AllOnEars processes live meeting audio, so how we handle that data matters more than it does for most software. This page sets out the controls we operate, the frameworks we work to, and where to verify each claim.
This section lists the privacy frameworks AllOnEars works to and where each stands. A chip reads "In place" only where the commitment is implemented in the product and reflected in the contract we sign with you.
GDPR
Art. 28 processor terms, data-subject request handling, retention limits and breach notification are in place.
In place
CCPA / CPRA
California disclosures in place. Global Privacy Control signals are honoured automatically.
In place
SOC 2 Type II
Readiness is underway. Our control environment is operated against the AICPA Trust Services Criteria for Security, Availability and Confidentiality, and the control mapping is available to customers under review. Independent attestation follows.
In progress
ISO 27001
Readiness is underway against the ISO/IEC 27001 Annex A control set, which our information security management practices are maintained to. Certification scope and timing are aligned to enterprise requirements.
In progress
EU Standard Contractual Clauses
The transfer mechanism for restricted transfers of personal data to our sub-processors outside the EEA.
In place
Data Processing Agreement
Offered to every customer, incorporating the GDPR Art. 28 terms and the SCCs where relevant.
In place
EU data residency
Application and database hosted in the European Union (Germany). Some sub-processors may process data outside the EU; see the Sub-processors page.
Each of the following is implemented in the product. Where a control is plan-gated, section 4 says so.
Encryption in transit
TLS on every public endpoint. Our network-edge provider terminates TLS and proxies traffic to our servers. The meeting bot reaches our platform over signature-verified webhooks and a token-protected audio connection.
Third-party tokens encrypted at rest
Calendar OAuth access and refresh tokens are AES-256-GCM encrypted under a key separate from the application signing secret, so a database dump yields no live calendar credentials.
Storage limitation
Meeting content past your retention window (365 days by default) is purged by a daily job, not left to accumulate — GDPR Art. 5(1)(e). Recordings held by our bot provider expire after 7 days.
Erasure and portability
Self-service from Settings → Privacy & data. Deletion also removes the underlying recordings held by our recording sub-processor, not merely our own rows. Exports never include credential material.
Prompt-injection defence
Meeting transcripts are fenced and treated strictly as untrusted data by the summarisation models, so a participant cannot speak an instruction that lands in another participant’s report.
In-meeting recording notice
In every bot mode, the bot joins as a named participant and posts a notice in the meeting chat that the meeting is being recorded and transcribed (pinned on Google Meet). When the screen-share view is on, the shared screen also shows a permanent line, "This meeting is being transcribed by AllOnEars". These support, but do not replace, the consent and notice you owe participants (see the Terms). Browser-microphone capture shows nothing to other people in the room.
Data residency
Our application and database are hosted in European Union (Germany). The meeting-bot provider's region is set at deployment, and an EU region is available by arrangement. Speech-to-text and language-model processing may take place outside the EU under Standard Contractual Clauses. Language-model requests are routed only to providers that do not retain prompts or train on them. A United States or dedicated deployment may be agreed for Enterprise customers; it is not a self-service setting.
Tenant isolation
Ownership checks on every resource access, scope-bound short-lived tokens, hashed passwords and API keys, and per-endpoint rate limiting.
Staff access and audit logging
Our internal admin console is limited to staff on an email allowlist. It shows account and billing details only, never transcripts, cards or facts. Every view of a customer and every change is written to an audit log, as is every refused attempt. Organisation administrators see their own workspace audit log.
Backups
A database backup is made every night and kept on our server for 14 days. We also email an AES-256 encrypted copy to a restricted staff mailbox on a schedule. Deleted data can remain in backups until those copies are deleted.
Every category of sub-processor that can touch personal data is listed, with its role and region, on our Sub-processors page; the named list is given to customers with the DPA. We sign a Data Processing Agreement incorporating the GDPR Art. 28 terms and, where relevant, the EU Standard Contractual Clauses. For meeting content you are the controller and we act solely as your processor.
We do not train models on your data. We do not use meeting content to train our own models, and our language-model requests are routed only to providers that do not retain prompts or train on them. Meeting content is processed to produce your output and to run and secure the service.
Every plan can turn on automated redaction of structured PII (emails, phone numbers, credit-card numbers, IBANs and national-ID numbers) in stored transcripts and in text sent to the language models. Live captions on the shared screen, and the audio sent to the speech-to-text provider, are not redacted. Business and Enterprise add Zero-Data-Retention mode: transcripts, cards, key facts and reports are not saved, the bot provider is told not to store the recording, and the short-lived live-view buffer is deleted when the meeting ends. They also let an organisation choose a shorter retention window. Enterprise terms, including any dedicated deployment, are agreed individually. These are how we expect to satisfy stricter internal policies without asking you to weaken them.
Email [email protected]. We acknowledge reports within one business day. Please allow a reasonable window to remediate before public disclosure; we do not pursue good-faith researchers who follow that process.
For urgent incidents affecting a live deployment, call +1 (650) 844-3277.
EU/UK residents: see the Privacy Policy. California residents: see the California Privacy Notice, which also carries the "Do Not Sell or Share" control. We do not sell or share personal information, and we honour Global Privacy Control signals automatically.
Send security questionnaires, vendor-assessment forms and DPA requests to [email protected]. We name our sub-processors, confirm the region your deployment uses, complete your assessment forms and countersign the DPA. Questions about a specific framework or audit requirement are answered directly by our security team, usually within two business days.
Юридическое лицо
AllOnEars Inc. Delaware C Corporation
Юридический адрес
3 Germay Drive Unit 4 #3321 Wilmington, DE 19804 United States