Draft — pending legal review. This text has not yet been approved by a lawyer. The Turkish version prevails.
Privacy Policy
Last updated: 28 September 2026
Meetci records, transcribes and summarises your meetings and follows up on the tasks. Meetings can contain sensitive information, so we collect as little as possible and keep it for as short as possible. This policy explains what we process and why, who we share it with, and your rights.
1. Data controller
Data controller: [COMPANY NAME] ("Meetci", "we")
Address: [ADDRESS]
MERSIS no.: [MERSIS]
Contact: support@meetci.app
This policy applies to the Meetci mobile app, the www.meetci.app website, and the invitation and share pages. For users in Türkiye it is based on the Turkish Personal Data Protection Law No. 6698 ("KVKK"); for users in the European Union and European Economic Area also on the General Data Protection Regulation ("GDPR"). Our KVKK information notice is on the KVKK Information Notice page.
2. Data we process
| Category | Examples | Source |
|---|---|---|
| Identity and contact | Name, email address, profile photo; the account identifier of your Apple or Google account when you sign in with them | You; Apple / Google sign-in |
| Account security | One-time sign-in and deletion codes (hashed only), session tokens, IP address, audit logs | Your use of the app |
| Meeting content | Audio recording, transcript, speaker labels, summary and report, decisions, highlights, meeting title, date and duration, audio/video files you import | You |
| Contacts | Name, email, phone and department of people you add to your Meetci contacts | You |
| Tasks and collaboration | Tasks, subtasks, due dates, comments and edit history, @mentions, file/photo/video attachments, invitations, activity history | You and the people you share tasks with |
| Voiceprint (only with explicit consent) | A mathematical summary computed from a person's voice (biometric data) | Meeting recordings of people who consented, or your own voice sample |
| Subscription | Plan, trial status, store, product, price, currency, country, transaction ID, renewal and cancellation events, campaign codes you used. We never receive your card details; Google or Apple takes the payment. | The store (via RevenueCat) and you |
| Usage | Minutes processed, AI model used, processing time and cost | Your use of the app |
| Device and notifications | Push token, platform, app version, notification preferences | Your device |
| Support | Emails you send us and their content; the app version and platform added when you write from the app | You |
We do not collect the advertising ID, location, your phone's address book or browsing history. We do not send marketing messages; if we ever want to, we will ask for your consent first.
3. Purposes and legal bases
| Purpose | Legal basis (KVKK art. 5 / 6 · GDPR) |
|---|---|
| Creating your account, signing you in and providing the service: processing recordings, producing transcripts, reports and tasks, distributing tasks, sending invitations and notifications, sharing and export | Performance of a contract (KVKK 5/2-c · GDPR 6(1)(b)) |
| Managing the trial, quota, subscriptions and campaign codes | Performance of a contract; legal obligation for tax and commercial law (KVKK 5/2-ç · GDPR 6(1)(c)) |
| Security: preventing abuse and fraud, rate limiting, audit logging, preventing repeated use of the free trial | Legitimate interest (KVKK 5/2-f · GDPR 6(1)(f)) |
| Measuring cost and quality of the service, fixing bugs | Legitimate interest |
| Answering support requests and data subject requests | Performance of a contract; legal obligation |
| Responding to lawful requests, protecting our rights in disputes | Legal obligation; establishment, exercise or defence of rights (KVKK 5/2-e) |
| Voice recognition: automatically matching speakers to people in your contacts | Explicit consent for special category (biometric) data (KVKK art. 6 · GDPR 9(2)(a)) |
4. Audio recordings
- The original stays on your phone. Recordings are kept in the app's private storage on your device and are excluded from device backups (iCloud / Google Drive) by default. The copy on your phone stays there until you delete it or uninstall the app.
- It goes to the server only to be processed. Audio is stored encrypted with AES-256-GCM using a per-file key and is deleted once the transcript is ready; a deletion request is also sent to the provider. An hourly cleanup job deletes any audio older than 24 hours, whatever its state. Audio files are not included in server backups.
