Legal
Privacy Policy
Your meeting data is among the most sensitive information you produce. This policy explains exactly what we collect, why we collect it, and how we protect it.
Last updated: February 2026
1. Information We Collect
We collect information that is necessary to provide and improve the Karnyx service. Here is a clear breakdown of what we collect and why.
Account Information
When you create an account, we collect your name, email address, and organization name. If you subscribe to a paid plan, our payment processor (Stripe) handles your billing information directly. We never store credit card numbers on our servers.
Meeting Audio and Transcripts
When you use Karnyx to capture a meeting, we process the audio to generate transcripts, summaries, action items, and other AI-derived insights. Audio may be processed locally on your device or transmitted to our servers for transcription, depending on your settings and plan.
Calendar Data
If you connect your calendar, we access event titles, times, participants, and meeting links. This allows Karnyx to automatically prepare context before meetings and associate recordings with the correct events. We do not access the content of calendar event descriptions unless you explicitly enable that feature.
Usage Data
We collect anonymized usage analytics to understand how the product is used and where to invest in improvements. This includes which features are accessed, session duration, and error reports. We do not track your meeting content for analytics purposes.
2. How We Use Your Data
- To provide the core service: transcription, summaries, action item extraction, and people-indexed meeting memory.
- To improve AI accuracy and reliability using aggregated, anonymized patterns. Your private meeting content is never used to train models.
- To send you service-related communications such as onboarding guides, feature updates, and security notifications.
- To detect and prevent abuse, fraud, and security threats.
- To comply with legal obligations when required by law.
3. Local-First Processing
Karnyx is designed with a local-first philosophy. Audio capture and initial processing happen on your Mac whenever possible. This means your raw audio data stays on your device by default and is only transmitted to our servers when cloud-based transcription or AI features require it.
When cloud processing is required, audio is transmitted over an encrypted connection, processed, and then deleted from our transcription servers. We do not retain raw audio on our infrastructure beyond the time needed to generate your transcript, unless you explicitly choose to store recordings in the cloud.
4. Data Storage and Encryption
All data stored on our servers is encrypted at rest using AES-256 encryption. All data transmitted between your device and our servers is encrypted in transit using TLS 1.3.
Encryption keys are managed through a dedicated key management service with automatic rotation. Database backups are encrypted with the same standard. At no point does your data exist in an unencrypted state on our infrastructure.
Our infrastructure is hosted on AWS with data centers in the United States. We implement network-level isolation, intrusion detection, and continuous monitoring across all production systems.
5. Third-Party Services
To deliver the Karnyx service, we work with a small number of trusted third-party providers. Each has been evaluated for their security practices and data handling policies.
- Deepgram: Speech-to-text transcription. Audio is processed and not retained after transcription is complete.
- OpenAI / Anthropic: AI-powered summaries, action items, and meeting insights. We send transcript text (not audio) and do not permit these providers to use your data for model training.
- Stripe: Payment processing. We never see or store your full credit card number.
- AWS: Cloud infrastructure, database hosting, and file storage.
We do not sell, rent, or share your data with advertisers or data brokers. Third-party access is limited strictly to what is needed to operate the service.
6. Data Retention and Deletion
We retain your meeting data for as long as your account is active or as needed to provide the service. Organizations can configure custom retention policies through the admin dashboard, after which meetings and associated data are automatically and permanently deleted.
When you delete your account, all associated data -- including transcripts, summaries, audio recordings, and usage data -- is permanently deleted within 30 days. This deletion is irreversible and includes all backup copies within our retention cycle.
7. Your Rights
You have full control over your data. Regardless of where you are located, we extend the following rights to all users:
- Access: Request a copy of all data we hold about you.
- Export: Download your meetings, transcripts, and summaries in a structured, portable format.
- Correction: Update or correct any inaccurate personal information.
- Deletion: Request permanent deletion of your account and all associated data.
- Restriction: Ask us to limit how we process your data in specific circumstances.
- Objection: Object to data processing based on our legitimate interests.
To exercise any of these rights, contact us at privacy@karnyx.ai. We respond to all requests within 30 days.
8. Cookies
Our website uses essential cookies required for authentication and session management. We use a minimal set of analytics cookies to understand aggregate traffic patterns. We do not use advertising cookies or third-party tracking pixels. You can disable non-essential cookies through your browser settings at any time.
9. Children's Privacy
Karnyx is designed for professional use and is not intended for individuals under the age of 16. We do not knowingly collect data from children. If we learn that we have collected personal information from a child under 16, we will delete that information promptly.
10. Changes to This Policy
We may update this privacy policy from time to time. When we make significant changes, we will notify you via email and update the date at the top of this page. We encourage you to review this policy periodically. Continued use of the service after changes are posted constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this privacy policy or how we handle your data, we want to hear from you.