Privacy
How Meet handles your data
What Meet collects, where it runs, who processes it, and how to reach us about it. Meet does not record or store the audio, video, or screen share of a meeting. An admitted third-party notetaker may record the live media it receives.
Security and trust
- Meet does not record or store the audio, video, or screen share of a meeting. An admitted third-party notetaker may receive and record live media under its own service; the room marks it, and the owner can refuse notetakers per room.
- Speech-to-text runs only on the device hosting the meeting: an Envisioning member’s Mac, iPhone, or iPad. That is usually the room owner’s device. The host can hand the meeting to another Envisioning member, and from then on that member’s device does the transcription. The host device keeps audio buffers in memory and discards them after recognition.
- Outside Meet’s own rooms, an Envisioning member can use ambient capture on their own Mac to transcribe a call that another service hosts. Meet writes that audio to temporary files on that Mac only and deletes them once the transcript reaches Meet.
- Guests wait in a waiting room until the owner admits them. Meet issues no LiveKit media credential before admission.
- While a guest is on the join page (before knocking), the host may see that someone is there, their join stage, display name once typed, and approximate city/country from the network edge. The host does not see email or a precise address.
- The host device produces live captions and shares them in the call. Durable notes contain only finalized transcript text.
At a glance
- Recording
- Meet does not record or store the audio or video of a meeting. If the owner admits a third-party notetaker, that service may record the media it receives under its own terms.
- Speech-to-text
- Runs only on the host device, an Envisioning member’s Mac, iPhone, or iPad. Audio stays in memory there, and the host device discards it after recognition.
- What leaves the host device
- Finalized transcript text only (speaker name, language, timestamps, text).
- Meeting notes
- After Meet finalizes the meeting, participants with artifact access can read them in Meet.
- Guests
- No account. Display name and email are required, except a declared recording notetaker, which provides a name only.
- Owners
- Verified @envisioning.com / @envisioning.io Google Workspace sign-in only.
Where things run
- Cloudflare Workers: web app and API (admission, tokens, room coordination). Per-room state and transcripts live in a Durable Object (SQLite). A separate D1 ledger holds operational metadata about Envisioning members (who signed in). It never holds transcripts, summaries, or guest emails. Artifact finalization uses Queues. Optional meeting summaries and the host's optional in-meeting task suggestions use Workers AI.
- LiveKit: realtime camera, microphone, and screen share (SFU + TURN). Media exists only for the call. Meet does not enable LiveKit recording/egress.
- Host device: local transcription (English, Portuguese, German; FluidAudio / Parakeet). The host device is not the media relay; every participant connects to LiveKit directly.
- Google: owner authentication only. Guests never sign in with Google.
What we store
- Room and meeting metadata (slug, owner identity, start/end, title/summary).
- Waiting-room and participant records (name, email, hashed admission secret).
- Short-lived join-page presence (stage, optional display name, city/country) while a guest is preparing to knock. It drops within about a minute of silence.
- Finalized transcript segments and summaries.
- Short-lived credentials: owner session (~8h), LiveKit room token (~2h), artifact access (~12h).
- Envisioning member sign-in records in an account ledger (name, email, last seen). The ledger holds no guest emails and no meeting content.
Live camera, microphone, and screen-share streams exist only as ephemeral WebRTC media. Meet stores admission secrets as hashes. Meet writes application logs without bearer tokens, transcript text, full emails, or admission secrets. The browser may keep your name and email in local storage on this device to prefill the join form. Meet does not use it for advertising.
Data retention
- Live media
- Session only. Streams are not archived.
- Host device outbox
- Holds pending transcript text until the control plane accepts it, then removes it.
- Waiting room / admission
- Tied to the meeting lifecycle. Waiting requests expire when the host lease ends or the meeting ends.
- Access tokens
- Owner session ~8 hours; LiveKit room token ~2 hours; artifact access ~12 hours.
- Member sign-in ledger
- Kept while the person is an Envisioning member. Guest emails are not stored there.
- Transcripts and summaries
- Meet keeps them in the room’s Durable Object after the meeting ends. Meet has no automatic purge or self-serve export/delete yet.
To request access to, or deletion of, meeting notes stored by Meet, write to contact@envisioning.com. See Legal basis and your rights.
Subprocessors
Envisioning operates Meet. These providers may process meeting-related data on Envisioning’s behalf:
| Provider | Role | Data |
|---|---|---|
| Cloudflare | Control plane, web hosting, queues, usage ledger, optional AI summary | Room state, transcript text, summaries; member sign-in metadata (not guest emails) |
| LiveKit | Realtime media (SFU + TURN), when using LiveKit Cloud | Ephemeral audio/video/data for the call; participant display identity |
| Member sign-in (Workspace OAuth); Google Calendar for members who connect it | Member identity; calendar events a member creates or reads. Not guest accounts | |
| Anthropic | Meeting notes (Claude API); reading events out of a forwarded email; a member’s own Claude, when the member connects it to Meet | Finalized transcript text and speaker names for notes; the text of an email a member forwards; notes and transcripts a member asks their Claude to read |
| Envisioning Core | Envisioning’s own CRM, operated by Envisioning | A record of each hosted meeting: summary, transcript, and the participant list with names and email addresses |
| TypeSafe AI | Filing suggestions for meeting notes a member imports from Granola, reached through Cloudflare Workers AI or Vercel AI Gateway | The imported note’s title, participant names and email domains, note text, and the start of its transcript |
Speech recognition runs on the host device (FluidAudio / Parakeet), not a cloud speech service. Cloudflare Workers AI, listed under Cloudflare, writes a summary when the Claude API is not in use, and may suggest tasks from the transcript during a meeting. Self-hosted LiveKit keeps media on infrastructure Envisioning operates instead of LiveKit Cloud.
Consent
- You join with your name and email.
- The owner must admit you before Meet issues any media credential.
- Finalized notes remain available in Meet to participants with artifact access.
Legal basis and your rights
Envisioning is the controller of the personal data Meet processes. The providers under Subprocessors process it on Envisioning’s behalf. This notice follows Brazil’s LGPD and the EU GDPR.
- Guests: Meet uses your name and email to provide the meeting you asked to join, including the waiting room and access to its notes.
- Envisioning members: Meet processes member data to run Envisioning’s internal tools, under the member’s working relationship with Envisioning and Envisioning’s legitimate interest.
- Captions, transcript, and notes: needed for live captions during the call and for the meeting’s record in Meet.
- Envisioning’s record of meetings: Envisioning keeps a record of who it met and when, as ordinary business record-keeping (legitimate interest).
You can ask to see, correct, export, or delete your data, or object to how it is used. Write to contact@envisioning.com. That address reaches Michell Zappa, Envisioning’s privacy contact and data protection officer (encarregado) under the LGPD. You can also complain to Brazil’s data protection authority (ANPD) or to the supervisory authority where you live in the EU.
Where data is processed
Residency controls (Cloudflare Durable Object EU jurisdiction, LiveKit EU region pinning, Regional Services / metadata boundary) are part of the production hardening checklist. Until those pins are enabled for a deployment, control-plane state and media may be processed outside the EU under each vendor’s DPA and transfer terms.
What to expect
- No account is required to join as a guest.
- No media is sent until the owner admits you.
- The host device produces captions. Meet does not upload audio to a cloud speech service.
- Meet does not keep a video archive of the call.
This is Meet’s privacy notice for guests and Envisioning members. See also the Terms of use.