Privacy policy
Last updated: 2 October 2026
Punkto is a tool for running structured meetings. This policy says what we collect, why, where it is processed, and which rights you have. It follows the General Data Protection Regulation (EU 2016/679).
1. Controller
Punkto is operated by an independent publisher based in France (SIREN 801 500 802). Questions about your personal data: contact@punkto.app
2. Data we collect
2.1 Account
- Email — the identifier used to sign in.
- Display name — chosen by you, editable later. If you skip it, we use the part of the email before the @.
- Plan — Free, Pro, Team, or Enterprise.
- Creation date of the account.
- Password — never stored in clear text. Hashed with Argon2id (Better Auth).
2.2 Session
- Title and type of the session.
- Scheduled date and time, if you set one.
- Board content — cards, votes, chat, shared files, action items, reactions.
- Participant emails typed into the board so they can receive the summary.
- Duration and status of the session.
2.3 Recording (Pro and above)
- Audio — stored temporarily on our EU server, sent to Mistral (France) for the transcript, then deleted once the transcript and the summary are saved. If transcription fails, the file is deleted within 24 hours. The account keeps the text, not the audio. There is no player and no download.
- Transcript — text produced by Mistral Voxtral, stored encrypted (AES-256-GCM).
- Summary — text produced by Mistral Small, stored encrypted the same way.
2.4 Payment
Card data is handled by Stripe. Punkto does not store the card number, the expiry date, or the CVV. We keep the subscription status and the Stripe customer id tied to your email.
2.5 Technical data
- Session cookie — Better Auth, authentication only.
- Language — cookie
punkto_locale. - IP address — not kept as a profile. Abuse limits can hold an address for a short window.
We do not collect an advertising profile, a browsing history for sale, or a browser fingerprint for tracking.
3. Legal bases (GDPR article 6)
- Contract (art. 6§1 b) — account, sessions, recordings, and payments, so we can provide the service you signed up for.
- Consent (art. 6§1 a) — the host turns recording on, and is responsible for telling participants and getting their agreement before it starts.
- Legitimate interest (art. 6§1 f) — security of the platform and abuse prevention (rate limits, short technical logs).
4. Why we process it
- Run the meeting in real time.
- Produce a transcript and a summary when the host asks.
- Email that summary to the addresses the host entered.
- Manage the subscription and the payment.
- Keep the service secure and available.
Never: third-party advertising, ad profiling, sale of data, or training of AI models on your content.
5. Where it lives
Meeting data is processed in the European Union. The application, the database, file storage, real-time sync, and the audio/video server run on our own machines at Hetzner (EU). LiveKit is software we host ourselves. LiveKit Inc. does not receive the stream.
Two processors sit outside that path, and only for what their role needs. Stripe, Inc. (United States) charges the card, under standard contractual clauses. If you choose “Continue with Google”, Google LLC (United States) receives the sign-in request. Meeting content is not part of either request.
Transcription and the summary go to Mistral AI (France). Transactional email goes to Brevo (France).
6. Security
- Transport — HTTPS/TLS. LiveKit media uses DTLS-SRTP.
- Transcripts and summaries — encrypted in the application with AES-256-GCM before they are stored. Passwords are hashed with Argon2id.
- Board content — cards, chat, and action items are stored as text in our EU database. Access is checked in the application, against the authenticated owner. This is not row-level security in the database, and it is not end-to-end encryption of the board.
- Confidential sessions — files are encrypted in the browser (AES-256-GCM) before upload. The key stays in the URL fragment (
#k=), which the browser does not send to the server. Punkto cannot read those files. Cards and chat in that mode are not covered by that key.
7. How long we keep it
- Account — until you delete it, from Account in the dashboard. Deletion removes the sessions, the transcripts, the summaries, and the authentication data.
- Boards — kept while the account exists. A board can carry a purge date. When that date passes, the board is deleted.
- Audio — temporary file on our EU server. Deleted once the transcript is saved, or within 24 hours if transcription fails. The text remains until the account is deleted.
- Ephemeral sessions — nothing is written to the database. The board disappears when it closes.
- Confidential files — removed from the server when the session ends.
- Technical logs — kept for at most 30 days.
- Backups — rolling 7 days, then overwritten.
8. Cookies and measurement
Cookies we set are limited to what the service needs:
- Session cookie — Better Auth. It keeps you signed in.
punkto_locale— your language. One year.
A page counter (Umami) runs on our own server. It does not set a tracking cookie and it is not a third party. We do not use Google Analytics, a Meta pixel, Mixpanel, or Amplitude.
9. Your rights
Under articles 15 to 22 of the GDPR you can ask for:
- Access — a copy of your personal data.
- Rectification — a correction.
- Erasure — delete the account and the data that goes with it, from the dashboard.
- Portability — your data in a structured, readable format.
- Objection — to a processing based on legitimate interest.
- Restriction — a pause while a dispute is examined.
- Withdrawal of consent — at any time, for processing that relied on consent. It does not undo what was already done.
Write to contact@punkto.app. We answer within 30 days. If a dispute stays unresolved, you can contact your national authority. In France, that is the CNIL — cnil.fr.
10. Recording and participants
Only the host can start a recording, and only on Pro and above. The host is responsible for telling participants and for obtaining their agreement before it starts, under the GDPR and the law of their country.
Punkto does not send an automatic notice to every participant when a recording starts. The host does that, in the room.
11. Minors
Punkto is for professional use. It is not meant for anyone under 16. If you know of such a use, write to contact@punkto.app.
12. Processors
Infrastructure we run ourselves (the application, PostgreSQL, file storage, LiveKit) is not a processor. The companies below are.
| Processor | Role | Where the data is | Safeguards |
|---|---|---|---|
| Hetzner Online GmbH | Servers we rent (EU) | European Union | GDPR. We operate the machines. |
| Mistral AI | Transcript and summary | France | API terms: content is not used to train models. |
| Brevo | Transactional email | France / EU | Data processing agreement. |
| Stripe, Inc. | Card payments | United States | Standard contractual clauses, PCI-DSS level 1. No meeting content. |
| Google LLC | Optional sign-in | United States | Only if you choose Google. No meeting content. |
13. Changes
We can update this policy. If a change affects your rights, we email you at least 15 days before it applies. The current text is this page.
14. Contact
Questions about this policy, or a request to exercise a right: contact@punkto.app