Privacy Policy — Tovma
Effective date: 14 July 2026
1. Introduction
Tovma is a meeting assistant that joins Google Meet calls as a visible participant ("◆ Tovma Bot"), records the audio, produces a transcript with speaker attribution, and emails a summary (recap) to the account holder. This policy explains what personal data we process, why, where it goes, and what rights you have. It applies to the service available at tovma.cc.
2. Who collects personal data?
The data controller is Anton Belov, an individual established at Nemanjina 3, 11000 Savski Venac, Belgrade, Serbia. You can reach us at contact@tovma.cc for anything in this policy.
3. Who is this policy addressed to?
Two groups of people:
- Users — the account holders who sign in with Google, connect their calendar, and invite Tovma to their meetings.
- Meeting participants — everyone else in a recorded meeting, whether or not they have any relationship with us. If you were in a meeting where Tovma was present, the sections on participant data and your rights apply to you.
4. How is data collected?
- From your account setup — when you sign in with Google and connect your Google Calendar.
- From meetings — the bot joins as a visible, named participant and records the meeting audio. Tovma does not support covert recording: the bot is always identifiable in the participant list.
- Automatically — technical logs generated by operating the service.
The meeting host is responsible for informing participants and obtaining any consent required by the laws that apply to them before the recording starts (see the Terms of Service). Participants who do not wish to be recorded can ask the host to remove the bot or can leave the meeting.
5. What personal data is collected?
| Category | Data | Source |
|---|---|---|
| Account data | Your Google account email and an OAuth token for your connected calendar (we never receive or store your Google password) | You / Google sign-in |
| Calendar data | Meeting titles, times, descriptions, join links, and organizer/attendee names and email addresses — read-only | Your connected Google Calendar |
| Meeting content | Audio recording of the meeting; transcript; speaker names and speaking timeline; AI-generated summary | The recorded meeting |
| Communications | Recap emails sent, support correspondence | You / the service |
| Technical data | Server logs, IP addresses, error reports | Automatic |
How we use it
- To provide the service (legal basis: contract) — joining meetings, recording, transcribing, generating and emailing recaps.
- To operate and secure the service (legal basis: legitimate interest) — logging, debugging, abuse prevention.
- To improve the service (legal basis: legitimate interest) — we may use meeting recordings and transcripts in de-identified form (names, emails, and other direct identifiers removed) to develop and improve our transcription and summarization technology, including training or fine-tuning models. We never sell your data, and we never use identified meeting content for training. Where the law gives you the right to object to this use, you may do so (see Section 9).
Google user data — Limited Use. Data obtained through Google APIs — your Google Calendar data and Google account information, including organizer and attendee names and email addresses wherever they appear (including inside transcripts) — is never used to train or improve AI/ML models. Tovma's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Security
Recordings, transcripts and recaps are stored on our own servers hosted at Hetzner (Germany), with access restricted to the operator. Data in transit is encrypted (TLS). Recap emails are sent from our own mail infrastructure (tovma.cc).
7. To whom is your data transmitted?
We use a small number of processors, each only for what the service needs:
| Processor | Purpose | Location |
|---|---|---|
| Vexa (Vexa.ai Inc.) | Primary meeting-bot infrastructure — joins the call and captures the audio; no meeting recordings are stored by Vexa by default | USA |
| Skribby (Skribe VOF) | Secondary meeting-bot infrastructure — joins the call and captures the audio | Belgium (EU) |
| Google (Gemini API) | Speech-to-text transcription | USA / EU |
| OpenRouter → Anthropic (Claude) | Generates the recap/summary from the transcript | USA |
We contractually prohibit our processors from using your meeting content for their own purposes, including training their own models. We do not sell personal data and do not share it with advertisers.
8. Is your data sent outside the European Union?
Yes. Meeting audio is captured by Vexa (USA), transcription is processed through the Google Gemini API, and the recap is generated via OpenRouter/Anthropic (USA). These transfers rely on Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Skribby is established in the EU (Belgium). Long-term storage of your recordings and transcripts is in Germany.
9. What are your rights?
Under the applicable data-protection law (the Serbian Personal Data Protection Act and, where it applies, the GDPR) you can: access your data, correct it, delete it, restrict or object to processing (including objecting to the de-identified improvement use in Section 5), receive a copy in portable form, and withdraw consent where processing is based on consent.
If you were a meeting participant and not a user: you have the same rights over the recordings and transcripts that include you. You can contact us directly at contact@tovma.cc to request deletion of a meeting's data, or ask the meeting host who invited the bot.
You also have the right to lodge a complaint with your supervisory authority.
10. How to exercise your rights?
Email contact@tovma.cc. We respond within one month. To locate a meeting we may ask for the approximate date/time and the host's identity.
11. Data retention
- Meeting audio: retained for up to 12 months, then automatically deleted. We do not keep raw audio indefinitely.
- Meeting transcripts and recaps: retained for the life of your account — until you request deletion or close your account.
- Account data: deleted within 30 days of account closure.
- Technical logs: retained for a short period (around 30 days) for security and debugging.
12. Revision of this policy
We may update this policy; material changes will be announced by email to users before they take effect. The current version is always available at https://tovma.cc/privacy.