← Back

Privacy policy

Last updated: 21 March 2026

1. Who we are

Intonation Labs Pte. Ltd. (“we”, “us”) operates IntoMeeting (the “Service”). We are incorporated in Singapore. We aim to handle personal data in line with the Singapore Personal Data Protection Act 2012 (PDPA). Where users are in the European Economic Area, the GDPR may also apply.

Privacy enquiries: info@intonationlabs.com

2. Data we collect

  • Account: Email, display name, identifiers from email/password or single sign-on.
  • Meeting audio: When you start capture, audio may be streamed for real-time transcription and AI features. Retention depends on our architecture (often processed in real time; confirm in your deployment docs).
  • Transcripts and AI output: Text from speech, AI suggestions, summaries, notes, and similar artefacts stored in your workspace.
  • Knowledge base: Documents or text you upload for retrieval during meetings.
  • Usage and technical data: Logs, diagnostics, and usage metrics to run and secure the Service.
  • Billing: If you subscribe, payment data is handled by our payment processor; we typically receive limited billing metadata, not full card numbers.
  • Local storage: Preferences (e.g. theme) may be stored in your browser.

3. How we use data

  • Provide transcription, AI assistance, meeting history, search, and sharing features you request.
  • Authenticate users, enforce limits, billing, and security.
  • Send service-related messages (e.g. verification, receipts) and optional product emails if you opt in.
  • Comply with law and protect rights.

We do not sell your personal data. We do not use your meeting transcripts or knowledge documents to train shared or public AI models for advertising or unrelated purposes. Third-party cloud and model providers process data on our instructions to operate the Service—see Section 6.

4. AI processing and accuracy

The Service uses automated processing, including machine learning models, to generate transcripts, suggestions, summaries, and similar output. Output may be wrong or incomplete; you should verify important information. This processing is part of delivering the Service, not an automated decision with legal or similarly significant effects about you in the GDPR sense. For your responsibilities when relying on AI output, see our Terms of Service (Section 8 — AI-generated outputs).

Transparency (including EEA users): When you use live transcription, AI answers, summaries, meeting prep, coaching tips, or similar features, you are interacting with an automated system that generates content. It is not a human and may produce errors; you should treat outputs accordingly.

5. Legal bases (EEA users)

Where GDPR applies, we rely on:

  • Contract: Providing the Service you signed up for.
  • Legitimate interests: Security, abuse prevention, and service improvement, balanced against your rights.
  • Consent: Where required for optional communications or non-essential cookies—you may withdraw consent.
  • Legal obligation: Where the law requires processing.

6. Processors and transfers

We use subprocessors (e.g. cloud hosting, authentication, speech and language APIs, payments, optional web search). They receive only what is needed to provide the Service and are bound by appropriate agreements.

Data may be processed in countries other than yours. Where required, we use safeguards such as Standard Contractual Clauses for transfers from the EEA/UK.

7. Retention

  • Meeting artefacts: until you delete them or delete your account, unless we must retain longer for law.
  • Account data: while the account exists; deleted or anonymised within a reasonable period after deletion.
  • Billing records: as required for tax and accounting law.

8. Your rights

Depending on your location, you may have rights to access, rectify, delete, port, or restrict processing, and to object or lodge a complaint with a supervisory authority. To exercise rights, contact info@intonationlabs.com. Where the app offers export or account deletion, you may also use those controls.

9. Security

We use technical and organisational measures appropriate to the risk, such as encryption in transit, access controls, and secure authentication. No method of transmission or storage is perfectly secure.

10. Children

The Service is not directed at children under 16. If you believe we have collected a child's data, contact us and we will take steps to delete it.

11. Changes

We may update this policy. We will post the new version and, for material changes, provide notice (e.g. email or in-app) where appropriate.

12. Contact

13. Cookies and similar technologies

Besides traditional HTTP cookies, we use similar browser technologies such as local storage and IndexedDB to run the app (for example to keep you signed in and to store UI preferences when you allow it). The table below summarises the main technologies by category. Where the law requires consent for non-essential use, we ask you on first visit and you can change your mind anytime: use Settings → Data & Privacy → Cookie preferences when signed in, or open this section from the marketing site footer (Cookie settings).

Reject non-essential turns off optional preference storage (e.g. theme) and optional crash diagnostics on this device, without disabling core sign-in or security features.

Technology / storagePurposeProviderTypical durationCategory
Firebase Auth sessionAccount sign-in and API authenticationGoogle (Firebase)Session / as configured by FirebaseStrictly necessary
Firebase App Check / reCAPTCHAAbuse prevention when App Check is enabledGooglePer Google / sessionStrictly necessary (where required for access)
Theme key (localStorage)Remember light/dark/system/stealth appearanceIntonation Labs Pte. Ltd.Until cleared or consent withdrawnFunctional (opt-in)
Cookie consent recordStore your choices for this siteIntonation Labs Pte. Ltd.Until cleared or updatedStrictly necessary
Sentry (client SDK)Error and performance diagnostics when DSN is configuredFunctional Software, Inc. (Sentry)Per Sentry session / policyAnalytics / monitoring (opt-in)
Google OAuth / Stripe (checkout)Sign-in with Google or payments when you use those flowsGoogle / StripePer provider policyStrictly necessary for that flow

Cookies and storage

We use strictly necessary storage to run the service (sign-in, security). With your permission we also save interface preferences and send optional error diagnostics. See how we use cookies.

Privacy — IntoMeeting