1. Where your data lives
Your account, meetings, transcripts and generated minutes are stored in a managed cloud database with role-based access controls and row-level security policies. Only your own account (and accounts you explicitly share with) can read or modify your meetings.
2. Encryption
- In transit: all traffic between your browser and our servers uses TLS (HTTPS).
- At rest: our database and storage providers encrypt data at rest using industry-standard ciphers.
3. How transcripts are processed
When you submit a transcript, we forward only the necessary content to a trusted AI inference provider to generate your summary, decisions, action items and attendee list. The generated outputs are stored against your meeting so you can review and edit them. We do not use your meeting content to train AI models for other customers.
AI providers may process your content in data centres outside Australia. We choose providers with appropriate confidentiality and security commitments, but you should avoid uploading content you are not authorised to share overseas.
4. Access controls
- Every database table that holds user content uses row-level security policies, so users can only see their own data.
- Privileged operations are gated by server-side checks; the browser cannot escalate its own permissions.
- Administrative access by our team is restricted, logged and used only for support or to investigate abuse.
5. Account security — your part
- Use a strong, unique password and do not reuse it on other services.
- Sign out of shared devices when you are done.
- Only invite collaborators you trust to view your meetings.
- Tell us straight away if you suspect your account has been accessed without permission.
6. Backups and availability
Our database is backed up by our cloud provider so we can recover from infrastructure failures. We aim for high availability but do not guarantee uninterrupted service.
7. Deleting your data
You can delete individual meetings at any time from your dashboard. Deletions remove the meeting, its transcript and its generated outputs from the live database. Closing your account removes your meetings within a reasonable period, subject to any legal hold or backup-retention window.
8. What we do not claim
We want to be honest with you. Aleph Minutes is not currently certified against frameworks such as SOC 2, ISO 27001, HIPAA or GDPR. We follow sensible security practices and will update this page as our compliance posture evolves. If your organisation requires a specific certification before adoption, please get in touch so we can discuss your requirements.
9. Reporting a security issue
If you believe you have found a security vulnerability, please report it via our Contact page with as much detail as you can share. We will acknowledge your report and investigate promptly.