privacy policy
last updated: 9 august 2026
what miniti does
miniti records meetings on your device, transcribes them using Deepgram, and generates summaries, questions, coaching, and optional specialist insights using OpenAI. optional integrations can connect Google Calendar, Attio, Twenty CRM, a docs MCP server, and a webhook you choose.
where your data lives
your saved meeting history - including transcripts, notes, summaries, coaching data, Sales insights, Playbook cards, and Granola CSV imports - is stored locally in the app's container on your device. miniti does not provide a cloud meeting archive or sync your history between devices.
some content is nevertheless transmitted for processing while you use network features. audio is streamed to Deepgram; transcript text and relevant meeting context are sent to OpenAI, either directly in bring-your-own-keys mode or through Miniti's managed API; and configured integrations receive the data described below. Miniti's managed API does not intentionally retain transcripts or generated insights as a meeting record.
data protection and security
miniti is designed around a privacy-first, local-first architecture. we apply the following technical and organisational measures to protect your data, including sensitive data such as Google user data obtained via Google OAuth:
encryption in transit
- network traffic between the app, Miniti's API, and supported third-party services uses HTTPS or secure WebSockets.
- OAuth authorisation flows with Google, Attio, and Twenty use their official HTTPS endpoints. their callbacks are handled by Miniti's API.
- the miniti.app website and all Netlify Functions endpoints enforce HTTPS with HSTS (
Strict-Transport-Security), and are protected by a strict Content Security Policy,X-Frame-Options,X-Content-Type-Options,Referrer-Policy, andPermissions-Policyheaders.
encryption at rest
- Deepgram and OpenAI API keys entered in bring-your-own-keys mode are stored in the Apple Keychain.
- saved meetings and the local calendar cache are stored within the app's sandboxed container and benefit from the protections provided by macOS or iOS and your device settings.
- Google, Attio, and Twenty OAuth tokens are stored server-side in Upstash Redis, keyed to the app's anonymous device identifier, for as long as the integration remains authorised.
access controls and principle of least privilege
- miniti requests the read-only Google Calendar events scope:
https://www.googleapis.com/. it does not request permission to create, edit, or delete events.auth/ calendar.events.readonly - access to production infrastructure is restricted to authorised administration accounts.
- bring-your-own-keys credentials remain on your device and are sent only to the API provider they authenticate.
data minimisation
- only calendar fields needed for meeting features are read: event identifier and title, start/end time and status, attendees and organiser, and conferencing links.
- calendar data is fetched on demand for the relevant time window only; miniti does not bulk-download or mirror your entire calendar history.
- calendar context is not used for advertising or creditworthiness. when a meeting is associated with a calendar event, limited context can be used to improve transcription, speaker naming, AI insights, reminders, and integrations you enable.
server-side handling of Google user data
Miniti's API performs the Google OAuth exchange, stores the resulting token bundle in Upstash Redis under your anonymous device identifier, fetches the requested calendar window from Google, and returns normalised events to the app. calendar event responses pass through the API but are not intentionally retained there as a calendar archive. the app caches relevant event data locally.
secure development practices
- the app is distributed as a signed and notarised macOS build and through the Apple App Store for iOS, providing integrity verification and tamper protection.
- dependencies are kept up to date and monitored for known vulnerabilities.
- OAuth client credentials are managed server-side and are not embedded in the distributed app.
- source code is stored in private repositories with access restricted to the developer.
incident response
if we become aware of a security incident affecting Google user data or other personal data, we will: (1) investigate and contain the incident; (2) notify affected users without undue delay via the email address on file (where available) and a notice at miniti.app; and (3) where required, notify the relevant supervisory authority within 72 hours in accordance with GDPR Article 33. you can report suspected security issues by contacting us.
google calendar integration
miniti can optionally connect to Google Calendar to display upcoming meetings, pre-fill meeting context, show countdowns and reminders, and automatically start recording when enabled. this requires your consent through Google's OAuth screen and uses the read-only calendar.events.readonly scope.
what data is accessed
- event titles
- start and end times
- attendee names and email addresses
- meeting links (e.g. Google Meet, Zoom URLs)
miniti does not access: event descriptions beyond conferencing links, calendar ACLs, free/busy data for other users, contacts, Gmail, Drive, or any other Google service.
how the data is used
- showing upcoming meetings, countdowns, and reminders
- pre-filling the title and attendee context when you explicitly start a scheduled meeting
- automatically starting a scheduled recording when you enable auto-start
- using a short title, attendee names, and company domains as Deepgram keyterms to improve recognition
- using attendee names, domains, and roles as context for AI insights and speaker-name inference
- sending calendar-linked meeting data to Attio, Twenty CRM, or your webhook when you enable those integrations
Google user data is used only to provide these user-facing features. it is not sold, used for advertising, used to determine creditworthiness, or used to train a general-purpose model for Miniti.
how the data is stored and protected
- calendar event data is fetched through Miniti's API for the requested time window and cached locally in the app's sandboxed container.
