Privacy Policy
Last updated: April 16, 2026
MeetHQ ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our meeting intelligence platform and related services (collectively, the "Service").
By accessing or using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, and password when you register for an account.
- Meeting Content: Audio recordings, transcripts, and any files you upload for analysis.
- User Preferences: Custom preferences, prompt configurations, goals, and organizational context you provide to improve AI analysis.
- Payment Information: Billing details processed through our third-party payment processor (Stripe). We do not store complete credit card numbers on our servers.
- Communications: Information you provide when contacting support or providing feedback.
1.2 Information Collected Automatically
- Usage Data: Pages visited, features used, actions taken, timestamps, and session duration.
- Device Information: Browser type, operating system, device identifiers, and IP address.
- Cookies and Similar Technologies: Session cookies for authentication and analytics cookies to understand service usage. See Section 7 for details.
- Log Data: Server logs including access times, error logs, and referring URLs.
1.3 Information from Third-Party Services
- Google Calendar and Google Meet: When you connect your Google account, we access calendar event metadata (titles, times, attendees, and conferencing links) and, where available, transcripts from Google Meet meetings you host. See Section 3A: Google API Services User Data for full details, including the scopes we request, how we store this data, and our Limited Use commitment.
- Other Calendar Integrations: When you connect a non-Google calendar (e.g., Microsoft Outlook), we access event metadata including titles, times, attendees, and meeting links to enable automated scheduling features.
- Sign-In with Google: If you sign in via Google, we receive your name, email address, and profile picture (scopes
emailandprofile) solely to create or authenticate your MeetHQ account. We do not request any additional scopes during sign-in. - Zoom: When you connect Zoom, we receive transcripts and recording metadata for meetings associated with your linked Zoom account, used solely to import them into MeetHQ for your analysis.
2. How We Use Your Information
We use the information we collect to:
- Provide and Operate the Service: Process meeting recordings, generate transcripts, produce AI-powered summaries, extract action items, and deliver decision intelligence.
- Personalize Your Experience: Tailor AI analysis based on your preferences, role context, and organizational priorities.
- Process Payments: Manage subscriptions, billing, and invoicing.
- Improve the Service: Analyze aggregate usage patterns to enhance features, fix bugs, and optimize performance.
- Communicate with You: Send transactional emails (e.g., password resets, subscription confirmations), service updates, and, with your consent, marketing communications.
- Ensure Security: Detect, prevent, and address fraud, abuse, and security incidents.
- Comply with Legal Obligations: Fulfill legal requirements, respond to lawful requests, and enforce our terms.
3. AI Processing and Your Content
MeetHQ uses artificial intelligence (including third-party AI providers such as Anthropic's Claude) to analyze meeting content. When we process your meeting data:
- Your meeting content is sent to AI providers solely for the purpose of generating summaries, action items, and insights for your use.
- We do not use your meeting content to train general-purpose AI models.
- AI-generated outputs (summaries, tasks, analyses) are stored in your account and are subject to the same access controls as your other data.
- We contractually require our AI providers to process your data only as instructed and to maintain appropriate security measures.
- You retain ownership of your meeting content and the AI-generated outputs derived from it.
3A. Google API Services User Data
This section describes how MeetHQ accesses, uses, stores, and shares data obtained through Google APIs. It supplements (and, in case of conflict, supersedes) the more general descriptions elsewhere in this Policy.
3A.1 Scopes We Request
When you connect your Google account from the Integrations page, MeetHQ requests the following OAuth scopes:
https://www.googleapis.com/auth/calendar.events.readonly— Read-only access to your Google Calendar events. We use this to display your meeting schedule inside MeetHQ, link calendar events to recordings, and identify meetings that are about to start.https://www.googleapis.com/auth/meetings.space.readonly— Read-only access to transcripts from Google Meet meetings you host. We use this to import those transcripts into MeetHQ so we can generate summaries, action items, and other insights for you.
If you sign in to MeetHQ with Google, we additionally request the standard email and profile scopes solely to create or authenticate your account. We do not request any further Google scopes.
3A.2 What We Store and Where
- Calendar event metadata (titles, start/end times, attendee email addresses, conferencing links, descriptions) is stored in our PostgreSQL database, encrypted at rest, hosted with our cloud infrastructure provider.
- Google Meet transcripts are stored as part of the associated MeetHQ meeting record, encrypted at rest, in the same database.
- OAuth access and refresh tokens are stored encrypted using application-level encryption (Active Record Encryption) so they cannot be read directly from the database.
3A.3 How Long We Keep It
- Synced calendar event metadata is retained only while your Google integration is connected. When you disconnect Google from /integrations, synced calendar events are deleted from our database within 30 days.
- Google Meet transcripts you have already imported are retained as part of the corresponding meeting record until you delete that meeting or your account.
- Disconnection also revokes our refresh token and stops all further access to your Google data.
