Last updated: July 12, 2026
Privacy Policy
Mesakem is a meeting and call summarization service. This Privacy Policy explains what information we collect, how we use it, and the choices users have.
Information we collect
- Account information such as name, email address, workspace, and authentication state.
- Meeting information such as meeting links, titles, times, organizer/requester email, processing status, transcripts, summaries, decisions, and action items.
- Calendar connection metadata when a user connects Google Calendar or Microsoft Outlook Calendar.
- Call-recording connector settings when a user connects a supported call-recording provider.
- Personal agent data: text messages sent and received through connected Telegram or WhatsApp channels, and tasks and reminders created by the user.
- Limited payment details: last four digits of a credit card and purchase date, received from our payment processor Cardcom. Full card details are never stored by us.
- Operational logs and audit events needed for security, support, reliability, and abuse prevention.
Google Calendar data
When a user connects Google Calendar, Mesakem requests read-only access to calendar events. Mesakem uses this access only to detect upcoming calendar events that contain meeting links such as Zoom, Microsoft Teams, or Google Meet links, so the user's visible meeting assistant can join and generate a summary.
Mesakem does not create, edit, or delete Google Calendar events. Mesakem does not sell Google user data. Mesakem does not use Google Calendar data for advertising.
The use and transfer of raw and derived user data received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Mesakem does not transfer Google user data to third-party AI/ML services for model training purposes.
Microsoft calendar data
When a user connects Microsoft Outlook Calendar, Mesakem requests delegated read-only calendar access to detect upcoming meetings and extract supported meeting links.
Recordings, transcripts, and summaries
Mesakem may process meeting and call audio/video to create transcripts and summaries. Summaries are sent only to verified recipient email addresses selected by the user.
Retention policy: All data — video recordings (meetings), phone call recordings, transcripts, and summaries — is retained until the user requests deletion. To request deletion, contact support@mesakem.com. Deletions are processed within 30 days, subject to legal retention obligations.
Recording consent
Laws in many jurisdictions require explicit consent from participants before recording a call or meeting. The user is responsible for obtaining, documenting, and honoring participant consent in accordance with applicable law in their organization and the participants' locations.
Mesakem does not and will not use meeting content to train general AI models without explicit written consent.
How we use information
- To provide meeting and call summaries.
- To detect upcoming meetings from connected calendars.
- To send summaries to verified email recipients.
- To secure accounts, prevent abuse, and maintain audit logs.
- To improve reliability and support users.
Data sharing
We share data only with service providers needed to operate Mesakem, such as hosting, database, email delivery, transcription, summarization, and storage providers. We do not sell personal data.
For organizations that require a Data Processing Agreement (DPA) under GDPR, one is available upon request at support@mesakem.com.
Sub-processors
We use the following third-party service providers to operate Mesakem. All providers are selected based on security and privacy compliance:
| Provider | Purpose | Location | Compliance |
|---|---|---|---|
| Vercel | Application hosting | Global Edge | SOC 2 Type II, GDPR |
| Render | Background processing | EU (Frankfurt) | SOC 2 Type II, GDPR |
| Cloudflare R2 | File storage | EU | SOC 2 Type II, ISO 27001, GDPR |
| OpenAI | AI summarization (API only — does not train models) | USA | SOC 2 Type II, GDPR |
| Deepgram | Transcription | USA | SOC 2 Type II, GDPR |
| Neon / Databricks | Database | EU | SOC 2 Type II, GDPR |
| Recall AI | Meeting bot (Zoom/Teams/Meet) | USA | GDPR |
| Cardcom | Payment processing | Israel | PCI DSS |
| Telegram / Meta (WhatsApp) | Personal agent channels | Global | GDPR |
OpenAI and model training
Mesakem uses the OpenAI API only — not the consumer ChatGPT product. Under OpenAI's terms of service, data sent via the API is not used to train AI models. Your meeting content, transcripts, and summaries will not be included in AI model improvement or used for OpenAI product development.
Data location and international transfers
User data is primarily processed and stored in the European Union (Frankfurt, Germany). Some processing, such as transcription and summarization, is performed through US-based service providers.
Israel is recognized by the European Union as providing an adequate level of data protection, allowing data transfers between Israel and the EU without additional mechanisms.
Security
- Encryption in transit: All communications are protected with TLS/HTTPS.
- Encryption at rest: Files (recordings, summaries) are encrypted in Cloudflare R2 storage.
- OAuth tokens and connector credentials: Stored encrypted and never exposed in the user interface.
- Access controls: Data access is limited to required personnel only, under confidentiality agreements.
- Audit logs: Administrative actions on user data are logged.
Users should not share passwords, API keys, or other secrets via chat, email, or any unencrypted channel.
User choices
- Users can disconnect calendar connections from the dashboard.
- Users can choose verified summary recipient email addresses.
- Users can request deletion or support by contacting us.
Your rights
If you are located in the European Union, Israel, or other jurisdictions with similar privacy laws, you have the following rights:
- Access: Receive a copy of the data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your data.
- Data portability: Receive your data in a structured, machine-readable format.
- Objection: Object to certain processing of your data.
- Withdraw consent: Withdraw consent at any time.
To exercise your rights, contact support@mesakem.com. We will respond within 30 days.
Contact
For privacy questions or deletion requests, contact: support@mesakem.com
Mesakem is operated by Januar Technologies Ltd, registered in Israel, as required under the Israeli Protection of Privacy Law 5741-1981.