Privacy Policy
This policy explains how MLOG collects, uses, stores and deletes your data. The one-line version: your meeting data is used only to generate your briefs, answers and minutes — never to train models, never sold.
01Core promises
These promises are built into the product’s behavior — each one you can point to in the interface:
- Your data is used only to generate your briefs, answers and minutes. We use your meeting content for no other purpose.
- Never used to train models. Recordings, transcripts, minutes and your knowledge base never enter model training — not ours, and not our vendors’, who are bound by the API terms under which we use them.
- Local-first. Audio is AES-256 encrypted onto your own device before any upload — on all four surfaces, including the web app and the browser extension (into the browser's private storage, OPFS); capture starts only when you press “Start recording” — no hidden capture, no background listening.
- We never sell personal information. No selling, renting or trading; no sentiment analysis, no mood scoring.
02Data we process
- Account information: name, email address, company and workspace settings — for sign-in, collaboration and billing.
- Meeting content: the audio you actively record, transcripts, minutes and linked documents — used only to generate your outputs and power your search.
- Usage and device data: crash reports, feature usage and credit metering — only for reliability, security and billing, itemised and auditable. Crash reports and usage events are processed by PostHog in the EU; they carry a pseudonymous account identifier and never carry meeting content. You can switch them off for this browser right here on this page, and signed-in users can switch them off for the whole account under Settings → Data & privacy.
- Cookies and local storage: we set no advertising or tracking cookies. Analytics uses your browser's local storage (not cookies) to keep a pseudonymous device identifier and your on/off choice, so the same browser is not counted twice. It stays until you clear this site's data or switch analytics off above. Sign-in uses a session token in local storage; clearing it signs you out. Nothing else is stored, and none of it leaves your browser except the analytics events described above.
This choice is remembered in this browser only, and it takes effect immediately — no account needed. If you are signed in, the switch under Settings → Data & privacy applies to your whole account, on every device.
03Storage & transmission
From your microphone to our database, data takes exactly three steps — encrypted at every one:
- Local: on the desktop and mobile apps, audio is AES-256 encrypted onto your own disk before anything is uploaded — offline-safe, with at most 5 seconds lost in a crash. The web app and the browser extension write each segment to this device first as well, AES-256 encrypted into the browser's own private storage (OPFS). The download page sets out how the surfaces differ. Every local copy is deleted as soon as its segment has been uploaded.
- In transit: uploads happen only when you are online and have authorized them; TLS 1.2+ end to end, no plaintext along the way.
- Cloud: encrypted at rest — the database and the object store both in the Asia-Pacific region, with no cross-region replication configured. Workspaces are strictly isolated and meeting content is workspace-only by default. Where your data is *processed* is a different question; “Sub-processors” below names every party that touches it.
04Retention & your right to delete
- Cloud audio is kept for 90 days by default, and 365 on the two higher paid tiers, counted from when each segment is written rather than from the end of the meeting; every Monday you get one digest listing what expires in the next 14 days. Transcripts, minutes and quoted evidence have no expiry — they stay until you delete the meeting or close the account, whether or not you are still subscribed. Local copies are yours, and cloud expiry never touches them.
- You can export or delete all of your data anytime under Settings → Data & privacy.
- Deletion cascades: audio, transcript, minutes, evidence links, search index and share links are removed together, and a confirmation is sent to you. Encrypted database backups are held for a limited period in the same region and are overwritten on a rolling basis; data in a backup is never restored into production except for disaster recovery.
- Closing your account deletes your identity, sessions, notifications, avatar, consent records and — for every workspace where you were the last remaining member — its meetings, recordings and knowledge base. Two things stay on purpose: the usage ledger and the billing records, which tax and accounting law require us to keep and which are unlinked from your identity; and the audit entry recording that the erasure happened, which is the only proof left that it did.
05Speaker identification
MLOG creates no voiceprints, stores none and matches none, and it processes no biometric data. Speakers are separated by the transcription model; you name them, and unnamed ones stay as “Speaker N”. Any label can be corrected by hand, and corrections apply to that meeting only.
06Your rights (GDPR / CCPA)
Wherever you are, we honor your rights to the GDPR and CCPA standard:
- Access, rectification, export (portability), erasure, restriction and objection — initiate them in-app under Settings → Data & privacy, answered within 30 days.
- For California residents: the rights to know, delete and opt out of sale equally apply — in fact, we sell no personal information at all.
- You can also exercise any of these rights by writing to support@mlog.ai.
07Sub-processors
We engage the following categories of sub-processors on a least-privilege basis. Write to us and we will send you the current named list.
| Category | Purpose | Residency | Constraints |
|---|---|---|---|
| Cloud infrastructure | Hosting, storage and backup | Singapore (database) · APAC (object storage) | Encrypted at rest · no cross-region replication |
| ASR providers | Speech-to-text (several, hot-swappable) | United States · global | Not used for training (bound by vendor terms) |
| LLM providers | Minutes generation and advisor Q&A (several, hot-swappable) | United States · global | Not used for training (bound by vendor terms) |
Sub-processors are listed by category so the list survives a vendor hot-swap. Five kinds are not in the table because they never touch meeting content, and we name them here for completeness: payments (receives your email address and the last four digits of your card), transactional email and push delivery (receive your address or device token and the notification text, meeting title included), the hosted job runner that schedules post-meeting processing (receives identifiers only), and — since 21 August 2026, when in-app purchases were switched on — the subscription service behind the App Store and Google Play (receives a workspace identifier and purchase events, never any meeting content).
08Data Processing Agreement (DPA)
Where your organisation acts as controller and requires a written data processing agreement, or Standard Contractual Clauses for transfers out of the EEA, write to support@mlog.ai and we will arrange the applicable terms with you.
09Browser extension
The MLOG browser extension does exactly one thing: record the audio of a meeting tab you choose. It has no content script, so it never reads the contents of any page you visit, and it records nothing until you press “Start recording”. Here is what each permission it asks for is actually used for:
- Tab audio capture: to record the audio of the tab you are on, from the moment you press “Start recording” until you press stop. Video is never requested — not a single frame of your screen is captured.
- Background document: to keep the recording loop running. The extension’s popup closes the moment it loses focus, so the recording cannot live there.
- Local storage: to remember that a recording is in progress, so one the browser cut short can still be uploaded afterwards. It holds a meeting identifier and a timestamp — no meeting content.
- Sign-in: to connect the extension to your MLOG account once, without typing your password again.
- Access to our API only: to create the meeting and upload the recorded audio. The extension talks to no other host.
MLOG’s use and transfer of any information received through the browser extension adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Extension data is used only to provide the features described here — never sold, never used for advertising, never used to train models.
What the extension promises about your recording is not the same as the desktop app, and the difference is on the download page — please read it there before you rely on either.
10Changes & contact
Material changes to this policy are announced 30 days in advance by email and in-app notice. For any privacy question, write to support@mlog.ai — we reply within one business day.