Security and Trust: Data Protection and Storage Policy
Last updated: July 2026
Sumarii handles meeting audio, transcripts, and minutes. We treat personal information in accordance with Japan’s Act on the Protection of Personal Information (APPI) and other applicable law.
In short
- We do not use your audio, transcripts, or minutes to train AI models, and neither do our subprocessors.
- Our AI subprocessors do not retain your data after processing.
- Your data is stored on infrastructure in Japan (Tokyo region).
- Sessions go to Trash first; delete from Trash or delete your account for permanent removal.
AI and training
Your audio, transcripts, and generated minutes are never used to train AI models, by us or by any of our subprocessors.
Our AI subprocessors operate under zero-retention terms. Your data is processed and discarded. It is not stored on their systems after the request completes.
Where your data is stored
Meeting audio, transcripts, and minutes are stored on infrastructure located in Japan (Tokyo region).
Speech recognition processing is currently performed by a provider in the United States. This transfer is covered by contract terms that establish a structure conforming to the standards under APPI Article 28(1). No copy of your audio is retained by that provider after processing.
Transactional email delivery and payment processing are also performed in the United States. All other processing occurs in the Tokyo region.
Deletion and retention
Deleting a session moves it to Trash. You can restore it from Trash.
Permanent deletion happens when you delete a session from Trash, or when you delete your account. Then:
- Audio is destroyed immediately (it is outside the application database and is not in database backups).
- Transcript, minutes, and metadata are removed from the live system immediately. Residual copies in database backups are purged within 7 days.
- Account deletion also permanently deletes the workspace and settings.
The one exception after account deletion is your email address, which we retain for as long as necessary to prevent repeated use of the free tier through re-registration. It is not used for any other purpose.
Encryption
- All traffic between your browser and Sumarii is protected with HTTPS.
- Stored data is encrypted at rest.
- Audio files are never served from public URLs. They are retrievable only through short-lived signed URLs.
Access control
- An authenticated session is required to use the service. By design, no unauthenticated third party can reach your data.
- Data is isolated per workspace, with access enforced at the database layer through row-level security.
- Sign-in is available with email and password, Google, or Microsoft. Optional authenticator-app multi-factor authentication (TOTP) can be enabled in account settings. Accounts using Google or Microsoft sign-in may also inherit MFA configured on those provider accounts.
- SAML-based single sign-on is not currently supported.
Operator access
Sumarii staff do not access customer data as a matter of routine.
Access occurs only for support at your request, or for investigating a system fault. It does not occur for any other purpose, and never for analysis, review, or product development.
Backups and availability
The application database is backed up daily.
Stored media is held on infrastructure with built-in replication and is resilient to underlying hardware failure.
If a service incident affects your data, we will notify affected users by email at the address registered to the account.
Subprocessors
We use the following subprocessors. Each processes data only within the stated purpose.
| Purpose | Processing region |
|---|---|
| Database, authentication, object storage (Supabase) | Japan (Tokyo) |
| Audio and media file storage | Japan (Tokyo) |
| Minutes generation and chat (via API) | Japan (Tokyo) |
| CDN and site security (Cloudflare) | Japan (Tokyo) |
| Speech recognition (via API) | United States |
| Transactional email | United States |
| Payment and subscription management (Stripe) | United States |
For subprocessors outside Japan, we ensure through contract a structure conforming to the standards under APPI Article 28(1).
Speech recognition and AI inference vendors are disclosed under NDA. Contact help@sumarii.com.
We will notify registered users by email before adding a subprocessor that processes customer content.
Understanding the external environment (外的環境の把握)
Where personal data is handled outside Japan, we assess that country’s personal data protection regime and apply safety management measures accordingly.
Personal data is handled in Japan. The only exceptions are speech recognition, transactional email delivery, and payment processing, which are performed in the United States.
Countries where personal data is handled: Japan and the United States.
Export
Sessions can be exported as docx, txt, srt, and audio. PDF is not currently supported.
Related documents
- Security checklist (item-by-item answers for vendor reviews)
- Information Security Basic Policy
- Privacy Policy
- Terms of Service
- Notation based on the Act on Specified Commercial Transactions
Reporting a vulnerability
If you find a security issue in Sumarii, contact help@sumarii.com. Steps to reproduce are appreciated. Please do not publish details of the vulnerability or any customer data before we have had a chance to investigate.