Privacy Policy
Last updated:
This Privacy Policy explains how Qennie (“Qennie”, “we”, “us”) collects, uses and protects personal information when you use our website at https://qennie.com and the Qennie service. By using Qennie you also agree to our Terms of Service.
1. What Qennie does
Qennie is an AI meeting notetaker. When you ask it to, Qennie sends a bot participant (“the notetaker”) into your Google Meet, Microsoft Teams or Zoom meetings. The notetaker records the meeting, the recording is transcribed, and an AI model produces a summary with key points and action items. Results are stored in a meeting library shared with your organization in Qennie.
You can connect a Google or Microsoft calendar with read-only access so Qennie can find upcoming meetings that have a video-call link and, depending on your settings, send the notetaker to them automatically. You can also send the notetaker to a meeting by pasting its link.
2. Information we collect
Account information. Your name, email address, a hashed password, whether your email is verified, and an optional profile image. When you sign in we store session records including IP address and browser user agent, used to keep you signed in and to protect your account.
Organization information. Organization names, memberships and roles, and invitations (the invitee’s email address, role and who invited them).
Calendar information. If you connect a calendar, we store the connected account’s email address and provider account identifier, the permissions granted, and your sync and auto-join preferences. For upcoming events we store the event title, start and end time, meeting link, calendar event identifier and the event details returned by the calendar provider (which may include organizer and attendee names and email addresses). We do not store your calendar OAuth access or refresh tokens; see section 4.
Meeting content. For meetings the notetaker joins: the meeting title, platform and link, start and end times, the names (and, where the platform provides them, email addresses) of participants, the audio and video recording, the transcript with speaker names and timestamps, and the AI-generated summary and action items.
Share links. If you share a meeting publicly, we store the share link, who created it, whether it includes video, and its optional expiry date.
Technical and diagnostic data. Server logs and error reports (including the request, browser type and the error details) so we can operate the service and fix problems.
We use only the cookies needed to keep you signed in and to secure sign-in flows. We do not use advertising or cross-site tracking cookies.
3. How we use information
We use the information above to:
- provide the service: create your account, join and record meetings, produce transcripts and summaries, and show them to you and your organization;
- send service emails such as email verification, password resets and organization invitations;
- keep the service secure, prevent abuse, and diagnose and fix errors;
- comply with legal obligations and enforce our Terms of Service.
We do not sell your personal information, we do not use it for advertising, and we do not use your meeting recordings, transcripts, summaries or calendar data to train generalized AI models.
Legal bases (EEA/UK). We process your data to perform our contract with you (providing the service), for our legitimate interests (security, fraud prevention and improving reliability), to comply with legal obligations, and with your consent where required (for example, connecting a calendar). You can withdraw consent at any time.
4. Google and Microsoft calendar data
When you connect a Google calendar, Qennie requests read-only access to your calendar events (calendar.events.readonly) and your email address. When you connect a Microsoft calendar, Qennie requests read-only access to your calendars (Calendars.Read), your basic profile to learn the connected mailbox address, and offline access so syncing continues while you are away. Qennie never creates, edits or deletes calendar events.
The OAuth refresh token you grant is passed directly to our calendar-sync provider, Recall.ai, which uses it to read your events on our behalf. Qennie does not store your calendar access or refresh tokens in its own database.
Qennie’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, for data received from Google and from Microsoft:
- we use it only to find the meetings you want the notetaker to join and record, and to show those meetings to you in Qennie;
- we transfer it to third parties only as needed to provide that feature (for example, to Recall.ai to sync your calendar and schedule the notetaker), to comply with law, or as part of a merger or acquisition with notice to you;
- we do not sell it;
- we do not use it for advertising, including personalized, retargeted or interest-based advertising;
- we do not use it to train or improve generalized or non-personalized AI or machine-learning models;
- no human at Qennie reads it unless you give us explicit permission for specific data, it is necessary for security purposes (such as investigating abuse), or it is required to comply with applicable law.
You can disconnect a calendar at any time in Qennie’s settings. Disconnecting deletes the calendar connection and its synced events from Qennie, cancels upcoming notetaker bookings for that calendar, and asks Recall.ai to delete the calendar on its side. You can also revoke Qennie’s access from your Google Account permissions or your Microsoft account apps page.
5. Meeting recordings and participant consent
When the notetaker joins a meeting, it processes the audio, video, displayed names and spoken words of everyone in that meeting, including people who do not have a Qennie account. The notetaker joins as a visible participant.
You, as the account holder who sends the notetaker, are responsible for telling meeting participants that the meeting is being recorded and transcribed, and for obtaining their consent wherever the law requires it. Recording laws differ between countries and states, and some require the consent of every participant. For recordings made through Qennie, the customer who sends the notetaker generally decides why and how the recording is made (acting as the “controller”), and Qennie processes it on that customer’s behalf.
If you took part in a meeting recorded by a Qennie customer and want to exercise your rights over that recording, please contact the person or organization who recorded it. You may also email us at info@qennie.com and we will help pass your request on.
7. International data transfers
Qennie’s application and database are hosted in the European Union (Germany). Some of our providers, listed above, process data in the United States and other countries. Where personal data from the EEA, UK or Nigeria is transferred to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and their UK equivalent) or other mechanisms permitted under the Nigeria Data Protection Act 2023.
8. How long we keep data
- Account and organization data is kept while your account is active.
- Recordings, transcripts and summaries are kept in your organization’s library until you ask us to delete them or your account or organization is deleted. Qennie copies each recording to its own storage; Recall.ai keeps its copy of the media only for a limited retention period and then deletes it automatically.
- Calendar connections and synced events are kept until you disconnect the calendar.
- Share links stop working when they expire or are revoked.
- Database backups are deleted automatically after 30 days, so deleted data may persist in backups for up to 30 days.
Qennie does not yet offer self-service deletion of individual meetings or of your account. To delete a meeting, your account or your organization’s data, email info@qennie.com from the email address on your account. We will confirm your request and complete it within 30 days, unless we must keep certain information to meet legal obligations.
9. Security
We protect your data with measures including encryption in transit (HTTPS), hashed passwords, access controls that scope data to your organization, short-lived signed links for recording playback, verification of incoming webhooks, and not storing calendar OAuth tokens in our database. No system is perfectly secure; if we become aware of a breach affecting your personal data we will notify you and the relevant authorities as required by law.
10. Your rights
Depending on where you live, including under the EU and UK GDPR and the Nigeria Data Protection Act 2023, you may have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate data;
- delete your data;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent at any time, without affecting earlier processing;
- not be subject to decisions based solely on automated processing that significantly affect you (Qennie makes no such decisions);
- complain to a data protection authority, such as your local EU supervisory authority or the Nigeria Data Protection Commission.
To exercise any of these rights, email info@qennie.com. We may need to verify your identity and will respond within the time required by law (usually within 30 days).
11. Children
Qennie is a business tool and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. We will change the “Last updated” date above and, for significant changes, notify you by email or in the app before they take effect.
13. Contact us
131 Continental Dr, Suite 305, Newark, Delaware 19713, USA
Email: info@qennie.com
Website: https://qennie.com