Trust & Privacy
How FUNDI processes, stores and protects meeting data. This page describes our current practices and platform capabilities.
Database, authentication, stored recordings, transcripts and analytics are kept in the project's configured EU region. Frontend static assets are served from the platform CDN edge.
All traffic to the app and backend uses TLS. Stored recordings, transcripts and database content are encrypted at rest by the cloud provider.
WebRTC media flows directly between participants' browsers. Signaling, recording uploads, chat messages and transcript storage pass through the managed backend.
Only users with the room identifier can join a live meeting. Recordings and recaps are tied to authenticated accounts and row-level security policies.
Data we process
- Account data: email, profile name, authentication tokens and role assignments.
- Meeting metadata: room ID, participant list, start/end times and duration.
- Recorded content: stored recordings, transcripts, chat logs, annotation snapshots and AI-generated recaps.
- Analytics: usage metrics used to improve reliability and product experience.
Recordings, transcripts and recaps are kept until the account owner deletes them or the account is closed. Users can request account and data deletion at any time.
Depending on your location, you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact the account owner or email privacy@example.com.
Subprocessors & infrastructure
FUNDI uses the following subprocessors to provide hosting, authentication, storage, edge delivery and AI-powered meeting analysis. All backend data for this deployment is processed in the Lovable Cloud Europe region unless otherwise noted.
| Subprocessor | Purpose | Region / hosting |
|---|---|---|
| Lovable Cloud | Managed database, authentication, storage and server functions. | EU (project region) |
| Supabase | Underlying PostgreSQL, Auth and Storage infrastructure. | EU (project region) |
| Cloudflare | CDN edge delivery and DDoS protection for static assets. | Global edge (EU POPs) |
| Lovable AI Gateway | Transcript summarisation, action-item extraction and recap generation. | Provider-dependent regions; no audio/video sent to models. |
This list is current as of July 2026. We notify account owners of material subprocessor changes and provide an up-to-date list on request.
FUNDI determines how account, billing and platform usage data are used. For meeting content uploaded or created by users — such as recordings, transcripts, chat logs and recaps — FUNDI processes this data on behalf of the meeting organiser or account owner. A Data Processing Agreement is available on request.
Primary backend data for this deployment remains in the Lovable Cloud Europe region. CDN edge delivery and AI processing may involve transient transfers outside the EU. Appropriate transfer safeguards are provided by the platform; details are available in the platform Data Processing Agreement.
Legal review notice
This page describes current technical practices and platform capabilities. It is maintained by FUNDI as enterprise-ready information and is not a legal guarantee of compliance with GDPR, HIPAA, SOC 2 or any other framework. Before making public compliance claims, have your legal counsel review this wording against your actual data processing agreements and security controls.