Security and privacy at IvreetMeet

This page states, plainly, what happens to a recording you upload to IvreetMeet: where it is stored, who can reach it, which third parties touch it, what is never done with it, and how it is deleted. It is written for the person in an organization who has to approve a service before a team may use it. Everything here mirrors the published privacy policy (Hebrew) and the product's code; nothing is claimed that is not in force.
Where the data is
| Data | Where | Notes |
|---|---|---|
| Recordings, speaker voice clips, files uploaded to the studio | Israel — Amazon Web Services, Tel Aviv region | Encrypted at rest, public access blocked |
| Accounts, meetings, transcripts, summaries, database | Servers in Iceland | Transcription jobs may run in other data centers, including the US |
| Summary generation | AI providers abroad | Text only, routing that does not retain content |
| Payments | Paddle (Merchant of Record) | Card details never reach IvreetMeet |
What is never done
- No training on customer recordings, transcripts or summaries.
- No selling of personal data.
- No audio sent to language-model providers.
- No categorisation of people, and no inference of a person's emotional or health state. Speakers get the names you give them.
- No cross-account access: an API key, an MCP connection or a share link is scoped to one organization.
Access and accounts
- Email verification before the first sign-in, or Google sign-in; passwords are stored hashed.
- Rate limits on sign-up, sign-in and uploads; disposable email domains refused.
- An organization account: every member sees the organization's meetings; a meeting, a speaker or the whole account can be deleted at any time.
- Share links carry a long random token; a public preview link serves only the first 20% of a transcript, server-side; per-speaker communication scores never appear on share links.
Speakers and consent
- Speaker separation inside one meeting is automatic and not biometric.
- Recognising the same person across meetings (a voiceprint) is off by default, switched on per organization, and only ever matches speakers whose consent was recorded.
- Unconsented voiceprints are deleted after 30 days; voiceprints unused for 365 days are deleted too.
API, MCP and integrations
- Personal API keys are stored hashed; each key belongs to one organization.
- AI clients connect through OAuth 2.1 with PKCE on an IvreetMeet approval page that names the app and the scopes; the approval can be revoked in the settings, and the user's password never reaches the app.
- Webhooks are signed (HMAC with a timestamp) and may only target public addresses.
- Connections to Jira, Slack, Google Drive and Fireberry hold tokens only, never the third party's data.
Transport, logs, monitoring
- HTTPS everywhere, with HSTS; the app cannot be framed by other sites.
- Access logs are kept for 24 months, as the privacy policy states.
- Automated monitoring of failed sign-ins, registration bursts and error rates alerts the operator.
Deletion
Deleting a meeting removes its recording, transcript, summary and speaker clips; deleting the account removes everything. Trial recordings made without an account are deleted within an hour of processing and are never kept for anything.
What is not claimed
Frequently asked questions
Is customer data used to train models?
No. Recordings, transcripts and summaries of registered users are never used to train models, in any plan.
Do recordings go to OpenAI, Google or another LLM provider?
No. The audio never leaves the transcription pipeline. Only transcript text is sent to a language-model provider to write the summary, through routing that does not retain content.
Where exactly is the data?
Recordings, speaker clips and studio files: encrypted object storage in Israel (Amazon Web Services, Tel Aviv region). Servers, database, transcripts and summaries: servers in Iceland. The subprocessor table in the privacy policy names each party.
Are you certified (ISO 27001, SOC 2)?
Not today, and we do not claim it. The controls in force are listed on this page; organizations that need a signed processing agreement or a questionnaire contact us before use.
How do I report a vulnerability?
Email ymzpe.net@gmail.com with the details. Please do not test against other customers' data.
Try it on your own recording
IvreetMeet transcribes and summarizes Hebrew meetings. The free plan covers 7 meetings and 120 minutes per organization each month.
Start free