Is your meeting confidential?
People say things in meetings they would never put in an email. Salary bands. A candid read on a partner. The negotiation floor. Legal strategy. That's what meetings are for — the medium where you can still think out loud.
Which makes it odd how rarely anyone asks where all that thinking-out-loud actually goes. The words leave your mouth, become audio, hit a server, possibly feed a model, possibly become a transcript, possibly get retained under a policy you agreed to by clicking "join." "Confidential" on a vendor homepage tells you nothing about any of that.
We put the word on our homepage too. So here's what we think it should be required to mean — three questions concrete enough to check, and our answer to each. Not because you should trust the answers, but because every one of them is verifiable, which is the only kind of confidentiality claim worth making.
Question 1: Who processes your words, besides the people in the room?
A translated meeting is, unavoidably, a processed meeting. Speech becomes text, text becomes another language, an AI writes the recap. The confidentiality question isn't whether machines touch your words — it's which machines, run by whom, under what terms.
Our answer: voice and chat translation run on our own engine, on dedicated servers in France — not routed through generic third-party translation APIs, so your negotiation doesn't transit a consumer service. The AI features that do use an external model (the recap) are pinned to an EU provider under zero-data-retention terms — your meeting content is processed and immediately discarded, not stored, not used for training. No meeting content reaches a US-domiciled model. Document translation goes through exactly one named sub-processor (DeepL's Document API, for file-format support), disclosed on our sub-processor list rather than "available on request."
The checkable part: every vendor that touches meeting data is named on the page, with what it does and where it's domiciled.
Question 2: What remains afterwards — and who decides?
A meeting leaves traces: chat history, files, recaps, sometimes a recording. Confidentiality isn't the absence of a record (a record in your language is half the product's value — we've argued it's the half the industry forgets). It's the record being yours:
- Recording is a host decision. It's available when the host turns it on — not a default, not a vendor's background process.
- Retention is yours to end. Data is kept until you or your team owner delete it — the criterion is written in the privacy policy, not implied.
- Deletion actually deletes. Erasing an account cascades across the database and sweeps every storage blob, recordings included. We audited our own codebase to make sure the cascade runs — and published what we found and fixed.
Question 3: Whose laws apply to the room?
Where data lives decides who can compel it and which rules protect it. For a bakery's stand-up, academic. For a bank, a clinic, a bidder in a public tender — the first question procurement asks.
Our answer: EU at every runtime hop. The translation engine runs in France, meeting orchestration in Paris, the database in Frankfurt; storage and analytics are EU-resident too. That's a jurisdiction you can name in a compliance review, not a region-of-convenience that shifts with the vendor's load balancer.
The quieter half: data never collected
One more property, easy to miss: your guests join by link, with no account. No sign-up means no profile, no address book upload, no identity graph of everyone who ever attended your meetings. The least exposed data is the data that was never collected — and it's also just how hospitality should work.
Make any vendor answer the same three questions
Take this list into your next procurement call — it works on us too:
- Which companies process meeting content, and is the list published?
- Does any AI feature retain meeting content after processing? Under what terms — marketing copy, or contract?
- In which jurisdictions does meeting data live, hop by hop?
- Who can start a recording, and can participants tell?
- When a customer deletes data, what proves the deletion ran — policy text, or an audited cascade?
If the answers arrive quickly and specifically, you're talking to a vendor who expected the questions. Our full set — DPA with a 72-hour breach window, sub-processor list, uptime terms, the GDPR audit — lives at Privacy & Security, one click deep, where procurement can get properly bored.
Check it yourself
- Read the security page — infrastructure, encryption, sub-processors, DPA, the audit.
- Try the live demo — no signup required, which is itself a data-collection answer.
- How a meeting actually runs — the infrastructure map, hop by hop, for the technically curious.
FAQ
Is a video meeting confidential by default?
No platform can promise that as a default — it depends on who processes the audio, what's retained afterwards, and where the data lives. Those are answerable questions: ask for the sub-processor list, the AI retention terms, and the jurisdiction of each hop. A vendor with real answers publishes them.
Does live translation mean an AI is listening to my meeting?
Yes — translation is processing, there's no way around that. What differs between vendors is which machines process it and what they keep. In InterMIND, voice and chat translation run on our own engine on dedicated EU servers, the recap AI is bound to zero-data-retention terms, and no meeting content reaches a US-domiciled model.
Who can record an InterMIND meeting?
Recording is controlled by the host — it's available when the host enables it, never a background default. Access controls cover who can join, present and record.
What happens to meeting data when I delete my account?
Deletion cascades across the database and sweeps every storage blob, recordings included. Retention until that moment is under your control — data is kept until you or your team owner delete it, per the published policy.
Where is InterMIND meeting data processed?
In the EU at every runtime hop: translation engine on our own infrastructure in France, meeting orchestration in Paris, database in Frankfurt, EU-resident storage and analytics. Document translation uses one named EU-disclosed sub-processor (DeepL), listed publicly.
Sources: DeepL — data security, checked August 2026. InterMIND claims in this post are documented on Privacy & Security — infrastructure, sub-processor list, DPA and the GDPR audit report — and in the audit write-up.