Privacy policy

Draft of 8 October 2026. Applies to the Meeting Ears desktop app, the Meeting Ears service and meetingears.com.

Early-access version · last updated 10 October 2026

Meeting Ears is in early access and sold directly by its maker. These terms are written in plain words for the first users; we will tell you by email before they change.

This policy explains what personal data Meeting Ears processes, why, where, for how long, and your rights. A shorter, plain-language version is in the guide Privacy and data.

1. Who is responsible

The controller of your personal data is Stefan Shabanov, postal address on request at shabanov.stefan@outlook.com (“we”, “us”). Contact: shabanov.stefan@outlook.com.

Data protection officer: none is appointed, as Meeting Ears is a small service run by one person; write to the contact address above.

2. Summary

  • Meeting Ears is a Windows desktop app plus an online service (the “service”). While you listen to a meeting, the app streams the audio, your meeting context and the recent transcript to the service, which uses Google’s Gemini AI models to transcribe and answer.
  • The service does not store audio, transcripts, answers or your context. It stores your account, plan, live-time ledger and usage counts.
  • Your meeting history, projects, presets and calendar data are stored on your computer, not by us.
  • We do not sell personal data, do not use your meetings to train AI models, and this website uses no cookies or analytics.

3. What we process, why, and on what legal basis

3.1 Account data

Your email address, the sign-in method (Google or email and password), a user id, whether your email is verified, and when the account was created. If you sign in with Google, Google tells us your email address and that it is verified; we do not receive your Google password. Passwords for email sign-in are handled by Google Identity Platform; we never see them.

Why: to create and secure your account and give you the plan you hold. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

3.2 Meeting content while you listen

Audio from your microphone and from your computer’s sound output (which during a call includes the other participants), the transcript lines, the lines you ask to answer or translate, the recent transcript sent with an answer, and your active context preset (meeting title, notes, documents and answer length). The app mostly does not send long silences.

Why: to produce the live transcript, answers and translations you ask for. How: the service passes the data to Google’s Gemini models, returns the result to your app and does not store the content. Legal basis: performance of a contract (Art. 6(1)(b)).

3.3 Prep briefs and Regenerate context

When you ask for a prep brief: the calendar meeting’s title, description, start time and the other attendees’ names, plus the notes of the attached preset. When you press Regenerate context (after a one-time notice): the notes of up to 3 recent meetings of that project (questions answered, their points and the last transcript lines) and the preset’s notes. Both are processed to write the text you asked for and are not stored. Legal basis: performance of a contract (Art. 6(1)(b)).

3.4 Plan, ledger and usage records

  • Your plan, the time balances (“buckets”) and every change to them (a ledger: grants, usage, expiry, refunds), with the plan or purchase they belong to.
  • For each meeting: its id, start and stop time, last activity, the reserved and billed seconds, whether it ran on our AI or your own key, and the number of answers. Not its content.
  • Daily usage counters (live time and number of answers per day) and monthly AI usage (tokens used, and the number of answers, briefs, translations and regenerated contexts).

Why: to bill live time, show your balance, enforce the fair-use limits, and prevent abuse. Legal basis: performance of a contract (Art. 6(1)(b)) and our legitimate interest in preventing abuse and keeping the service available (Art. 6(1)(f)).

3.5 Your own Gemini API key

If you add one, the key is stored encrypted (see Security) with its last four characters and the time it was checked. It is used only to run your meetings’ AI work on your Google account. Legal basis: performance of a contract. When your key is used, Google processes the content under the terms of your own Gemini API account.

3.6 Referrals

Your referral code, which account referred yours, and the rewards that resulted. We store account ids and purchase ids for this, not email addresses. Legal basis: performance of a contract.

3.7 Payments (when payments open)

During early access, the Founders licence is paid by bank transfer: we receive your name, the amount, the date and the bank reference, and keep them with the receipt as accounting records. When card payments open, a payment provider named here will process them; we will receive a purchase id, the plan, the amount, its status and refunds or chargebacks, never your full card number. That provider acts as an independent controller for the payment data it collects. Legal basis: performance of a contract, and legal obligations for accounting and tax records (Art. 6(1)(c)).

3.8 Technical logs

The service writes operational logs that identify you only by a salted hash of your user id and never contain audio, transcripts, context, keys or tokens. Google Cloud’s request logs record technical data about each request to the service, such as the IP address, time, address requested and response status. Why: to run, secure and debug the service. Legal basis: legitimate interest (Art. 6(1)(f)).

