Last updated: 2026-05-20
This Privacy Policy explains how Minuta handles the information connected to your use of our website (minutapp.tech) and the Minuta macOS desktop application. Minuta captures audio locally, then uses cloud processors for transcription, speaker diarization, summaries, translations when enabled, and AI copilot suggestions.
We keep the service narrow: an account to sign in, subscription state if you pay for Pro, and the meeting content needed to provide the cloud AI features you request. Analytics and diagnostics are configured separately and must not include meeting content.
Who we are
Minuta is operated by the Minuta team. You can reach us at support@minutapp.tech for any privacy-related question, including exercising the rights described below.
Cloud processing architecture
Audio is captured locally on your device. Audio chunks and narrow text payloads are sent through reviewed cloud providers (listed below) for transcription, summaries, diarization, copilot answers, and translation. Transcripts, summaries, copilot answers, and exports are stored in the desktop app's local SQLite database.
The provider chain for transcription is: Deepgram (primary ASR), then OpenAI Whisper (fallback), then Groq Whisper (last-resort fallback). For summaries and copilot answers the chain is: OpenAI (primary), then Anthropic (fallback), then Groq (last-resort). After a meeting, the app may upload the meeting WAV to a private, short-lived S3 staging object so Modal/pyannote can return speaker time ranges. If you enable DeepL translation, transcript text (not audio) is also sent to DeepL.
Minuta's API is designed as a transient processing layer and is configured not to log raw audio, transcripts, prompts, summaries, attached documents, or generated responses. Saved meeting records — recordings, transcripts, summaries, speaker labels, and context files you attach — remain in the desktop app's local storage unless you choose to export them, attach them to support, or send them to another service.
Information we collect
Account information: the email address and, optionally, the first and last name you provide when signing up. Your password is handled by AWS Cognito and we never see it in plaintext.
Subscription information: if you subscribe to Minuta Pro, we store your Stripe customer identifier, subscription status, billing period dates, and the Stripe subscription identifier. Stripe itself holds your card data — we never receive it.
Site access logs: when you visit minutapp.tech, CloudFront (our CDN) records the request IP, user agent, requested URL, and timestamp. These logs help us detect abuse and plan capacity; they are retained for up to 30 days.
Anti-bot signals: form submissions are evaluated by Google reCAPTCHA v3. Google receives your IP address and browser fingerprint to generate a score; we receive only that score and do not persist it.
Meeting content processed for AI features: audio segments, meeting WAV files, transcripts, speaker timing data, optional context excerpts, prompts, summaries, and copilot responses may pass through Minuta's API and the subprocessors listed below so the product can transcribe, diarize, summarize, translate, and answer during meetings.
Optional desktop usage analytics: the desktop app can send anonymous usage events only if you opt in. These events are limited to product milestones such as install, first meeting started, first transcript completed, launch activation, or a Pro upgrade click, plus coarse attribution fields. They do not include meeting audio, transcripts, documents, prompts, generated responses, meeting titles, participant names, or the words spoken in a meeting.
Diagnostics and error reporting: if Sentry or similar diagnostics are enabled, reports may include technical metadata such as app or browser version, operating system, stack traces, and the page or feature where an error happened. They are not used to collect meeting content and must not include meeting audio, transcripts, attached documents, prompts, or generated responses.
Support correspondence: when you email support@minutapp.tech, we keep the conversation for as long as needed to help you and meet any legal obligations.
Information we do NOT collect
We do not collect meeting content for analytics, advertising, or sale to data brokers. We do not use desktop analytics or diagnostics to collect meeting audio, transcripts, documents, prompts, summaries, or generated responses.
We do not collect usage analytics from the desktop app unless you explicitly opt in, and opt-in analytics never carry meeting content. We do not receive or store your full payment card number.
How we use your information
Operate the service — authenticate you, keep your account working, deliver software updates, and track subscription state.
Process payments — via Stripe, who handles card storage and PCI compliance for us.
Protect the service — block abuse and brute-force attacks with reCAPTCHA and Cognito's built-in safeguards.
