Skip to content
MeetingStow
Product Privacy Terms Refunds Buy MeetingStow

Legal

Privacy Policy

Your recordings and meeting intelligence stay on your Mac. This policy explains the limited information we process to sell, deliver, support, and validate MeetingStow.

Last updated: September 12, 2026

Who we are Local meeting data Data we process Purposes and legal bases Service providers Retention Your rights Security Contact

BBDF Consulting LTD ("BBDF", "we", "us", or "our") operates MeetingStow, the MeetingStow website, purchase and download pages, and license validation service. We are the data controller for personal data processed through those services.

This policy does not make us the controller of meeting recordings created by a customer. Meeting content is stored and processed locally by the customer, and the customer is responsible for using that content lawfully.

1. Who we are

BBDF Consulting LTD
Company number: HE 448175
VAT number: 60019627E
Mosfylion 57, Kissonerga Beach Villas II, Villa 7
Kissonerga 8574, Pafos, Cyprus
General support: support@meetingstow.com
Data protection: dpo@meetingstow.com

Our data protection contact is Federico Blancato. You can use the data protection address above for privacy questions or requests.

2. Meeting content stays local

We do not receive your recorded audio, transcripts, speaker labels, people list, meeting titles, recaps, action items, decisions, voice templates, or disclosure records through MeetingStow's normal operation.

MeetingStow stores and processes recordings, transcript and recap files, people data, disclosure records, voice templates, and settings on your Mac. Speaker diarization, transcription, voice matching, and recap generation run on your Mac. You can generate recaps with Apple's on-device Foundation Models framework when Apple Intelligence is available or with the optional local Qwen recap model on supported Apple Silicon Macs.

Each disclosure record contains the disclosure text, the associated meeting and meeting provider, a timestamp, and the user's attestation that they notified participants and obtained any required permission. Disclosure records remain local and under your control.

Voice templates are stored in an AES-GCM encrypted local archive, with the encryption key kept in macOS Keychain. Although encrypted locally in normal operation, voice templates may constitute biometric or sensitive personal data in some jurisdictions.

If you select an optional Qwen engine, your Mac downloads its model from Hugging Face. The transcription model is approximately 2.19 GB and the recap model is approximately 1.72 GB. Those downloads disclose ordinary connection data, such as your IP address and request metadata, to Hugging Face, but they do not send your meeting audio, transcript, or recap to Hugging Face or to us. Apple may likewise receive ordinary connection data when macOS obtains system speech or intelligence assets. Local processing is subject to the security and privacy behavior of macOS and the model provider.

Meeting content leaves your Mac only when you choose to move, export, share, back up, or otherwise transmit it.

3. Personal data we process

Purchase and delivery information

Stripe provides us with the purchaser's name and email address, Checkout Session and payment identifiers, product and price identifiers, payment status, refund or dispute status, and transaction time. We do not receive or store full payment card numbers.

We use this information to generate a license, provide a protected download link, send the license email, verify continued eligibility for downloads, and maintain accounting records. Our private Cloudflare R2 storage contains purchase entitlement records, hashed license lookup records, and a marker showing whether the delivery email was sent.

License activation and validation information

MeetingStow sends the entered license key and the following information to our license service when you activate the app and during later launch checks:

  • a randomly generated installation identifier;
  • whether the check is an activation or launch check;
  • app version and build number;
  • macOS version and processor architecture;
  • Mac model identifier, processor count, and physical memory;
  • locale and time zone; and
  • network metadata supplied by Cloudflare, including IP address, user agent, approximate city, region and country, ASN, edge location, and Cloudflare request identifier.

We do not collect the Mac serial number, hostname, MAC address, advertising identifier, contact list, meeting content, or files during license validation. The installation identifier is random and is not a hardware fingerprint.

Support information

If you contact us, we process your email address, the contents of your message, attachments you choose to provide, and the information needed to resolve your request. Please do not send meeting recordings or transcripts unless they are necessary and you are authorized to share them.

Website measurement and security information

Our hosting and security provider receives standard request information such as IP address, browser type, requested URL, timestamps, and security signals. On public pages, MeetingStow uses Google Consent Mode with analytics and advertising storage denied by default. This sends limited, cookieless measurement signals for page views, checkout starts, purchases, and engagement with the example without reading or writing Google measurement cookies. Google necessarily receives an incoming IP address to deliver each request. For visitors in the EU, Switzerland, and the United Kingdom, Google states that Analytics uses it only to derive coarse location information before immediately discarding it; the address is not logged or available in Analytics. If you select "Allow" in the privacy notice, Google may use analytics and advertising measurement cookies or similar browser storage to connect activity across pages and attribute visits and purchases. We remove non-attribution query parameters before sending page locations, so protected download tokens, campaign context identifiers, and Stripe Checkout Session identifiers are not included in measurement URLs.

After you select "Allow" on a tagged visit, we keep a minimal campaign snapshot in that tab's session storage for no longer than 24 hours. It contains a random opaque context identifier, capture time, validated values for source, medium, campaign, content, and campaign ID when present, and an optional validated Google click-identifier type and value. We do not save search terms, full referrers, email addresses, purchase credentials, meeting content, IP addresses, or user agents in this snapshot. A new valid tagged visit replaces the complete snapshot; selecting "Not now" clears it.