- If your plan has run out: the encrypted audio of a recording that could not be processed because the trial or quota ended is kept for at most 30 days so it can be processed once your plan is active again, then deleted.
- Transcripts, summaries, reports and tasks are kept until you delete them or your account.
5. Voice recognition (biometric data)
Voice recognition is an optional feature that automatically matches the speakers in your meetings to people in your contacts. It is off by default.
- A voiceprint (a mathematical summary of a voice) is created for people who have given explicit consent. Under KVKK art. 6 and GDPR art. 9 a voiceprint is biometric, i.e. special category, personal data and is processed only on the basis of explicit consent.
- When you turn on voice recognition for a person, you declare that you have given them the information notice and obtained their explicit consent. For your own voiceprint you give the consent yourself.
- Voiceprints are created on Meetci's own servers, stored encrypted (AES-256-GCM) and never sent to any third party, including AI providers. They are used only for matching in your own meetings and are never shared with other users.
- Temporary speaker summaries computed for matching are kept encrypted for 7 days.
- Voiceprints are deleted immediately when consent is withdrawn, the person is deleted or voice recognition is turned off, and automatically after 12 months without use.
- A person who uses Meetci can see under Profil › "Sesim hakkında" (About my voice) who has recorded consent for them, and with one tap withdraw all consents and have their voiceprints deleted.
6. AI processing
We use OpenAI as our AI service provider for transcription and analysis (summary, decisions, task suggestions). For processing, the provider receives the audio, the transcript and the context needed to write the report (meeting date, chosen template, names and departments of people in your contacts). Under OpenAI's API terms this data is not used to train their models by default.
AI output is a suggestion: tasks and person matches are not sent to anyone until you confirm them and tap "Distribute tasks". Output may be wrong; check it before relying on it for important decisions. We do not take decisions based solely on automated processing that produce adverse effects for you.
7. Who we share data with
People you share with. People you assign a task to or add as watchers see their own tasks and subtasks, the meeting title and date, and the part of the transcript the task came from (about ±30 seconds). If you create a share link, anyone with the link can see the report; the transcript is not included unless you explicitly add it.
Our service providers (processors) receive only the data needed to provide the service, limited by contract to that purpose:
| Provider | Country | Purpose | Data |
|---|---|---|---|
| OpenAI, L.L.C. | USA | Transcription and analysis | Audio (during processing), transcript, report context |
| RevenueCat, Inc. | USA | Subscriptions and purchase validation | Pseudonymous user ID (no email or name), purchase and subscription details, country, price |
| Google LLC / Google Ireland Ltd. | USA / EU | Google sign-in, Google Play billing, Android notifications (Firebase Cloud Messaging) | Account ID, purchase details, push token and content |
| Apple Inc. / Apple Distribution International | USA / EU | Sign in with Apple, App Store billing, iOS notifications | Account ID, purchase details, push token and content |
| 650 Industries, Inc. (Expo) | USA | Delivering push notifications | Push token, notification title and body |
| Resend, Inc. | USA | Sending email (sign-in codes, invitations, deletion codes) | Email address, email content |
| [HOSTING PROVIDER] | [COUNTRY] | Servers, database and encrypted file storage | All data stored in the service |
If you turn off "show content in notifications", push notifications carry only a generic text. We do not sell your personal data or share it for advertising. Where legally required, we may share it with competent authorities to the extent the law requires.
8. International transfers
Some of the providers above are located outside Türkiye (mainly in the USA), so your personal data is transferred abroad. These transfers are safeguarded by the standard contracts announced by the Turkish Personal Data Protection Board under KVKK art. 9 and, for EU users, by the European Commission's standard contractual clauses or adequacy decisions under the GDPR. Voiceprints are never transferred abroad.