- Google OAuth access and refresh tokens are stored in Upstash Redis under your anonymous device identifier while connected.
- communication between the app, Miniti's API, and Google uses HTTPS.
data sharing
miniti does not sell or rent Google Calendar data. it is handled by Miniti's API and Upstash as described above. limited title and attendee context can be sent to Deepgram and OpenAI to provide meeting features. when you configure Attio, Twenty CRM, or a webhook, relevant calendar-linked meeting fields can also be sent to that destination. full attendee email addresses are included in configured webhook payloads; Deepgram receives keyterms rather than email addresses, and OpenAI attendee context uses names, domains, and roles.
data retention and deletion
calendar data is refreshed as the relevant window changes. disconnecting Google Calendar asks the API to revoke and delete the server-side token bundle and clears the app's connected state and event cache. uninstalling the app removes its local cache, but you should also revoke Miniti from your Google account permissions page if you did not disconnect first.
revoking access
you can disconnect Google Calendar at any time from Settings in the app. this removes the stored OAuth credentials and stops all calendar data access. you can also revoke miniti's access from your Google account permissions page at any time.
Google API Services User Data Policy / Limited Use
miniti's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. specifically:
- miniti uses Google user data only to provide or improve user-facing features that are prominent in the requesting application's user interface.
- miniti transfers limited Google user data only when necessary to provide or improve the user-facing features described above, when you direct Miniti to use a configured integration, or when required by law.
- miniti does not use or transfer Google user data for serving advertisements, including retargeted, personalised, or interest-based advertising.
- miniti does not allow humans to read Google user data unless you give affirmative consent for specific data, access is necessary for security or support, access is required by law, or data has been aggregated and anonymised for internal operations.
- miniti does not use Google user data to develop, improve, or train generalised or non-personalised AI and/or ML models.
email collection and communications
you can download miniti without submitting your email. if you choose to join the newsletter on this website, your email and optional name are sent to resend and stored as a contact so we can send occasional product updates, changelogs, and announcements.
by submitting the newsletter form, you consent to receiving these communications. every email includes an unsubscribe link - you can opt out at any time with one click, and we will stop sending you updates immediately. you can also request full deletion of your contact data by contacting us.
we do not sell, rent, or share your email address with any third parties for their own marketing purposes.
what is sent to third parties
- Deepgram: live audio, language and transcription settings, personal dictionary terms, and—when available—meeting-title, attendee-name, and company-domain keyterms.
- OpenAI: transcript text and rolling insight state; relevant title and attendee context; and, for Playbook, retrieved documentation excerpts used to ground an answer.
- Miniti's managed API: anonymous device identifier, usage and subscription state, managed insight requests and responses in transit, Google/Attio/Twenty OAuth data, and opt-in diagnostics. it does not store a server-side copy of your meeting history.
- your docs MCP: topic searches from Playbook. in managed mode Miniti's API contacts the URL you provide; in bring-your-own-keys mode the app contacts it directly.
- Attio: when you send manually or enable auto-sync, Miniti can match attendee domains and create a note containing meeting title, timing, notes, summaries, decisions, topics, Sales fields, and action-item tasks. the full transcript is not uploaded to Attio.
- Twenty CRM: when you send manually or enable auto-sync, Miniti can match attendee domains and create a linked note containing meeting title, timing, notes, summaries, decisions, topics, Sales fields, and optional action-item tasks. the full transcript and coaching metrics are not uploaded to Twenty.
- your webhook: when configured, Miniti posts a detailed meeting payload that can include the transcript, insights, coaching metrics, speaker names, calendar event ID, and attendee names, domains, and email addresses.
these services process data under their own privacy policies.
managed mode and pro
managed free and Pro send a random device identifier to Miniti's API for entitlement, quota, session, and reliability controls. audio streams to Deepgram using a short-lived credential issued through the API. transcript and insight requests pass through the API to OpenAI and responses return to the app; Miniti does not intentionally retain them as meeting records.
macOS Pro is handled by Polar, including its license key. iOS Pro is an auto-renewable subscription handled by Apple. Miniti receives the information needed to verify and apply the relevant entitlement but does not receive full card details.
bring your own keys mode
if you provide your own Deepgram and OpenAI API keys, transcription and core AI requests go directly from the app to those providers rather than through Miniti's managed metering. optional Google Calendar, Attio, Twenty CRM, managed Playbook, website, and user-configured webhook or MCP features can still involve Miniti's API or the destinations described above.
api keys
api keys you enter are stored locally on your device. they are never sent to miniti's servers.
