Legal / Privacy
Privacy Policy.
What we collect, why, and the choices you have.
1. Overview
This policy explains how Teamy ("we", "us") handles personal data when you use getteamy.com and our applications (the "Service"). We act as the data controller for account and usage data. For content your team stores in a workspace, the workspace owner decides what is collected and shared there, and we process it on their behalf to provide the Service.
The short version: we collect what we need to run a team workspace, we do not sell personal data, and we do not use your content to train AI models.
2. What we collect
Account data. Name, email address, password (stored only as a salted hash), avatar, job title, timezone, and your notification, marketing and appearance preferences.
Workspace content. Documents, tasks, comments, uploaded media, meeting transcripts and other material you or your teammates put into a workspace. This may contain personal data; what it contains is up to you and your team.
Billing data. Plan, seat count and invoice history. Card details are collected and stored by Stripe, our payment processor; we never see your full card number.
Usage data. Product analytics events (pages and features used, with your user id), application logs and error reports. Analytics are processed in the EU through PostHog.
Viewing statistics on shared media. When someone views content through a public share link, we count views and watch time using a session identifier and a one-way, daily-rotating hash of network data. We cannot identify visitors from it, and we do not build viewer profiles.
Support conversations. If you use the in-app support chat or email us, we keep the conversation to help you and to improve support. The support chat runs on our own infrastructure; no third party receives it.
Cookies. We use a session cookie to keep you signed in and functional cookies tied to analytics and support chat. We do not use advertising cookies.
3. Why we process data and on what legal basis
- To provide the Service (account, content, billing, sharing): performance of a contract.
- To secure the Service (logs, abuse prevention, rate limiting): legitimate interest in protecting the Service and its users.
- To improve the product (analytics): legitimate interest in understanding how the product is used; analytics identifiers are scoped to the product.
- To send transactional email (verification codes, invitations, notifications you have enabled): performance of a contract.
- To send product updates: your consent, given at signup or in settings, withdrawable at any time.
- To comply with the law (tax, accounting, valid legal requests): legal obligation.
4. Meeting transcription and AI connectors
Meeting audio recorded with our desktop application is transcribed on your device. The audio itself is not uploaded; the transcript is uploaded to your workspace only when you save it, and is then workspace content like any document.
If you connect a third-party AI assistant to your workspace (for example Claude, ChatGPT or another MCP-compatible tool), content that the assistant requests is sent to that provider under its own privacy policy. You choose whether to connect an assistant and which provider to use; we log connector activity in your workspace so the team can see what it accessed.
5. Who we share data with
We share personal data only with the processors we need to run the Service:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting and file storage | Germany / EU |
| Stripe | Payment processing | EU / US |
| Resend | Transactional email delivery | US |
| PostHog (EU cloud) | Product analytics and logs | EU |
We also share data when you direct us to (public share links, invited teammates, AI connectors you enable) and when the law requires it. Where a processor is outside the EEA, transfers rely on Standard Contractual Clauses or an adequacy decision.
6. Retention
- Account data is kept for as long as your account exists.
- Deleted workspaces, documents and tasks are soft-deleted first, so accidental deletion can be reversed, then purged from live systems; backups roll off on a fixed schedule after that.
- If you delete your account, we remove or anonymize your personal data within 30 days, except records we must keep for legal reasons (for example invoices).
- Verification codes expire within minutes; session cookies expire when your session ends.
- Aggregated statistics that cannot identify you may be kept indefinitely.
7. Security
Data is encrypted in transit (TLS) and at rest with our storage providers. Passwords are stored as salted hashes and are never logged. Access to production systems is limited to the people who operate the Service. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you and the relevant authority as the law requires.
8. Your rights
If you are in the EEA, the UK or a jurisdiction with similar rules, you can ask us to access, correct, delete, or export your personal data, to restrict or object to processing, and you can withdraw consent at any time. You can also complain to your data-protection authority.
For content inside a workspace owned by someone else (for example your employer), direct your request to the workspace owner; we will assist them as their processor.
To exercise any right, email mantas@getteamy.com. We answer within 30 days.
9. Children
The Service is not directed at children and may not be used by anyone under 16. We delete accounts we discover to belong to children.
10. Changes to this policy
When we change this policy we update the version date at the top. For material changes we will ask you to review and accept the new version in the app, and may also notify you by email. Earlier versions are available on request.
11. Contact
Privacy questions and requests: mantas@getteamy.com.