Last updated 16 August 2026
You are the controller of the personal data in your meetings. You decide what meetings to take notes in and who is in them.
TruNotes is the processor. We handle that data only to provide the service, only on your instructions, and never for our own purposes.
Account details (name, email), meeting audio until it is transcribed, transcripts and summaries, the names and email addresses of people who join a meeting, scanned pages you add to a note, and — where voice matching is used — anonymous mathematical representations of a voice that are not stored against a person's identity.
We do not process special-category data deliberately. Whether it ends up in a transcript depends on what is said in the room, which is why you control who is in it.
This is the complete list. We will tell you by email before adding to it, so you have a chance to object.
Purpose: Speech to text
Sees: Meeting audio and the transcript produced from it
Their copy of the audio and transcript is deleted as soon as ours is stored.
Purpose: Writes the summary, decisions and action items
Sees: The transcript text
Content sent through the API is not used to train models.
Purpose: Database, sign-in and file storage
Sees: All stored customer content
Every customer is separated at the database level, not in application code.
Purpose: Sends the notes by email
Sees: The notes in an email, and recipient addresses
Only for meetings where notes are actually sent.
Purpose: Sends the notetaker into a Zoom, Teams or Google Meet call
Sees: The call audio, and the participant list the platform reports
Only for online meetings you ask it to join — never for a meeting recorded on the phone. Its recording is destroyed once ours is transcribed.
Purpose: Runs the service that orders transcription and writing-up
Sees: Audio and transcripts in transit
Processes in memory; does not retain customer content.
Purpose: Hosts the website and the web app
Sees: Content you view in a browser, in transit
Does not store customer content.
Your account, meetings, transcripts and files are stored in Frankfurt, Germany.
Transcription and summarisation are performed in the United States by the providers above, so audio and transcript text leave the EU for that processing. Those transfers rely on the European Commission's Standard Contractual Clauses.
Meeting audio: deleted as soon as the transcript is stored, usually within minutes. There is no setting that keeps it.
Notes, transcripts and summaries: kept until you delete them or close your account. They are the record; they do not silently expire.
Meetings taken with no allowance left: still captured and kept. The audio is destroyed as usual, the transcript is stored, and only the written summary waits until the allowance resets. Running out of minutes does not cost you the meeting.
After account deletion: removed immediately, including files.
Encrypted in transit and at rest. Customers are separated at the database level rather than by application code. Changes to a meeting record are written to an append-only log. Consent is timestamped for every session. There is no analytics or tracking software of any kind in the app.
More detail in the security overview.
If someone asks you for their data, or to have it corrected or deleted, we will help you answer within the time the law allows. Account holders can already export and delete their own data from the app.
If we ever suffer a personal data breach affecting you, we will tell you without undue delay and within 72 hours of becoming aware of it, with what we know at the time.
We will answer reasonable security questionnaires and provide the information needed to demonstrate compliance. We do not hold SOC 2 or ISO 27001 today, and we would rather say so than imply otherwise.
When your agreement with us ends, your content is deleted. Say so in writing beforehand if you need it exported first.
support@trunotes.ai. For a signed copy of this agreement on your paper or ours, ask.