Legal

Privacy Policy

AllOnEars puts a real-time intelligence layer over live conversations, so how we handle that audio matters more than it would for most software. This policy sets out exactly what we process and on what basis.

Effective October 1, 2026AllOnEars Inc.

This Privacy Policy explains how AllOnEars Inc. ("AllOnEars", "we") processes personal data when you use the AllOnEars service, which adds a real-time augmented-intelligence layer over live audio (meeting bots and browser microphone capture, speech-to-text, and AI-generated context cards and summaries).

1Who we are (controller) and our two roles#

The controller of your account, billing and usage data is AllOnEars Inc., a Delaware C Corporation with its registered address at 3 Germay Drive, Unit 4 #3321, Wilmington, DE 19804, United States. You can reach us at [email protected] or +1 (650) 844-3277.

For the meeting content you capture using AllOnEars (audio, transcripts, context cards, key facts, reports), you are the controller and we act only as your processor, on your documented instructions, under our Data Processing Agreement. See also our Sub-processors page.

People in the EU and UK can also send data-protection enquiries to [email protected].

2What we process#

  • Account data — name, email, hashed password (or, if you sign in with Google or Microsoft, the identity that provider gives us), plan, billing status.
  • Meeting content — audio streamed from a meeting or microphone, the participant names the meeting platform shows, the transcripts and translations produced from the audio, speaker labels, and the AI context cards, key facts, key notes and reports derived from them. Depending on what participants say, this may contain special-category or confidential information (see section 4).
  • Context material — documents, glossary terms, notes and CRM records you add or connect so that cards fit your business. Terms and short extracts of this material are sent to our speech-to-text provider to improve recognition.
  • Calendar data — when you connect a calendar, event details and meeting links used to schedule recordings. OAuth tokens we store are encrypted at rest (AES-256-GCM). Our meeting-bot provider also receives the access it needs to sync your calendar.
  • Contact and sales records— when you write to us, request a demo or use "Talk to sales", we keep your name, email, company, phone number and message. When you create an account, we add your name and email to the same list so that we can help you get started.
  • Usage & technical data — minutes used, timestamps, IP address, and operational and security logs. We do not currently use a third-party error-tracking or analytics service.

3Purposes and lawful bases (GDPR Art. 6)#

  • Providing the service (transcription, cards, scheduling) — performance of contract, Art. 6(1)(b).
  • Meeting recording & transcription — carried out on your instructions as processor; you are responsible for establishing the lawful basis and for obtaining any required participant consent and notice (see our Terms). To help you, a bot joins the meeting as a named participant ("AllOnEars" unless an Enterprise customer sets its own name) and posts a notice in the meeting chat that the meeting is being recorded and transcribed, in the spoken language where it is known. When the screen-share view is on, the shared screen also shows a permanent line: "This meeting is being transcribed by AllOnEars". Browser-microphone capture shows no notice to other people in the room; the app asks you to confirm that you have told them.
  • Billing, fraud prevention and tax — contract and legal obligation, Art. 6(1)(b)/(c), and legitimate interests Art. 6(1)(f).
  • Security and service operation — legitimate interests, Art. 6(1)(f).
  • Contact, sales and onboarding follow-up — legitimate interests, Art. 6(1)(f).
We do not train models on your data
We do not use your meeting content to train our own models. Our requests to language models are routed only to providers that do not retain prompts or train on them. Your content is processed to produce your output and to run and secure the service, and for nothing else.

4Special-category data (Art. 9)#

Conversations can incidentally reveal special-category data (e.g. health, political or religious views, trade-union membership). We do not seek out or use special-category data for our own purposes. Where such data appears in meeting content, we process it only as your processor, on your instructions; you as controller are responsible for establishing an Art. 9(2) condition (typically the explicit consent of participants) before such content is captured. If you cannot ensure this, do not record meetings where special-category data is likely to be discussed.

