Legal · Privacy

Privacy Policy

Last updated April 23, 2026 · Effective for minuto.vibepoint.dev

Minuto handles confidential meeting recordings for audit, legal, and consulting teams. Privacy is not a feature here — it is the product. This page explains what we collect, why, and the controls you have.

At a glance

  • Meeting transcripts and MoMs are encrypted with AES-256-GCM at the application layer.
  • Audio files live in private buckets, gated by row-level security.
  • We never sell your data, never train shared models on it, and never expose it to other users.
  • Optional TOTP MFA — your choice, fully reversible.
  • One-click export of everything in a portable JSON format.
  • 30-day soft-delete window before any data is irreversibly removed.

1. What we collect

We collect the data you provide directly: first name, last name, email, country, an optional username, and — if you tell us — your industry, department, role, and organization. You may also verify a phone number. When you use the Service, we collect the meeting audio you upload, the transcripts and minutes we generate from it, and the tasks you create from those minutes.

2. How we use it

Personal data is used to operate the Service: authenticate you, deliver generated minutes, send transactional notifications, process credit purchases, and personalize defaults (for example, pre-filling your transcription language based on your country). We do not use your data for advertising and do not sell it to third parties.

3. Encryption & storage

Sensitive payloads — transcripts, MoM versions, audio metadata — are encrypted with AES-256-GCM using a master key managed in a secrets vault, before being written to the database. Audio files are stored in a private object store, accessible only via signed URLs scoped to the owning user. All API access is gated by row-level security policies that require both an authenticated session and (for sensitive actions) an MFA-elevated session.

4. MFA factors

When you enrol in TOTP MFA, the cryptographic secret backing your authenticator app is held by our authentication provider. Minuto staff cannot read it. You may unenroll at any time; doing so immediately drops your session back to single-factor and removes the requirement to provide a second factor on subsequent logins.

5. Sharing & collaborators

You can grant view or edit access on individual meetings to specific users, or generate password-protected share links that expire after 15 minutes. Share-link views are recorded in an audit log visible to the meeting owner.

6. Discovery & friends

Other users can find you by username only — never by email, name, or organization. Email addresses become visible only after a friend request is accepted. We do not display activity metrics (meeting counts, last-active timestamps) on public profiles, and search results are capped to prevent enumeration.

7. Sub-processors

We rely on a small set of vetted providers to deliver the Service:

  • Lovable Cloud (managed Supabase) — application database and authentication.
  • Lemon Squeezy — payment processing.
  • OpenRouter and privacy-reviewed model providers — minutes generation.
  • Replicate — audio transcription.

8. Export your data

You can download every piece of data tied to your account at any time from your profile. The export is a single JSON file containing your profile, meetings, decrypted transcripts and minutes, tasks, friendships, and credit history.

10. Retention & deletion

Active account data is retained while your account exists. When you request deletion, the account enters a 30-day grace window during which you can cancel and restore everything. After 30 days, all related rows and audio files are purged from primary storage.

11. Your rights

You may access, correct, export, or delete your personal data at any time through the in-product profile. Where local law (GDPR, the Philippines DPA, CPRA, etc.) grants additional rights — including objection to processing or lodging a complaint with a supervisory authority — those rights apply.

12. Contact

Privacy questions or requests: privacy-minuto@vibepoint.dev. See also our Terms of Service and Refund Policy.