privacy policy

last updated: 9 august 2026

what miniti does

miniti records meetings on your device, transcribes them using Deepgram, and generates summaries, questions, coaching, and optional specialist insights using OpenAI. optional integrations can connect Google Calendar, Attio, Twenty CRM, a docs MCP server, and a webhook you choose.

where your data lives

your saved meeting history - including transcripts, notes, summaries, coaching data, Sales insights, Playbook cards, and Granola CSV imports - is stored locally in the app's container on your device. miniti does not provide a cloud meeting archive or sync your history between devices.

some content is nevertheless transmitted for processing while you use network features. audio is streamed to Deepgram; transcript text and relevant meeting context are sent to OpenAI, either directly in bring-your-own-keys mode or through Miniti's managed API; and configured integrations receive the data described below. Miniti's managed API does not intentionally retain transcripts or generated insights as a meeting record.

data protection and security

miniti is designed around a privacy-first, local-first architecture. we apply the following technical and organisational measures to protect your data, including sensitive data such as Google user data obtained via Google OAuth:

encryption in transit

encryption at rest

access controls and principle of least privilege

data minimisation

server-side handling of Google user data

Miniti's API performs the Google OAuth exchange, stores the resulting token bundle in Upstash Redis under your anonymous device identifier, fetches the requested calendar window from Google, and returns normalised events to the app. calendar event responses pass through the API but are not intentionally retained there as a calendar archive. the app caches relevant event data locally.

secure development practices

incident response

if we become aware of a security incident affecting Google user data or other personal data, we will: (1) investigate and contain the incident; (2) notify affected users without undue delay via the email address on file (where available) and a notice at miniti.app; and (3) where required, notify the relevant supervisory authority within 72 hours in accordance with GDPR Article 33. you can report suspected security issues by contacting us.

google calendar integration

miniti can optionally connect to Google Calendar to display upcoming meetings, pre-fill meeting context, show countdowns and reminders, and automatically start recording when enabled. this requires your consent through Google's OAuth screen and uses the read-only calendar.events.readonly scope.

what data is accessed

miniti does not access: event descriptions beyond conferencing links, calendar ACLs, free/busy data for other users, contacts, Gmail, Drive, or any other Google service.

how the data is used

Google user data is used only to provide these user-facing features. it is not sold, used for advertising, used to determine creditworthiness, or used to train a general-purpose model for Miniti.

how the data is stored and protected

data sharing

miniti does not sell or rent Google Calendar data. it is handled by Miniti's API and Upstash as described above. limited title and attendee context can be sent to Deepgram and OpenAI to provide meeting features. when you configure Attio, Twenty CRM, or a webhook, relevant calendar-linked meeting fields can also be sent to that destination. full attendee email addresses are included in configured webhook payloads; Deepgram receives keyterms rather than email addresses, and OpenAI attendee context uses names, domains, and roles.

data retention and deletion

calendar data is refreshed as the relevant window changes. disconnecting Google Calendar asks the API to revoke and delete the server-side token bundle and clears the app's connected state and event cache. uninstalling the app removes its local cache, but you should also revoke Miniti from your Google account permissions page if you did not disconnect first.

revoking access

you can disconnect Google Calendar at any time from Settings in the app. this removes the stored OAuth credentials and stops all calendar data access. you can also revoke miniti's access from your Google account permissions page at any time.

Google API Services User Data Policy / Limited Use

miniti's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. specifically:

email collection and communications

you can download miniti without submitting your email. if you choose to join the newsletter on this website, your email and optional name are sent to resend and stored as a contact so we can send occasional product updates, changelogs, and announcements.

by submitting the newsletter form, you consent to receiving these communications. every email includes an unsubscribe link - you can opt out at any time with one click, and we will stop sending you updates immediately. you can also request full deletion of your contact data by contacting us.

we do not sell, rent, or share your email address with any third parties for their own marketing purposes.

what is sent to third parties

these services process data under their own privacy policies.

managed mode and pro

managed free and Pro send a random device identifier to Miniti's API for entitlement, quota, session, and reliability controls. audio streams to Deepgram using a short-lived credential issued through the API. transcript and insight requests pass through the API to OpenAI and responses return to the app; Miniti does not intentionally retain them as meeting records.

macOS Pro is handled by Polar, including its license key. iOS Pro is an auto-renewable subscription handled by Apple. Miniti receives the information needed to verify and apply the relevant entitlement but does not receive full card details.

