Sumnote: Privacy Policy
Last updated: July 13, 2026 · Effective date: July 13, 2026
Sumnote Inc. (“Sumnote,” “we,” “us,” or “our”) provides an AI-powered meeting-intelligence service that records and transcribes meetings and turns them into structured updates to your project-management workflow. This Privacy Policy explains what personal information we collect, how we use and protect it, who we share it with, and the choices and rights you have.
This policy applies to our website, web application, meeting bots, and related services (together, the “Service”). It is written to meet our obligations under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec’s Act respecting the protection of personal information in the private sector (as amended by Law 25), applicable U.S. state privacy laws, and Australia’s Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It is also designed to reflect the requirements of U.S. state biometric-privacy laws that apply to voiceprints (see Voiceprints).
Sumnote Inc. is a company incorporated in Ontario, Canada, and is the organization responsible for your personal information. Our data is hosted in the United States (see International data transfers).
Sumnote’s Privacy Officer, the person in charge of the protection of personal information, is reachable at privacy@sumnote.com. Contact them with any question about this policy or to exercise a privacy right.
1. Who this policy covers
- Account holders and their team members (“users”): the people who sign up for and use Sumnote.
- Meeting participants who are not Sumnote users (“guests”): people whose voice and words are captured because a Sumnote user recorded a meeting they were in. Protections specific to guests appear throughout this policy: in Recording meetings, Voiceprints, and Improving Sumnote and training our models.
2. Information we collect
Information you give us
- Account information: your name, email address, password (stored only in hashed form), and workspace/team details.
- Profile and settings: your preferences, including your consent choices and your declared country and (for the US and Canada) state or province of residence, which you select when you sign up.
- Billing information: if you subscribe to a paid plan, our payment processor (Stripe) collects your payment details. Card numbers are handled directly by Stripe and never touch Sumnote’s servers. We receive your billing email, billing address, tax ID, and transaction history.
- Content you create or upload: projects, tasks, comments, and files, and any meeting recordings or transcripts you create or upload.
Meeting information
- Meeting audio captured when you record a meeting (whether by adding our meeting bot to a call, by recording a call through your browser, or by recording an in-person meeting with your device’s microphone). Meeting audio and transcripts can include the voices and words of guests, people who are not Sumnote users.
- Transcripts generated from that audio, and the action items, decisions, and summaries our system extracts from them.
- Voiceprints (biometric information): only if you, or a guest, separately and affirmatively consent. See Voiceprints below for the full treatment; this is the most sensitive category of data we handle and it is governed by its own rules.
Information collected automatically
- Usage and activity data: how you and your team interact with the Service (for example, creating, editing, completing, or reviewing tasks and meetings). We use this to operate the Service and, where you allow it, to improve it.
- Device and technical data: IP address, browser and device type, and similar technical information. We use your IP address to: pre-fill your residence on the sign-up form; flag, on an advisory basis, when your declared residence appears inconsistent with where you are connecting from; recognize returning devices and detect suspicious sign-ins as part of account security (approximate location is derived from a locally hosted geolocation database; your IP address is not sent to the geolocation provider for this); and maintain ordinary security and infrastructure logs. Your IP address never determines what features you can use; only the residence you declare does.
- Cookies: see Cookies below.
3. How we use your information
We use personal information to:
- Provide the Service: create and manage your account; record and transcribe your meetings; extract action items, decisions, and summaries; and update your project-management workflow.
- Recognize speakers, only with separate consent, by comparing voices in a meeting against stored voiceprints of people who have consented, so that statements and tasks are attributed to the right person (see Voiceprints).
- Communicate with you: send service messages such as sign-up confirmations, password resets, billing notices, and notifications. We send marketing messages only where permitted, and you can unsubscribe at any time.
- Improve Sumnote and train our own models, where this applies to you and you have not opted out, using activity data and meeting content, with direct identifiers removed (see Improving Sumnote and training our models).