5Automated processing and profiling#

Context cards and summaries are generated automatically by AI from the transcript. This is automated processing but it does not produce legal or similarly significant effects on any individual, and we make no solely-automated decisions about you within the meaning of GDPR Art. 22. Output is assistive, can be inaccurate, and should not be relied on as a sole record. If you use AllOnEars output to make decisions about identifiable people, you are responsible for applying appropriate human review and for any Art. 22 obligations that arise from your use.

6Sub-processors and international transfers#

We use the categories of third-party processor listed on our Sub-processors page (meeting bot, speech-to-text, language model, network edge, payment, email, sign-in and calendar, hosting, and an optional CRM). Some process data outside the EEA; where they do, transfers rely on the European Commission's Standard Contractual Clauses and supplementary safeguards under GDPR Chapter V. The region in which meeting recordings are processed by our bot provider is set at deployment; EU-region processing is available for enterprise customers by arrangement — contact [email protected]. We give advance notice before adding or replacing a sub-processor so you may object.

To find the encyclopedia article shown on a context card, our servers send short search terms taken from the conversation to Wikipedia (Wikimedia Foundation, United States). The request contains the term only, not the audio, the speaker or your account, but a term can be the name of a person or organisation mentioned in the meeting. This is a public service, so there is no data-processing agreement with it.

7Retention#

Account data is kept for the life of your account. Meeting content (transcripts, context cards, key facts, interaction records and generated reports) is automatically deleted after 365 days, or sooner on request. Business and Enterprise customers can set a shorter window for their organisation. Billing and usage records, such as timestamps and minutes used, are not meeting content and are kept with your account. With Zero-Data-Retention mode, meeting content is not saved at all.

  • Recordings held by our bot provider expire on their own after 7 days. With Zero-Data-Retention mode, the recording is not stored.
  • Live-session caches that drive the in-meeting view expire automatically: the last 200 caption lines until 4 hours after the latest one, and shared caption translations for 2 hours. With Zero-Data-Retention mode they are cleared when the meeting ends.
  • Backups. A database backup is made every night and kept on our server for 14 days. We also email an AES-256 encrypted copy of the database to a restricted-access staff mailbox on a schedule; the password is not sent with it, and we keep those copies for a limited period and delete older ones. Data you delete from the live service can therefore remain in backup copies until those copies are deleted.
  • Contact and sales records are kept until you ask us to delete them.

You can delete your entire account at any time (Settings → Danger Zone), and can request deletion of individual sessions by contacting us. Deleting your account deletes your account and meeting content, deletes your customer record at our payment provider, instructs our bot provider to delete the underlying meeting recordings it stores, and flushes the associated live-session caches. Backup copies and contact and sales records are not part of that automatic deletion; email [email protected] to have the contact and sales records deleted.

8Your rights#

Under the GDPR you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and to lodge a complaint with your local supervisory authority. Account holders can export or delete their data in-app, or by emailing [email protected]. If your data was processed by a customer of ours (i.e. you were a participant in someone else's meeting), that customer is the controller — please contact them; we will assist them in responding to your request.

California residents have additional rights, including the right to opt out of any sale or sharing of personal information. See our California Privacy Notice.

9Children#

AllOnEars is a business service that is not directed to children. You must be at least 18 years old to create an account. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact [email protected] and we will delete it.

10Security#

We use encryption in transit (TLS), AES-256-GCM encryption at rest for stored OAuth credentials, hashed passwords and API keys, scoped access tokens, tenant isolation, rate limiting, and audit logging. Our database and cache are not published on the server's public network interface. Access to our internal admin console is limited to named staff, shows account and billing details but never meeting content, and every use of it is logged. Our servers are hosted in European Union (Germany). No system is perfectly secure; we will notify you and the relevant supervisory authority of a personal-data breach as required by Art. 33/34. Our full security posture is set out in the Trust Center.

11Changes#

We will post changes here and, for material changes, notify account holders. Continued use after the effective date constitutes acceptance.

Legal entity
AllOnEars Inc.
Delaware C Corporation
Registered address
3 Germay Drive
Unit 4 #3321
Wilmington, DE 19804
United States