Last updated: 10 September 2026

Privacy Policy

We believe privacy is a right, not a feature. This policy explains clearly what data we collect, why, and how we protect it.

The short version

  • Your recordings and notes are never used to train AI models
  • We never sell or share your data with third parties for commercial purposes
  • All data is stored in the European Union, encrypted at rest and in transit
  • You can delete your account and all data at any time
  • We only collect data we actually need
  • Our website uses cookieless analytics; advertising measurement only with your consent

1. Who we are

MeetingNotes.work is a web application that helps professionals turn meeting recordings into structured output using AI. References to "we", "us" or "our" in this policy refer to the operator of MeetingNotes.work.

KvK (Chamber of Commerce): 61617539

For privacy questions: [email protected]

2. What data we collect

2.1 Account data

  • Email address (used for authentication and account management)
  • Subscription status and plan
  • Date of account creation and last login

2.2 Meeting data

  • Audio recordings you make within the app
  • Transcripts generated from your recordings
  • AI-generated output (summaries, emails, CRM notes)

This data is exclusively yours. We process it only to provide the service and never use it for any other purpose.

2.3 Knowledge base data

  • Documents (PDFs) you upload
  • Website content indexed from URLs you add
  • Text snippets you enter manually

2.4 Calendar data (optional)

If you connect Google Calendar or Outlook, we read your calendar events to provide context to the AI (meeting title, attendees, date). We request only the minimum permissions needed and never modify your calendar.

2.5 Technical data

  • IP address (anonymised after 30 days)
  • Browser type and version
  • Error logs and performance data

3. How we use your data

  • Providing the service: Processing recordings, generating AI output, managing your account
  • Improving reliability: Error monitoring and performance diagnostics
  • Billing: Processing payments via Stripe
  • Communication: Sending account-related emails (no marketing without consent)

We never: sell your data, share it with advertisers, use it to train AI models, or access it without a legal basis.

4. AI processing and third parties

4.1 OpenAI (AI processing)

We use the OpenAI API to transcribe recordings and generate output. This means your audio and text is sent to OpenAI's servers for processing. Our agreement with OpenAI includes:

  • Your data is not used to train OpenAI's models
  • OpenAI processes data only as a processor on our behalf
  • Data is not retained longer than technically necessary for processing

More information: OpenAI Privacy Policy

4.2 Google / Microsoft (calendar and email)

If you connect Gmail, Google Calendar, Outlook or Microsoft 365, the respective provider processes data according to their own privacy policy. We request only minimum required permissions. You can revoke integrations at any time from your account settings, or from your Google Account / Microsoft account security settings.

Specifically, MeetingNotes.work requests the following permissions and uses them only as described:

  • Calendar (read-only) — Google scope calendar.events.readonly / Microsoft Calendars.Read: we read the title, time, attendees and description of your upcoming meetings to link a recording to the right meeting and to give the AI context. We never create, modify or delete calendar events.
  • Sending e-mail (Google) — Google scope gmail.send: after you have reviewed and edited the AI-generated follow-up inside MeetingNotes.work and clicked "Send via Gmail", we send that one message from your Gmail account to the recipients you chose. This scope only allows sending; we cannot read, search, list or modify anything in your mailbox, and we never send anything without your explicit click.
  • Email drafts (Microsoft) — Microsoft Mail.ReadWrite: we create a draft message in your own Outlook mailbox containing the follow-up you reviewed. The draft is never sent by us; you send it yourself from Outlook. We do not read, search or store your existing emails.
  • Basic profile (email address): used only to show which account is connected.

Access and refresh tokens are stored encrypted (AES-256-GCM) and are deleted — and revoked at the provider — when you disconnect the integration or delete your account. Calendar data is used at the time of processing and is not retained beyond the meeting context stored with your recording.

Google API Services User Data Policy. MeetingNotes.work's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data for advertising, we do not sell it, we do not use it to train AI models, and humans do not read it except with your explicit consent, for security purposes, to comply with the law, or for internal operations where the data has been aggregated and anonymised.

4.3 Cloud storage

Audio recordings and knowledge base files are stored on servers within the European Union. All files are encrypted at rest (AES-256) and in transit (TLS 1.3).