- Keep the Service secure and accountable: detect, investigate, and prevent fraud, abuse, and security incidents, and maintain audit records of consent decisions and of access to and changes in sensitive data.
- Comply with law: meet our legal obligations and respond to lawful requests.
Legal basis and consent. We collect and use personal information with your consent and as reasonably necessary to provide the Service you have asked for. For sensitive information, which includes biometric information such as voiceprints, we rely on your separate, express, opt-in consent, and we collect it only where it is reasonably necessary for the speaker-recognition feature. You can withdraw consent at any time (see Your rights and choices).
4. Recording meetings
Sumnote lets you record meetings in three ways: by adding the Sumnote AI bot to a virtual call; by capturing a virtual call’s audio through your browser; or by recording an in-person meeting with your device’s microphone. In each case the recording is initiated by you.
You are responsible for telling the other people in the meeting that it is being recorded and for obtaining any consent the law requires in the places where the participants are located. Recording-consent laws differ by jurisdiction: some require that everyone in the conversation consents. When you start a recording through your browser or your device’s microphone, Sumnote displays a reminder of this before recording begins; the responsibility remains with you. The specific terms governing it are set out in our Terms of Service.
Where our bot joins a virtual call, it appears as a visible participant named “Sumnote AI,” and the calling platform may show its own “recording in progress” indicator. Where you record through your browser or your device microphone, there is no bot, so it is especially important that you inform participants yourself.
5. Voiceprints (biometric information)
Speaker recognition is optional, off by default, and governed by the strictest protections in this policy. A voiceprint is a mathematical representation of a person’s voice used to recognize that person across meetings. It is biometric information and, in some places, sensitive information under law. We treat it accordingly.
We never enroll or store a voiceprint without separate, affirmative consent.
- Voice recognition is a distinct opt-in, separate from any other setting. Turning it on requires a deliberate, affirmative choice, recorded with a timestamp (and the version of the consent language you agreed to) in an append-only consent record. Turning off any other feature, or opting out of model training, has no effect on it, and vice-versa.
- A workspace must enable the feature, and the individual must consent, before any voiceprint is stored.
How speaker matching works. When speaker recognition is active for a meeting, our system briefly analyzes the voice of each speaker in the recording in order to compare it against the stored voiceprints of people who have consented. These comparisons are transient computations performed within our own systems: they are not retained, and no voiceprint is stored for anyone who has not consented; speakers who don’t match a consented voiceprint simply appear as unnamed speakers.
Where the feature is available. Because of biometric-privacy laws, voiceprints are enrolled and stored only for people who tell us they reside in the United States (excluding Illinois), Canada (excluding Quebec), or Australia. We determine this from the residence you declare, not from your IP address. If you are outside those regions, the Service still works; speaker recognition simply does not store a voiceprint for you, and you appear as an unnamed speaker.
Your declared residence. You select your country (and, for the US and Canada, your state or province) when you sign up. To change it later, contact us at privacy@sumnote.com or through in-app support and we will update it for you. If your declared residence changes to a region where voiceprints aren’t offered, any voiceprint we hold for you is deleted and the related consents are revoked, and that change is recorded in your consent history.
Guests. If a Sumnote user identifies someone in a meeting who is not a Sumnote user, we email that person a request for consent before any voiceprint is stored. The request names the specific meeting it concerns, and the person can decline, including by indicating they were not in that meeting. No voiceprint is enrolled or stored unless and until that person affirmatively consents and confirms they took part in the meeting. A short excerpt of the meeting audio is held only to create the voiceprint after consent; it is deleted as soon as the guest responds (or the request expires; consent requests expire after 30 days), and in any case within 30 days. The residence a guest declares in the consent flow is subject to the same regional limits as for users. A guest’s voiceprint is used only in the workspace where they gave consent, and nowhere else.
How voiceprints are protected and kept.
- Voiceprints are encrypted at rest (AES-256-GCM) using versioned encryption keys that support key rotation, and are stored in a separate database from the rest of your data.
