NovaMeet
Legal

Privacy & Rights

Effective date: February 2026  ·  Self-hosted platform

What we collect

Meeting metadata, transcripts, notes, and task items you create or upload. Authentication data such as MFA devices and API keys are stored for security purposes only.

How data is used

Data is processed solely to provide transcription, AI summaries, and task extraction, and to power audit logs for administrator actions. Your data is never sold or shared with third parties.

Data ownership

You own your meeting content. This is a self-hosted platform — your data stays entirely within your own infrastructure. Administrators can manage users but do not have access to user content by default.

Security

We support TOTP and WebAuthn passkeys, per-device credential limits, API key revocation, and full audit trails for all administrator changes. Passwords are hashed with Argon2id.

Your rights

You may request a full export of your data via GET /api/export (authenticated). You can revoke API keys and remove passkeys at any time from the Settings page. Contact your system administrator for deletion requests.

Contact

Reach your system administrator for data access, correction, or deletion requests. For questions about this policy, contact your instance administrator directly.