Privacy Policy.
Last updated: May 2026
TymitHub is a meeting recording and transcription platform built around data sovereignty. This policy explains what data we collect, how we use it, and the rights you have over your information.
Data we collect
- Email address and account credentials (registered organisers)
- Meeting audio recordings and transcriptions (stored on your plan's infrastructure — see below)
- Participant names (provided voluntarily at meeting join)
- Meeting metadata: title, date, duration, language, participant count
- Security and audit logs: login timestamps, IP addresses, actions performed
How we use your data
- To generate meeting transcripts and AI-drafted minutes
- To authenticate users and manage access to your organisation's account
- To enforce data retention policies you configure
- To send transactional emails (verification, account deletion confirmations)
- To detect and prevent fraudulent or abusive use of the platform
Where your data lives
Where your data lives depends on your plan. Free and Starter plans use TymitHub's shared managed infrastructure — your data is logically isolated from other organisations, encrypted at rest and in transit, and hosted in EU data centres. Business plans include a dedicated managed server for hardware-level isolation. Enterprise plans support fully self-hosted deployment on infrastructure you control, so meeting content never leaves your environment. Regardless of plan, the SaaS layer (account and authentication data) always runs on TymitHub's secure servers. Meeting content is never sold or used for advertising. When AI minutes generation is enabled, transcripts are sent to Anthropic's API and are subject to Anthropic's privacy policy.
Infrastructure security by plan
TymitHub provides increasing levels of data isolation as you move up plans — so your security posture can match your organisation's compliance requirements.
Free & Starter
Shared managed EU infrastructure. Your data is logically isolated from other tenants, encrypted at rest (AES-256) and in transit (TLS 1.3). Shared hardware with strict access controls and no cross-tenant data access.
Business
Dedicated managed server. Your organisation's recordings, transcripts, and minutes reside on hardware reserved exclusively for you. No shared tenancy at the storage layer.
Enterprise
Full data sovereignty. Deploy TymitHub on servers you own — your data centre, private cloud, or air-gapped environment. Meeting content never leaves infrastructure you control.
All plans
Encrypted backups, regular third-party security audits, EU data residency, and a strict no-advertising policy on your meeting content.
Retention and deletion
Meeting data is retained on your org server according to the retention window you configure (default: 12 months). Account data held by the SaaS layer is deleted within 30 days of an account deletion request, which you can initiate from Account Settings. Audit logs may be retained for up to 24 months for security and compliance purposes.
Your rights under GDPR
- Right of access — request a full export of your data at any time from Account Settings
- Right to erasure — request account deletion; data is purged within 30 days
- Right to rectification — update your profile and organisation data at any time
- Right to restrict processing — contact us to restrict specific processing activities
- Right to portability — data exports are provided in machine-readable JSON format
- Right to object — you may object to processing not strictly necessary for service delivery
Cookies and tracking technologies
TymitHub uses a small number of cookies. The table below describes each category, its purpose, and whether your consent is required.
| Category | Name | Purpose | Consent |
|---|---|---|---|
| Essential | tymithub_cookie_consent | Stores your cookie consent choice so we do not ask again for 12 months. | Not required |
| Essential | Session / CSRF tokens | Keep you signed in and protect against cross-site request forgery attacks. | Not required |
| Analytics (inactive) | Google Analytics | Measures traffic and navigation behaviour to help us improve the product. Will only be loaded after your consent. | Required — not yet active |
| Marketing (inactive) | Meta Pixel | Tracks conversions and enables remarketing on Meta platforms. Will only be loaded after your consent. | Required — not yet active |
Contact & complaints
For any privacy-related request, contact us at privacy@tymithub.com. If you believe your rights have been violated, you may lodge a complaint with your national data protection authority.
Questions about privacy?
Our team responds to all personal data requests.