- A voiceprint is automatically deleted after 18 months without being recognized in a meeting, and when you withdraw consent or delete your account.
- You can delete an individual enrolled voice sample at any time (your voiceprint is then rebuilt from your remaining samples), or withdraw consent entirely, which deletes your voiceprint.
We never sell voiceprints, never share them with third parties for their own purposes, and never use them to train any third party’s models.
6. Improving Sumnote and training our own models
We use activity data and meeting content to improve the Service and to train our own narrow models (for example, to better recognize who a task should be assigned to). We do not use this data to train any third party’s models, and we do not sell it.
Where this applies. Training uses data only from people who tell us they reside in the United States (including Illinois, Texas, and Washington) or in Canada excluding Quebec. The training regions are not identical to the voiceprint regions: Illinois is included for training but excluded from voiceprints (its biometric law restricts voiceprints, not training on ordinary work text) while Australia is the reverse, included for voiceprints but not for training. For people in those regions, this is on by default, and you can opt out at any time. For everyone else (including residents of Quebec and Australia), training is off by default and your data is not used for training. Opting out does not affect how the product works; it only stops your data from being used for improvement and training. This is a separate choice from voice recognition.
Meetings can include people who are not Sumnote users. Meeting content used for training can include things said by guests. Account holders are responsible for informing participants that a meeting is recorded and processed (see our Terms of Service), and any guest may contact us at privacy@sumnote.com to object to our processing of their information; we will respond to such requests as required by applicable law.
What we do to limit what’s in the training data.
- Direct identifiers are removed. Before any content is stored for training, we automatically strip out email addresses and phone numbers. We are honest that this is redaction, not full anonymization: names spoken in a meeting and the substance of what was discussed may remain, because resolving who is being referred to is part of what these models are designed to learn.
- Our trained models produce structured signals (a suggested assignee, a risk score, a predicted date) rather than free-form text shown to other users, which limits the ways one customer’s information could surface to another.
- We exclude data we shouldn’t train on. Internal/staff accounts, people in regions we don’t train on, and anyone who has opted out are excluded, and the exclusion is applied every time a training set is produced, so it also holds if a setting was ever wrong.
- Where training happens. Training runs on a specialist GPU provider (RunPod) in the United States, which only ever receives the redacted training set described above, never audio, and never voiceprints.
When you opt out or delete your account. You are excluded from all future training sets immediately, and your captured data is erased from our training-capture systems. Each training set is a full snapshot rebuilt from current data, and we keep only the most recent one or two, so any copy of your data in a previously exported set is deleted at the next refresh, before it would be used to train a new model. Models that have already been trained encode aggregate patterns and cannot be made to individually “un-learn” a person, but the underlying data is deleted as described.
7. How we share information: sub-processors
We do not sell your personal information. We share it only with service providers (“sub-processors”) who process it on our behalf to run the Service, under terms that require them to protect it and use it only for the services they provide to us. We maintain a current list of sub-processors and give customers advance notice (at least 30 days where practicable) before adding a new one.
Always-on sub-processors (process data for every customer):
| Provider | Purpose | What they process | Location |
|---|---|---|---|
| Amazon Web Services | Cloud infrastructure and storage | All customer data (account, meeting audio, transcripts, files) | United States |
| Anthropic | AI extraction of action items, decisions, summaries | Meeting transcripts (text only) | United States |
| OpenAI | Backup speech-to-text transcription; backup extraction | Meeting audio (transcription); transcripts (extraction) | United States |
| AssemblyAI | Primary speech-to-text transcription | Meeting audio | United States |
| RunPod | GPU compute for training Sumnote's own models | The redacted training set only (identifiers stripped; no audio; no voiceprints) | United States |
| Google (Gmail SMTP) | Outbound email | Recipient email address and message content | United States |
| Google (Firebase Cloud Messaging) | Push notifications | Device push tokens and notification previews | United States |
Conditional sub-processors (only in the stated circumstances):
| Provider | Activates when | What they process |
|---|---|---|
| Google (Workspace APIs) | You sign in with Google or connect Google Calendar / Meet | Authentication tokens; calendar events you sync; meeting metadata |
| Zoom | You connect your Zoom account | Authentication tokens and meeting metadata. The call itself is handled by Zoom as your meeting platform, under Zoom's own terms |
| Stripe | We launch paid plans and you subscribe | Billing details and transaction history (card data handled by Stripe directly) |
We use AssemblyAI for speech-to-text only; voiceprints are computed within our own systems, not by AssemblyAI. We do not use any analytics provider that tracks you inside the application.
