Last updated 16 August 2026
Meeting audio is destroyed once the notes are written. Customer data is stored in the EU. Customers are separated at the database level rather than by application code. Every change to a meeting record is written to a log that cannot be edited. There is no analytics or tracking software of any kind in the app.
We are a small company and we would rather tell you exactly where we are than imply a maturity we have not reached. What we do not have yet is listed at the bottom of this page.
Accounts, meetings, transcripts, summaries and files are stored in Frankfurt, Germany.
Transcription and summarisation run in the United States, so audio and transcript text leave the EU for that step. Those transfers rely on Standard Contractual Clauses. Every provider that touches your content is named in the data processing agreement — the full list, not a sample.
We do not claim UAE data residency, and you should not read “Frankfurt” as meaning it. The record is stored in the EU; the audio and the transcript are processed in the US on the way there.
Audio is uploaded, transcribed, and then destroyed — usually within minutes. Our transcription provider's copy is deleted as soon as ours is stored.
The one exception is deliberate. A host on a paid plan may choose, for a single meeting, to keep that meeting's audio for a limited time — 30 days on Pro, 90 on Enterprise. It is off by default, decided per meeting rather than as an account-wide setting, and the room is shown when it is on. That host can play it back inside the app; there is still no download, and nobody else can reach it.
Access is enforced by the database itself. Every table carries rules that limit rows to the account they belong to, so a mistake in application code cannot expose another customer's meetings.
Files are private and reachable only through links that expire. The storage rules restrict each person to their own folder.
Within our own team, access to production data is limited to the founder and used only to investigate a fault or answer a support request.
This is recorded.Reading a customer's meeting for support goes through a route that refuses to work without a stated reason and writes an entry before it returns anything. Automated processing — writing a meeting up, emailing the notes — is logged the same way. The log cannot be edited or deleted, by us or by anyone, and it survives the deletion of the meeting it refers to.
What it does not cover, said plainly: direct queries run in our hosting provider's own console are covered by that provider's logs rather than ours. We would rather tell you the edge of what we capture than imply we capture everything.
Encrypted in transit with TLS everywhere, and at rest by our infrastructure providers. Sign-in tokens are held in the iOS keychain rather than ordinary app storage.
Email with a one-time code, Sign in with Apple, or Google. The app can additionally be locked with Face ID, so a phone left on a table does not expose a meeting record.
Four things, and that is the entire list: the microphone, to take notes; Face ID, if you switch on the app lock; your calendar; and speech recognition.
Speech recognition is used for one thing: so a note you started by saying “Hey Siri, take a TruNote” can be finished by saying “save it”, without touching the phone. It runs entirely on your iPhone — the audio is not sent to Apple and not sent to us, the words it hears are never stored, and it listens only while a hands-free note is being dictated. Refuse the permission and everything else still works.
The calendar is read-only and never swept. When you start a meeting it looks for the entry happening at that moment, so the notes carry the meeting's real name and the invitee list is known. Nothing else in your diary is read, stored or sent, and a meeting with no matching entry sends nothing at all. It can be switched off in Settings, and then no calendar request is ever made.
No location, no contacts, no advertising identifier, and no tracking permission request — because there is nothing doing any tracking.
Every change to a meeting record — a regenerated summary, a corrected name, a speaker assignment, a manual edit — is written to an append-only log with who did it and when. Rows are never updated or deleted while the meeting exists.
Consent is recorded with a timestamp for every session, so it is possible to show when a room was told notes were being taken.
You can delete your account yourself, from Settings in the app. It takes effect immediately and cannot be undone. No email, no waiting.
One consequence follows from what TruNotes is: a meeting other people attended is not deleted out from under them. It passes to one of them. Everything that was yours alone is destroyed.
Our database is hosted by Supabase in Frankfurt on infrastructure with redundant storage. Because meeting audio is destroyed after transcription, nothing held in reserve anywhere contains recordings — only the written record.
Being straight about the current limit: we are on a hosting tier without scheduled point-in-time backups, and moving to one is on our list before we take on business-critical customers. If continuity matters to your evaluation, ask us where this stands rather than assuming — the answer changes.
Report anything you find to support@trunotes.ai. We will acknowledge within one business day.
If a breach affects your personal data, we will tell you without undue delay and within 72 hours of becoming aware of it, with what we know at the time rather than waiting until we know everything. We will not quietly work out the wording first.
Written plainly, because you will ask and because finding out later is worse:
support@trunotes.ai. We answer security questionnaires — send yours.
See also our privacy policy, terms and data processing agreement.