Privacy
This page explains what happens to data on the public website, in the free tool and in the Chrome extension. The rules for recordings and transcripts after they reach your account also form part of the agreement accepted at sign-up.
Who is responsible for the data
The controller for account data, the public website, the account-free sample, support requests and Talkenda's own product analytics is NeuroCodeLab Maciej Śnieżyński, a Polish sole proprietorship, tax ID 7123295462. Contact for data matters: kontakt@talkenda.com. For meeting content submitted by a customer, the customer is generally the controller and Talkenda acts as processor on that customer's documented instructions.
Your rights and a complaint to the supervisory authority
Which rights apply depends on the legal basis and circumstances of the processing. You may request access, rectification, erasure, restriction and portability of your data, object to processing and, where processing relies on consent, withdraw it without affecting earlier lawful processing. Self-service account export and deletion are available in Settings; for other requests, write to kontakt@talkenda.com. For meeting content, first contact the person or organisation that used Talkenda and is generally the controller; Talkenda supports that controller as processor. If you believe the processing infringes the GDPR, you may lodge a complaint with the President of the Polish Personal Data Protection Office (UODO).
We do not use tracking cookies
We measure public page views with our own Umami installation at analityka.niebieskizeszyt.pl on our OVHcloud VPS. We send the public path, safe UTM campaign labels, referring origin and language; the connection exposes the IP address and browser header to the server. The session token stays in tab memory only. A separate funnel receives pseudonymous registration, product usage and payment milestones, their time, plan, language and campaign. We do not send email addresses, card details, conversation content, titles, meeting identifiers or private meeting URLs. Public-page session recordings and click maps start only with your consent: text and forms are masked, account pages and the audio upload tool are excluded, and recording lasts at most 5 minutes. The browser stores only your consent choice, not a person identifier; change it through Analytics settings on public pages. Browser measurement respects Do Not Track and Global Privacy Control. We use neither Google Analytics nor advertising network pixels.
Functional account and referral cookies
After sign-in we use a session cookie. When you deliberately open a referral link, we store a signed code for 30 days to award the bonus and a random, signed browser identifier for 365 days to prevent multiple accounts from one device. They contain no meeting content, IP address or card data and are not used for advertising. Deleting them does not block the site, but may prevent the bonus from being attributed.
Protected meeting links
A meeting owner can protect a public link with a password. We store only its salted scrypt hash. After a correct password, the browser receives a functional HttpOnly cookie for 12 hours containing a signature bound to the current link and hash; revoking or replacing the link, or changing the password, invalidates that access. To enforce five attempts per 15 minutes, for no more than 24 hours we store only an HMAC of the link, IP address and browser version — never those values in plain form.
Chrome extension: what it accesses
After you tick the consent box, the extension may send the recognised meeting-room URL to Talkenda solely to match it with an event in your calendar; it does not collect browsing history. After you click “Record”, it captures audio from the active tab, microphone audio and, on Google Meet and Microsoft Teams, visible captions, speaker names and your mute state. It also uses the signed-in account ID and email address to prevent a recording from moving to another account. The microphone settings page performs a short access check but neither stores nor sends that audio.
Chrome extension: local storage, upload and deletion
During recording, audio and captions are held locally in the browser's IndexedDB. When recording ends, the extension sends them over encrypted HTTPS to talkenda.com together with the platform, start time and — for a recognised room — its URL, so Talkenda can create a transcript, map speakers, generate the note and enable search. A successful upload or an explicit “Discard recording” deletes the local copy; after an error it remains local until retry or discard. A local counter of at most three successful uploads and the rating-prompt decision remain in extension storage. The server copy follows the retention period of the account plan and can be deleted by the user in the app.
