← Home

Privacy policy

Last updated: 2 October 2026

Punkto is a tool for running structured meetings. This policy says what we collect, why, where it is processed, and which rights you have. It follows the General Data Protection Regulation (EU 2016/679).

1. Controller

Punkto is operated by an independent publisher based in France (SIREN 801 500 802). Questions about your personal data: contact@punkto.app

2. Data we collect

2.1 Account

  • Email — the identifier used to sign in.
  • Display name — chosen by you, editable later. If you skip it, we use the part of the email before the @.
  • Plan — Free, Pro, Team, or Enterprise.
  • Creation date of the account.
  • Password — never stored in clear text. Hashed with Argon2id (Better Auth).

2.2 Session

  • Title and type of the session.
  • Scheduled date and time, if you set one.
  • Board content — cards, votes, chat, shared files, action items, reactions.
  • Participant emails typed into the board so they can receive the summary.
  • Duration and status of the session.

2.3 Recording (Pro and above)

  • Audio — stored temporarily on our EU server, sent to Mistral (France) for the transcript, then deleted once the transcript and the summary are saved. If transcription fails, the file is deleted within 24 hours. The account keeps the text, not the audio. There is no player and no download.
  • Transcript — text produced by Mistral Voxtral, stored encrypted (AES-256-GCM).
  • Summary — text produced by Mistral Small, stored encrypted the same way.

2.4 Payment

Card data is handled by Stripe. Punkto does not store the card number, the expiry date, or the CVV. We keep the subscription status and the Stripe customer id tied to your email.

2.5 Technical data

  • Session cookie — Better Auth, authentication only.
  • Language — cookie punkto_locale.
  • IP address — not kept as a profile. Abuse limits can hold an address for a short window.

We do not collect an advertising profile, a browsing history for sale, or a browser fingerprint for tracking.

3. Legal bases (GDPR article 6)

  • Contract (art. 6§1 b) — account, sessions, recordings, and payments, so we can provide the service you signed up for.
  • Consent (art. 6§1 a) — the host turns recording on, and is responsible for telling participants and getting their agreement before it starts.
  • Legitimate interest (art. 6§1 f) — security of the platform and abuse prevention (rate limits, short technical logs).

4. Why we process it

  • Run the meeting in real time.
  • Produce a transcript and a summary when the host asks.
  • Email that summary to the addresses the host entered.
  • Manage the subscription and the payment.
  • Keep the service secure and available.

Never: third-party advertising, ad profiling, sale of data, or training of AI models on your content.

5. Where it lives

Meeting data is processed in the European Union. The application, the database, file storage, real-time sync, and the audio/video server run on our own machines at Hetzner (EU). LiveKit is software we host ourselves. LiveKit Inc. does not receive the stream.

Two processors sit outside that path, and only for what their role needs. Stripe, Inc. (United States) charges the card, under standard contractual clauses. If you choose “Continue with Google”, Google LLC (United States) receives the sign-in request. Meeting content is not part of either request.

Transcription and the summary go to Mistral AI (France). Transactional email goes to Brevo (France).

6. Security

  • Transport — HTTPS/TLS. LiveKit media uses DTLS-SRTP.
  • Transcripts and summaries — encrypted in the application with AES-256-GCM before they are stored. Passwords are hashed with Argon2id.
  • Board content — cards, chat, and action items are stored as text in our EU database. Access is checked in the application, against the authenticated owner. This is not row-level security in the database, and it is not end-to-end encryption of the board.
  • Confidential sessions — files are encrypted in the browser (AES-256-GCM) before upload. The key stays in the URL fragment (#k=), which the browser does not send to the server. Punkto cannot read those files. Cards and chat in that mode are not covered by that key.

7. How long we keep it

  • Account — until you delete it, from Account in the dashboard. Deletion removes the sessions, the transcripts, the summaries, and the authentication data.
  • Boards — kept while the account exists. A board can carry a purge date. When that date passes, the board is deleted.
  • Audio — temporary file on our EU server. Deleted once the transcript is saved, or within 24 hours if transcription fails. The text remains until the account is deleted.
  • Ephemeral sessions — nothing is written to the database. The board disappears when it closes.
  • Confidential files — removed from the server when the session ends.
  • Technical logs — kept for at most 30 days.
  • Backups — rolling 7 days, then overwritten.

8. Cookies and measurement

Cookies we set are limited to what the service needs:

  • Session cookie — Better Auth. It keeps you signed in.
  • punkto_locale — your language. One year.

A page counter (Umami) runs on our own server. It does not set a tracking cookie and it is not a third party. We do not use Google Analytics, a Meta pixel, Mixpanel, or Amplitude.

9. Your rights

Under articles 15 to 22 of the GDPR you can ask for:

  • Access — a copy of your personal data.
  • Rectification — a correction.
  • Erasure — delete the account and the data that goes with it, from the dashboard.
  • Portability — your data in a structured, readable format.
  • Objection — to a processing based on legitimate interest.
  • Restriction — a pause while a dispute is examined.
  • Withdrawal of consent — at any time, for processing that relied on consent. It does not undo what was already done.

Write to contact@punkto.app. We answer within 30 days. If a dispute stays unresolved, you can contact your national authority. In France, that is the CNIL — cnil.fr.

10. Recording and participants

Only the host can start a recording, and only on Pro and above. The host is responsible for telling participants and for obtaining their agreement before it starts, under the GDPR and the law of their country.

Punkto does not send an automatic notice to every participant when a recording starts. The host does that, in the room.

11. Minors

Punkto is for professional use. It is not meant for anyone under 16. If you know of such a use, write to contact@punkto.app.

12. Processors

Infrastructure we run ourselves (the application, PostgreSQL, file storage, LiveKit) is not a processor. The companies below are.

ProcessorRoleWhere the data isSafeguards
Hetzner Online GmbHServers we rent (EU)European UnionGDPR. We operate the machines.
Mistral AITranscript and summaryFranceAPI terms: content is not used to train models.
BrevoTransactional emailFrance / EUData processing agreement.
Stripe, Inc.Card paymentsUnited StatesStandard contractual clauses, PCI-DSS level 1. No meeting content.
Google LLCOptional sign-inUnited StatesOnly if you choose Google. No meeting content.

13. Changes

We can update this policy. If a change affects your rights, we email you at least 15 days before it applies. The current text is this page.

14. Contact

Questions about this policy, or a request to exercise a right: contact@punkto.app