Privacy Policy
Effective
Semiotic Intelligence Inc. (“we,” “us,” or “our”) provides Semiotic, a service for shared-room audio recording, transcription, organizing recordings, asking questions about them, and connecting authorized external agents through our MCP interface.
This policy explains how we handle information from our devices, application, website, and support interactions. The service is currently offered to organizations for use in US offices.
1. Our commitments
- Customer content is confidential. We use it to provide the service to your organization and for the limited support, security, and legal purposes described below.
- No model training. We do not use customer content or personal information to train, fine-tune, or improve AI or machine learning models, or to build model-training, evaluation, or benchmarking datasets. This includes de-identified, anonymized, and aggregated versions of that information. We also prohibit our service providers from using customer content, including those derived versions, for any of these purposes.
- No selling your information or advertising with it. We do not sell personal information or disclose it for cross-context behavioral advertising. We do not use customer content for advertising.
- No routine staff listening or reading. Our team's access to customer content is limited as explained in Section 5.
- Deletion is available. Your organization can request deletion of a recording or its workspace content, including the related transcripts, notes, and search data.
“Customer content” includes audio, transcripts, notes, summaries, questions, answers, attachments, and the search representations we create from them. Running a model to transcribe audio, organize content, or answer an authorized user's question is part of providing the service; it does not authorize model training.
2. Your organization's role
If a company or other organization provides your workspace or records a meeting you attend, that organization decides what to record, why to record it, and who may access it. We process its customer content on its behalf and according to its instructions.
Workspace administrators and other authorized users may access content as permitted by their roles and the organization's sharing settings. A company workspace is not necessarily private from the company that manages it.
Your organization is responsible for providing recording notices and obtaining the consents required for its use of the service. Accepting our Terms of Service is not consent on behalf of everyone who may be recorded.
For questions about why your organization recorded a conversation or who it shared it with, contact the meeting organizer or workspace administrator. You may also contact us at founders@semiotic.com, including if you were recorded without having an account. We will help identify the appropriate organization where possible and handle requests as required by applicable law.
We handle account administration, billing, support, and security information for our own service operations, as described in this policy.
3. Information we collect
Recordings and content. When recording is enabled, a shared-room device can capture voices and other sounds within microphone range, including conversations outside a scheduled meeting. We receive the audio uploaded from the device and the content generated or submitted through the application, including transcripts, notes, questions, and answers.
Recording status and controls depend on the device and software supplied to your organization. Stopping recording does not delete audio already captured or stop processing previously uploaded content. A remote pause must reach the device before it takes effect. If a device is offline, unplug it to stop capture immediately. Devices may retain local audio before and after upload until those copies are cleared.
Account and business information. Names, work email addresses, organization and workspace details, account identifiers, access permissions, subscription information, and billing or shipping details that you provide.
Device and operational information. Device identifiers, software versions, IP addresses, connection and upload status, timestamps, feature usage totals, error codes, and security and access logs.
Support communications. Messages and information you choose to send when contacting us. Any customer content included in a support request remains subject to our content protections.
Agent connections. Connection details, permissions, and records of requests made through our MCP interface. An agent may submit questions and receive the content its authorized access allows.
Information comes from you, your organization and its users, people whose voices or information are recorded, connected devices, and the service providers that help us operate the service. Recordings can contain sensitive personal or business information depending on what participants say. Transcription may include speaker labels, which do not by themselves establish a person's identity. Separate experimental voice-enrollment tools are outside the shared-room cloud service covered here; making voice identification available to customers would require additional notice and any required consent.
4. How we use information
We use information to:
- Record, upload, transcribe, organize, store, search, and retrieve customer content, and answer authorized questions about it.
- Authenticate users and devices, enforce access permissions, and support customer-authorized agent connections.
- Manage subscriptions, payments, delivery, returns, and customer support.
- Investigate specific security incidents, protect accounts, and comply with legal obligations.
- Understand and improve service reliability using operational information, such as upload failures, response times, and feature usage totals.
Operational analysis does not authorize us to read or listen to customer content, extract conversation material into a product-improvement dataset, or train models on it. We exclude customer content from routine analytics and diagnostic logs.
We use cookies and similar browser storage for sign-in, security, preferences, and service operation. We do not use advertising cookies or cross-site advertising trackers for this service.
5. Who can access information
Your organization and people it authorizes. We make content available according to workspace permissions and your organization's instructions.
Our personnel. Our founders, employees, and contractors do not routinely listen to recordings or read customer content. They may access the minimum content necessary only:
- With permission from an authorized customer representative to investigate a specific support issue;
- To investigate or respond to a specific suspected security incident; or
- When required by law.
Personnel with access must be authorized and bound by confidentiality obligations. Staff access to customer content must be recorded. Support access is limited to the approved purpose and ends when it is no longer needed. Permission to troubleshoot does not permit model training or unrelated product research.
Service providers. We use providers for hosting, storage, transcription, AI processing, and business operations. They receive only the information needed for their role and must follow contractual restrictions on confidentiality, security, use, and deletion. We do not permit providers to use customer content to train or improve models or to advertise to you.
Our current infrastructure providers are:
- Supabase: account authentication, workspace records, private audio storage, transcripts, notes, and search data.
- Microsoft Azure: speech transcription and AI processing for search, summaries, and answers. Audio is sent to Azure for transcription; relevant text and questions are sent for the other requested features.
