Security & Privacy
Security & Privacy
This page describes how InterMIND handles your data in plain terms. For legal language, see the Privacy Policy and Terms of Service; for the buyer-facing summary with the GDPR audit and DPA links, see the Privacy & Security feature page.
Encryption
In transit. All connections to InterMIND go over HTTPS / WSS (TLS). HTTP requests are redirected to HTTPS automatically — there is no plaintext fallback. This covers the web app, the WebSocket server that carries chat and signaling, and our own calls to the translation engine. Meeting audio and video travel over WebRTC with DTLS-SRTP between your browser and the media server of our own engine in France; the media server decrypts each stream to forward it to the other participants and to the speech-recognition and translation pipeline.
At rest. The database (Neon, Frankfurt) encrypts its storage with AES-256; recordings, attachments and export archives on Tigris object storage are covered by server-side encryption that is always on. OAuth integration tokens and OIDC client secrets are additionally encrypted at the application level (AES-256-GCM) before they are written, and OIDC session tokens are stored encrypted in the session cache. Vendor statements: Neon security overview, Tigris S3 API.
End-to-end encryption: no. Translation is processing — speech recognition and translation run on our own engine, on our own servers in Germany and France, and that engine has to read the content to translate it. InterMIND is therefore transport-encrypted and encrypted at rest, and the content is readable by our infrastructure at the point of processing; it is not end-to-end encrypted, and no plan or setting changes that. What we offer instead is a verifiable data path: EU at every hop, our own engine for live speech rather than a third-party model, AI features on the gateway your organization selects (our own tenant, no training on your data), and retention you control. Voice notes are transcribed by Azure AI Speech in that same tenant. If end-to-end encryption outranks everything else for you, products built around it — Element, Wire, Threema — are the better fit, and none of them documents translation; we say the same in our messenger comparison.
Authentication
| Method | Status |
|---|---|
| Email + verification code | Available |
| Sign in with Google (OAuth 2.0) | Available |
| Sign in with Microsoft (OAuth 2.0) | Available |
| SSO (Google / Microsoft, automatic team join by verified domain) | Available on Business and Enterprise plans |
| Enterprise SSO via your own IdP (OIDC — Okta, Microsoft Entra ID, Google Workspace) | Available on Business and Enterprise plans |
Passwords are never stored — sign-in is either a one-time verification code or an OAuth flow with Google / Microsoft. Sessions are kept in HTTP-only cookies; you can sign out from the profile menu at any time.
Enterprise SSO uses OpenID Connect Authorization Code with PKCE (S256), state, and nonce. ID tokens are validated against the IdP's published JWKS (signature, issuer, audience), and a sign-in is accepted only for email domains the team has verified via DNS — your IdP is authoritative only for domains you have proven to own. OIDC client secrets are encrypted at rest, and every SSO sign-in is recorded in the team audit log. Setup: SSO Setup.
Real-Time Translation
Real-time voice and subtitle translation runs on InterMIND's own infrastructure — speech audio is processed on our private WebSocket service, not sent to a public OpenAI / Google Translate / Azure endpoint.
Document translation (PDF, DOCX, DOC, PPTX, XLSX) uses DeepL as the translation provider. Files are uploaded to DeepL over a TLS connection for translation and the result is returned to your meeting chat. DeepL's data handling is governed by DeepL's own privacy terms — they do not retain content for training.
AI Features
Meeting recaps, document summaries, the writing assistant, Ask AI and Mia (the AI participant you can address by name in a meeting) run on a language-model gateway of a hyperscaler, in InterMIND's own tenant — the same gateway your organization most likely already uses for its own AI:
| Gateway | Region | Status |
|---|---|---|
| Azure OpenAI (Microsoft) | EU Data Zone — processing and storage inside EU member states | Default |
| Google Vertex AI (Google Cloud) | EU multi-region endpoint | Available — organization admins pick it in Settings |
| Amazon Bedrock (AWS) | EU (Frankfurt) or any region you choose, in your own AWS account — you add an IAM access key with Bedrock invoke rights; the models, quotas and Marketplace agreement stay yours | Available — organization admins enter their AWS account in Settings |
| Your own endpoint | Wherever you run it | Available — any OpenAI-compatible server (for example vLLM in your data centre or a deployment in your own tenant) |
An organization admin chooses the gateway on the Integrations page; the choice applies to every AI feature of the organization at once, and AI features can be switched off for the whole organization — transcription and translation keep working. What leaves InterMIND for an AI call is the meeting transcript and the chat window at meeting end, the shared documents, the editor text or the question asked; all gateways are configured with zero data retention and no training on your content. Mia's voice is synthesized by the same vendor as the gateway (Azure AI Speech, Google Cloud Text-to-Speech, EU regions); with your own endpoint Mia answers in text.
