Privacy
How we handle your transcripts
Communication is sensitive. This page explains exactly what happens to your data — what we redact before any AI sees it, what we deliberately keep and why, and what Myc accesses when you connect a meeting tool.
Effective 2026-08-24
Your meeting transcripts may contain sensitive personal and business information. Before any transcript is sent to the AI for analysis, Making Yourself Clear automatically removes identifying information using a defense-in-depth approach. The redaction is designed to protect third parties who aren’t in your meeting (customers, competitors, colleagues mentioned in passing) and sensitive identifiers like SSNs, employee IDs, addresses, and credentials. This page explains exactly what happens — and what we deliberately leave intact, and why.
How we protect your data
We use encryption and layered security procedures to protect the confidentiality of your data — including the sensitive data we handle for you, such as Google Meet transcripts and Google Calendar information from a connected account.
- In transit: traffic between you and Making Yourself Clear, and between our service and the AI provider, is encrypted with TLS 1.2 or higher.
- At rest: your transcripts, the redacted text, your analyses, and the access tokens for any connected meeting account are encrypted at the application layer with AES-256-GCM under a per-organization key, with the root key held in a cloud key-management service (AWS KMS, HSM-backed). Beneath that, the hosting provider (Railway) encrypts the database and all backups at rest at the storage level.
- Access and isolation: content is isolated at the API layer — every endpoint authorizes the caller against a record’s owner before returning data, and a probe for a record you have no relationship to returns “not found” (not “forbidden”) so records can’t be enumerated by id — so one customer can never reach another’s data. Our automated analysis pipeline processes only the redacted text, and inside the app even our own administrators see the initials version, not real names. Administrative actions are recorded to an append-only audit log. Self-hosting is available for customers who require true vendor zero-knowledge — where we never hold your data at all.
- Minimized before AI, never used for training: personal information is removed by our redaction layer before any transcript is sent to the AI provider, and your data — including data obtained through Google Workspace APIs (Meet and Calendar) — is never used to develop, improve, or train generalized or non-personalized AI or machine-learning models.
- Private until you share: your coaching analyses — the reports, quotes, and scores — stay visible only to you until you choose to share them with a coach, team lead, or organization. Your organization can see program-level activity (for example, how many meetings you’ve analyzed), while an assigned coach sees only your name until you share — not your meetings, their titles or dates, or any content.
- Our role under privacy law: Making Yourself Clear acts as a Data Processor under GDPR Art. 28; a Data Processing Agreement is available, pending legal review before signing.
For the full technical detail — security architecture, sub-processors, compliance posture, and downloadable documentation — see our Trust & Security page.
What happens when you upload a transcript
- 1
You upload a transcript
The file is parsed to text and stored in your account. It is not sent anywhere external yet.
- 2
PII redaction (before any AI call)
A local redaction layer (Microsoft Presidio plus custom recognizers) scans the transcript before any AI call. Every person’s name — the meeting participants (speakers) and anyone mentioned but not present alike — is reduced to bare initials (e.g. "Sarah Chen" becomes "S_C", used consistently throughout), so the AI can still follow who said what without seeing real names. Other sensitive items — emails, phone numbers, addresses, government identifiers, employee IDs, API keys, dates of birth — are replaced with placeholder tokens like <EMAIL_ADDRESS_1>, <EMPLOYEE_ID_1>. The original text never leaves our backend.
- 3
Redacted text is sent to the AI provider
Only the redacted transcript is sent to the AI provider (OpenAI by default). We send every request with store=false, which disables OpenAI-side storage of the conversation, and OpenAI does not train on API data. Standard provider retention (up to 30 days, for abuse-monitoring) still applies.
- 4
AI response references speakers by name
The AI only ever saw initials — every person’s name, yours included, is reduced to bare initials before the request leaves our backend. A reversible mapping of initials to names is kept encrypted on our side and applied when your analysis is displayed, so the coaching reads with real names even though none were sent. You can confirm exactly what was sent on any analysis via “View what was sent to the AI”, which always shows the redacted version. Other redacted details — emails, phone numbers, ID numbers — stay masked everywhere, including for you.
What we detect and redact
The redaction layer is configured with multiple aggressiveness levels (Conservative, Standard, Permissive). Standard is the default. The categories below are detected across all levels.
Identity
- Names of people (everyone) — Every person’s name is reduced to bare initials — both the meeting participants (speakers) and anyone mentioned but not present (customers, competitors, absent colleagues, family members). The same person maps to the same initials consistently throughout the transcript.
- Dates of birth — Explicit DOB references ("DOB 03/14/1968", "born March 14, 1968").
- Employee / staff IDs — Common formats like EMP-####, EMPID-####, STAFF-####.
Contact information
- Email addresses — Any string matching standard email patterns.
- Phone numbers — US and international formats.
- Physical addresses — US, Canada, and UK street address patterns.
Government & financial identifiers
- Social security numbers — US SSN patterns.
- Passport numbers — US passport identifiers.
