Security

Security starts with collecting only what is needed.

MeetingAgreement documents the agreement—not the conversation. The service does not record the meeting or store its audio, video or transcript.

Data minimization

We do not need to collect the meeting itself.

Information that MeetingAgreement does not collect does not need to be stored as part of the service. The focus is on what participants agreed, not on what was said in the conversation.

The conversation stays outside MeetingAgreement™

MeetingAgreement does not record or transcribe the meeting and does not create AI summaries. A user may, however, enter information in an agreement’s title, description, location or rules.

What the service needs to retain

Where relevant, MeetingAgreement may handle account and user information, participant names and email addresses, the agreement and its published versions, and which version a participant accepted and when. Necessary technical security data is also processed so that the service can operate.

Access and ownership

You should know who can see what.

A personally owned agreement does not automatically become available to an organization merely because the user belongs to that organization.

An agreement created in an organizational context may be organization-owned and managed within the organization according to its policies and permissions. The context in which the agreement is created and the organizational visibility that applies should be clear.

Accounts and technical safeguards

Concrete safeguards without exaggerated promises.

Accounts and sessions

Passwords are stored as hashes, not in plain text. The application uses session management and a necessary session cookie for sign-in and security. Changes are protected by server-side checks and CSRF protection.

Web-interface safeguards

Dynamic content is HTML-escaped before it is displayed. The public website also sends a content security policy that limits which resources may load and prevents the page from being embedded on other websites.

The agreement link

The link provides access to the current agreement and can be shared through the channel already used for the meeting. Each participant identifies themselves when responding.

Cookies and external services

Clear boundaries around what the service does.

Necessary cookies, not behavioral tracking

The public website uses no analytics or marketing cookies. The application session cookie is necessary for the service to operate and is not used for advertising or behavioral tracking.

Meeting and AI services are separate

Teams, Zoom and other meeting, AI, transcription or recording services are separate from MeetingAgreement. MeetingAgreement can clarify what participants agreed about the use of such tools, but it does not process their meeting content.

Privacy and personal data

Learn more about how your information is handled.

The Privacy notice explains more fully what personal data may be processed, why it is needed and which rights you may have.

Read the Privacy notice

Security is continuous work.

Security is about limiting the information that is processed, controlling access and being clear about the safeguards the service uses.

Contact us about security