Security

Security & data handling

Last reviewed: 26 July 2026

The short version: Wazomind is local-first. Your meeting content stays on your device, your provider API key never ships inside the app, everything on the wire is encrypted, and there is no covert mode. Below is exactly how that works — written plainly for you and for the IT or procurement team that has to sign off.

Where does my meeting content live?

On your device. Audio, transcripts, notes, summaries, uploaded knowledge-base documents and cross-meeting history are stored locally by default. Wazomind's servers do not receive or retain your meeting content in the ordinary course of using the app. You can export or delete it at any time.

What gets sent off my device, and to whom?

Only what's needed to transcribe and assist: short segments of audio and text go to your chosen AI provider (Groq by default) to be processed and returned. That's it — no third parties, no advertising networks. If you enable offline mode, even that stops: processing happens on your device and nothing leaves it.

Where is the API key kept?

If you use the managed service, the provider key is held server-side behind our proxy and is never embedded in the app you download — so it can't be extracted from the client. If you bring your own key, it lives locally on your device and is sent directly to your provider, never to us.

How is data protected in transit?

All network traffic uses HTTPS with certificates issued and auto-renewed by Let's Encrypt. We hold as little as possible server-side, and what we do hold — a session identifier, optional email, and usage counters for metering — is separated from any meeting content, which we never have.

What about payments?

Billing is handled by Lemon Squeezy, our merchant of record. We never see or store full payment-card details; Lemon Squeezy processes payment and tax under their own security and privacy program. We receive only your subscription status to unlock paid features.

Is there a covert or "undetectable" mode?

No — deliberately. Wazomind shows a recording indicator and is built to be used openly, in meetings you are legitimately part of. It is not designed to hide from other participants or to deceive. See our Acceptable Use Policy for where that line sits.

What controls do I have over my data?

You can export and delete your local data directly in the app. For the small amount of account/usage data the managed service holds, you can request access or deletion by emailing privacy@wazomind.com. Depending on where you live, you may have rights under laws such as the GDPR or CCPA; we honor valid requests.

Reporting a vulnerability

If you believe you've found a security issue, please email security@wazomind.com with the details and steps to reproduce. We'll acknowledge your report, keep you updated, and won't pursue researchers who act in good faith and avoid privacy violations or service disruption.

Building a security or procurement review? This page plus our Privacy Policy and Terms cover most questionnaires. For anything else, email security@wazomind.com.