Privacy Policy

Last updated: September 7, 2026

This Privacy Policy explains what information DenwaysMeet (the "Service"), provided by [Company Legal Name], collects, how we use it, who we share it with, and the choices you have. It's meant to be read alongside our Terms of Service.

1. Information we collect

Account & organization information

Your name, email address, password (stored as a salted hash, never in plain text), and profile details you add (avatar, status, preferences). If you create or join an organization, we store its name, members, roles, and settings.

Content you create

Messages, files, images, voice messages, custom stickers/emoji, tasks, support tickets, and anything else you post or upload ("Your Content") - stored so we can deliver it to the people you're communicating with and show it back to you later.

Meeting content

Live audio/video during a call is relayed in real time through our video infrastructure provider (LiveKit) to the other participants; we don't currently record or permanently store call audio/video ourselves (see §3, "Recordings," for the planned-but-not-yet-active state of that feature). If live captions/transcription is used in a call, the resulting text is stored as a transcript tied to that meeting. If AI meeting minutes are generated, the minutes (and the transcript they're based on) are stored with the meeting.

Billing information

Payment card details are collected and processed directly by Stripe, our payment processor - we don't receive or store your full card number ourselves. We do store your subscription plan, billing history, and invoices.

Technical & usage information

IP address, browser/device type, and session activity, used for security (detecting suspicious logins), keeping you signed in, and diagnosing problems.

Cookies

We use exactly one cookie: nx_session, which keeps you signed in. It's set to httpOnly (invisible to page scripts) and secure in production, and expires after 30 days (or 12 hours if you don't check "remember me" at login). We don't use advertising, analytics, or third-party tracking cookies.

2. How we use your information

  • To operate the Service - deliver messages, run calls, sync your data across devices;
  • To provide features you opt into, including AI features (see §4 below);
  • To process billing and prevent fraud;
  • To communicate with you - service notices, security alerts, and (if you don't opt out) product updates;
  • To keep the Service secure and investigate abuse; and
  • To comply with legal obligations.

We don't sell your personal information, and we don't use your message or meeting content to serve you ads.

3. What we store, and for how long

This section describes our actual current retention behavior, which varies by data type - it isn't a single uniform policy.

Messages

How long your messages are kept depends on your organization's plan: 15 days on the Free plan, 180 days on Starter, and indefinitely (until deleted) on Business, Enterprise, and Education plans. When a message reaches its plan's retention limit, its text content is cleared and it's marked deleted - we don't currently hard-delete the underlying row (this preserves things like reply threads and reaction counts that reference it), so no further message text is retrievable, but the message's existence/metadata may persist. Deleting a message yourself works the same way, immediately.

Uploaded files (images, attachments, voice messages, stickers)

Files you upload are retained as long as your account or organization exists. We do not currently run an automated process to delete files that are no longer referenced by any message (for example, if you start uploading a file and never send it, or after the message it was attached to is deleted) - those files remain in storage. We're working to close this gap; until then, treat any file you upload as retained indefinitely by default.

Meeting transcripts & AI-generated minutes

If live captioning/transcription is used during a call, the resulting transcript is stored with no automatic expiry - it persists for as long as the meeting's organization exists, the same as messages on an unlimited-retention plan. AI-generated meeting minutes are stored the same way.

Recordings

Cloud call recording is an allocated feature on paid plans (with a storage quota per plan tier), but as of this policy's last-updated date it is not yet an active feature - no meeting recordings are currently being made or stored. We'll update this policy with specific retention terms before turning it on.

AI usage logs

We keep metadata about AI feature usage - which feature was used, which AI model, token counts, timing, and success/failure - for billing and reliability purposes. These logs do not contain the actual message or transcript text sent to the AI provider; that content lives only in the underlying message/transcript records described above (and, transiently, on the AI provider's own systems per their terms - see §4).

Deleting your organization

An organization owner can permanently delete the organization from its settings. Doing so immediately and permanently deletes that organization's records from our database - messages, files' metadata, meetings, transcripts, tasks, and everything else tied to it. Underlying file bytes in our object storage may not be purged in the same instant as the database records; we're working to close this gap too.

4. AI features & what we send to AI providers

DenwaysMeet's AI features are powered by two third-party providers: Anthropic (Claude) and Google (Gemini). Each DenwaysMeet AI feature is configured to use one of these providers by the platform operator. Depending which features you and your organization use, the following categories of content may be sent to whichever provider is configured:

  • AI assistant chat - your conversation with the assistant, plus recent room messages as context;
  • Room summaries - the text of the messages being summarized;
  • Message translation & writing assistance - the specific message text being translated or improved;
  • AI meeting minutes - the full transcript of the meeting, including each speaker's name and what they said;
  • Cross-meeting search ("meeting memory") - relevant snippets (including speaker names and quoted speech) from your organization's past meeting transcripts/minutes, retrieved to answer a question you ask; and
  • Live captions (where the Gemini Live engine is enabled) - your raw microphone audio is streamed directly from your browser to Google for real-time transcription; it does not pass through our own servers in that configuration.

These providers process this content to generate the requested output (a reply, a translation, a summary, a transcript) and return it to DenwaysMeet. We don't control, and this policy doesn't cover, how Anthropic or Google independently handle data under their own privacy terms - we encourage you to review Anthropic's and Google's own privacy/data-use terms for their APIs if you want to understand their side of the processing. If your organization needs a specific data-processing agreement with either provider (common for enterprise/education customers), contact us.

5. Other service providers we use

We share limited information with the following providers, only as needed to run the parts of the Service that depend on them:

  • Stripe - payment processing and billing;
  • LiveKit - real-time relay of call audio/video between participants;
  • Giphy - GIF search (your search terms, not your messages, are sent to Giphy when you use the GIF picker);
  • Cloud object storage (an S3-compatible provider) - stores uploaded files, avatars, and stickers; and
  • An email delivery provider - sends transactional email on our behalf (verification links, password resets, notifications).

6. When we share your information

Beyond the service providers above, we share personal information only when: your organization's other members/admins can see content you post there, as expected for a workspace product; you ask us to (e.g. exporting data); it's needed to comply with a legal obligation, court order, or valid legal process; or as part of a merger, acquisition, or sale of assets, in which case we'll give notice before your information is transferred and becomes subject to a different privacy policy.

7. Security

We use industry-standard measures to protect your information, including encryption of data in transit (TLS), hashed (not plain-text) password storage, and access controls on who inside our organization can reach production data. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.

8. Your rights & choices

You can access and update most of your account information directly from Settings. You can leave an organization at any time, and an organization owner can delete the organization entirely (see §3 for what that does and doesn't remove). If you're in the EU/UK, California, or another jurisdiction with its own data-protection law, you may have additional rights - such as access, correction, deletion, portability, or objection to certain processing - that go beyond what's built into the product today; contact us at the address below and we'll handle the request manually where it isn't yet self-service.

9. Children's privacy

DenwaysMeet is not directed at children under 13, and we don't knowingly collect personal information from anyone under 13 outside of an account created and managed by a parent, school, or other responsible organization on their behalf. See our Terms of Service for how this applies to educational/institutional accounts.

10. International data transfers

Depending on where our infrastructure and service providers are located, your information may be processed in a country other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers. [Specify the actual region(s) your deployment's database/storage/subprocessors operate in once finalized.]

11. Changes to this policy

We may update this Privacy Policy from time to time. If a change is material, we'll give reasonable notice before it takes effect (such as an in-app notice or an email). The "Last updated" date at the top always reflects the current version.

12. Contact

Questions about this policy or your data? Reach us at privacy@developedbymishab.fun.