Security and Trust: Data Protection and Storage Policy
Last updated: August 2026
Sumarii handles meeting audio, transcripts, and minutes. We treat personal information in accordance with Japan’s Act on the Protection of Personal Information (APPI) and other applicable law.
In short
- We do not use your audio, transcripts, or minutes to train AI models, and neither do our subprocessors.
- Our AI subprocessors do not retain your data after processing.
- Your data is stored on infrastructure in Japan.
- Sessions go to Trash first; delete from Trash or delete your account for permanent removal.
AI and training
Your audio, transcripts, and generated minutes are never used to train AI models, by us or by any of our subprocessors.
Our AI subprocessors operate under zero-retention terms. Your data is processed and discarded. It is not stored on their systems after the request completes.
Where your data is stored
Meeting audio, transcripts, and minutes are stored on infrastructure located in Japan.
Speech recognition is processed via an API provider; no copy of your audio is retained by that provider after processing. Transactional email delivery and payment processing (Stripe) use service providers.
Deletion and retention
Deleting a session moves it to Trash. You can restore it from Trash.
Permanent deletion happens when you delete a session from Trash, or when you delete your account. Then:
- Audio is destroyed immediately (it is outside the application database and is not in database backups).
- Transcript, minutes, and metadata are removed from the live system immediately. Residual copies in database backups are purged within 7 days.
- Account deletion also permanently deletes the workspace and settings.
The one exception after account deletion is your email address, which we retain for as long as necessary to prevent repeated use of the free tier through re-registration. It is not used for any other purpose.
Encryption
- All traffic between your browser and Sumarii is protected with HTTPS.
- Stored data is encrypted at rest.
- Audio files are never served from public URLs. They are retrievable only through short-lived signed URLs.
Access control
- An authenticated session is required to use the service. By design, no unauthenticated third party can reach your data.
- Data is isolated per workspace, with access enforced at the database layer through row-level security.
- Sign-in is available with email and password, Google, or Microsoft. Optional authenticator-app multi-factor authentication (TOTP) can be enabled in account settings. Accounts using Google or Microsoft sign-in may also inherit MFA configured on those provider accounts.
- SAML-based single sign-on is not currently supported.
Operator access
Sumarii staff do not access customer data as a matter of routine.
Access occurs only for support at your request, or for investigating a system fault. It does not occur for any other purpose, and never for analysis, review, or product development.
Backups and availability
The application database is backed up daily.
Stored media is held on infrastructure with built-in replication and is resilient to underlying hardware failure.
If a service incident affects your data, we will notify affected users by email at the address registered to the account.
Subprocessors
We use the following subprocessors. Each processes data only within the stated purpose.
| Purpose |
|---|
| Database, authentication, object storage (Supabase) — stored in Japan |
| Audio and media file storage — Japan |
| Minutes generation and chat (via API) |
| CDN and site security (Cloudflare) |
| Speech recognition (via API) |
| Transactional email |
| Payment and subscription management (Stripe) |
Providers process data under contractual safeguards.
Speech recognition and AI inference vendors are disclosed under NDA. Contact help@sumarii.com.
We will notify registered users by email before adding a subprocessor that processes customer content.
Countries where data is handled
Countries where personal data is handled: Japan.
Export
Sessions can be exported as docx, txt, srt, and audio. PDF is not currently supported.
Related documents
- Security & trust (overview)
- Security checklist (item-by-item answers for vendor reviews)
- Information Security Basic Policy
- Privacy Policy
- Terms of Service
- Notation based on the Act on Specified Commercial Transactions
Reporting a vulnerability
If you find a security issue in Sumarii, contact help@sumarii.com. Steps to reproduce are appreciated. Please do not publish details of the vulnerability or any customer data before we have had a chance to investigate.