Privacy Policy
Draft pending legal review
This document was written against how GroupMeet actually works, not from a template — but it has not yet been reviewed by a lawyer, and every bracketed value below must be completed before it can be relied upon.
1. Who we are
[LEGAL ENTITY NAME] (“GroupMeet”, “we”, “us”) operates the service at groupmeet.app. For privacy questions, contact [PRIVACY CONTACT EMAIL], or write to [REGISTERED POSTAL ADDRESS].
Where an organization invites you into its own GroupMeet workspace, that organization decides what happens in its space and we act on its instructions. This policy covers what we do with your information.
2. What we collect
Information you give us
- Account details — your name, email address and password. Passwords are stored only as a PBKDF2-HMAC-SHA256 hash with a per-account salt.
- Content you create — meeting titles, meeting notes, decisions and tasks, study materials, discussion questions, resources, prayer requests, and files you upload.
- Consultation information — where you use booking and consultation features, the appointment details and any documents you attach.
- Guest names — if you join a meeting as a guest without an account, the display name you type.
Information we generate
- Meeting records — which rooms you own or joined, host and co-host assignments, and when you last entered a room.
- Session records — a hash of your sign-in token and its expiry.
- Security records — at sign-up we store a hashed IP address and your browser's user-agent string to detect automated abuse.
- Access logs — every view or upload of a consultation document is recorded with the account responsible, a hashed IP address and a timestamp, so it is always possible to establish who accessed a health record.
- Administrative logs — actions taken by platform administrators on accounts, and API request logs for organizations using the developer API.
3. Video and audio
Live audio and video are carried by our real-time infrastructure provider and are not recorded or stored by default. A meeting host holds a permission that allows recording. If a host starts a recording, everyone in the meeting should be told before it begins — see our Disclosures and the host obligations in the Terms.
4. AI features
Some features — study assistance and meeting summaries — send the relevant text to a model hosted by our infrastructure provider on its own network. This content is not sent to a separate third-party AI vendor and is not used to train a public model. AI output can be wrong; treat it as a draft, never as advice.
5. Why we use your information
- To run meetings, workspaces and the features you switch on.
- To authenticate you and keep accounts secure.
- To take payment and manage subscriptions.
- To send transactional email such as password resets.
- To investigate abuse, and to meet legal obligations.
We do not sell your personal information, and we do not use meeting content to advertise to you.
6. Who processes data with us
These are our subprocessors. Each receives only what it needs to do its job. This list is part of our transparency obligations — it is kept accurate and updated whenever a provider changes.
| Provider | Purpose | What it receives |
|---|---|---|
| Cloudflare | Hosting, database, file storage, real-time video, AI | Effectively all service data |
| Stripe | Payments and subscriptions | Billing identifiers and transaction details. Card numbers go to Stripe, never to us. |
| Resend | Transactional email | Your email address and the message content |
| Crossway | ESV scripture text | The passage reference requested |
7. How long we keep things
Account and workspace content is kept while your account is active. Expired sessions are deleted automatically. When an account is deleted, its personal data is removed or anonymized within [RETENTION PERIOD], except where we must retain records for legal, tax or dispute-resolution reasons.
8. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal information, to object to or restrict certain processing, and to complain to a data protection authority. Contact [PRIVACY CONTACT EMAIL] and we will respond within [RESPONSE WINDOW].
[CONFIRM WHICH REGIMES APPLY — UK/EU GDPR, CCPA/CPRA, OTHERS — AND WHETHER A REPRESENTATIVE OR DPO IS REQUIRED]
9. International transfers
Our providers operate globally, so your information may be processed outside your country. [CONFIRM TRANSFER MECHANISM — E.G. STANDARD CONTRACTUAL CLAUSES]
10. Children
GroupMeet is not intended for children under [AGE]. If a workspace is used in a school or youth setting, the organization running it is responsible for obtaining any parental consent required.
11. Changes
We will post any change here and update the date above. For material changes we will notify account holders by email before the change takes effect.