Privacy Policy
Last updated: 2026-08-28 · Beta
1. Data We Collect
Email, name (from Google), meeting audio·transcripts·summaries, usage stats. If you connect a Google integration, we process only the data that feature needs (see section 5). If you use automatic speaker recognition, we also store voice characteristics (speaker embeddings) — sensitive data covered separately in section 2.
2. Sensitive Data (Biometric) — Speaker Voices (PIPA Article 23)
**Automatic speaker recognition is optional and off by default.** Recording, transcription, summaries — every core feature of Micky works without it. [What we store] When you name a speaker in a transcript or enroll a voice in settings, we compute **voice characteristics (a speaker embedding)** from that audio and store it. Because it exists to recognise a specific person, it is **biometric identification data (sensitive data)** under Korea's PIPA. We store a numeric vector, not the audio, and the original voice cannot be reconstructed from it. [Where it is stored] Speaker embeddings live **on your device only** by default (local SQLite). They are not sent to our servers and we cannot see them. [Team sharing — separate consent] On a Team plan, embeddings are uploaded to the cloud (Supabase, Seoul region) **only after you turn on “Share speaker list with team” in settings**, and only for speakers enrolled after that. Speakers enrolled beforehand are never shared retroactively, and you can turn the switch off at any time. [Enrolling other people] If you enroll someone other than yourself, **get their consent first.** Collecting a meeting participant's biometric data without consent may violate PIPA, and responsibility for obtaining that consent rests with you as the person enrolling them. [Retention and deletion] The speaker list is kept until you delete it. You can delete any individual speaker from settings, which removes it from your device and — if shared — from the cloud. Deleting your account deletes it too. [No overseas transfer] Speaker embeddings are never transferred outside Korea. They are computed on your device, and when shared they are stored in the Seoul region.
3. Where Data Is Stored
Local-first on your device (SQLite). When cloud sync is enabled, data is stored in Supabase (Seoul region, ap-northeast-2), isolated per user.
4. Never Shared or Sold · No Staff Access to Meeting Content
Meeting and email data is never shared or sold for advertising, marketing, or analytics. It is entrusted only to the sub-processors in section 5, and only as far as running the service requires. **Our staff do not read your meeting audio, transcripts, summaries, or meeting titles.** The admin console does not display meeting content — only what support needs: the meeting's id, time, length, whether it succeeded, and why it failed. Titles are hidden too: an AI writes them from the meeting, so a title is a summary of the content. Three exceptions only: (a) you explicitly ask us to, in a support request; (b) the law requires it; (c) statistics from which no individual can be identified.
5. Sub-processors (PIPA Art. 26)
We entrust the processing of personal data to the companies below in order to run the service. We announce any change to this list before it takes effect. · Supabase, Inc. — servers, data storage, authentication (Seoul region, ap-northeast-2) · Anthropic, PBC — meeting summaries, document generation, agent replies · OpenAI, L.L.C. — speech-to-text (Whisper), image generation · Deepgram, Inc. — live speech-to-text · Google LLC — sign-in (OAuth), image generation (Gemini), **voice conversation (Live Micky)**, and — only if you turn them on — Gmail send, Calendar, Drive · Vercel Inc. — web hosting · Resend (Plus Five Five, Inc.) — email delivery · PostHog, Inc. — product analytics · Functional Software, Inc. (Sentry) — error monitoring · Paddle.com Market Limited — payments (Merchant of Record). Payments are currently disabled.
