Dinner Minutes — Privacy Policy
Draft v0.1 · 2026-09-06 · NOT YET IN EFFECT. Prepared for attorney review (Ryan @ KKOS) per wayfinder ticket 19. Bracketed items are open decisions or providers not yet chosen.
This policy explains what Dinner Minutes collects, why, and how long we keep it. The short version: your records live on your device and in your inbox, not on our servers. We process a meeting's inputs long enough to produce your PDFs, deliver them, and then delete our copy.
1. What we collect
Account information. Your email address and, if you provide it, your name. Accounts are managed by our authentication provider, Clerk. Sign-in is by magic link or Google/Apple sign-in; we do not store passwords.
Attestations. When you add an entity you attest that you are authorized to keep its records and are preparing them for your own entity. We keep the text of that attestation, your account identifier, and the timestamp, permanently. This is our record that the Service was used as intended.
Meeting inputs, in flight. To compile a meeting you send us: the entities and attendees meeting, the agenda, two receipt photos, and a dictated recap (audio and its transcript). We use these only to produce your records.
Billing. Payment is handled by Stripe. We keep the Stripe customer identifier and the fee history needed to bill you (meeting date, pre-tip amount, fee). We never see or store full card numbers.
Waitlist. If you join the waitlist on our website, we store your email address in Clerk until we invite you or you ask to be removed.
Technical logs. Standard server logs (timestamps, request paths, error messages) that do not include the contents of your meetings. Our website currently sets no analytics or advertising cookies. [Decision: add privacy-respecting analytics, e.g. Cloudflare Web Analytics, yes/no.]
2. How we use it
To operate the Service: authenticate you, read receipts, transcribe and draft, generate PDFs, email them to you, bill you, and support you. To protect the Service and its users. To meet legal obligations. We do not sell personal information, do not share it for advertising, and do not use your meeting content to train AI models.
3. How long we keep it
| Data | Retention |
|---|---|
| Receipt photos, recordings, transcripts, agendas, generated PDFs | Deleted from our servers as soon as your device confirms it received them. If no confirmation arrives, deleted within about 1 hour anyway. |
| Emailed PDFs | Delivered to your inbox. Your inbox is the archive; we keep no copy after delivery is confirmed. |
| Attestations | Kept permanently. |
| Account information | Kept while your account is open; deleted within 30 days of account closure, except where law requires longer. |
| Billing records | Kept as long as law and our payment processor require, typically 7 years. |
| Waitlist email | Until invited or removed on request. |
4. What stays on your device
The app stores your entity roster, meeting history, coverage records, and finished PDFs in your browser's local storage on the device you use. This data is device-locked in the current version: it does not sync to other devices and it is not on our servers. Clearing browser data or uninstalling the app removes it. Your emailed PDFs are unaffected.
5. Who processes data for us
We use a small number of service providers, each bound to use data only to provide their service to us:
- Clerk — authentication, attestations, waitlist.
- Stripe — payments.
- Render — application hosting (in-flight meeting processing).
- Cloudflare — website hosting and network security.
- [Transactional email provider — Postmark/Resend, not yet chosen] — delivering your PDFs.
- [Receipt reading — AWS Textract, not yet confirmed] — reading receipt photos.
- [Transcription and drafting — provider not yet confirmed] — transcribing recaps and drafting minutes. Contractually, these providers do not retain or train on your content. [Confirm each provider's zero-retention terms before launch.]
We disclose personal information when required by law or to protect rights and safety. We will tell you about a legal demand for your data unless prohibited from doing so. Because we keep no meeting content after delivery, there is usually nothing to produce.
6. Security
Data in transit is encrypted. Access to production systems is limited and logged. No system is perfectly secure; the design choice that matters most is that we hold as little as possible for as short a time as possible.
7. Your choices and rights
- Access and export. Everything the Service produces is already delivered to you by email and stored on your device.
- Deletion. Close your account from the app or by emailing us; we delete account data as described above. Attestations and billing records are retained as stated.
- Waitlist removal. Email us and we remove you.
- State privacy rights. Residents of California and other states with privacy laws may have rights to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information. Send requests to hello@dinnerminutes.app; we will verify and respond within the time the law allows.
8. Children
The Service is for adults acting for business entities. We do not knowingly collect information from anyone under 18.
9. Where data is processed
The Service is operated from the United States. If you use it from elsewhere, your data is processed in the US.
10. Changes
We will post changes here and email account holders about material changes at least 30 days before they take effect.
11. Contact
Dinner Minutes · Empire Oaks Estate LLC [confirm] · [mailing address] · hello@dinnerminutes.app