Last updated 1 September 2026
AVAY is a video meeting service with an AI participant that transcribes conversations, writes notes, and answers questions during a call. This policy describes exactly what data that involves, which companies process it, and where it is stored. It names them specifically rather than referring to "third parties", because a meeting is a private conversation and you are entitled to know who else is in the path.
Accounts are handled by Clerk. When you sign up we receive your email address, your name, and — if you sign in with Google or Apple — the profile information that provider returns. We do not receive or store your password.
A meeting is not recorded unless somebody records it. By default nothing is stored as media and only the text above is kept. If a host uses cloud recording, the audio and video of that meeting are stored as a file in Cloudflare R2 (United States) and listed on the Recordings page for the account that made it. A recording is kept until it is deleted — by you, from that page, or with your account.
If you connect an external system, the credential you provide is encrypted at rest with AES-256-GCM before it is stored, and the encryption key is held outside the database. Credentials are never returned to the browser after they are saved.
This is the disclosure that matters most, so it gets its own section. There are two paths and, on this service, both can be running during the same meeting.
The record is written on our servers. While transcription is on, short segments of your microphone audio are sent from your device to us and forwarded to OpenRouter, which turns them into text. That text is what the transcript, the notes and the meeting's memory are built from. We do not keep the audio after it has been recognised. This path works in every browser, which is why it exists: it used to happen only in Chrome and Edge, and everyone else was silently missing from the record.
The live caption on your own screen is drawn by your browser. It uses the browser's own speech recognition, which is not on-device, and which company receives that audio depends on the browser you are in — in every case under that company's privacy policy rather than ours, and without passing through our servers. It is also what hears the agent's name when you say it.
Wherever there is no live caption, you are still transcribed, by the path above.
Both happen only while transcription is switched on. With it off, no audio leaves your machine for either purpose and nothing is written down.
Transcript text, and the speaker names attached to it, are sent to a language model to generate the notes and to answer questions asked during the meeting. On avay.ai that model is Anthropic's, called directly. Transcript content leaves our servers for this purpose.
A deployment can instead be configured to reach a model through a router such as OpenRouter, which puts the router and whichever provider it forwards to in the path. That is not a change anybody can make quietly: the consent screen described below is generated from the endpoint the server is actually configured to call, so changing it asks everybody again rather than carrying an old answer forward.
If you attach a connector, the AI may call that external system on your behalf during a meeting, sending it whatever query is needed to answer the question. Connectors are scoped to the account that attached them, and a meeting host can switch any connector off for an individual meeting.
None of this begins until you have said it may. The first time you sign in, AVAY shows you a screen naming exactly what is sent, and to which companies — the same information as the table below — and asks you to agree. Nothing from your meetings is sent to your browser's speech recognition or to a language model until you do, and if you decline, the rest of AVAY goes on working: you can hold meetings, use video and chat, and read everything already recorded. Only the notes, decisions, actions and answers stop.
You can withdraw that permission at any time from your account page inside the app, and the model calls stop immediately. If we ever add or change a company in that list, we ask again rather than carrying your old answer forward — consent is to a named set of recipients, not to a category.
We do not send an AI service your email address, your name on the account, your payment details, or any video. We do not use your meeting content to train models. Every company named below is bound by a written agreement to process this data only on our instructions and to protect it to a standard equal to the one described in this policy; we do not send personal data to a processor that will not commit to that.
| Processor | What it receives | Where |
|---|---|---|
| Fly.io | All stored data — transcripts, notes, accounts | United States (iad) |
| Clerk | Identity and authentication data | United States |
| Microphone audio while transcription is on, in Chrome and Edge only, for the live caption drawn on your own screen; sign-in profile if you use Google | Google infrastructure | |
| OpenRouter | Microphone audio while transcription is on, for the speech recognition the meeting's record is written from | Routed to the speech provider |
| Anthropic | Transcript text and speaker names, sent for notes, decisions, action items and answers | Anthropic's infrastructure |
| Resend | Your email address and the contents of any email we send you — a meeting summary, the welcome message, or a lifecycle email if you asked for those | United States |
| Cloudflare | Audio and video streams when the relay or broadcasting is used, and cloud recordings stored at rest | Cloudflare network |
| Polar | Billing details for a subscription bought on avay.ai — we never see or store your card | Polar and its payment processor |
| Apple | Microphone audio while transcription is on, in Safari and in the iPhone app only, for the live caption drawn on your own screen; sign-in profile if you use Apple. Also billing for a subscription bought inside the iOS app — Apple tells us only that a subscription exists, which plan it is and when it renews, never your name, your address or your payment method | Apple's infrastructure |
| Your connectors | Only what a tool call requires, and only if you attach one | Whoever operates that server |
There are two kinds and they are governed differently, which is the distinction that matters and the one most policies leave out.
Email about your own account and your own meetings. The welcome message when you create an account, and a meeting's summary sent to somebody who asked for it during that meeting. These go to people who asked by doing the thing that produces them.
A short sequence about what AVAY does — three messages over about ten days. This is marketing, and it goes only to addresses recorded as having asked for it. Creating an account is not asking, and neither is typing your address into a meeting to be sent that meeting's notes: both are recorded as consent to hear about the thing you did, and nothing more.
Every email carries a one-click unsubscribe — in the message, and in the headers your mail program reads. It needs no account and no sign-in, it takes effect immediately, and an unsubscribed address is not written to again by any route, including the account and meeting email above.
We do not sell your address, and we do not give it to anybody to advertise to you. It reaches one company outside ours, Resend, which is what puts our mail in your inbox.
Meeting content is currently retained indefinitely until you delete it. Deleting a meeting removes its transcript, notes and chat from our database. Deleting your account removes the meetings you own.
A self-hosted deployment can set an automatic retention window with the
AVAY_RETENTION_DAYS setting, after which older meetings are purged.
A transcript captures everyone who spoke, not only the person who started it. If you turn transcription on, you are recording other people's words. Tell them. Some jurisdictions require the consent of everyone present before a conversation may be recorded or transcribed, and it is your responsibility to obtain it.
Traffic is encrypted in transit. Media between participants is carried over WebRTC, which is encrypted in transit by design. Connector credentials are encrypted at rest. Meeting content is not end-to-end encrypted — it cannot be, because the AI features require the service to read it.
AVAY is not intended for anyone under 16 and we do not knowingly collect their data.
If this policy changes materially we will update the date at the top of this page. This document describes the system as it actually behaves on the date shown.
Write to contact@avay.ai with any question about this policy or your data.