- Fly.io: hosting the application, agent connection service, and background processing. Processing can involve temporary audio, transcripts, and recovery copies as well as account and connection information. Our application and processing worker are configured in Toronto, Canada.
- Vercel: hosting this public website and serving its pages and assets. Website requests can include IP addresses, browser information, and ordinary request logs. The landing page does not upload workspace recordings to Vercel.
Information may be processed outside the United States, including in Canada and the locations used by our configured Supabase and Azure services. Contact founders@semiotic.com for current deployment-location and provider details before providing information that has location restrictions.
Provider retention. We store your archive so you can revisit and search it. Azure's handling of processing requests is separate: applicable abuse-monitoring and service settings may permit limited retention and authorized review of flagged content. We do not promise zero retention for all Azure requests or that no provider personnel could ever access information. No-training commitments and retention periods are separate protections. Contact founders@semiotic.com for the current settings relevant to your workspace.
When billing, delivery, or support requires another provider, we disclose the provider's relevant role to the customer before sharing information. Payment and delivery providers receive the account, transaction, or shipping information they need, rather than access to the recording archive. A returned device may still contain local audio pending secure clearing.
External agents and other destinations you choose. If you connect an external agent, export content, or direct us to share it, the recipient may keep its own copy under its own terms. Disconnecting the agent stops future authorized access through that connection but does not erase copies already received. Our no-training restrictions on our providers do not control an independent agent or provider that your organization chooses.
Legal disclosures. We may disclose information where required by law or binding legal process. We limit disclosure to what is required and notify the affected customer when legally permitted.
A change in our business. If the service is acquired or transferred, relevant information may transfer to the successor subject to these privacy and confidentiality commitments. We will not provide prospective buyers with recordings or transcripts as routine transaction due diligence.
6. Retention and deletion
Your organization can request an export or deletion by contacting founders@semiotic.com. We verify the requester's authority and help customers handle requests from recorded participants.
- Workspace customer content
- Kept while the workspace is active to provide its archive, unless the customer requests earlier deletion. We delete requested content from active systems within 30 days after verifying a deletion request, or within 30 days after the subscription ends. This includes audio, transcripts, notes, answers, and related search data under our control.
- Local device audio
- Upload does not by itself delete local audio. Copies remain until supported storage cleanup or a device wipe removes them. An offline device cannot receive a remote deletion command; the customer must reconnect or return it, or follow our local deletion instructions. Returned devices are cleared before reuse.
- Backup copies of deleted content
- Removed through backup expiration within 90 days after deletion from active systems. Backups are restricted to recovery use; if restored, deletion requests are reapplied.
- Account details and ordinary operational and security logs
- Deleted or de-identified within 90 days after account closure or the relevant logged event, as applicable, except for the records listed below. De-identification here does not apply to retaining customer content.
- Support correspondence
- Kept for up to 12 months after resolution. Customer content attached to a support case follows the workspace-content deletion schedule.
- Billing and transaction records
- Kept for up to seven years where needed for accounting, tax, and legal obligations. These records do not include workspace recordings or transcripts.
- Privacy-request records
- A minimal record of the request and our response is kept for up to three years to demonstrate that it was handled. We do not retain the underlying recording for this purpose.
Where law requires us to preserve particular information, we keep only what is required for that obligation, restrict its use, and delete it when the requirement ends. We explain any relevant limitation when responding to a deletion request, unless prohibited by law.
We instruct our providers to delete applicable information in accordance with our contracts and the disclosed retention periods. We cannot erase copies independently exported or retained by your organization, meeting participants, or customer-selected agents.
7. Security
We protect information using encrypted connections, access controls, private cloud storage, and permissions that separate customer workspaces. Staff access must be authorized, limited to the purposes above, and recorded. Devices may contain locally stored audio; physical possession of a device can expose that audio, so devices must be kept in locations controlled by your organization.
These protections do not mean that content is end-to-end encrypted or technically inaccessible to us: our service must process content to provide transcription, search, and answers. No system can guarantee absolute security. If we become aware of unauthorized access to or disclosure, loss, alteration, or destruction of customer content in our systems or those of our providers, we notify affected customers without undue delay and provide information and assistance required by law and our terms.
8. Privacy requests and choices
Depending on applicable law, you may have rights to access, obtain a copy of, correct, or delete personal information; learn how it is processed; and exercise other privacy rights. Contact founders@semiotic.com. We may need information to verify your identity or an authorized agent's authority, and we will respond within the applicable legal deadline.
For content controlled by a customer organization, we ordinarily coordinate with that organization rather than independently changing its records. This does not limit any duty we have to respond directly under applicable law.
If we deny a request, you may ask us to reconsider by replying to the decision or emailing founders@semiotic.com. We will provide any appeal information required by applicable law. We do not discriminate against people for exercising privacy rights.
Because we do not sell personal information or share it for cross-context behavioral advertising, there is no such sale or advertising sharing to opt out of.
9. Children
The service is for adult business users and is not designed for recording children. Customers must not use it for child-directed recording. If you believe a child's information has been collected inappropriately, contact founders@semiotic.com so we can investigate and arrange appropriate deletion.
10. Changes and contact
We will update the effective date when this policy changes and give customers at least 30 days' notice of material changes, unless a shorter period is required by law or an urgent security need. A policy update does not override the confidentiality or no-training commitments in our Terms of Service or retroactively authorize new uses of previously collected customer content.
Company: Semiotic Intelligence Inc. Privacy and support: founders@semiotic.com