When you continue to checkout with an allowed snapshot, our server validates it again and gives Stripe only an opaque campaign reference. Stripe returns that reference with a completed Checkout Session so we can associate the verified order with the privately stored campaign context. We keep separate private context, checkout-journey, and completed-order attribution records in Cloudflare R2; their object keys use one-way hashes and repeated requests are treated idempotently. Campaign context records may include the validated campaign values and optional click identifier, but do not include customer name or email, IP address, user agent, meeting content, license key, or download token. Historical Google-linked records created by an earlier version used a validated click reference with Stripe; they remain available during their existing retention period. Attribution is optional and its failure does not affect checkout, license delivery, or protected downloads. Google Analytics advertising signals and personalized-ad features remain disabled. Your privacy choice is stored in your browser and can be changed at any time through "Privacy choices" in the footer. Stripe may use necessary payment, security, and preference technologies on its hosted checkout under Stripe's own policy.

4. Why we process data

  • Contract: to process purchases, provide the installer and license, validate the license, supply updates, and respond to customer requests.
  • Consent: to use optional measurement cookies and advertising click attribution when you select "Allow." You may withdraw that consent at any time through "Privacy choices."
  • Legitimate interests: to obtain limited cookieless website measurement, prevent fraud and license abuse, secure the website and services, diagnose delivery or activation problems, and establish or defend legal claims.
  • Legal obligations: to maintain tax, accounting, payment, and compliance records.

License validation automatically checks whether the associated Stripe purchase is paid, for the correct product, and not refunded or disputed. If a check is rejected and you believe that result is wrong, contact us for human review.

We do not sell personal data, use meeting content to train artificial intelligence models, or use license validation information for advertising.

5. Service providers and international transfers

We share personal data only as needed with providers that help operate MeetingStow:

  • Stripe for hosted checkout, payment processing, fraud controls, refunds, and tax functions;
  • Cloudflare for website hosting, security, serverless functions, and private release and entitlement storage;
  • Brevo for transactional license and download email delivery;
  • Google for limited cookieless measurement and, when you allow it, cookie-based Google Analytics and Google Ads measurement;
  • Hugging Face when your Mac downloads the optional Qwen speech or recap models; and
  • Apple for macOS platform services, Keychain, system speech assets, and on-device Foundation Models.

These providers may process data outside Cyprus or the European Economic Area. Where required, transfers are protected through adequacy decisions, standard contractual clauses, or another lawful transfer mechanism. We may also disclose information when required by law, to protect legal rights or safety, or as part of a corporate transaction subject to appropriate safeguards.

6. How long we retain data

  • Local meeting data: controlled by you and retained on your Mac until you delete or move it.
  • Purchase, entitlement, and license records: for the life of the license and afterward where reasonably necessary to provide proof of purchase, prevent fraud, or meet legal obligations.
  • Billing and tax records: generally up to 10 years from the transaction, or longer if required for an audit or legal claim.
  • License validation audit records: up to 12 months from each validation, unless a record is required longer to investigate abuse, a security incident, or a legal claim.
  • Support correspondence: up to 24 months after the last interaction, unless a longer period is needed for an unresolved issue or legal obligation.
  • Transactional email delivery records: for as long as needed to prevent duplicate delivery and support the associated license.
  • Website and advertising measurement: your privacy choice remains in your browser until you change it or clear browser storage. A permitted campaign snapshot remains only in the current tab's session storage and expires after 24 hours. Event- and user-level Google Analytics data is configured for retention for up to 14 months. First-party campaign context, checkout-journey, and completed-order attribution records, including compatible historical records, are retained for up to 14 months unless needed longer to resolve a specific discrepancy or legal claim. Google retains cookieless and Google Ads measurement data according to the account settings and its policies.

We may retain de-identified or aggregated information that can no longer reasonably identify you.

7. Your rights

Subject to applicable law, you may have the right to:

  • access and receive a copy of your personal data;
  • correct inaccurate or incomplete data;
  • request deletion of data;
  • restrict or object to certain processing;
  • receive portable data where applicable; and
  • lodge a complaint with a supervisory authority.

Email dpo@meetingstow.com to exercise a right. We may need to verify your identity using your purchase email, Stripe receipt, or license details. Some information may be retained where required by law or necessary to establish, exercise, or defend legal claims.

In Cyprus, you may contact the Office of the Commissioner for Personal Data Protection. You may also contact the supervisory authority where you live or work.

8. Security

We use HTTPS, restricted administrative access, encrypted secrets, private object storage, hashed license lookup keys, and signed access links. MeetingStow encrypts local voice templates and protects their key with macOS Keychain. No system is completely secure, so we cannot guarantee absolute security.

Protected download links and license keys should be kept private. Contact us promptly if you believe either has been exposed or misused.

9. Children

MeetingStow is a professional productivity product and is not directed to children under 16. We do not knowingly collect personal data from children through the purchase or license service without appropriate authorization.

10. Changes to this policy

We may update this policy when MeetingStow, our providers, or legal requirements change. We will publish the revised policy here and update the date above. Material changes will be communicated through the website, purchase email, or app where reasonably practical.

11. Contact

For privacy matters, email dpo@meetingstow.com. For product or purchase support, email support@meetingstow.com.

MeetingStow

Meetings, remembered.

Product How it works Privacy Policy Terms Refund Policy Support

Native to macOS. Local by default.

© 2026 BBDF Consulting LTD.

BBDF Consulting LTD, company number HE 448175, Cyprus.