analytics
the app does not include general behavioural product analytics. an optional Share Diagnostics setting sends structured reliability events such as errors, reconnects, and health states in managed mode. those events can include an anonymous device and diagnostics-session identifier, meeting identifier, app mode, event category, and bounded technical details; they are designed not to include transcript or audio content.
the website loads PostHog's EU service for page and conversion analytics. it uses browser storage and identifiers to distinguish visits and records actions such as downloads, video plays, newsletter submissions, and support requests. after a newsletter or support form succeeds, the submitted email and name can be associated with those events. website functions also process connection information such as IP address and user agent for security, rate limiting, and download analytics.
the website also loads the X Ads pixel used for advertising measurement. X can receive visit and conversion information; an X click identifier may be stored in a seven-day cookie and associated with conversion events. newsletter conversion measurement can include the submitted email address. these providers handle information under their own policies.
no account required
miniti does not require an account to use the managed free tier or bring-your-own-keys mode. Polar collects the information needed for macOS Pro billing and licensing. Apple handles the Apple Account and billing relationship for iOS Pro.
data retention and deletion
meeting content is retained locally until you delete it in the app or uninstall Miniti. network processors retain data according to their own service terms; Miniti's managed API does not intentionally retain transcript or insight payloads as meeting history.
Google user data is retained locally in the event cache as needed and the OAuth token bundle is retained server-side while connected. disconnect in Settings to revoke and delete the stored token and clear cached events, or revoke access through your Google account permissions page.
email contact data (email and optional name submitted via the newsletter form) is retained in Resend until you unsubscribe or request deletion via support. we respond to deletion requests without undue delay and at the latest within 30 days.
anonymous device identifiers used in managed mode are retained for as long as the device uses miniti. you can request deletion by contacting us with your device ID.
diagnostic events are retained as a bounded recent window when Share Diagnostics is enabled. website analytics, advertising, security, and provider records follow the retention controls of PostHog, X, Netlify, and the relevant service.
to request deletion of any personal data we hold, contact us.
gdpr
miniti processes minimal personal data. the legal basis for processing is contract performance (providing the service you use), consent (product update emails when you submit the newsletter form), and legitimate interest (website analytics and conversion measurement, plus anonymous usage tracking in managed mode).
saved meeting history is local, so you can view, export, or delete it in the app. this does not automatically erase copies already sent to a webhook, Attio, Twenty, or another provider you configured.
audio and transcript data sent to deepgram and openai may be transferred to servers in the united states. both providers maintain appropriate safeguards for international data transfers under their respective data processing agreements.
if you joined the newsletter, you can unsubscribe from product updates at any time via the link in any email, or request full deletion of your contact data by contacting us.
if you use managed mode, you can request deletion of your anonymous usage data by contacting us. since the device identifier is a random UUID not linked to your identity, we cannot associate it with you unless you tell us your device ID.
disclaimer
miniti is provided "as is" without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, or non-infringement. use it at your own risk.
limitation of liability
in no event shall miniti or its developer be liable for any indirect, incidental, special, or consequential damages arising from the use or inability to use the app, including but not limited to loss of data, lost recordings, or missed meeting content.
third-party services (subprocessors)
miniti uses the following third-party services. we are not responsible for their availability, accuracy, pricing, or data handling. your use of these services is subject to their respective terms.
- deepgram - real-time speech-to-text transcription and speaker identification
- openai - AI-generated summaries, action items, and meeting analysis
- google - calendar sync for upcoming meetings and auto-start (read-only, opt-in)
- attio - optional CRM integration on macOS (manual send or calendar-driven auto-sync)
- Twenty - optional Twenty Cloud CRM integration on macOS (manual send or calendar-driven auto-sync)
- your configured docs MCP and webhook providers - Playbook retrieval and meeting automation at destinations you choose
- polar - macOS Pro subscription payments and license management
- apple - iOS distribution, subscription payments, and entitlement verification
- vercel - backend API hosting for managed mode
- upstash - backend data storage (device usage tracking, subscription state)
- netlify - website hosting and support form submissions
- resend - email delivery and contact management (product update newsletters, unsubscribe handling)
- posthog - website analytics and conversion measurement (EU service)
- X - website advertising and conversion measurement
recording consent
you are responsible for complying with all applicable laws when using miniti, including any laws regarding recording conversations. many jurisdictions require consent from all parties before recording. miniti does not provide legal advice on recording consent.
your content
you own your meeting recordings, transcripts, and any content generated by the app. miniti claims no rights to your data.
changes
we may update these terms at any time. continued use of miniti after changes constitutes acceptance.
copyright
© 2026 Ian Ahuja. all rights reserved.
miniti, the miniti name, and the miniti logo are the property of Ian Ahuja. you may not copy, modify, or distribute the app or its assets without permission.
questions or data requests? get in touch.