Last updated 13 August 2026
AVAY is a video meeting service with an AI participant that transcribes conversations, writes notes, and answers questions during a call. This policy describes exactly what data that involves, which companies process it, and where it is stored. It names them specifically rather than referring to "third parties", because a meeting is a private conversation and you are entitled to know who else is in the path.
Accounts are handled by Clerk. When you sign up we receive your email address, your name, and — if you sign in with Google or LinkedIn — the profile information those providers return. We do not receive or store your password.
We do not record audio or video. Meetings are not stored as media; only the text described above is kept.
If you connect an external system, the credential you provide is encrypted at rest with AES-256-GCM before it is stored, and the encryption key is held outside the database. Credentials are never returned to the browser after they are saved.
This is the disclosure that matters most, so it gets its own section.
Transcription uses your browser's built-in speech recognition. In Chrome and Edge, that feature is not on-device: the browser streams your microphone audio to Google's speech recognition servers and returns text. This happens under Google's own privacy policy, not ours, and we never receive the audio itself — only the resulting text.
This only happens while transcription is switched on. If transcription is off, no audio leaves your machine for this purpose and nothing is written down. Firefox and Safari do not implement this feature, so participants using those browsers are not transcribed at all and will not appear in the meeting's transcript or notes.
Transcript text is sent to a language model provider to generate notes and to answer questions asked during the meeting. We currently route these requests through OpenRouter, which forwards them to the model provider serving the selected model. Transcript content leaves our servers for this purpose.
If you attach a connector, the AI may call that external system on your behalf during a meeting, sending it whatever query is needed to answer the question. Connectors are scoped to the account that attached them, and a meeting host can switch any connector off for an individual meeting.
| Processor | What it receives | Where |
|---|---|---|
| Fly.io | All stored data — transcripts, notes, accounts | United States (iad) |
| Clerk | Identity and authentication data | United States |
| Microphone audio during transcription; sign-in profile if you use Google | Google infrastructure | |
| OpenRouter | Transcript text sent for notes and answers | Routed to the model provider |
| Cloudflare | Audio and video streams when the relay or broadcasting is used | Cloudflare network |
| Your connectors | Only what a tool call requires, and only if you attach one | Whoever operates that server |
Meeting content is currently retained indefinitely until you delete it. Deleting a meeting removes its transcript, notes and chat from our database. Deleting your account removes the meetings you own.
A self-hosted deployment can set an automatic retention window with the
AVAY_RETENTION_DAYS setting, after which older meetings are purged.
A transcript captures everyone who spoke, not only the person who started it. If you turn transcription on, you are recording other people's words. Tell them. Some jurisdictions require the consent of everyone present before a conversation may be recorded or transcribed, and it is your responsibility to obtain it.
Traffic is encrypted in transit. Media between participants is carried over WebRTC, which is encrypted in transit by design. Connector credentials are encrypted at rest. Meeting content is not end-to-end encrypted — it cannot be, because the AI features require the service to read it.
AVAY is not intended for anyone under 16 and we do not knowingly collect their data.
If this policy changes materially we will update the date at the top of this page. This document describes the system as it actually behaves on the date shown.
Write to contact@avay.ai with any question about this policy or your data.