Legal · Privacy
Privacy Policy
Last updated April 23, 2026 · Effective for minuto.vibepoint.dev
Minuto handles confidential meeting recordings for audit, legal, and consulting teams. Privacy is not a feature here — it is the product. This page explains what we collect, why, and the controls you have.
At a glance
- Meeting transcripts and MoMs are encrypted with AES-256-GCM at the application layer.
- Audio files live in private buckets, gated by row-level security.
- We never sell your data, never train shared models on it, and never expose it to other users.
- Optional TOTP MFA — your choice, fully reversible.
- One-click export of everything in a portable JSON format.
- 30-day soft-delete window before any data is irreversibly removed.
1. What we collect
We collect the data you provide directly: first name, last name, email, country, an optional username, and — if you tell us — your industry, department, role, and organization. You may also verify a phone number. When you use the Service, we collect the meeting audio you upload, the transcripts and minutes we generate from it, and the tasks you create from those minutes.
2. How we use it
Personal data is used to operate the Service: authenticate you, deliver generated minutes, send transactional notifications, process credit purchases, and personalize defaults (for example, pre-filling your transcription language based on your country). We do not use your data for advertising and do not sell it to third parties.
3. Encryption & storage
Sensitive payloads — transcripts, MoM versions, audio metadata — are encrypted with AES-256-GCM using a master key managed in a secrets vault, before being written to the database. Audio files are stored in a private object store, accessible only via signed URLs scoped to the owning user. All API access is gated by row-level security policies that require both an authenticated session and (for sensitive actions) an MFA-elevated session.
4. MFA factors
When you enrol in TOTP MFA, the cryptographic secret backing your authenticator app is held by our authentication provider. Minuto staff cannot read it. You may unenroll at any time; doing so immediately drops your session back to single-factor and removes the requirement to provide a second factor on subsequent logins.
6. Discovery & friends
Other users can find you by username only — never by email, name, or organization. Email addresses become visible only after a friend request is accepted. We do not display activity metrics (meeting counts, last-active timestamps) on public profiles, and search results are capped to prevent enumeration.
7. Sub-processors
We rely on a small set of vetted providers to deliver the Service:
- Lovable Cloud (managed Supabase) — application database and authentication.
- Lemon Squeezy — payment processing.
- OpenRouter and privacy-reviewed model providers — minutes generation.
- Replicate — audio transcription.
8. Export your data
You can download every piece of data tied to your account at any time from your profile. The export is a single JSON file containing your profile, meetings, decrypted transcripts and minutes, tasks, friendships, and credit history.
10. Retention & deletion
Active account data is retained while your account exists. When you request deletion, the account enters a 30-day grace window during which you can cancel and restore everything. After 30 days, all related rows and audio files are purged from primary storage.
11. Your rights
You may access, correct, export, or delete your personal data at any time through the in-product profile. Where local law (GDPR, the Philippines DPA, CPRA, etc.) grants additional rights — including objection to processing or lodging a complaint with a supervisory authority — those rights apply.
12. Contact
Privacy questions or requests: privacy-minuto@vibepoint.dev. See also our Terms of Service and Refund Policy.