Skip to content

Security

Privacy is the foundation, not a feature

Every layer of Mets — from the browser to the database — is designed so your conversations belong to you alone.

Always encrypted

App connections use TLS 1.3, audio and video use DTLS-SRTP. You can't turn it off.

E2EE when you need it

End-to-end encrypted rooms use keys only participants know. The server relays data it cannot read.

Data in the European Union

Database, accounts, recordings and transcripts in eu-west-1. The media server runs on our own EU infrastructure.

Least-privilege access

Row Level Security on every table, short-lived access tokens and an audit log for admins.

How we protect a meeting, step by step

  1. 1

    Joining

    You enter with a one-time token valid for 2 hours, issued after checking permissions, room password and lobby.

  2. 2

    Transport

    Media flows through our SFU in the EU, encrypted with DTLS-SRTP. In E2EE rooms your browser encrypts it as well.

  3. 3

    Storage

    Recordings go to private storage, encrypted at rest. Only people you grant access can open them.

  4. 4

    Processing

    Transcription runs on our own servers. AI summaries are only created when you enable them for a meeting.

  5. 5

    Deletion

    You set the retention period. When it ends — or when you ask — we delete recordings, transcripts and summaries.

Being honest about end-to-end encryption

E2EE means nobody outside the call — including us — can see or hear it. That comes at a price: in an E2EE room the server can't record or transcribe, because it has no access to the content. So you decide when maximum confidentiality matters more than the convenience of captions and summaries.

Compliance and documents

  • Data processing agreement (Art. 28 GDPR) for businesses
  • List of sub-processors with data locations
  • Retention policies set by your organisation admin
  • Data export and deletion on request
  • Security audit log on the Business plan

Report a vulnerability

Found a security issue? Email security@mets.ulewicz.space. We reply within 48 hours and never take legal action against good-faith researchers.

Privacy made in the EU

Your meetings are not the product

We build Mets in Poland on infrastructure inside the European Union. We don't sell data, we don't show ads and we don't train models on your conversations.

Where your data livesAll in the EU
  • Database, accounts and recordingseu-west-1 · Ireland
  • Media server (SFU)Our own infrastructure · EU
  • Speech recognitionOur own servers · EU
  • Company and teamWarsaw · Poland
  • Data in eu-west-1

    Accounts, transcripts and recordings are stored in Ireland, inside the EU. No transfers to the US on standard plans.

  • Our own media server

    Audio and video flow through our LiveKit server in the EU, always encrypted with DTLS-SRTP. No third-party video cloud.

  • End-to-end encryption on demand

    In E2EE rooms the key never reaches the server. Only the people in the call can decrypt it.

  • Access locked down at the database

    Every row is protected by Row Level Security policies. You only see your meetings and what others have shared with you.

  • No ads, no profiling

    No ad trackers and no data sales. We make money from subscriptions — and only from subscriptions.

  • GDPR-ready from day one

    Data processing agreements for businesses, retention rules, and export or deletion on request.

Your next meeting can start right now

No install, no credit card. Create an account in 30 seconds or join with a code from a friend.