This policy explains how MLOG collects, uses, stores and deletes your data. The one-line version: your meeting data is used only to generate your briefs, answers and minutes — never to train models, never sold.
These promises are built into the product’s behavior — each one you can point to in the interface:
Your data is used only to generate your briefs, answers and minutes. We use your meeting content for no other purpose.
Never used to train models. Recordings, transcripts, minutes and your knowledge base never enter any model training — not ours, not our vendors’; vendors are bound by zero-retention terms.
Local-first. Audio is encrypted to your own device before any upload; capture starts only when you press “Start recording” — no hidden capture, no background listening.
We never sell personal information. No selling, renting or trading; no sentiment analysis, no mood scoring.
02Data we process
Account information: name, work email, company and workspace settings — for sign-in, collaboration and billing.
Meeting content: the audio you actively record, transcripts, minutes and linked documents — used only to generate your outputs and power your search.
Usage and device data: crash logs, feature usage and credit metering — only for reliability, security and billing, itemised and auditable.
03Storage & transmission
From your microphone to our database, data takes exactly three steps — encrypted at every one:
Local: audio is AES-256 encrypted to your device; offline-safe, ≤5s loss on a crash.
In transit: uploads happen only when you are online and have authorized them; TLS 1.3 end to end, no plaintext along the way.
Cloud: encrypted at rest in the Singapore region, never replicated across regions; workspaces are strictly isolated and meeting content is workspace-only by default.
04Retention & your right to delete
How long raw audio is kept in the cloud depends on your tier (we remind you before it expires and offer a one-click export). Textual evidence — quotes, timecodes and bilingual minutes — is kept for as long as you subscribe. Your original recording always keeps a copy on your own device, and cloud expiry does not touch it.
You can export or delete all of your data anytime under Settings → Data & Privacy.
Deletion cascades: audio, transcript, minutes, index and share links are removed together; backups are purged within a 30-day rolling window, with a confirmation sent to you.
Closing your account triggers the same deletion flow for all of your data.
05Voiceprints (biometric data)
To identify speakers automatically, workspace members may choose to enroll a voiceprint. Voiceprints are biometric data and we treat them to the strictest standard:
Fully optional, with separate explicit consent — declining affects nothing else; unidentified speakers simply appear as “Speaker N”.
Used only for speaker identification, never for any other purpose; results are labeled with their source and can be corrected by hand.
Revocable anytime — withdrawing consent deletes the voiceprint template immediately, and future meetings no longer auto-identify you.
06Your rights (GDPR / CCPA)
Wherever you are, we honor your rights to the GDPR and CCPA standard:
Access, rectification, export (portability), erasure, restriction and objection — initiate them in-app under Settings → Data & Privacy, answered within 30 days.
For California residents: the rights to know, delete and opt out of sale equally apply — in fact, we sell no personal information at all.
You can also exercise any of these rights by writing to [email protected].
07Sub-processors
We use the following categories of sub-processors under a least-privilege principle; any addition or change is announced in advance, and DPA customers receive a live, named list.
Category
Purpose
Residency
Constraints
Cloud infrastructure
Hosting, storage and backup
Singapore
Encrypted at rest · in-region residency
ASR providers
Speech-to-text (several, hot-swappable)
Singapore / nearest region
Zero retention · never for training
LLM providers
Minutes generation and advisor Q&A (several, hot-swappable)
Singapore / nearest region
Zero retention · never for training
Sub-processors are listed by category so the list survives vendor hot-swapping; the table above updates in lockstep with this policy.
08DPA appendix (Data Processing Agreement)
Pro workspaces can sign our standard Data Processing Agreement: it includes the full named sub-processor list, advance change notifications, Standard Contractual Clauses (SCC) and custom retention policies. Write to [email protected] to request it.
09Changes & contact
Material changes to this policy are announced 30 days in advance by email and in-app notice. For any privacy question, write to [email protected] — we reply within one business day.