Privacy Policy
Version 1.1 · 2026-09-03
Version 1.1 · effective 2026-09-03
This is the version in force. If we revise it, the new version appears here with a new number and date, and we give notice of material changes before they take effect. Ask us if you want to know how a clause works in practice, and we will tell you plainly.
What Routenna collects, why, how long it keeps it, and how to make us delete it. It describes what the product actually does today, and the practices here do not get looser without notice.
1. What we collect
- Account data: name, work email, and organization membership, via Google or Microsoft sign-in.
- Meeting data: recordings (unless the organization chooses transcript-only mode, in which case no audio is ever stored), transcripts, and the structured findings extracted from them.
- Calendar data: event details needed to schedule capture, under credentials the customer connects and can revoke.
- Website form data: what you submit through the contact and access-request forms.
2. What we do not do
- No advertising trackers and no analytics scripts on this website.
- No sale or sharing of personal information for advertising.
- No training of shared AI models on customer data.
3. Retention and deletion
Audio retention follows the customer organization’s policy. Deletion: by retention window, by request, or by account deletion: is executed by an engine that verifies the data is actually gone and records the verification.
4. Notice at collection (California: CCPA/CPRA)
Categories collected: identifiers (name, email), professional information (organization, role), and audio/electronic information (meeting recordings and transcripts, where the customer directs capture). Purpose: providing the service described above. We do not sell personal information and do not share it for cross-context behavioral advertising. How to exercise your rights is in section 5 below. Retention periods are in section 3: audio for the number of days the customer sets, 30 by default and 365 at most; transcripts, extractions and account records for as long as the account is open, and then deleted on request or on account deletion.
5. Your rights, and how to exercise them
Write to hello@routenna.com with the word privacy in the subject. A person reads it; there is no ticket queue. We will acknowledge within five business days and answer substantively within thirty days, and we will tell you if we need longer and why.
You can ask us what personal data we hold about you and get a copy of it; ask us to correct it; ask us to delete it; and ask us to stop processing it. If you are a California resident, that includes the CCPA and CPRA rights to know, delete, correct, and to limit the use of sensitive personal information. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is no opt-out to offer you for either. We will not treat you differently for asking.
If you are an employee or a client of one of our customers, the meeting record you appear in belongs to that customer rather than to us: we process it on their instructions. Write to us anyway and we will tell you who holds it and pass your request to them.
We will need enough information to be sure the request is yours, and we will ask for the least that establishes it.
6. Legal bases for processing
Where the GDPR or UK GDPR applies, we rely on these bases. Providing the service to the organization that asked for it is performance of a contract. Keeping the service secure, preventing abuse, and improving reliability are our legitimate interests, balanced against the rights of the people concerned. Meeting the obligations that apply to us, such as tax and accounting records, is legal obligation.
For meeting participants, the customer organization is the controller and decides the basis on which a conversation is recorded, including obtaining consent where the law requires it. We act as processor on that organization’s instructions. Section 2 of the Terms of Service says the same thing from the other side, and it is not a formality: it is the reason the consent controls exist in the product.
7. International transfers
Routenna is operated from the United States and its infrastructure is hosted there. If you are outside the United States, using the service means your data is transferred there.
Every subprocessor we use is under a data processing agreement that incorporates the European Commission’s Standard Contractual Clauses, or an equivalent approved mechanism, for transfers out of the EEA and UK. The register on the subprocessors page names each vendor, what it processes, and which agreement is in force. Where a vendor’s agreement binds on acceptance of its terms rather than a separate signature, the register says so rather than implying a countersigned document exists.