Privacy Notice

Effective: August 27, 2026

This notice describes what data RT²M processes, what it does not store, where its servers run, and who has access.

Who handles your data

RT²M is operated by us at rt2m.app. For any data protection question, or if you want the data we hold about you deleted, write to hello@rt2m.app. Meetings are created and managed by the administrator of your own organisation; everyone in your organisation can see the email address and role of the other members on the team page.

What we store, and what we do not

We do not store meeting audio: the translation happens in the memory of the processing job, and in normal operation no audio file is written. The transcript, too, lives only for the duration of the meeting, in the same place. The service that relays the audio and data connection does not record the meeting either: by default it neither records nor stores media, and recording would require a separate service and a storage bucket configured by us — we use neither, and our code contains no call for it. The media stream travels over an encrypted channel (SRTP, with DTLS-SRTP key exchange). What we do store falls into four groups. First: the account you sign in with — your email address, your password if you sign in with one, and the identifier returned by Google or Microsoft if you sign in that way. Second: your organisation details — its name, plan, quota, terminology glossary, the company email domains registered to it, the email address and role of every member, and quota top-up and plan change requests together with the note written on them. Third: the metadata of your meetings — the meeting identifier and its optional title, who created it, which languages appeared in it, when it started, how long it lasted, and how many minutes you used; without the content of the conversation. Fourth: whatever you send us yourself — feedback, a contact request or a quote request, with the message, email address, phone number, company name and job title you put in it. Two things we spell out separately, because they may be surprising. If you give your email address in order to see prices, we store it on its own — simply because you looked at the prices. And alongside a message you send us we keep which page and which meeting it came from, and if you are signed in, your account email address is attached even when you did not type it. The name, email address and language you give when joining travel inside the join token issued to the service that relays the connection. On the public demo and on the quote request we use your IP address to limit abuse: it is counted in memory only and may appear in the server log, but it does not go into the database.

Where our servers run

The database and the authentication run in Germany, in Frankfurt (the eu-central-1 region). Our own server, which runs the translation agent and the dispatcher, is also in Germany, in Nuremberg. The website is served by an external hosting provider, and the application runs on EU servers. The service that relays the audio and data connection of the meeting, and the AI services that do the speech recognition, the translation and the summary, do not run on our infrastructure, and we do not choose where they are located. Which provider does which job, and where it runs, is listed by name on our subprocessors page.

Who we pass data to (processors)

To run the service we use subcontractors — processors. Their categories: relaying the audio and data connection of the meeting; speech recognition, translation and producing the meeting summary; running the database and the sign-in; serving the website; delivering account email (signup confirmation, password reset, invitation) and the meeting summaries; signing in with an external account; and finally page-view analytics, plus the visitor analytics that loads only with your consent. We do not list them by name in this notice, because the list can change: we keep it on a separate page, where every provider is shown together with what it does for us and where it runs.

How long we keep it

Audio: we do not keep it. Transcript: at the end of the meeting — once the summary has been generated and sent — we delete it and the process exits; it never reaches a database or a file. A copy of the summary also stays in the Sent folder of our own sending mailbox, with the meeting summary in the body of the email; that copy is deleted automatically after 5 days. Account, organisation, meeting and usage data, and the message you send us, currently have no automatic deletion deadline: we keep them for as long as we need them to run the service and to account for your quota, or until you ask us to delete them.

Your rights

You can ask for a copy of the data we hold about you, ask us to correct it, or ask us to delete it — write to hello@rt2m.app. The meeting summary reaches only those who gave an email address when joining; if you give none, you receive no email. Your cookie decision is valid for one year; to change it, delete the rtm_consent cookie from your browser.

Cookies and what stays in your browser

Three kinds of cookie come from us: rtm_consent keeps your cookie decision for one year, rtm_locale keeps the language you chose, also for one year, and the sign-in cookies keep your session alive. The visitor analytics script loads only if you click accept on the banner — never before that; once it has loaded, it sets cookies of its own in your browser. Page-view analytics runs on every page, regardless of the answer you gave on the banner. Your local browser storage keeps the name and email address you last entered, the audio mode you chose and the currency — those stay on your device and never reach us.

Subprocessors: who does what for us, and where it runs →

Privacy Notice — RT²M