bring your own keys mode

if you provide your own Deepgram and OpenAI API keys, transcription and core AI requests go directly from the app to those providers rather than through Miniti's managed metering. optional Google Calendar, Attio, Twenty CRM, managed Playbook, website, and user-configured webhook or MCP features can still involve Miniti's API or the destinations described above.

api keys

api keys you enter are stored locally on your device. they are never sent to miniti's servers.

analytics

the app does not include general behavioural product analytics. an optional Share Diagnostics setting sends structured reliability events such as errors, reconnects, and health states in managed mode. those events can include an anonymous device and diagnostics-session identifier, meeting identifier, app mode, event category, and bounded technical details; they are designed not to include transcript or audio content.

the website loads PostHog's EU service for page and conversion analytics. it uses browser storage and identifiers to distinguish visits and records actions such as downloads, video plays, newsletter submissions, and support requests. after a newsletter or support form succeeds, the submitted email and name can be associated with those events. website functions also process connection information such as IP address and user agent for security, rate limiting, and download analytics.

the website also loads the X Ads pixel used for advertising measurement. X can receive visit and conversion information; an X click identifier may be stored in a seven-day cookie and associated with conversion events. newsletter conversion measurement can include the submitted email address. these providers handle information under their own policies.

no account required

miniti does not require an account to use the managed free tier or bring-your-own-keys mode. Polar collects the information needed for macOS Pro billing and licensing. Apple handles the Apple Account and billing relationship for iOS Pro.

data retention and deletion

meeting content is retained locally until you delete it in the app or uninstall Miniti. network processors retain data according to their own service terms; Miniti's managed API does not intentionally retain transcript or insight payloads as meeting history.

Google user data is retained locally in the event cache as needed and the OAuth token bundle is retained server-side while connected. disconnect in Settings to revoke and delete the stored token and clear cached events, or revoke access through your Google account permissions page.

email contact data (email and optional name submitted via the newsletter form) is retained in Resend until you unsubscribe or request deletion via support. we respond to deletion requests without undue delay and at the latest within 30 days.

anonymous device identifiers used in managed mode are retained for as long as the device uses miniti. you can request deletion by contacting us with your device ID.

diagnostic events are retained as a bounded recent window when Share Diagnostics is enabled. website analytics, advertising, security, and provider records follow the retention controls of PostHog, X, Netlify, and the relevant service.

to request deletion of any personal data we hold, contact us.

gdpr

miniti processes minimal personal data. the legal basis for processing is contract performance (providing the service you use), consent (product update emails when you submit the newsletter form), and legitimate interest (website analytics and conversion measurement, plus anonymous usage tracking in managed mode).

saved meeting history is local, so you can view, export, or delete it in the app. this does not automatically erase copies already sent to a webhook, Attio, Twenty, or another provider you configured.

audio and transcript data sent to deepgram and openai may be transferred to servers in the united states. both providers maintain appropriate safeguards for international data transfers under their respective data processing agreements.

if you joined the newsletter, you can unsubscribe from product updates at any time via the link in any email, or request full deletion of your contact data by contacting us.

if you use managed mode, you can request deletion of your anonymous usage data by contacting us. since the device identifier is a random UUID not linked to your identity, we cannot associate it with you unless you tell us your device ID.

disclaimer

miniti is provided "as is" without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, or non-infringement. use it at your own risk.

limitation of liability

in no event shall miniti or its developer be liable for any indirect, incidental, special, or consequential damages arising from the use or inability to use the app, including but not limited to loss of data, lost recordings, or missed meeting content.

third-party services (subprocessors)

miniti uses the following third-party services. we are not responsible for their availability, accuracy, pricing, or data handling. your use of these services is subject to their respective terms.

you are responsible for complying with all applicable laws when using miniti, including any laws regarding recording conversations. many jurisdictions require consent from all parties before recording. miniti does not provide legal advice on recording consent.

your content

you own your meeting recordings, transcripts, and any content generated by the app. miniti claims no rights to your data.

changes

we may update these terms at any time. continued use of miniti after changes constitutes acceptance.

© 2026 Ian Ahuja. all rights reserved.

miniti, the miniti name, and the miniti logo are the property of Ian Ahuja. you may not copy, modify, or distribute the app or its assets without permission.


questions or data requests? get in touch.