Weaver Privacy Policy
Last updated: 3 September 2026
Who we are
Weaver is a work tool made by a small independent team. It turns scattered meeting notes into one connected picture: who was there, what was decided, and what needs doing. Our goal is to make that useful without turning your working conversations into someone else's product.
privacy@weavecompanion.com
What we collect
Account information. When you sign up we store your email address, a hashed (unreadable) version of your password, and your first name. We never store your password in plain text.
Meeting content. Transcripts you paste, files you upload, audio you record in the Weaver mobile app, and recordings captured by the meeting bot when you connect a live call. These are stored on our servers because they are the material Weaver works from.
Extracted data. Weaver derives structured information from your meetings: participants, decisions, action items, project summaries, and vector embeddings used for search. This is tied to your account and used only to answer your questions and organise your projects.
Usage and billing. If you subscribe, Stripe processes your payment. We receive a customer ID and subscription status. We never see or store full card details. We log basic usage counts for abuse prevention.
Technical data. Standard server logs (IP address, timestamp, HTTP status code) retained for up to 30 days for security monitoring.
What we do not collect
- Location data
- Contacts or calendar access beyond a meeting link you explicitly paste
- Advertising identifiers
- Device usage data or analytics beyond what is described above
Recording with the mobile app
The Weaver app for iPhone and Android can record through your device's microphone, either to capture a meeting you are in or to take a note you dictate to yourself. Recording only ever happens after you tap record, and the app shows you that it is recording for as long as it continues, including a persistent notification on Android while the screen is locked.
Audio is held on your device only until the recording is uploaded for transcription, and the local copy is deleted as soon as it has been sent. We do not access your microphone at any other time, and the app never records in the background without you starting it.
You are responsible for making sure that recording a given conversation is permitted, and that the people in it are aware, as required where you and they are located.
Recording live calls
When you connect a Zoom, Teams or Google Meet call, a bot joins the meeting and is visible to everyone in it. The same responsibility applies: please make sure recording is permitted and that participants know.
How your data is used
Your data is used for one purpose, which is making Weaver work for you.
Transcripts, audio and questions are processed by Google's Gemini API to transcribe speech, extract structure and generate answers. Google's API terms prohibit using API inputs to train their models. Extracted data is stored on our infrastructure and queried on your behalf when you ask a question.
We do not sell your data. We do not share it with advertisers. We do not use it to train AI models.
Third-party services
- Google Gemini, for transcription, extraction and answering questions.
- Recall.ai, only when you connect a live meeting bot to a call. Weaver uses Recall's European region.
- Stripe, for payment processing.
- Resend, for transactional email such as address verification.
No other third parties receive your data.
Data retention and deletion
You can delete an individual meeting or an entire project at any time. Deleting a project removes its meetings, transcripts, decisions, action items and embeddings.
You can permanently delete your account from the account settings in the app or on the web. Deleting your account irreversibly erases your profile and credentials, all meeting content, and all extracted data. There is no waiting period and we do not keep a shadow copy.
Stripe retains billing records as required by financial regulations. We cannot delete those on your behalf, and they contain no meeting content.
Security
- Meeting content, including transcripts, titles, project names and summaries, is encrypted at rest with AES-256-GCM, using a separate random nonce for every stored value.
- Passwords are hashed with Argon2id, the current OWASP recommendation, using the argon2-cffi defaults. Older accounts still holding a legacy PBKDF2 hash are upgraded to Argon2id automatically the next time they sign in.
- Data in transit is encrypted with TLS.
- Access to production systems is limited to the core team.
Children
Weaver is not intended for users under 16. We do not knowingly collect data from children.
Your rights
Depending on where you live, you may have the right to access, correct or export your data, in addition to the deletion right described above. Contact privacy@weavecompanion.com for any of these requests. We will respond within 30 days.
Changes to this policy
If we make material changes we will notify you by email and update the date at the top of this page. Continued use of Weaver after changes constitutes acceptance.
Contact
privacy@weavecompanion.com
See also our Terms of Use.