Privacy policy
Last updated: 16 September 2026
This policy explains what merme collects, why, where it is stored, who processes it on our behalf, and the rights you have. It applies to merme.ai, meet.merme.ai and app.merme.ai and to every merme product. We wrote it to be read, not skimmed.
1. Who is responsible
The data controller is merme (“merme”, “we”), Tbilisi, Georgia. For anything in this policy, write to support@merme.ai.
2. What we collect
Account data — your name, email address and profile picture from your Google account, and the workspace you belong to.
Calendar data — upcoming events that contain a Google Meet link: title, start and end time, attendee emails and the link. Events without a Meet link are not stored.
Meeting content — the audio of meetings the merme bot joins, captured by our bot vendor; the transcript and the structured notes produced from it; the speaker timeline (who spoke when).
Contact-form leads — the email address and any name, company or message you leave on our contact page.
Billing — the hour package you buy and a payment token from our payment provider. We never see or store card numbers.
Technical — server logs with IP addresses and user agents, kept for security and debugging.
3. Google user data
merme uses Google Sign-In and the Google Calendar API. We request the Calendar read-only scope to find meetings with a Meet link and join them at the right time. We read event titles, times, attendees and Meet links; we never write to your calendar, never read events without a Meet link beyond what is needed to skip them, and never access your email, contacts or files.
merme's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google data is never used for advertising, never sold, never used to train AI models, and is read by a person only with your explicit consent for support, or where the law requires it. You can revoke access at any time from your Google Account permissions page — see the Help page.
4. Why we use it, and on what basis
To provide the service you signed up for (contract): signing you in, syncing your calendar, joining meetings, producing and storing notes, billing.
With your consent: the bot joining your meetings, storing a contact-form lead, and any support access to your content.
Legitimate interest: securing the service, preventing abuse, and improving reliability using aggregate, non-content metrics.
5. Where your data lives
Our servers and database run in the European Union. Data is encrypted in transit (TLS) and at rest. Meeting audio is held by our bot vendor only as long as needed to process it, then deleted; we keep only text.
6. Who processes data for us
We use a small set of subprocessors, each under a data-processing agreement: Google (sign-in, Calendar API, Workspace email), MeetStream.ai (the meeting bot and short-term audio storage), our speech and summarization service (transcription and notes), Fly.io (application hosting, EU), Neon (database, EU), Vercel (web hosting), Cloudflare (DNS), Resend (transactional email, EU), Flitt (payments). We do not sell data and we do not share it with anyone else.
7. Not used for training
Your meeting content, notes and calendar data are never used to train AI models — ours or anyone else's.
8. How long we keep it
Account data: while your account exists. Calendar events: until the meeting is past and processed, then only the meeting record. Notes and transcripts: while your workspace keeps them; you can delete a note at any time. Contact-form leads: up to 12 months. Server logs: 30 days. Deleting your account removes everything you own within 30 days, except records the law requires us to keep (invoices).
9. Your rights and how to exercise them
Under the Law of Georgia on Personal Data Protection and, for users in the European Union, the GDPR, you can access the data we hold about you, correct it, export it (notes download as Markdown), restrict or object to processing, withdraw consent, and have your data deleted. To exercise any of these, email support@merme.ai from your account address; we respond within 30 days. You may also complain to the Personal Data Protection Service of Georgia or your local supervisory authority.
10. Meeting participants
When the merme bot joins a meeting it is visible in the participant list. The Host who invited it is responsible for telling participants the meeting is recorded, as local law requires. If you attended a recorded meeting and want your name removed from a transcript, write to us.
11. Cookies
merme uses one session cookie to keep you signed in and one to remember your language. No advertising or cross-site tracking cookies.
12. Changes
We update this policy when the service changes and note the date at the top. Material changes are announced in the app and by email.
Questions about this policy: support@merme.ai