The most current sub-processor list is published at /legal/subprocessors.
Google user data and Limited Use
When you sign in with Google or connect Google Calendar or Google Meet, Sumnote accesses a limited set of Google user data: your basic profile and email address (to identify your account), the calendar events within a bounded window that we sync with your Sumnote meetings, and the Google Meet links we create at your request. We use this data only to provide those features to you.
Limited Use. Sumnote’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data for advertising, we do not sell it, we do not allow humans to read it except with your consent, for security, or to comply with law, and we do not use data obtained through the Google Calendar or Google Meet scopes to develop, improve, or train generalized or non-personalized AI or machine-learning models.
8. International data transfers
Sumnote is operated from Canada, and our infrastructure and sub-processors are located in the United States. If you are in Canada or Australia, your personal information will be transferred to, and processed in, the United States and other countries where our sub-processors operate.
We take reasonable steps to ensure that anyone who processes your personal information overseas protects it consistently with this policy and with applicable law, and we remain accountable for it. Where required, transfers are made under appropriate contractual safeguards. By using the Service, you understand that your information will be handled as described in this policy in those locations.
For individuals in Australia: the overseas recipients of your personal information are located in the United States, as set out in How we share information above (APP 8).
9. How long we keep information
We keep personal information only as long as needed for the purposes described in this policy, then delete or de-identify it. Key periods:
| Data | Retention |
|---|---|
| Account information | For the life of your account. Account deletion has a 30-day grace period (see below), after which the account is permanently deleted |
| Meeting audio, transcripts, and content | Deleting content removes it from your workspace immediately; the underlying data is retained until your account is deleted |
| Voiceprints | Auto-deleted after 18 months of not being recognized in a meeting; deleted on consent withdrawal and account deletion |
| Pre-consent guest voice excerpt | Deleted as soon as the guest responds or the request expires, and in any case within 30 days |
| Short per-speaker audio clips created during processing | Deleted after 30 days |
| Training data (raw captured activity) | Deleted after 24 months once exported; excluded from future training sets and erased on opt-out or account deletion |
| Exported training sets | Only the most recent one or two snapshots are kept; superseded snapshots (and any opted-out or deleted data in them) are deleted at the next refresh |
| Consent records | Retained in an append-only ledger for as long as necessary to evidence consent decisions under applicable law |
| Encrypted backups and storage version history | Aged out on a rolling schedule |
Deleting your account. When you request account deletion, your account enters a 30-day grace period: if you sign back in during that time, the deletion is cancelled automatically, and we send a reminder about a week before it becomes final. After the grace period, your account is permanently deleted, and the data listed here (your voiceprint, your audio and speaker clips, your personal content, and your captured training data) is removed from our operational systems. Some information may persist for a limited time in encrypted backups and storage version history, which age out as above.
10. Your rights and choices
Subject to applicable law, you can:
- Access the personal information we hold about you.
- Correct information that is inaccurate or out of date, including your declared residence, which we will update on request.
- Delete your information, including by deleting your account.
- Withdraw consent: turn off voice recognition (deleting your voiceprint), or opt out of model training, at any time, without affecting how the product works.
- Object to or restrict certain processing.
- Complain to us or to a regulator (see Contact and complaints).