- Driver license numbers — US driver license identifiers.
- Medical license numbers — Healthcare professional license identifiers.
- Credit card numbers — Full and partial references ("Amex ending in 1234", expiration dates).
Credentials
- API keys and tokens — OpenAI keys (sk-/pk-), Stripe keys, webhook secrets, generic labelled secrets.
Network & location
- IP addresses — IPv4 and IPv6 addresses.
- URLs — Web addresses that may identify internal systems (Conservative aggressiveness only).
- Locations — Cities, regions, countries (Conservative aggressiveness only).
- Nationalities / religions / political groups — Detected as NRP entities.
What we don’t redact (and why)
Some categories of information are intentionally preserved in the redacted transcript. These are deliberate design choices, not oversights — each has a specific reason.
Who-said-what (turn attribution)
We keep the conversation’s turn-by-turn structure and a consistent initials label for each speaker (e.g. "S_C"), so the AI can follow who said what and give coherent coaching — "S_C, you interrupted D_P twice in the first five minutes" — without ever seeing a real name. If your security team wants speaker turns anonymised further, contact us.
Organization names (off by default)
Detection of organization names is configurable and off by default. If your admin turns it on in admin settings, organisation names mentioned in the transcript will also be redacted.
Meeting dates, times, and structural markers
Timestamps, turn numbering, and other structural metadata are kept so the AI can reason about timing and flow. These don’t identify individuals on their own.
Before and after
A representative example of a short 1:1. Every name — the speakers (Sarah Chen, Daniel Park) and people mentioned but not present — is reduced to consistent initials; other sensitive identifiers become opaque tokens.
What you upload
Sarah Chen: Daniel, I’m worried about hitting the Q3 number. Mark from sales said his contact Alex is pushing back hard, and our customer called me on +1-415-555-0142 to complain. My employee ID for the escalation is EMP-4421. Daniel Park: Tell me more about what Mark said.
What the AI sees
S_C: <D_P>, I’m worried about hitting the Q3 number. <M_> from sales said his contact <A_> is pushing back hard, and our customer called me on <PHONE_NUMBER_1> to complain. My employee ID for the escalation is <EMPLOYEE_ID_1>. D_P: Tell me more about what <M_> said.
What happens at the AI provider
- Requests are sent with store=false on OpenAI, which disables OpenAI-side storage of the conversation; OpenAI does not train on API data. On the default tier, OpenAI’s standard 30-day abuse-monitoring retention applies. Zero data retention is available on request for Enterprise clients on a per-contract basis (via an OpenAI enterprise agreement) and is not in effect on the default tier; bring-your-own-endpoint or self-host route around vendor retention entirely.
- Customer organizations can configure their own LLM endpoint per-org (Azure OpenAI, enterprise OpenAI, OpenAI-compatible proxy, or Anthropic-direct) so transcripts route through their own contract instead of ours. Set up by your organization admin in Settings.
- We never send raw transcripts to any third-party service for storage, analysis, or any other purpose.
- In a self-host deployment you can point Myc at a Private LLM Deployment — an in-VPC model or a provider Managed Private Endpoint — so even the redacted text never leaves your perimeter. See our Trust & Security page for more details.
How your data is stored on our side
- Customer data lives in a managed Postgres database (Railway-managed Postgres, US West region). Customer content is encrypted at rest at the application layer with AES-256-GCM under a per-organization key; on our hosted service the root key is held in AWS KMS (adding decrypt audit + key revocation). Beneath that, the hosting provider (Railway) encrypts the database and all backups at rest at the storage level.
- Each coachee's content is isolated at the API layer: every endpoint resolves a record's owner and authorizes the caller before returning any data, and a probe for a record you have no relationship to returns "not found" so records can't be enumerated by id. Coachees outside an organization see only their own data.
- Raw transcript text and the redacted version (the exact text sent to the AI) are stored separately. You can view the redacted version on each analysis result.
- A reversible mapping of placeholder tokens to original values is kept securely — encrypted at rest, configurable per-organization — and is used only to restore real names at read time for you and the people you have shared an analysis with.
- You can delete any individual meeting transcript and its analyses at any time from the run detail page.
How long we keep your data, and how to delete it
We keep your data only as long as we need it to provide the service to you, and you stay in control of removing it.
- While your account is active: your transcripts, redacted text, and analyses are retained so your history and progress stay available to you. You can delete any individual meeting transcript and its analyses at any time from the run detail page.
- Connected meeting accounts: the access tokens for a connected Google or Zoom account are stored encrypted only while the connection is active. Disconnecting the account deletes those tokens immediately and stops all future imports, and asks the provider (Google or Zoom) to revoke Myc’s access on your behalf; if that provider-side revocation doesn’t go through, we prompt you to remove Myc yourself. You can also revoke Myc’s access yourself at any time from your Google Account (myaccount.google.com/permissions) or your Zoom account settings.