Provide cloud AI features — transcribe audio, identify speaker time ranges, summarize meetings, translate text when enabled, and answer copilot prompts.
Communicate with you — transactional emails (sign-up confirmation, payment receipts, important account changes) and responses to your support requests.
Legal bases for processing
For users in the European Economic Area, United Kingdom, and jurisdictions with similar laws, the legal bases for processing your information are: performance of the contract (running your account and subscription); our legitimate interests (fraud prevention, security, service improvement); and compliance with legal obligations (tax, accounting).
Service providers (subprocessors)
Amazon Web Services (regions: us-east-1, us-east-2) — hosting, API gateway, DynamoDB database, S3 storage, CloudFront CDN, and private S3 staging for diarization audio.
AWS Cognito — identity and authentication. Handles user sign-up, sign-in, and password management. We never see your password in plaintext.
Deepgram — speech-to-text transcription. Primary ASR provider for the /transcribe endpoint. Receives audio segments over HTTPS.
OpenAI — speech-to-text fallback (Whisper) and chat completions for summaries and copilot answers (primary chat provider). Receives audio segments for transcription fallback and transcript/context text for completions.
Anthropic — chat completions for summaries and copilot answers (fallback provider). Receives transcript and context text only; no audio.
Groq — speech-to-text (last-resort transcription fallback) and chat completions (last-resort completions fallback). Minuta sends Groq requests with the provider's no-data-retention header where the Groq API supports it.
Modal / pyannote — speaker diarization. Processes meeting audio to return speaker time ranges.
Stripe — billing and payment processing. Stores payment card data; we only persist the Stripe customer identifier and subscription state.
DeepL — translation of transcript text segments, only when you enable translation. Audio is never sent to DeepL.
Plausible and Sentry — analytics and diagnostics providers used only when configured (inert by default). Desktop analytics are opt-in and anonymous; diagnostics are configured to exclude meeting content.
We only share information with these providers to the extent necessary to deliver the service. Each has its own privacy commitments and (where applicable) a Data Processing Agreement in place with us.
International transfers
Our infrastructure and subprocessors may process account, subscription, and meeting-content data outside your country of residence, including in the United States. For users in the European Economic Area or the United Kingdom, we rely on Standard Contractual Clauses or another valid transfer mechanism with each provider to protect the transfer.
Data retention
Account data is retained while your account is active. If you delete your account, we delete the associated Cognito user and subscription record.
Billing records are kept for up to 7 years after subscription termination to comply with tax and accounting obligations.
Saved meeting records are stored by the desktop app on your computer until you delete them or uninstall the app. Minuta's API does not keep a server-side meeting archive as part of normal cloud processing.
Diarization audio staged in S3 uses short-lived presigned URLs and a lifecycle rule that expires staging objects after 1 day. AI request logs are configured to avoid raw meeting content.
CloudFront access logs are retained for up to 30 days.
Support emails are kept for as long as needed to help you and meet any legal obligations.
Your rights
Subject to the applicable law, you have the right to access the personal data we hold about you, have it corrected, request its deletion, export it in a portable format, object to or restrict its processing, and withdraw any consent you previously gave.
Contact support@minutapp.tech to exercise any of these rights. We will respond within 30 days and at no cost, unless the law specifies otherwise.
You also have the right to lodge a complaint with a data protection authority in your country.
Cookies and local storage
The site uses localStorage to remember your chosen currency, interface language, cookie-consent choice, and — after you sign in — your session tokens. We do not use third-party tracking cookies or advertising pixels.
When you accept or decline optional cookies in the site banner, Minuta stores only that choice, the consent model version, and the timestamp so we can honor your LGPD/GDPR preference on future visits.
reCAPTCHA and Stripe may set their own cookies on pages where their scripts run, as described in their respective privacy notices.
Children
Minuta is not directed at and not intended for use by anyone under 16 years old. We do not knowingly collect information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
Changes to this policy
We may update this Privacy Policy to reflect changes to the service or the law. When we make a material change, we will update the "last updated" date above and, if you have an account, let you know by email.
Questions or requests: support@minutapp.tech.