4.4 Stripe (payments)

Payments are processed by Stripe. We never have access to your full payment card details — Stripe processes these directly and provides us only with an anonymised token. Stripe is certified as a PCI DSS Level 1 processor. More information: Stripe Privacy Policy

4.5 Hanko (authentication)

Login is handled by Hanko, which processes your email address for the sign-in flow. More information: Hanko Privacy Policy

5. Data retention

  • Audio recordings: Automatically deleted 90 days after recording
  • Transcripts and AI output: Retained while your account is active, or until you delete them
  • Knowledge base content: Retained while your account is active, or until you delete it
  • Account data: Retained while your account is active
  • Billing records: 7 years as required by law
  • Logs: IP addresses anonymised after 30 days, logs deleted after 90 days

When you close your account, all data (except billing records required by law) is permanently and irreversibly deleted within 30 days.

6. Your rights (GDPR)

Under the GDPR you have the right to:

  • Access: Request a copy of the data we hold about you
  • Correction: Ask us to correct inaccurate data
  • Erasure: Request deletion of your data
  • Portability: Receive your data in a machine-readable format
  • Objection: Object to processing based on legitimate interest
  • Restriction: Request that we restrict processing of your data
  • Withdraw consent: Withdraw consent you gave earlier (for example for advertising cookies) at any time

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with your national data protection authority.

7. Data transfers outside the EU

Your data is primarily processed and stored within the European Union. For AI processing via the OpenAI API, data may be sent to servers in the United States. OpenAI participates in the EU–US Data Privacy Framework and provides additional contractual guarantees via Standard Contractual Clauses (SCCs). If you consent to the LinkedIn Insight Tag (see section 10), LinkedIn may transfer the data it collects to the United States under its own safeguards, described in LinkedIn's privacy policy.

8. Security

We implement appropriate technical and organisational measures to protect your data, including encryption at rest and in transit, access controls, and regular security reviews. However, no system is 100% secure. If you discover a security issue, please report it to [email protected].

9. Cookies in the app

The application at app.meetingnotes.work uses only strictly necessary cookies required for authentication and session management. We do not use tracking or advertising cookies inside the app. Our public website uses the analytics and, with your consent, advertising technology described in the next section.

10. Analytics and advertising cookies

10.1 Plausible Analytics (no cookies, no consent required)

On our public website (www.meetingnotes.work) we measure visits with Plausible Analytics. Plausible does not use cookies, does not store personal data, does not track you across websites and does not build a profile of you. It records aggregated data only: page views, referrer, country, device type and browser. IP addresses are not stored. Plausible is an EU company and processes this data on servers in the European Union. Because no personal data is stored and no cookies are set, we load Plausible without asking for consent, on the basis of our legitimate interest in knowing how our website is used. More information: Plausible data policy.

We also record when a visitor clicks a "Try it free" button, and which page they were on. This is an aggregated count and is not linked to any person.

10.2 LinkedIn Insight Tag (only with your consent)

We advertise on LinkedIn. To see whether those advertisements lead to visits and sign-ups, we would like to use the LinkedIn Insight Tag on our public website. The Insight Tag is a small script from LinkedIn that sets cookies in your browser and sends data to LinkedIn, including the URL you visited, your IP address, device and browser characteristics and a timestamp. If you are logged in to LinkedIn, LinkedIn can link this data to your LinkedIn profile. LinkedIn uses it to report to us, in aggregated form, how our campaigns perform, and may use it to show you advertisements from us on LinkedIn.

We only load the LinkedIn Insight Tag after you have clicked "Accept" in the cookie banner. If you click "Decline" or do not make a choice, the tag is not loaded and no data is sent to LinkedIn. You can change your choice at any time through the "Cookie preferences" link in the footer of every page.

More information about how LinkedIn processes this data: LinkedIn Privacy Policy and LinkedIn Cookie Policy. LinkedIn members can opt out of targeted advertising in their LinkedIn ad settings; anyone can opt out of LinkedIn's use of Insight Tag data via LinkedIn's guest controls.

10.3 How the consent banner works

  • On your first visit we show a banner with two equal buttons: "Decline" and "Accept" (Dutch: "Weigeren" / "Accepteren").
  • Your choice is stored in your browser's local storage under the key mn_consent with the value granted or denied. This is not a cookie and is not sent to us or to anyone else; it only prevents the banner from appearing again.
  • Only if you chose "Accept" do we load the LinkedIn Insight Tag on that and later visits.
  • You can reopen the banner and change your choice via "Cookie preferences" in the footer, or by clearing your browser's site data.

11. Changes to this policy

We may update this policy occasionally. We will notify you of significant changes via email. The date at the top of this page reflects the most recent update. Continued use of the service after changes constitutes acceptance of the updated policy.

12. Contact

Questions or concerns about this privacy policy? Contact us at [email protected].