fraud, and run our business); consent (for non-essential cookies, certain marketing, and any special-category data — which you can withdraw at any time); and legal obligation. Withdrawing consent does not affect processing already carried out.

Analytics, advertising, and security tools

Analytics and marketing measurement follow your cookie choices and your region's consent model — see our Cookie Policy.

PostHog (product analytics)

Privacy-minimizing and schema-first: product events come from a defined, validated event list, and we do not transmit names, emails, transcript contents, or recording contents. PostHog also receives automatic application-error reports (exception messages and stack traces), which can contain technical diagnostic details but not your meeting content.

Google Analytics (pageview and campaign measurement)

Page URLs sent to it are limited to the route path and sanitized campaign parameters, and we do not send Meeting.ai's product-event taxonomy or account identity.

Microsoft Clarity (heatmaps and session replay)

Replay is built from page structure, performance signals, and interactions such as clicks, scrolling, and navigation. Meeting.ai explicitly masks the full document before Clarity uploads it, so page text and images — including transcript, chat, file, and meeting contents — are not sent, and we do not use Clarity's Identify API. Clarity may process page URLs and browser, device, network, and approximate-location metadata; see our Cookie Policy for retention details.

Meta (advertising measurement)

Where the Marketing category is allowed — with your consent in consent-first regions, or by default with an opt-out in opt-out regions (see our Cookie Policy) — we use the Meta Pixel and Meta Conversions API for campaign attribution, conversion measurement, and optimization of Meeting.ai's own advertising. Data sent to Meta may include page and conversion events, device and connection data, Meta cookie identifiers, and limited account identifiers used to match events; we do not send Meta your meeting recordings, transcripts, summaries, notes, files, or chat contents.

In the mobile apps

Optional analytics in the Meeting.ai mobile apps stay off until you enable them in the app. There, the Marketing category means AppsFlyer install and campaign attribution and, on iOS, the system App Tracking Transparency permission request; controls are in the app's settings. The web mechanics described in our Cookie Policy (cookies, the consent notice, footer links) apply to our websites.

Sentry (error and performance monitoring)

Sentry receives error, stack, and performance information, an internal user identifier, and, where relevant, internal meeting or thread identifiers. Before sending, we remove request bodies, headers, cookies, URL query strings, and common email and authentication-token patterns. Error reports can still contain incidental technical details, but we do not include meeting content in error messages.

Google reCAPTCHA (bot and fraud prevention)

Runs on sign-in, verification, and redemption flows (subject to Google's Privacy Policy and Terms).

How we share information

We share personal information only as needed:

  • with service providers and subprocessors that help us run the Services under contract — including our backend and AI-processing infrastructure, PostHog, Google Analytics, and Microsoft Clarity (analytics), Sentry (error monitoring), Google reCAPTCHA (security), the sign-in providers you connect (Google, Microsoft, Apple, Zoom), payment processors (Stripe, Xendit, Apple, Google), AppsFlyer (mobile attribution), and cloud hosting and content-delivery providers;
  • with Meta, where the Marketing category is allowed (see our Cookie Policy), to measure and improve Meeting.ai's own advertising campaigns;
  • at your direction, with tools and skills you connect and people you share content with;
  • for legal and safety reasons, to comply with law or protect our rights and users; and
  • in a business transfer such as a merger or acquisition, subject to this Policy.

We do not sell your personal information for money or allow third parties to place ads on the Services.

International transfers

We are based in Singapore, and your information may be processed in Singapore and in other countries where we or our subprocessors operate, which may have different data-protection laws. Where required (for example, transfers out of the EEA or UK), we use appropriate safeguards such as the European Commission's Standard Contractual Clauses.

Retention

We keep personal information for as long as your account is active and as needed to provide the Services, and afterward only as required for legitimate business or legal purposes (such as tax, accounting, dispute resolution, and security). When no longer needed, we delete or de-identify it, or securely isolate it where deletion is not immediately possible (for example, in backups).

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or port your personal information, and to withdraw consent. You can review and update much of your information in the app and can request to delete your account. To exercise rights, email legal@meeting.ai; we respond within the time required by law (generally within one month under the GDPR). You will not be discriminated against for exercising your rights.

In the EEA, UK, or Switzerland, you may also lodge a complaint with your local supervisory authority, the UK ICO, or the Swiss FDPIC. You can opt out of marketing emails at any time; we may still send service and transactional messages.

United States — California and other states

If you are a California resident, the CCPA/CPRA gives you rights to know, access, correct, and delete your personal information and to opt out of its "sale" or "sharing", and not to be discriminated against for exercising them. We do not sell your personal information for money. Depending on applicable law, using Meta marketing tools may be considered "sharing" for cross-context behavioral advertising. You can opt out at any time: use Your Privacy Choices in the footer (which opens the cookie controls — switch Marketing off), or turn on a browser opt-out preference signal such as Global Privacy Control, which we honor as a request to opt out of sharing. To exercise other rights, contact legal@meeting.ai. Residents of other US states with similar laws have comparable rights, which we honor where applicable.

Singapore (PDPA)

We handle personal data in line with Singapore's Personal Data Protection Act. You may request access to or correction of your personal data, and withdraw consent, by contacting legal@meeting.ai.

Children

The Services are for users 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has given us information, contact us and we will take reasonable steps to delete it.

Security

We use appropriate technical and organizational measures, including encryption in transit (TLS), access controls, and a limited-access model for personnel. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. Protect your account credentials and use the Services in a secure environment.

Changes to this Policy

We may update this Policy from time to time. We will update the "Last updated" date and, for material changes, take reasonable steps to notify you. Your continued use after changes take effect means you accept the updated Policy.

Contact

Questions or requests: legal@meeting.ai — Bahasalab Automation Pte. Ltd., 171 Tras Street, #04-175 Union Building, Singapore 079025.