Chrome extension: recipients and Limited Use
The Security page derives every active data recipient from the current configuration and separately states whether audio leaves the hosting environment. Extension data is used only to provide and securely maintain the meeting-notes features. We do not sell it or use it for personalised advertising, credit scoring or model training. A human may access it only with your explicit consent for specific support, for security, or where required by law. Talkenda's use of information received through the extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
Technical support requests
When you submit the meeting-page form, we store the case number, your description, meeting code and status, a controlled error code, stage timings, and the time and wording version of any optional consent for human content access. We do not automatically copy the title, participants, audio, transcript or summary. Messages and the technical case snapshot remain with the account; deleting the meeting detaches it from the case, while deleting the account removes the request and its message queue.
What we measure
We record which sections of the page were shown and for how long, whether the preview film started playing, and what was clicked — along with the path, language, referrer and campaign parameters from the address. After sign-in, we also store the first product milestones on the account, including extension connection, accepted extension recording and ready result, together with plan, language and source. These events contain no audio, captions, meeting title or room URL. They are used to find where users stop and improve the product. We automatically remove these event details after 90 days, in a cycle running every 5 minutes. For an existing account, we retain only the identifier and type of an already counted milestone and its original date, to avoid counting it again and preserve the checklist. We remove its visitor identifier, path, language, referrer, campaign parameters, click identifier and metadata. After account deletion, the next cycle removes expired markers. Account-linked markers are not anonymous. This period applies to Talkenda funnel analytics; a daily schedule in the separate Umami installation removes event data older than 90 days and session recordings and heatmaps older than 30 days. This applies to the active analytics database.
Free transcription without an account
After you explicitly confirm that you may process the file, we accept one recording to produce a transcript. Audio is deleted immediately after successful speech recognition; the file, result and metadata are deleted within 24 hours. The sample never enters diarisation, embeddings or a summary model. To enforce 3 attempts in a rolling 24-hour window, we retain until expiry an irreversible HMAC of the IP address and browser version; the IP address itself is not stored.
How we recognise returning visits
Instead of a browser identifier we compute an irreversible hash of the IP address, browser version and current date. The IP address itself is never stored and the hash changes every day, so visits from two different days cannot be joined into one profile.
Where it lives and for how long
In the European Union, together with the rest of the service. We do not pass this data to other companies and do not combine it with any external dataset.
Early access list
The email address you leave in the sign-up form is kept so we can write to you when we open access — and for nothing else. We do not sell it, pass it on, or add it to any marketing list. To come off the list, send one message to the address below and it is deleted.
Connected MCP clients and AI agents
Only after explicit OAuth consent may the MCP client you choose receive, at your request, the account name and email, language, technical identifiers and versions required for follow-up operations, and the meeting and team metadata, participants, transcripts, notes, action items and change history available to you. Read, write and team scopes are shown before consent; you can revoke a connection or token in Settings. Talkenda does not send this data on its own and does not return secrets, recording URLs or internal processing state. The response recipient is the external AI service you selected, which retains its copy under its own terms and privacy policy; Talkenda does not control retention on that service.
Account
When you create an account through Google we receive your email address, name and profile picture. In Settings you can permanently delete the account without contacting support by typing your own address. The operation removes your meetings, audio, transcripts, notes, tasks, integrations, tokens and sessions from the active system and detaches funnel events from the account. You must first cancel an active plan and reach the end of its paid period; recording or processing must finish, and a sole team administrator must transfer the role. Independent copies saved by other users and minimal records required by law or security are not deleted. Data may remain in a protected backup until its scheduled overwrite and is not used to restore a deleted account except as part of full disaster recovery.
Optional Google Calendar connection
Signing in does not give Talkenda access to your calendar. Only after you choose “Add Google account” in Settings does a separate consent screen request read-only access to your subscribed calendar list and events. We store OAuth tokens, selected calendar identifiers and the event metadata needed to display and schedule a meeting: title, time, attendee response and join link. We use Google data only for these visible features — never for advertising, sale or model training — under the Google API Services User Data Policy, including Limited Use. Disconnecting the account clears the local access and refresh tokens and stops synchronization; meetings created earlier remain in your account until you delete them or delete the whole account.
Questions: kontakt@talkenda.com