Security
Privacy is the foundation, not a feature
Every layer of Mets — from the browser to the database — is designed so your conversations belong to you alone.
Always encrypted
App connections use TLS 1.3, audio and video use DTLS-SRTP. You can't turn it off.
E2EE when you need it
End-to-end encrypted rooms use keys only participants know. The server relays data it cannot read.
Data in the European Union
Database, accounts, recordings and transcripts in eu-west-1. The media server runs on our own EU infrastructure.
Least-privilege access
Row Level Security on every table, short-lived access tokens and an audit log for admins.
How we protect a meeting, step by step
- 1
Joining
You enter with a one-time token valid for 2 hours, issued after checking permissions, room password and lobby.
- 2
Transport
Media flows through our SFU in the EU, encrypted with DTLS-SRTP. In E2EE rooms your browser encrypts it as well.
- 3
Storage
Recordings go to private storage, encrypted at rest. Only people you grant access can open them.
- 4
Processing
Transcription runs on our own servers. AI summaries are only created when you enable them for a meeting.
- 5
Deletion
You set the retention period. When it ends — or when you ask — we delete recordings, transcripts and summaries.
Being honest about end-to-end encryption
E2EE means nobody outside the call — including us — can see or hear it. That comes at a price: in an E2EE room the server can't record or transcribe, because it has no access to the content. So you decide when maximum confidentiality matters more than the convenience of captions and summaries.
Compliance and documents
- Data processing agreement (Art. 28 GDPR) for businesses
- List of sub-processors with data locations
- Retention policies set by your organisation admin
- Data export and deletion on request
- Security audit log on the Business plan
Report a vulnerability
Found a security issue? Email security@mets.ulewicz.space. We reply within 48 hours and never take legal action against good-faith researchers.
Privacy made in the EU
Your meetings are not the product
We build Mets in Poland on infrastructure inside the European Union. We don't sell data, we don't show ads and we don't train models on your conversations.
- Database, accounts and recordingseu-west-1 · Ireland
- Media server (SFU)Our own infrastructure · EU
- Speech recognitionOur own servers · EU
- Company and teamWarsaw · Poland
Data in eu-west-1
Accounts, transcripts and recordings are stored in Ireland, inside the EU. No transfers to the US on standard plans.
Our own media server
Audio and video flow through our LiveKit server in the EU, always encrypted with DTLS-SRTP. No third-party video cloud.
End-to-end encryption on demand
In E2EE rooms the key never reaches the server. Only the people in the call can decrypt it.
Access locked down at the database
Every row is protected by Row Level Security policies. You only see your meetings and what others have shared with you.
No ads, no profiling
No ad trackers and no data sales. We make money from subscriptions — and only from subscriptions.
GDPR-ready from day one
Data processing agreements for businesses, retention rules, and export or deletion on request.
Your next meeting can start right now
No install, no credit card. Create an account in 30 seconds or join with a code from a friend.