Security and privacy
Understand what happens to your meeting data
Meeto encrypts meeting media in transit using WebRTC. Recording and AI capture are opt-in features for paid hosts, meeting content is not used for AI training, and owners control sharing of saved materials. This overview explains the practical limits as well as the controls.
Encryption protects media while it travels
Meeto uses WebRTC (DTLS-SRTP) encryption in transit. This protects the media connection between a participant's device and the meeting infrastructure. Meeto is not end-to-end encrypted; server-side features such as recording and AI processing can access media when enabled.
The difference matters when deciding whether a service fits your organisation's requirements. Encryption in transit does not mean that only the participants can decrypt the content. Review the call data section of the Privacy Policy before using Meeto for information subject to special confidentiality or processing requirements.
Browser camera and microphone permissions remain under your control. Grant them to join with audio or video, and use the call controls to turn devices off when you do not want to transmit.
Recording and AI capture are an explicit choice
Cloud recording and AI capture require a paid host and are opt-in. A visible indicator shows when capture is active. Before starting capture, tell participants what will be saved, why it is needed and who will receive it. The host is responsible for the consent required by applicable law and the Terms of Service.
Meeting content is not used to train AI models. Enabling transcription or an AI summary still means that content is processed to provide that feature. You can find the processing providers and their roles in the Privacy Policy's provider list.
Review a generated summary before relying on it or sharing it. A useful recap is still an AI output and may omit context or contain mistakes. Keep access to the resulting recording, transcript and summary aligned with the purpose of the meeting.
Saved content and shared links need their own controls
| Content | What to expect |
|---|---|
| In-meeting chat | Deleted when the meeting ends |
| Cloud recording | Automatically expires after 90 days; the owner can delete it earlier |
| Transcript and AI recap | Can remain after media expiry, until the host deletes them or the account is deleted |
| Shared meeting materials | Anyone with the shared link can open them while sharing is enabled |
| Account deletion | Available through account settings; legal retention exceptions apply |
Recording expiry does not automatically delete its transcript or recap. If you need to remove the full saved record of a conversation, check each type of material. The complete retention schedule also covers account records, meeting metadata, security logs and legally required preservation.
Treat meeting and recording links as access information. Share them only with intended recipients. The owner can disable sharing or delete saved materials; this does not retrieve copies that someone has already downloaded or captured outside Meeto.
When an employer or another organisation hosts the meeting, ask that organisation about its recording and data handling choices. It may control the meeting content and decide how to respond to access or deletion requests.
Restrict an embedded widget to your website domains
A Meeto widget uses a public embed key with the mk_live_ prefix. The key is designed to appear in browser code. Access is restricted to the website origins configured for the key, so add only the domains where you intend to use the widget.
Keep private credentials, host secrets and management tokens out of website source code. Follow the developer documentation when setting up allowed domains and testing an embed on your production site.
If you embed Meeto in your own product, tell your users that meetings are provided through Meeto and give any notices or obtain any consents your use requires. The service's privacy policy also applies to calls entered through a widget.
Security questions, reports and privacy requests
Contact support@meeto.me for a suspected security issue, a privacy request or a question about using Meeto in your organisation. Meeto is operated by KeepFlow L.L.C-FZ, Dubai, U.A.E.
For a technical report, describe the affected feature, when the problem occurred and the steps needed to reproduce it. Share a minimal example that avoids other people's data. Do not email passwords or private access tokens.
This page is a practical overview. The Privacy Policy contains the full data handling terms, processing locations and rights information. If you need a particular certification, contractual commitment or processing arrangement, ask about that requirement before relying on it.
Frequently asked questions
Are Meeto video meetings encrypted?
Meeting media uses WebRTC (DTLS-SRTP) encryption in transit. Meeto is not end-to-end encrypted: the service relays media, and server-side recording or AI processing can access content when those features are enabled.
Are meetings recorded automatically?
Cloud recording and AI capture are opt-in features that require a paid host. A visible indicator appears when capture is active. Hosts are responsible for telling participants about recording and obtaining the consent required for their meeting.
Does Meeto use meeting content to train AI models?
No. Meeting content is not used to train AI models. When the host enables AI features, content is processed to provide the requested transcription or summary. The Privacy Policy describes the providers used to deliver the service.
What happens when a recording expires?
Cloud recordings automatically expire after 90 days, and the owner can delete them sooner. Transcripts and AI recaps can remain after the recording expires, until the host deletes them or the account is deleted. Legal preservation requirements may override ordinary retention periods.
How can I report a security issue or request deletion?
Email support@meeto.me with a description of the issue or request. For a suspected vulnerability, include the affected feature and steps to reproduce it without exposing other people's data. Account deletion is also available from account settings.
Put it to work
Open your Meeto account to set it up, or explore the working product first.