6. Cross-Border Transfers (PIPA Art. 28-8)
Supabase, the primary store for your meeting data, is in the Seoul (ap-northeast-2) region, so the original meeting data stays in Korea. Some data is transferred abroad for the processing below. [recipient / country / items / purpose / when & how / retention] · Anthropic, PBC (US, privacy@anthropic.com) — transcript text / summaries and documents / HTTPS API call when you use the feature / deleted after processing, not used for training · OpenAI, L.L.C. (US, dsar@openai.com) — audio and summary text / transcription and image generation / HTTPS API call when you use the feature / deleted after processing, not used for training · Deepgram, Inc. (US, privacy@deepgram.com) — audio / live transcription / HTTPS stream while recording / deleted after processing, not used for training · Google LLC (US, dpo-google@google.com) — email and summary text / sign-in, image generation, and (if connected) Gmail, Calendar, Drive / HTTPS API call when you use the feature / deleted after processing, not used for training · Google LLC (US, dpo-google@google.com) — **voice conversation audio and the meeting details looked up during it (titles, summaries, action items, assignee names)** / Live Micky voice conversation / HTTPS stream **while you have a voice conversation open** / deleted after processing, not used for training, no human review · Vercel Inc. (US, privacy@vercel.com) — access logs and request data / web hosting / when you use the web app / up to 30 days · Resend (US, support@resend.com) — email address and name / sending you email / when we send an email / for as long as the delivery record is kept · PostHog, Inc. (US, privacy@posthog.com) — anonymised usage logs and interaction recordings on the web and landing pages (clicks, scrolling, time on page; **form inputs are masked and never recorded**) / product analytics / while you use the app, web or landing pages / 12 months · Functional Software, Inc. (US, compliance@sentry.io) — error logs and device info / diagnosing errors / when an error occurs / 90 days [Refusing the transfer] Write to hello@joshua.site if you do not want your data transferred abroad. These transfers are required to transcribe and summarise — the core of the product — so refusing means you cannot use those features, and you may ask us to delete your account instead. Deletion of data already processed follows sections 9 and 10.
7. Google Integration Data (optional)
Every Google integration is optional — Micky works fully without connecting any of them. We request the minimum scope a feature needs, and only at the moment you turn that feature on. · gmail.send — sends a follow-up email drafted from your meeting summary. Only a message you have reviewed and clicked Send on is sent. Micky does not read your mailbox. · calendar.events — shows your upcoming meetings, and creates only the follow-up events you confirm. · drive.file — saves a meeting note you explicitly export to your own Drive. Micky cannot access any file it did not create. · Google data is never used for advertising or sold, and is never used to train AI models. · No human reads this data, except (a) with your explicit consent, (b) for security or legal compliance, or (c) in aggregated/anonymized form. · You can disconnect any integration at any time in Settings. Micky's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. Generative AI (AI Framework Act Art. 31)
Micky runs on generative AI. Summaries, notes, mindmaps, summary images, decks, reports and email drafts are all AI-generated and can be wrong — check the original meeting before you act on anything that matters. Anything you export carries a note that it was AI-generated.
9. Right to Delete
Each note and email-knowledge item can be deleted immediately — local audio and cloud copies are removed irrecoverably. Full account deletion requests to hello@joshua.site are processed within 7 days.
10. Retention
**Transcripts, summaries, and meeting records** are kept until you delete them. **Audio files** have a cloud retention window that depends on your plan. When the window closes the audio is deleted automatically; the transcript and summary stay. · Trial / Free: 7 days · Starter: 30 days · Pro: 90 days · Max, Team, Enterprise: no time limit · During the beta we keep audio with no time limit regardless of plan. ⚠️ **Meetings recorded in the browser exist only in the cloud.** Once the window closes that audio cannot be recovered, and neither re-transcription nor re-enrolling a speaker is possible. Meetings recorded with the desktop app keep a playback copy on your device. If you move to a lower plan, **the new window applies to earlier meetings too** — retention is measured from the meeting start time. Download anything you want to keep before downgrading. [Team dissolution] When a team is dissolved, its team folders, shared glossary and team speaker roster are **sealed for 90 days**. During that time no one, including members, can open them, and you may request a migration. After 90 days they are destroyed. Each member's own meetings and transcripts stay in their personal account. Inactive accounts are cleaned up 12 months after a notice email. [Voice conversation log] What you say to Live Micky is kept **only on your own device** (local SQLite). It is never uploaded, and we cannot see it. You can clear it from Settings at any time, and it goes away when you remove the app.
11. Data Protection Officer (PIPA Art. 30, 31)
For questions, complaints or redress about how we handle personal data, contact us — we answer without delay. · Data Protection Officer: Jaeho Jung (Head of Product) · Contact: jhjung@joshua.site You may also contact the Korean authorities: · Privacy Infringement Report Centre (privacy.kisa.or.kr / 118) · Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)
12. Changes
Material changes are announced in-app and by email before they take effect. A new sub-processor or transfer destination is announced at least 30 days in advance.