3A.4 Who Can Access Your Google Data
Your Google data is scoped to your MeetHQ account and is not visible to other users. MeetHQ employees do not access your Google user data except: (a) with your explicit consent (for example, when you grant access for support troubleshooting); (b) for security investigations such as responding to suspected abuse; (c) to comply with applicable law; or (d) where the data has been aggregated and anonymized so that it can no longer be associated with you.
3A.5 AI Processing of Google Data
- Google Meet transcripts are processed by our third-party AI provider (Anthropic's Claude API) for the same summarization, action-item extraction, and analysis purposes as your other meeting recordings. Anthropic processes this content under a data processing agreement that prohibits using customer data to train or improve their generalized AI models.
- Google Calendar event metadata (titles, times, attendees) is not sent to any third-party AI provider. It is used only inside MeetHQ to display your schedule and link events to meetings.
3A.6 Limited Use of Google User Data
MeetHQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we affirm that we do not:
- Use Google user data to serve advertisements;
- Sell or transfer Google user data to data brokers, advertising networks, or information resellers;
- Use Google user data to train, develop, or improve generalized or non-personalized AI/ML models;
- Allow humans to read Google user data, except (a) with the user's explicit consent for specific messages or content, (b) where necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized.
3A.7 Revoking Access
You can disconnect Google from MeetHQ at any time on the Integrations page. You may also revoke MeetHQ's access directly from your Google Account at myaccount.google.com/permissions. Either method stops all further access to your Google data and triggers deletion of synced calendar events as described in Section 3A.3.
4. How We Share Your Information
We do not sell your personal information. We may share information in the following circumstances:
- Service Providers: We share data with trusted third-party vendors who assist in operating our Service (e.g., cloud hosting, payment processing, AI analysis, email delivery). These providers are contractually bound to use your data only for the purposes we specify.
- AI Processing Partners: Meeting content is shared with AI providers (e.g., Anthropic) strictly for analysis purposes, subject to data processing agreements.
- Payment Processors: Billing information is shared with Stripe to process transactions.
- Legal Requirements: We may disclose information if required by law, regulation, legal process, or governmental request.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
- With Your Consent: We may share information for other purposes when you provide explicit consent.
5. Data Retention
- Account Data: Retained for as long as your account is active. Upon account deletion, we remove your personal data within 30 days, except as required by law.
- Meeting Content: Recordings, transcripts, and AI-generated summaries are retained while your account is active. You may delete individual meetings at any time.
- Usage Logs: Aggregated and anonymized usage data may be retained indefinitely for analytics and service improvement.
- Billing Records: Retained as required by applicable tax and accounting regulations.
- Google User Data: Synced calendar event metadata is retained only while your Google integration is connected and is deleted within 30 days of disconnection. Imported Google Meet transcripts are retained as part of the associated meeting until you delete that meeting. See Section 3A for full details.
6. Data Security
We implement industry-standard security measures to protect your information, including:
- Encryption in transit (TLS 1.2+) and at rest for all stored data.
- Secure password hashing using bcrypt.
- User-scoped data isolation ensuring you can only access your own data.
- Regular security assessments and monitoring.
- Access controls and authentication for all administrative functions.
While we strive to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
7. Cookies and Tracking Technologies
We use the following types of cookies:
- Essential Cookies: Required for authentication, session management, and security (e.g., CSRF tokens). These cannot be disabled.
- Analytics Cookies: Help us understand how the Service is used so we can improve it. You may opt out of non-essential analytics cookies through your browser settings.
We do not use third-party advertising cookies or cross-site tracking technologies.
8. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Portability: Request your data in a structured, commonly used, machine-readable format.
- Restriction: Request that we limit the processing of your data in certain circumstances.
- Objection: Object to processing based on legitimate interests.
- Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
To exercise these rights, contact us at privacy@meethq.io. We will respond within 30 days (or as required by applicable law).
Revoking Google Access: You can disconnect Google at any time from your Integrations page or by visiting Google Account Permissions. Disconnection stops all further data access and triggers deletion of synced calendar events as described in Section 3A.3.
9. International Data Transfers
Your data may be processed in countries other than your own. We ensure appropriate safeguards are in place for cross-border transfers, including standard contractual clauses or equivalent mechanisms recognized by applicable data protection authorities.
10. Children's Privacy
The Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will promptly delete it.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to know what personal information we collect and how it is used.
- Right to delete personal information we have collected.
- Right to opt out of the sale or sharing of personal information. We do not sell or share your personal information as defined under CCPA/CPRA.
- Right to non-discrimination for exercising your privacy rights.
- Right to correct inaccurate personal information.
- Right to limit use of sensitive personal information.
12. European Economic Area (GDPR)
If you are located in the EEA, UK, or Switzerland, we process your data under the following legal bases:
- Contract Performance: Processing necessary to provide the Service you requested.
- Legitimate Interests: Processing for service improvement, security, and fraud prevention, balanced against your rights.
- Consent: Where you have given explicit consent (e.g., marketing communications).
- Legal Obligation: Processing required to comply with applicable law.
You may lodge a complaint with your local supervisory authority if you believe your data protection rights have been violated.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date and, where appropriate, by email. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
14. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, contact us at:
- Email: privacy@meethq.io

