Privacy Policy
Last updated: February 26, 2026
1. Introduction
HeyMeet ("we," "our," or "the Service") is a macOS desktop application that provides real-time transcription and AI-powered meeting assistance. This Privacy Policy describes how we collect, use, and protect your information when you use our Service, website, and related services.
By using the Service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Hashed password (we never store plaintext passwords)
- Account creation date
2.2 Device Information
When you use the macOS app, we may collect:
- Device name and identifier
- macOS version
- Application version
- Last activity timestamp
2.3 Transcription Data
Audio is streamed over an encrypted connection for real-time transcription and is immediately discarded after processing. No audio recordings are ever made, stored, or retained by us or our infrastructure providers. Only the resulting text transcript is used to generate AI suggestions. Transcripts are processed in real-time and are not stored on our servers after the session ends.
2.4 Usage Data
We collect aggregated usage metrics:
- Number of AI requests per day
- Transcription minutes used
- Token usage (input/output counts)
This data is used solely for enforcing plan limits and improving the Service.
2.5 Payment Information
Payment processing is handled by our third-party payment provider, Paddle (Paddle.com Market Limited). We do not collect, store, or process credit card numbers or payment details directly. Please refer to Paddle's Privacy Policy for details on how they handle payment data.
3. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve the Service
- Process your subscription and manage your account
- Enforce usage limits associated with your plan
- Send essential service communications (e.g., account verification, security alerts)
- Detect and prevent fraud, abuse, or violations of our Terms
- Comply with legal obligations
We do not sell, rent, or trade your personal information to third parties. We do not use your data for advertising purposes.
4. Data Sharing
We share data only in the following circumstances:
- AI Model Providers: Text transcripts are sent to third-party AI model providers for generating responses. These providers process data according to their own privacy policies and data processing agreements.
- Payment Processor: Paddle processes payments on our behalf as Merchant of Record.
- Legal Requirements: We may disclose information if required by law, subpoena, or government request.
5. Data Security
We implement industry-standard security measures to protect your data:
- All data in transit is encrypted using TLS/HTTPS
- Passwords are hashed using bcrypt with appropriate cost factors
- Authentication uses short-lived JWT tokens
- Audio is encrypted in transit, processed in real time, and never stored
While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
6. Data Retention
- Account data: Retained for as long as your account is active
- Transcription data: Not stored — processed in real-time only
- Usage metrics: Retained for billing and analytics purposes
- After account deletion: We delete your personal data within 30 days, except where retention is required by law
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing of your data
- Data portability
To exercise any of these rights, contact us at the email address provided below.
8. GDPR Compliance (EEA Users)
For users in the European Economic Area, we process personal data based on:
- Contract performance: Processing necessary to provide the Service you subscribed to
- Legitimate interests: Fraud prevention, service improvement, and security
- Legal obligations: Tax and regulatory compliance
Paddle acts as the Merchant of Record for EEA transactions and handles VAT/tax compliance.
9. Children's Privacy
The Service is not intended for users under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
10. Cookies and Local Storage
Our website uses:
- Session cookies: Essential for authentication (login state)
- Local storage: Language preference only
We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
11. Marketing Communications
During registration, you may optionally opt in to receive marketing communications from us. If you consent, we may send you:
- Product updates, new features, and improvements
- Promotional offers and special deals
Marketing consent is entirely voluntary and does not affect your ability to use the Service. You can withdraw your consent at any time through your account settings or by using the unsubscribe link included in every marketing email. We do not share your email address with third parties for their marketing purposes. We record the date and time of your consent for compliance purposes.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes by posting the updated policy on this page with a revised "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:
Email: Contact Support