Legal
Privacy policy
What NeurTask collects, why, who else sees it, and what you can make us delete. Written to describe what the system actually does rather than what would be convenient.
One cookie, no trackers
No analytics script, no advertising pixel and no consent banner, because there is nothing to consent to.
Contents
- Who we are
- Data we collect directly
- Meeting content
- Why we process it, and on what basis
- Who else processes your data
- Transfers outside the EU
- How long we keep it
- Your rights
- Security
- Cookies and local storage
- Children
- Changes
Last updated
Who we are
NeurTask is operated by NeurTask, part of Gaddr AB, Stockholm, Sweden. For the purposes of the EU General Data Protection Regulation we are the controller of the personal data described under “Data we collect directly”, and the processor of the meeting content you put into the service. You remain the controller of that.
Questions, access requests and deletion requests: privacy@neurtask.com. Our data processing agreement sets out the Article 28 terms.
Data we collect directly
- Account data. Your name, email address, password hash, and the workspace you belong to.
- Calendar events. If you connect Google Calendar, we read your events so the notetaker knows which meetings to join. The grant is read-only. We do not create, modify or delete anything in your calendar.
- Billing data. On a paid plan: billing name, address, VAT number and a card token held by our payment processor. We never see or store full card numbers.
- Technical data. IP address, browser type and timestamps in server logs, kept for security and debugging. Logs never contain meeting content.
- Contact and mailing-list data. If you email us or join the mailing list, the address and message you send.
Meeting content
When a meeting is recorded, we process the audio, the transcript derived from it, the summary derived from the transcript, and the action items derived from the summary. All four are personal data about everyone who spoke, not only about you.
The notetaker is always visible. It joins as a named participant and appears in the participant list for the whole call. There is no silent mode. Where recording happens from your own browser tab instead, no participant is added, and you are responsible for telling the other people on the call that you are recording.
Why we process it, and on what basis
| Purpose | Lawful basis |
|---|---|
| Providing the service you asked for | Performance of a contract |
| Transcribing and summarising your meetings | Performance of a contract |
| Taking payment and meeting our tax obligations | Contract and legal obligation |
| Keeping the service secure and diagnosing faults | Legitimate interests |
| Transactional email about your account | Performance of a contract |
| Mailing-list email you asked to receive | Consent, withdrawable at any time |
We do not process meeting content for any purpose other than producing the artefacts you asked for. Your content is never used to train models. Not ours, not a third party’s, and not as an opt-in setting.
Who else processes your data
The current list lives on the sub-processors page and is the authoritative version. We publish changes there before they take effect and email account holders 30 days ahead of adding a sub-processor that touches meeting content.
Transfers outside the EU
Meeting audio and transcript text are processed in the United States. Our application servers run in Stockholm and the database is pinned to the EU, but speech-to-text and summarisation are performed by providers based in the US, which means that content crosses the Atlantic. Transfers rely on the European Commission’s standard contractual clauses.
If that is not acceptable for your data, the Enterprise deployment keeps all processing inside your own infrastructure. We would rather tell you this on the privacy page than have you discover it in a security questionnaire.
How long we keep it
Deleting a meeting removes the recording, the transcript and the summary together. Deleting your account removes your account data and the meetings you own.
There is currently no automatic expiry. Per-workspace retention windows, including delete-after-transcription, are being built and are not available yet. Until they ship, meeting content is kept until you delete it. This is stated here, on the security page, and nowhere is it described as working.
Server logs are kept for 30 days. Contact email is kept for two years. Invoices and the records behind them are kept for seven years, because Swedish bookkeeping law requires it.
Your rights
Under GDPR you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to processing, and to receive it in a portable format. Email privacy@neurtask.com and we will respond within 30 days.
There is no self-service export endpoint yet, so requests are handled manually. If you are not satisfied with how we handle one, you can complain to your national supervisory authority. In Sweden that is Integritetsskyddsmyndigheten (IMY).
If you spoke in a meeting recorded by one of our customers, we process that recording on their instructions. Send the request to them. We will support them in answering it, and you can copy us.
Security
- TLS in transit, encryption at rest for recordings, transcripts and summaries.
- Meeting content is scoped to a single workspace and is not readable across tenants.
- Meeting content is never written to application logs.
- Access to production data is limited to the engineers who need it and is not routine.
We do not hold SOC 2 or ISO 27001 certification. Report a vulnerability to security@neurtask.com. We will not take legal action against good-faith research.
Cookies and local storage
One cookie and two local storage keys, listed in full on the cookie policy. No analytics, no advertising, no third-party scripts, no fingerprinting, and therefore no consent banner.
Children
The service is not intended for anyone under 16 and we do not knowingly collect their data.
Changes
Material changes are announced by email to account holders before they take effect. The date at the top of this page is the last substantive revision.
Questions about this document: privacy@neurtask.com. All documents are listed on the legal index.