Skip to content

Security

What you say in a meeting stays yours.

Plain answers about what we keep, where it goes, and what we never do. This page describes the product as it works today; when that changes, this page changes first.

Last updated 5 October 2026

  • Only what you start

    Mindrunner records only when you press Record, and only the audio you choose. No bot joins your calls.

  • Your tap, every time

    Nothing reaches another person unless you approve it. The database itself enforces this.

  • Keep less, for less time

    Audio is deleted after 7 days. Anything else goes when you delete it.

  • Prove it

    Our accuracy tests are public, misses included, so you don't have to take our word for it.

What we keep, and for how long

Meeting audio
Encrypted, then deleted automatically 7 days after upload. In private mode on Mac, it never leaves your computer.
Transcripts and records
Until you delete the meeting. Deleting removes the transcript, record, share links and audio.
Email threads you forward
Read into a record like a meeting, and kept until you delete it.
Calendar link
Encrypted before it's stored, never shown again, and deleted with its events when you disconnect.
Your account
Your Google account id and verified email, to sign you in and send what you ask for.
Backups
Roll off within 7 days of a deletion.

How it's protected

Encrypted in transit and at rest. Every connection uses HTTPS. Audio, transcripts and records are stored encrypted on Google Cloud.

Walled off by the database. The tables that hold meetings, promises and agent actions use Postgres row-level security: every request runs as your workspace, and the database itself refuses rows that belong to anyone else.

Secrets sealed twice. A private calendar link works like a password, so we encrypt it again in our own code (AES-256-GCM) before storing it, and never send it back to your browser.

Signed or rejected. Payment events and forwarded email are checked by cryptographic signature before anything in them is read. Public links, sign-in and AI endpoints are rate-limited.

An audit trail. Changes to promises and meeting deletions are recorded in your workspace's audit log.

The background agent's limits

Mindrunner works through your promises in the background: heads-ups before they're due, drafts of what you promised, check-ins when someone else is late, and briefs before you meet again. It is built to be safe to leave running.

  • You choose how far it goes for each kind of work: off, suggestions, or ready-made drafts.
  • Every card shows the words it came from. No evidence, no card — the database won't store one.
  • Anything that would reach another person needs your approval. That's a rule in the database, not only a button in the app.
  • Drafts open in your own email, so they go from you, not from us.
  • What you do from a card can be undone, and it has a daily limit on how often it interrupts you.
  • It never guesses a person's name or email address. If it isn't sure who, it leaves a blank.

AI and your data

Your meetings are never used to train AI models: not by us, and not by the providers we use. We switch off Deepgram's model improvement on every request, and we use Google's paid Gemini API, which does not train on what we send.

What people say in a meeting is treated as words to understand, never as instructions to follow. Our public test includes calls where someone tries to give the AI orders, and we publish how it does. PromiseBench

The people you follow up with see only what you confirmed — decisions, promises and open questions — never the transcript or the audio.

Recording, openly

No bot joins your calls, so nothing appears in the attendee list. That makes it your job to tell people when the law or your workplace requires it, and to record only where you have the right to. Mindrunner is never built or marketed as hidden or undetectable.

Who processes data for us

Google Cloud & Firebase
Hosting, database, file storage and sign-in (United States)
Deepgram
Speech-to-text, with model training switched off on every request
Google Gemini (paid API)
Drafting meeting records from transcripts
Resend
Sending the emails you choose to send
Cloudflare
Receiving email threads you forward to Mindrunner
Paddle
Payments and tax, when you subscribe
PostHog
Product analytics without meeting content, autocapture or session recording

They process data only to provide these services to us. We don't sell data.

Where we are

Mindrunner is a young company in private beta. We don't have a SOC 2 report yet; we'll say so here the day we start an audit, not before. If your company needs a security review or a data processing agreement, tell us and we'll work through it with you.

Found a vulnerability? Reply to any email from Mindrunner and it reaches the founding team directly. Please give us a reasonable time to fix it before sharing it, and don't access other people's data while testing. We'll credit you if you'd like.

More detail: Privacy · Terms