Skip to content

Privacy Policy

Last updated: September 3, 2026

This document is a plain-language template and a starting point. It is not legal advice; have counsel review and adapt it before you rely on it.

1. Who this covers

Prosody is a business-to-business meeting-intelligence platform sold to companies (“customers”). If you use Prosody because your employer has an account, your employer is the controller of your data and their own policies also apply. This policy explains what Prosody does with data on their behalf and on ours.

2. What we collect

  • Account information — name, work email, company name, hashed password, and role within the workspace.
  • Uploaded transcripts — the meeting transcript files you export from Zoom or Microsoft Teams and upload, and the speaker segments parsed from them.
  • OAuth tokens — access and refresh tokens for the Jira or ClickUp workspace you connect, stored encrypted at rest.
  • Derived data — per-line Valence, Arousal and Dominance scores, the mood timeline, detected tense moments, and the draft action items generated from a transcript.
  • Review feedback — the confirm, edit and reject decisions your reviewers make on drafts.
  • Operational data — logs, timestamps and basic usage metrics needed to run and secure the service.

3. How we use it

We use this data only to provide and operate the service: parsing transcripts, scoring emotional tone, drafting action items, creating issues in your connected tools once a human confirms them, generating meeting reports, sending transactional email, and producing your company-wide analytics. We also use aggregated, non-identifying operational metrics to keep the service reliable and secure.

We do not sell transcripts or personal data, and we do not use your transcript content, emotion scores or action items to train machine-learning models.

4. Subprocessors

We share the minimum data necessary with a small set of subprocessors that help us run the service:

  • Anthropic — the Claude API receives transcript text and emotion scores to draft action items. This is the only place transcript content is sent outside Prosody.
  • Atlassian (Jira) and ClickUp — receive the contents of a ticket you have confirmed, so that it can be created in your workspace.
  • Our email provider — receives the recipient address and message content for transactional email such as invitations and notifications.
  • Our cloud hosting and database provider — stores and processes data on our behalf under contract.

A current list of subprocessors is available on request; material additions will be announced to customer administrators before they take effect.

5. Retention

Transcripts, derived scores and action items are retained for the life of your workspace so that history and analytics remain available. You can delete an individual meeting, or an entire workspace, at any time from the application; deletion removes the associated transcripts, scores and drafts from our production systems, with backups aging out on a rolling schedule. Account records tied to billing or legal obligations may be kept longer as required by law.

6. Tenant isolation and security

Each customer's data is strictly isolated from every other tenant across storage and processing. OAuth tokens are encrypted at rest using Fernet symmetric encryption. Data is transmitted over TLS. Access to production data by Prosody staff is limited to what is needed to operate and support the service.

7. Your rights

Depending on your location, you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing. Workspace administrators can action most of these directly in the application, including exporting and deleting data. For anything else, or if you are an end user whose employer holds the account, contact us and we will route your request appropriately.

8. Changes to this policy

We may update this policy as the product changes. When we make material changes we will update the date above and notify customer administrators.

9. Contact

Questions about privacy or a data request: contact us.