Foo AI Corp.
Your recordings stay yours
Recording uploads audio so it can be transcribed and summarized; dictation does not, unless you switch on Cloud dictation. This page is about what happens to the things that do get uploaded — where they sit, who can open them, how long they last, and what we strip out of them.
No model training
The providers that transcribe and summarize your audio work under no-training terms, and nothing you record is used to train a model. Every request we send carries that instruction; it is not a setting you have to find.
Which companies those are, and what each one receives, is set out in the Privacy Policy and generated host by host in the Trust Center.
Storage scoped to your organization
Recordings and summaries are written under a path reserved for your organization, and no other customer account can read it. What decides whether a recording leaves the device is workspace membership, not your plan: if you belong to a workspace and your role permits recording, it uploads when you stop; if you do not, it stays where it was made.
Who can open what
Five roles — owner, admin, manager, member, viewer — with departments that mirror your org chart and access control at the folder level. A viewer can be granted read and nothing else; the database enforces that, not only the interface.
When someone creates a share link, that summary becomes readable by anyone holding the link until it is revoked. That is the one path by which a summary leaves the roles above, and it is deliberate.
How long it stays
Deleting a recording moves it to your workspace Trash, where an admin can restore it for up to 30 days before the audio, the transcript and the summary are removed for good. On every plan an admin can set a retention policy that deletes them automatically after a chosen period — a policy can empty the Trash sooner than 30 days.
You can delete a recording, a summary, or the whole account from inside the product. Account deletion is described step by step in the Privacy Policy.
Masking personal identifiers
An admin can switch on pattern-based masking of personal identifiers in new transcripts, on any plan. It is off until someone turns it on, and it applies going forward — it does not rewrite transcripts you already have.
What it replaces, and with what: card numbers become [card number], account numbers [account number], phone numbers [phone number], and national identity numbers [national ID]. Card numbers are Luhn-validated in any format, so a number that cannot be a card is left alone. Account numbers are matched at 9 to 19 digits and only next to a banking word, which is why an amount or a date is not touched. Phone and identity patterns follow your workspace language setting rather than the language of the sentence.
Where the full list lives
This page says what we do. The Privacy Policy is the legally operative document and names every recipient in legal terms; the Trust Center is generated from the code and lists every host the app can reach. If those three ever disagree, write to us — that is exactly the report we want.