Security & Data Handling

Last updated: July 21, 2026

Least privilege

The Zoom Meeting SDK app requests only what it needs to let the Owner's assistant join the Owner's meetings and, for externally-hosted meetings, to mint an On-Behalf-Of token attributed to the Owner. No broad account-management or data-export scopes are requested.

Credential handling

Data in transit and at rest

Recording transparency

The assistant always joins as a clearly named, visible participant with a branded video tile. It does not attempt to hide its presence. If recording permission is revoked, or a host removes it, it stops capturing and leaves.

Access control

Only the Owner can trigger joins (via their private calendar or private chat channel) and only the Owner can access stored transcripts and recordings. There is no public or multi-tenant access to meeting content.

Data minimization & retention

Only data needed to produce the Owner's notes is processed. Content is retained at the Owner's discretion and can be deleted on request. Meeting content is never sold, shared with third parties (beyond the processors listed in the Privacy Policy), or used to train models.

Reporting a vulnerability

Please report any security concern to ronnie@ronniesamuel.com.