9. Retention
| Data | Period |
|---|---|
| Audio on the server | Deleted once the transcript is ready; in any case within 24 hours. Recording waiting because your plan ran out: at most 30 days. |
| Audio on your phone | On your device until you delete it or uninstall the app |
| Transcripts, reports, tasks, comments, attachments, contacts | Until you delete them or your account |
| Voiceprints | Immediately when consent is withdrawn, the person is deleted or the feature is turned off; automatically after 12 months without use |
| Temporary speaker summaries (voice recognition) | 7 days |
| When you delete your account | The account is closed immediately; remaining data is permanently deleted within 24 hours (details: Account and data deletion) |
| Raw subscription notifications (webhooks) | 90 days |
| Subscription and purchase records | For the life of the account and as required by tax/commercial law [PERIOD] |
| Usage and cost records | Detached from your account on deletion (no longer linked to you) and kept for statistics |
| Trial / campaign reuse prevention | Irreversible digest (HMAC) of the deleted account's email and sign-in identifiers: [PERIOD] |
| Audit logs | [PERIOD]; IP addresses in these logs are deleted when your account is deleted |
| Session tokens | At most 30 days; revoked immediately on sign-out or account deletion |
| Invitation links | Valid for 14 days |
| Support correspondence | [PERIOD] |
When a period ends, the data is deleted, destroyed or anonymised.
10. Security
- All connections are encrypted with TLS (HTTPS).
- Audio files and voiceprints are stored encrypted with AES-256-GCM using separate keys.
- Access tokens are short-lived (15 minutes) and refresh tokens rotate on every use.
- The admin panel requires two-factor authentication (TOTP) and every action is audit-logged; administrators cannot see your meeting content, only usage statistics.
- Share links use unguessable 256-bit tokens; only their hashes are stored on the server.
No system is perfect; in the event of a data breach we will notify the authority and affected people as required by law.
11. Your rights and requests
Under KVKK art. 11 you have the right to learn whether your personal data is processed, request information about it, learn the purpose of processing and whether it is used accordingly, know the third parties it is transferred to in Türkiye or abroad, request rectification if it is incomplete or inaccurate, request erasure or destruction under KVKK art. 7, request that these actions be notified to third parties it was transferred to, object to a result against you arising exclusively from automated analysis, and claim compensation for damage caused by unlawful processing.
Users covered by the GDPR also have the rights of access, rectification, erasure, restriction, data portability and objection, and may lodge a complaint with the supervisory authority in their country. Where processing is based on consent, you may withdraw it at any time.
In the app: Profil › "Verilerimi indir" (Download my data) gives you a JSON copy of your data, Profil › "Hesabımı ve verilerimi sil" (Delete my account and data) deletes your account, and Profil › "Ses tanıma" (Voice recognition) manages voice recognition and consents. The app interface is currently in Turkish.
Requests: send your request from the email address registered with us to support@meetci.app, or in writing to [ADDRESS]. We answer free of charge within 30 days at the latest; if the request involves additional cost, the fee set by the Board may apply. If your request is rejected, you find the answer insufficient or we do not answer in time, you may complain to the Turkish Personal Data Protection Board.
12. Other people's data
Meeting recordings, contacts and tasks contain other people's data. Before recording, it is your responsibility to inform the people in the meeting and, where required, obtain their consent, and to share the data of people you add to your contacts or assign tasks to lawfully. The app reminds you of this before recording. Voice recognition always requires the person's explicit consent.
If your name or voice appears in Meetci and you cannot reach the user concerned, you can write to support@meetci.app to exercise your rights.
13. Cookies
www.meetci.app and the share pages use no cookies, analytics or advertising trackers, and load no third-party resources (fonts, scripts). The admin panel uses strictly necessary session and security cookies for authorised Meetci staff only. The mobile app keeps your session in your device's secure storage (iOS Keychain / Android Keystore) and does not use the advertising ID.
14. Children
Meetci is designed for work and professional use and is not directed at people under 18. If we learn that we process data of someone under 18, we delete it; you can let us know.
15. Changes and contact
We may update this policy when the product or the law changes. We announce significant changes in advance in the app or by email; the current version is always on this page.
Questions: support@meetci.app