We provide a consent record (“Consent Evidence Pack”) on request, documenting your consent choices and their history (including the version of the consent wording in effect at each decision), available for both users and guests.
How to exercise your rights. Many choices (voice recognition, training opt-out, deleting samples, deleting your account) are available directly in your settings. For anything else (including changing your declared residence), email privacy@sumnote.com. We will verify your identity and respond within the time required by law (within 30 days under PIPEDA; without unreasonable delay under the APPs). We do not charge for reasonable requests. If we refuse a request, we will explain why, and you may ask us to reconsider (see also Additional information for United States residents).
Guests who were sent a voice-consent request can manage or remove their voiceprint at any time using the link in that email or at https://app.sumnote.com/consent/manage, or by emailing us. Guests can also object to any other processing of their information by emailing privacy@sumnote.com.
11. Additional information for United States residents
Depending on your state, you may have rights to access, correct, delete, and obtain a copy of your personal information, and to opt out of the sale of personal information, the sharing of personal information for cross-context behavioral advertising, targeted advertising, and certain profiling. Sumnote does not sell personal information and does not share it for targeted or cross-context behavioral advertising, so there is nothing to opt out of on that front. We do not discriminate against you for exercising a privacy right.
You can exercise your rights through your settings or by emailing privacy@sumnote.com, including through an authorized agent where your state’s law provides for one. If we decline a request, you may appeal by replying to our response or emailing privacy@sumnote.com with “Appeal” in the subject line; we will respond to appeals within the period your state’s law requires. Voiceprint handling for residents of states with biometric-privacy laws is described in Voiceprints above.
12. How we protect your information
We use technical and organizational safeguards appropriate to the sensitivity of the data, including:
- Encryption in transit (TLS) for data moving between your device and the Service.
- Encryption at rest for file storage and backups; voiceprints and other embeddings are additionally encrypted at the application layer (AES-256-GCM) with versioned keys and stored in a separate database.
- Access controls: role-based access, restricted network access (internal services are not reachable from the internet), and a separate, two-factor-protected authentication system for administrative access.
- Audit logging: an append-only audit trail records access to sensitive data (who viewed, downloaded, exported, changed, or deleted what) and administrative and authentication events, so access can be reviewed; consent decisions are recorded in their own append-only ledger.
- Account protections: passwords stored only as salted hashes, optional two-factor authentication, and active-session management that lets you review and revoke your signed-in sessions.
No system is perfectly secure, but we work to protect your information and to detect and respond to incidents. If a data breach occurs that creates a real risk of significant harm (Canada) or is likely to result in serious harm (Australia), we will notify affected individuals and the relevant authority as required by law, including under Australia’s Notifiable Data Breaches scheme.
13. Cookies
Within the application we use only the cookies needed to sign you in and keep you signed in: a session cookie and, if you choose “remember me,” a persistence cookie. We do not use third-party advertising or tracking cookies inside the application. Our marketing website may use limited cookies, described in the notice presented there.
14. Children
Sumnote is not intended for anyone under 18, and we do not knowingly collect personal information from children. If you believe a minor has provided us personal information, contact us and we will delete it.
15. Changes to this policy
We may update this policy from time to time. If we make a material change, we will notify you (or your account’s administrators) and update the “Last updated” date above. For changes that affect a consent you have given, we will seek your renewed consent where required.
16. Contact and complaints
Sumnote Inc., 52 Mabelle Avenue, Etobicoke, Ontario M9A 4X9, Canada. For any question about this policy, or to exercise a privacy right, reach us using the form below, or email privacy@sumnote.com.
If you have a privacy concern, please contact us first; we want to resolve it. You also have the right to complain to a privacy regulator:
- Canada, Office of the Privacy Commissioner of Canada (OPC): www.priv.gc.ca
- Quebec, Commission d’accès à l’information du Québec (CAI): www.cai.gouv.qc.ca
- Australia, Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au
- United States, your state Attorney General