Security & privacy

Your meetings are yours

What we store, who can see it, how long we keep it, and who we share it with. In plain language, and consistent with our Privacy Policy.

The short version

Private by default

New meetings are visible only to the person who recorded them, until they share.

No training on your data

We don’t use your recordings to train AI models, and we never sell your data.

You press Start

On Mac, iPhone and Apple Watch, nothing records until you start it.

Encrypted

Audio is encrypted at rest, and everything moves over TLS.

Recording

What other people in the call see

It depends on how you record. Either way, tell people you’re recording and follow the consent rules where you and they are.

Mac, iPhone or Apple Watch

Nothing joins the call. The audio is captured on your device, so participants see nothing from Kolasys. That makes telling them your job.

The meeting bot

It joins as a participant everyone can see, named “Kolasys AI” by default. Team workspaces can change the name. It only joins meetings you send it to, or your calendar meetings when automatic recording is on in Settings.

Retention

How long we keep things

Audio

Kept until you delete the meeting, so you can play it back and re-transcribe. Turn on “Auto-delete audio after transcription” in Settings to remove each new recording’s audio as soon as the transcript is done. It is off unless your workspace turns it on, and deleted audio can’t be recovered.

Transcripts and notes

Kept while your account is active, or until you delete the meeting.

Account data

Deleted within 30 days of closing your account.

Server logs

Kept for up to 90 days for security and diagnostics.

Deletion

Delete a meeting, or everything

One meeting

Delete any meeting from the web or the iPhone app. Its audio, transcript, notes and action items go with it.

Your whole account

In the iPhone app: Settings → Account → Delete Account. Not on iPhone? Email hi@kolasys.ai from your account’s address and we’ll delete it. If others share your workspace, only your membership and your personal data are removed.

Access

Keys, webhooks and who sees what

API keys

Shown once when you create them and stored only as a hash. Revoke a key any time in Settings. A key reaches only its own workspace.

Visibility everywhere

The same private / shared rule applies on the web, the apps, the REST API and the MCP server.

Signed webhooks

Every webhook carries a signature you can verify, and admins can rotate the secret.

Kolasys does not have a SOC 2 report of its own today. Our hosting providers, Vercel and Railway, run SOC 2 compliance programs. Found a security issue? Email hi@kolasys.ai.

Processors

Who we share data with, and why

Only what each service needs to do its job. Google, Microsoft, Slack and Notion receive or share data only after you connect them.

Anthropic

AI summaries, Ask AI, Shortcuts, and topic extraction

Data: Transcript text, meeting notes, and your questions

OpenAI

Audio transcription (Whisper) and meeting search indexing

Data: Audio files; transcript text

Deepgram

Speaker identification, and live transcription in the Mac app on paid plans

Data: Audio

Recall.ai

Meeting bot that joins and records calls you send it to

Data: Meeting link, meeting audio and video, participant names

AWS S3

Audio file storage

Data: Audio files

Neon (PostgreSQL)

Database

Data: All structured data

Vercel

Web app hosting

Data: Requests to the web app and API

Railway

Background processing (transcription and summaries)

Data: Audio files and transcript text while they are processed

Upstash (Redis)

Job queue

Data: Recording IDs (no content)

Clerk

Authentication

Data: Name, email, sign-in profile

Stripe

Payment processing

Data: Email, billing info

Resend

Transactional email

Data: Name, email; meeting summaries when summary emails are on

Expo

Push notifications to the iPhone and Apple Watch apps

Data: Device push token, meeting title, summary headings

PostHog

Product analytics

Data: Usage events (no content)

Sentry

Error monitoring

Data: Error traces (no content)

Google

Calendar sync, when you connect Google Calendar

Data: Read-only access to event titles, times, attendees, and meeting links

Microsoft

Calendar sync, when you connect Outlook

Data: Read-only access to event titles, times, attendees, and meeting links

Slack

Posting meeting notes, when you connect it

Data: Meeting title, summary, notes, action items, and link

Notion

Saving meeting notes, when you connect it

Data: Meeting title, summary, notes, action items, and link

The full legal text is in our Privacy Policy. Questions about deleting your data are answered on Support.

Start free — 3 meetings a month, no card

Download the Mac app, or start on the web. Upgrade when you need more.