BETA

The service is in beta. You may see slight delays — thank you for your patience. Hit a problem? Write to us

Security

Security and privacy at IvreetMeet

Updated 22 September 2026
בעברית
Security and privacy

This page states, plainly, what happens to a recording you upload to IvreetMeet: where it is stored, who can reach it, which third parties touch it, what is never done with it, and how it is deleted. It is written for the person in an organization who has to approve a service before a team may use it. Everything here mirrors the published privacy policy (Hebrew) and the product's code; nothing is claimed that is not in force.

Where the data is

DataWhereNotes
Recordings, speaker voice clips, files uploaded to the studioIsrael — Amazon Web Services, Tel Aviv regionEncrypted at rest, public access blocked
Accounts, meetings, transcripts, summaries, databaseServers in IcelandTranscription jobs may run in other data centers, including the US
Summary generationAI providers abroadText only, routing that does not retain content
PaymentsPaddle (Merchant of Record)Card details never reach IvreetMeet

What is never done

  • No training on customer recordings, transcripts or summaries.
  • No selling of personal data.
  • No audio sent to language-model providers.
  • No categorisation of people, and no inference of a person's emotional or health state. Speakers get the names you give them.
  • No cross-account access: an API key, an MCP connection or a share link is scoped to one organization.

Access and accounts

  • Email verification before the first sign-in, or Google sign-in; passwords are stored hashed.
  • Rate limits on sign-up, sign-in and uploads; disposable email domains refused.
  • An organization account: every member sees the organization's meetings; a meeting, a speaker or the whole account can be deleted at any time.
  • Share links carry a long random token; a public preview link serves only the first 20% of a transcript, server-side; per-speaker communication scores never appear on share links.

Speakers and consent

  • Speaker separation inside one meeting is automatic and not biometric.
  • Recognising the same person across meetings (a voiceprint) is off by default, switched on per organization, and only ever matches speakers whose consent was recorded.
  • Unconsented voiceprints are deleted after 30 days; voiceprints unused for 365 days are deleted too.

API, MCP and integrations

  • Personal API keys are stored hashed; each key belongs to one organization.
  • AI clients connect through OAuth 2.1 with PKCE on an IvreetMeet approval page that names the app and the scopes; the approval can be revoked in the settings, and the user's password never reaches the app.
  • Webhooks are signed (HMAC with a timestamp) and may only target public addresses.
  • Connections to Jira, Slack, Google Drive and Fireberry hold tokens only, never the third party's data.

Transport, logs, monitoring

  • HTTPS everywhere, with HSTS; the app cannot be framed by other sites.
  • Access logs are kept for 24 months, as the privacy policy states.
  • Automated monitoring of failed sign-ins, registration bursts and error rates alerts the operator.

Deletion

Deleting a meeting removes its recording, transcript, summary and speaker clips; deleting the account removes everything. Trial recordings made without an account are deleted within an hour of processing and are never kept for anything.

What is not claimed

No ISO 27001 or SOC 2 certification, no third-party penetration-test report, and no signed data-processing agreement by default. If your organization needs any of these, write to ymzpe.net@gmail.com before use.

Frequently asked questions

Is customer data used to train models?

No. Recordings, transcripts and summaries of registered users are never used to train models, in any plan.

Do recordings go to OpenAI, Google or another LLM provider?

No. The audio never leaves the transcription pipeline. Only transcript text is sent to a language-model provider to write the summary, through routing that does not retain content.

Where exactly is the data?

Recordings, speaker clips and studio files: encrypted object storage in Israel (Amazon Web Services, Tel Aviv region). Servers, database, transcripts and summaries: servers in Iceland. The subprocessor table in the privacy policy names each party.

Are you certified (ISO 27001, SOC 2)?

Not today, and we do not claim it. The controls in force are listed on this page; organizations that need a signed processing agreement or a questionnaire contact us before use.

How do I report a vulnerability?

Email ymzpe.net@gmail.com with the details. Please do not test against other customers' data.

Try it on your own recording

IvreetMeet transcribes and summarizes Hebrew meetings. The free plan covers 7 meetings and 120 minutes per organization each month.

Start free