- Deleting your whole account: you can delete your account and all associated personal data at any time from your account settings. Deletion takes effect after a 7-day grace period — sign back in during that window to cancel — after which we irreversibly erase your coaching content, connected-account data, sessions, and credentials; we retain only non-content administrative audit records as required for security and legal purposes. Operator-assisted erasure also remains available on request at security@makingyourselfclear.com.
Your rights
Depending on where you live, you may have some or all of the following rights over your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — delete your data. You can delete any individual meeting transcript and its analyses at any time from the run detail page, and you can delete your entire account and all associated personal data at any time from your account settings.
- Restriction and objection — ask us to restrict, or object to, certain processing of your data.
- Portability — receive the personal data you provided in a portable, machine-readable format.
- Withdraw consent — where processing is based on your consent, withdraw it at any time (for example, by disconnecting a connected account or deleting the relevant content).
How to exercise these rights. For deletion, use the self-service controls described above. For any other request, email us at support@makingyourselfclear.com (security or privacy concerns: security@makingyourselfclear.com) and we will respond within the timeframe required by applicable law. Where we process meeting content on behalf of an organization (for example, your employer or coaching provider) that acts as the data controller, we will direct your request to that organization and assist them in responding. Exercising these rights does not affect the lawfulness of processing carried out before your request, and does not diminish any statutory rights you have under applicable law.
Connecting your meeting tools (Zoom, Google Meet)
Instead of uploading each transcript by hand, you can connect a meeting account once and Myc will import new transcripts from meetings you host automatically. Connecting is optional, always your choice, and you can disconnect at any time. Here is exactly what Myc accesses, and why.
Google Meet
When you connect a Google account, Myc requests:
- Your Meet transcripts — to read the text transcript of Meet meetings you host, so there is something to analyze. Text only — never audio or video, and never meetings you don’t host.
- Your upcoming calendar events (read-only) — only if you turn on automatic transcription. Myc looks at your upcoming meetings solely to find the Meet meetings you organize, so it can switch Google’s transcript generation on for them. This is used in the moment and not stored, and Myc never writes to your calendar.
- Your meeting settings — with your permission, Myc turns on the “generate transcript” setting for your own meetings, and nothing else — it does not touch recording or notes.
- Your basic Google profile (name, email) — to identify your account and match your own voice in the transcript.
Zoom
When you connect a Zoom account, Myc requests:
- Your cloud-recording transcripts — the audio-transcript text from cloud recordings of meetings you host — text only, never audio.
- Your meeting settings — when you connect, Myc turns on cloud recording and transcript generation for your own meetings, so your recordings produce a transcript to import; if you opt in, it also turns on automatic recording. It changes only your own settings, on your own account — and nothing else.
- Your basic Zoom profile — to identify your account.
Imported transcripts are treated exactly like transcripts you upload yourself: PII-redacted before any AI call, encrypted at rest, and never used to train any model (see the sections above). The access tokens for your connected accounts are encrypted at rest. Google and Zoom user data is used only to provide the coaching features described on this page — we never sell it, never use it for advertising, and never otherwise share it. The only third party we send your transcript content to for analysis is the AI provider you select, and then only the redacted text; the sub-processors that operate the service (hosting, key management, email, monitoring) are listed in our sub-processor list. Nothing imported from a connected account is analyzed without your approval. By default, you confirm each imported transcript before it is analyzed. You can enable automatic analysis as a standing choice, subject to a per-connection cost cap and a significant-speaker filter that skips meetings where your contribution was minimal.
You can disconnect a meeting account any time from Connected Apps in Myc. Disconnecting immediately deletes the stored tokens (stopping all future imports) and asks the provider to revoke Myc’s access on your behalf; if that provider-side revocation doesn’t go through, we prompt you to remove Myc directly. Disconnecting — or uninstalling Myc from your Zoom account, which Zoom signals to us automatically so we run the same teardown — also deletes any imported meetings still awaiting your review and your recurring-series import preferences; transcripts you already reviewed and imported into your coaching account stay yours as first-party content, removable anytime via per-run or full-account deletion. You can also revoke Myc’s access yourself at any time from your Google Account (myaccount.google.com/permissions) or your Zoom account settings.
Myc requests only the minimal Google API scopes the connect-once features need — read-only access to your Meet transcripts (no Drive scope) and, only if you enable auto-transcription, read-only calendar access to locate your meetings plus a transcription-settings toggle for your own meetings. That Google user data is used only to provide these coaching features and is never used to train AI models. Myc’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Changes to this policy
We keep this policy current. If we change how we access, use, store, or share Google or Zoom user data, we will update this page and the effective date above and, for material changes, notify connected users by email before the change takes effect. Your continued use of Making Yourself Clear after a change means you accept the updated policy.
Questions or concerns?
For a deeper technical security overview — architecture, encryption, access controls, sub-processors, and compliance posture — see our security overview. If your security or legal team needs additional documentation (data flow diagram, DPA, white paper, SOC 2 status), contact security@makingyourselfclear.com.