Privacy, in plain language

Where your meeting data goes

Recording and transcription happen on your device. Cloud features are optional and have different data paths, which we explain below without collapsing everything into “the cloud.”

Last updated: August 28, 2026

The short version

  • • Meetly records and transcribes locally. Cloud AI receives transcript text, not recording audio.
  • • Cloud AI routes through OpenRouter only to an approved model/provider endpoint with formal Zero Data Retention and provider data collection denied.
  • • Optional iCloud Library Sync can sync recordings and meeting data to your private CloudKit database. Optional Connect AI stores encrypted meeting text and metadata, never audio.
  • • If no privacy-compliant AI endpoint is available, Meetly fails closed instead of silently sending the meeting somewhere else.

Your data map

The exact path depends on the features you enable. Swipe the table horizontally on a small screen.

DataOn your deviceOptional iCloud syncCloud AI summaryMeetly storage
Recording audioRecorded and stored locally.Synced as encrypted-in-transit audio chunks to your private Apple CloudKit database when Library Sync is enabled.Not sent.Meetly does not operate a recording-storage server.
Transcript and meeting detailsStored locally with the meeting.Transcript, summary, metadata, and supported preferences can sync through CloudKit.Transcript text is sent only when you request a cloud summary. Audio is not included.No Meetly summary backend stores a plaintext copy. Connect AI is a separate, optional encrypted service described below.
Generated summaryReturned to and stored on your device.Can sync with its meeting when Library Sync is enabled.Processed transiently by OpenRouter and the selected model provider under the controls below.Not retained by a Meetly summary server.
Operational and product telemetryApp settings and local diagnostic state.Apple processes CloudKit operational metadata under its terms.Request time, model/provider, token use, latency, cost, request IDs, IP/network and abuse-prevention data may be processed.With analytics consent, Meetly sends a minimal allowlisted set of content-free product events. No transcript, summary, audio, title, filename, email, or Apple ID is included.

Cloud AI summaries and OpenRouter

Meetly calls OpenRouter directly from the app. OpenRouter routes the transcript to the approved model endpoint for your device region. Meetly does not run an intermediary summary backend.

Content controls

  • • Formal Zero Data Retention is required on every normal route.
  • • Provider data collection and training use are denied.
  • • OpenRouter prompt/response logging is disabled.
  • • Provider and model allowlists prevent an unapproved fallback.

What “ZDR” does not mean

ZDR means the approved inference endpoint does not retain prompt or response content after processing. It does not mean no metadata is processed. OpenRouter retains operational metadata and says a small sample of prompts may be categorized anonymously using a ZDR model, without association to an account or user.

Current regional routes

Device regionModelApproved provider routeRequired privacy policy
Global, including Taiwan and South KoreaGPT-5.6 LunaOpenRouter → AzureFormal ZDR; data collection/training denied; no provider fallback.
Mainland China, Hong Kong, and MacauKimi K2.6OpenRouter → CoreWeave, with DeepInfra as the approved fallbackFormal ZDR; data collection/training denied; fail closed outside this allowlist.

These routes are remotely managed so Meetly can rotate a restricted runtime key or change an approved model/provider without waiting for an app release. The app also contains a restricted runtime key so summaries can continue if Firebase Remote Config is unavailable. The OpenRouter management credential is never included in the app.

China, Hong Kong, Macau, and VPNs

  • • Meetly selects the Greater China route only when the device Region is CN, HK, or MO. It does not infer this from language, IP address, SIM, or Chinese text. Taiwan and South Korea stay on the global route.
  • • A VPN may change network reachability or the location OpenRouter/providers infer, but it normally does not change Meetly's selected route unless the device Region changes.
  • • The regional route is designed to improve availability. We do not guarantee VPN-free operation because reachability can vary by country, carrier, Wi-Fi provider, and upstream policy.
  • • If OpenRouter or every approved endpoint is unavailable, Meetly shows an error and keeps your transcript local. It does not silently switch to direct Kimi or another unapproved provider.

What OpenRouter and providers may still process

To route, bill, secure, and troubleshoot the request, OpenRouter and the selected provider may process timestamps, requested and served model, provider, token counts, cache usage, latency, cost, completion status, data/edge region, request or generation IDs, app attribution, user agent, IP address, and related network or abuse-prevention signals. Meetly does not add participant names, meeting titles, meeting IDs, or user identifiers to optional OpenRouter metadata fields.

See OpenRouter's current data collection, Zero Data Retention, and privacy documentation. Provider eligibility can change; Meetly's request and preset restrictions are designed to fail closed if an endpoint no longer qualifies.

Emergency compatibility route

Meetly's release owner can remotely enable a temporary direct OpenAI compatibility route with a separate key if the normal OpenRouter service has a serious release-wide problem. It is off by default, is never an automatic retry after a failed summary, and is identified in Settings when active. Because this route bypasses OpenRouter, it does not inherit OpenRouter's route-level ZDR enforcement; OpenAI's applicable API terms and data controls govern that processing. Local recording and transcription do not require either cloud route.

iCloud Library Sync (optional beta)

If you enable Library Sync, Meetly uploads recording chunks, transcripts, summaries, meeting metadata, and supported preferences to your private CloudKit database so your Meetly library can be restored and synchronized. Apple processes and stores that data under your Apple account and Apple's terms. Meetly does not describe ordinary CloudKit storage as end-to-end encrypted.

Turning sync off stops future syncing but may not delete records already stored in iCloud. You can manage iCloud data through Apple's controls. Because this feature is beta, export important meetings and confirm recordings before uninstalling the app.

Connect AI (optional)

What is uploaded

When enabled, Meetly uploads AES-256-GCM encrypted transcript text, summaries, participants, highlights, action items, and meeting metadata to mcp.getmeetly.ai. Recording audio is not included.

How access works

The encryption key is generated on your device and kept in the iOS Keychain. Authorized requests decrypt the minimum needed data in request memory. The MCP service does not persist or log meeting plaintext, connection keys, bearer tokens, tool arguments, transcripts, or generated artifacts. Tool results are then handled under your connected agent provider's terms.

Processors and retention

Supabase processes encrypted meeting blobs, device records, and OAuth metadata; Vercel forwards requests on the branded MCP domain. Encrypted blobs and device records remain until deletion. You can revoke access in Meetly; deletion requests to founder@edgefirst.app are completed within 30 days, subject to legal and security requirements.

Privacy-safe product analytics

If you consent to analytics, Meetly uses Firebase Analytics and PostHog for a small, allowlisted set of product events such as onboarding progress, recording completion, summary success or failure category, feature use, and subscription state. Events can include coarse app, device, locale, route, duration bucket, and acquisition-attribution information. They do not include recording audio, transcript or summary text, meeting titles, filenames, participant names, email addresses, Apple IDs, or advertising identifiers.

Session replay requires separate consent, is sampled, masks all text and images, and is limited to approved non-sensitive screens. RevenueCat processes purchase and entitlement information. You can change analytics and replay choices in Settings.

Your controls

  • • Use local recording and transcription without Cloud AI.
  • • Turn iCloud Library Sync, Connect AI, analytics, or replay off.
  • • Delete local recordings and transcripts in Meetly.
  • • Revoke connected-agent access from Settings.

Recording responsibility

You are responsible for obtaining any consent required to record or process a conversation and for confirming that your use meets applicable laws, workplace rules, and confidentiality obligations.

Questions or data requests?

Contact us about this policy or optional Meetly service data:

founder@edgefirst.app