3.9 This website

The website is static. It sets no cookies and uses no analytics. The hosting provider (Cloudflare) processes the IP address and request data of visitors to deliver the pages and protect them. It remembers your light/dark choice in your browser’s local storage, which never leaves your browser. See Cookies.

3.10 Support

If you email us, we process your message and email address to answer it. Legal basis: legitimate interest, or contract where it concerns your account.

4. People in your meetings

The audio you capture contains the voices and words of other people. For their data,. You must tell participants that you use Meeting Ears and obtain their consent where the law requires it; see the acceptable use policy. The service does not keep their data after processing it.

5. Data that stays on your computer

The app stores on your computer, in %APPDATA%\meeting-ears-overlay: your meeting history (transcripts, questions and answers), projects, context presets and their documents, calendar events and links, and settings. Your sign-in refresh token and calendar access are encrypted with Windows (DPAPI). We have no access to these files; you control them, including how long history is kept (Settings → Privacy & data) and deleting it.

6. Google Calendar data

If you connect Google Calendar, the app asks Google for read-only access to your calendar events (scope calendar.events.readonly). The app reads the events on your computer to show your meetings, remind you, attach context, and match meetings to your history. Calendar data and the access token stay on your computer and are not sent to our servers, except the details of one meeting when you ask for a prep brief (see 3.3).

Meeting Ears’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, and do not use it to train AI models.

7. Service providers

ProviderWhat forData
Google Cloud (Google Cloud EMEA Limited / Google LLC)Hosting the service (Cloud Run), database (Firestore), key encryption (Cloud KMS), logs (Cloud Logging), AI models (Vertex AI Gemini)All service data in section 3
Google Identity Platform (Firebase Authentication)Sign-in and email verificationAccount data
Cloudflare, Inc.Serving this websiteVisitors’ request data
Card payment provider (planned)Payments, once they openPayment data

Google acts as our processor under the Google Cloud data processing terms. Under those terms, Google does not use customer data to train its AI models without permission..

8. Where data is processed, and transfers

  • The service runs in Google Cloud’s europe-west1 region (Belgium). The database is in Google’s EU multi-region (eur3), and encryption keys are in europe-west1.
  • The Gemini models are currently called through Google’s global endpoint, so meeting content may be processed outside the European Economic Area while a request runs. Google Identity Platform also runs on Google’s global infrastructure.
  • Transfers outside the EEA rely on.

9. How long we keep data

DataKept
Audio, transcripts, answers, context, prep-brief and Regenerate inputNot stored; processed in memory for the request
Account, plan, ledger and meeting recordsWhile your account exists; deleted on account deletion, except records we must keep by law
Daily usage counters90 days, then deleted automatically
Monthly AI usage recordsAbout 13 months (400 days from the start of the month), then deleted automatically
Processed payment events400 days, then deleted automatically
Your own Gemini keyUntil you remove it or delete your account
Service and request logs30 days
Invoices and accounting records
Support emails2 years after the last message

10. Security

  • All traffic between the app and the service is encrypted (TLS). Only the desktop app’s main process holds your sign-in token; the token is never put in a web address.
  • The database can be reached only by the service; every record is keyed by your verified user id.
  • Your own Gemini key is encrypted with AES-256-GCM under a per-key data key, which is itself encrypted by a key held in Google Cloud KMS and bound to your account.
  • Logs are designed to contain no meeting content and no secrets.

11. Your rights

Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to its processing, to data portability, and to withdraw consent where processing is based on consent. To use them, email shabanov.stefan@outlook.com from your account’s email address. We answer within one month.

Data on your computer is under your control: you can view, export (History → Export) and delete it yourself.

You may also complain to a data protection supervisory authority, in particular in your country of residence or where we are established: the Bulgarian Commission for Personal Data Protection (cpdp.bg).

We make no decisions about you based solely on automated processing that have legal or similarly significant effects.

12. Children

Meeting Ears is not meant for children. You must be at least 18 to create an account.

13. Changes to this policy

We will publish changes on this page with a new date, and tell you in the app or by email before material changes take effect.

14. Contact

Stefan Shabanov, postal address on request at shabanov.stefan@outlook.com. Email: shabanov.stefan@outlook.com.