Recordings and Transcripts
| Data | Storage | Retention |
|---|---|---|
| Meeting recordings | S3-compatible object storage | Stored until you delete them |
| Transcripts | Linked to the recording / meeting | Same as the recording |
| Chat messages | Database, linked to the meeting or channel | Until you delete them, or — for ad-hoc meetings — purged when the call ends |
You control retention: your content stays available for as long as your account or team workspace is active, and you can delete any recording, channel, or message at any time. Deleting your account permanently erases all associated content across our database and storage. We do not impose an automatic expiry — you decide how long your content is kept. See our Privacy Policy for the full retention statement.
Where Your Data Lives
InterMIND's primary application region is Paris (CDG, France) on Fly.io; the database lives in Frankfurt, Germany. Recordings and files are kept on S3-compatible storage pinned to EU regions (Frankfurt / Amsterdam). There is currently no per-customer region pinning.
What Other Parties See
| Party | What they see |
|---|---|
| InterMIND | Meeting metadata, chat content, recordings (until you delete them), transcripts, your account info |
| DeepL | Only the contents of documents you ask to translate, on a per-file basis |
| Microsoft (Azure OpenAI, Azure AI Speech — the default AI gateway) | The meeting transcript and chat window at meeting end, shared documents, editor text and Ask AI questions, for the AI features above; Mia's answers for text-to-speech; the audio of a voice note recorded in a channel, for speech-to-text — EU Data Zone, zero data retention, never used for training |
| Google (Vertex AI, Cloud Text-to-Speech — only for organizations that selected this gateway) | The same content as above, on Google's EU endpoints — zero data retention, never used for training |
| Google / Microsoft (if you sign in with them) | Your name, email, profile photo — standard OAuth scopes only |
| Stripe (if you pay) | Billing details (card, address) — InterMIND never sees the raw card number |
| Sentry, PostHog (error & analytics) | Anonymous usage events and crash traces; meeting content is never sent |
What InterMIND Does Not Do
- No model training on your data. Conversations, documents, and recordings are not used to train any AI model.
- No selling or sharing. Your data is not sold or shared with advertisers.
- No third-party tracking inside meetings. No tracking pixels, no ad SDKs in the meeting room.
Deleting Your Data
| To delete | How |
|---|---|
| A single recording | Open the meeting → Recordings → delete |
| A standalone chat history | Open the channel → Delete Channel Permanently (removes the channel and all its messages, files, and history) |
| Your entire account | Profile → Settings → Delete account, or contact security@intermind.com |
Account deletion removes your profile, meetings, recordings, transcripts, and chat history. Backups may take up to 30 days to age out.
Reporting a Security Issue
If you believe you have found a security vulnerability in InterMIND, we want to hear about it.
How to reach us. Email security@intermind.com with a short description of the issue and enough detail to reproduce it (steps, affected URL, screenshots or a proof of concept). Encrypted email is fine if you prefer. A machine-readable contact is also published at /.well-known/security.txt (RFC 9116).
What to expect. We aim to acknowledge a report within 3 business days and to keep you updated as we investigate and fix. When a report leads to a fix, we are happy to credit you by name if you would like acknowledgement.
What we ask. Please practice responsible disclosure: report the issue to us privately first and give us reasonable time to fix it before any public discussion. Do not access, modify, download, or retain data belonging to other users or accounts beyond the minimum needed to demonstrate the issue, do not degrade or disrupt the service, and delete any data or screenshots captured during testing once the report is closed.
Scope. In scope: intermind.com and its APIs, the InterMIND web, mobile, and desktop applications, and our WebSocket service. Out of scope: findings that require physical access to a user's device, social engineering of our staff or users, volumetric denial-of-service, and reports from automated scanners without a demonstrated, exploitable impact.
Rewards. We do not run a paid bug-bounty program at this time, so we are not able to offer monetary rewards. We do genuinely value good-faith reports and will acknowledge them.
Safe harbor. We will not pursue or support legal action against researchers who act in good faith, follow this policy, and avoid privacy violations, data destruction, and service disruption. If in doubt about whether an action is authorized, ask us first at security@intermind.com.
Related
- Privacy Policy — Legal text
- Subprocessors — Providers we use and where they process data
- Terms of Service — Legal text
- Billing & Plans — Plan-level data handling differences