Privacy Policy
Last updated: July 2026
Protecting your personal data matters to us. This privacy policy explains what data we process when you use withmo, for what purpose, and what rights you have under the General Data Protection Regulation (GDPR).
1. Controller
The controller within the meaning of the GDPR is modulo8 GmbH, Maria-Goeppert-Straße 1, 23562 Lübeck, Germany, represented by Managing Director Torben Rogge. Contact: hello@withmo.io. Further details are available in our Imprint.
Due to our company size, a Data Protection Officer is not legally required (§ 38 BDSG) and none has been appointed. For any privacy questions, please contact us directly at the address above.
2. General Principles
We process personal data only to the extent necessary to provide a functioning platform and our services. Depending on the purpose, the legal basis is Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(f) GDPR (legitimate interest), Art. 6(1)(c) GDPR (legal obligation), or Art. 6(1)(a) GDPR (consent).
3. Hosting and Technical Infrastructure
withmo runs entirely on our own infrastructure hosted by Hetzner Online GmbH, at their Falkenstein, Germany data center. Our database (MongoDB) and object storage for recordings (MinIO) are self-hosted and also located in this data center.
In addition to local storage, an encrypted backup of the object storage is kept with Cloudflare, Inc. (Cloudflare R2). This transfer is based on the EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
Authentication (Single Sign-On) runs through an Authentik instance we also operate ourselves, and does not constitute a data transfer to a third party.
4. Server Log Files
Every time you access our platform, our system automatically collects data such as browser type and version, operating system used, referrer URL, time of the server request, and a truncated IP address. This data is used solely to ensure stable operation and IT security (Art. 6(1)(f) GDPR) and is automatically deleted after 7 days.
5. Account and Registration Data
When you register, we collect your name, email address, and organization membership. Sign-in runs through our self-hosted Authentik instance; passwords are stored there only in hashed form. The legal basis is Art. 6(1)(b) GDPR.
6. Meeting Data: Recordings, Transcripts, and Summaries
When recording is enabled, withmo creates audio or screen recordings of meetings, transcribes them, and generates automated summaries, decision logs, and action items via our AI assistant, Mo. This data may also include information about participants who do not themselves hold a withmo account (see Section 7). The legal basis is Art. 6(1)(b) GDPR toward the contracting organization, and, to the extent third parties are affected, Art. 6(1)(f) GDPR.
Important note on participant consent: recording a non-public spoken conversation without the consent of everyone involved is a criminal offense under German law (§ 201 StGB). Obtaining the required consent of all participants before starting a recording is the responsibility of the meeting organizer or the organization using withmo, as set out in our Terms of Service. We strongly recommend actively informing participants and obtaining their consent before every recording.
7. Meeting Participants Without Their Own Account
If a person is invited to a meeting or captured in a recording without being a withmo user themselves, we process their name, email address, and, where applicable, their spoken contributions as part of the recording and transcript. Because this data is not collected directly from the individual concerned, we provide this notice pursuant to Art. 14 GDPR. The legal basis is Art. 6(1)(f) GDPR — the inviting organization's legitimate interest in documenting its meetings.
8. Calendar and Invitation Data
For scheduling, we process the title, time, participant list, and conference link of your meetings, as well as calendar invitations received by email in ICS format.
9. Payment Data
Payments are processed by our payment provider, Stripe Payments Europe, Ltd. We ourselves store only your selected plan, the number of seats booked, and your Stripe customer reference. Full payment and card details remain exclusively with Stripe.
10. Integrations (Slack, Jira, Linear, Webhooks)
If you optionally connect withmo to Slack, Jira, Linear, or a custom webhook, we transmit only the content you configure, such as decisions or action items, to that service. Access tokens are stored encrypted. You and your organization are independently responsible for the data processing performed by that third-party provider.
11. Cookies and Local Storage
We use only strictly necessary cookies and browser storage — specifically an authentication session cookie set by our Authentik instance, and a locally stored language preference. These are exempt from consent requirements under § 25(2) TTDSG. We do not use marketing, analytics, or tracking cookies.
12. Use of Artificial Intelligence
To generate transcripts, speaker recognition, summaries, and suggested action items, we use the following AI services as processors:
AssemblyAI, Inc. — transcription and speaker recognition (diarization). Processing takes place exclusively in AssemblyAI's European data center in Dublin, Ireland. A data processing agreement and EU Standard Contractual Clauses are in place.
Mistral AI SAS — generation of summaries, decision logs, and suggested action items. Mistral AI is a French company; processing takes place within the EU, with no international data transfer required for this purpose.
No automated decision-making within the meaning of Art. 22 GDPR that produces legal or similarly significant effects takes place. The summaries, decision logs, and metrics generated by Mo serve solely as organizational support and are reviewed and used at the discretion of our users.
13. Recipients and Processors Overview
Hetzner Online GmbH (hosting, Germany) · Cloudflare, Inc. (encrypted backup, Cloudflare R2) · AssemblyAI, Inc. (transcription, EU data center in Dublin) · Mistral AI SAS (AI-generated summaries, EU) · Stripe Payments Europe, Ltd. (payment processing) · Brevo SAS / Brevo GmbH (transactional email delivery). Data processing agreements pursuant to Art. 28 GDPR, or the respective provider's standard contractual terms, are in place with each of the above.
14. International Data Transfers
Personal data is transferred to countries outside the EU/EEA only in connection with Cloudflare (USA, based on EU Standard Contractual Clauses). All other processing — hosting, database, object storage, AssemblyAI transcription, Mistral AI, Stripe, Brevo — takes place within the EU.
15. Retention Periods
Account data: for the duration of the contractual relationship; deleted within 30 days of termination, unless statutory retention obligations require otherwise.
Meeting recordings are not stored as persistent audio or video files: voice recordings are processed solely for transcription and are not retained afterward. Transcripts, summaries, and other derived meeting data are deleted from our database as soon as you delete the relevant meeting or close your account. A copy may persist for up to 7 days in our encrypted database backups — including the offsite copy — until overwritten by our backup rotation.
Invoice and payment data: 10 years pursuant to § 147 of the German Fiscal Code (AO) / § 257 of the German Commercial Code (HGB).
Server log files: 7 days.
16. Your Rights as a Data Subject
You have the right, at any time, to access (Art. 15 GDPR), rectify (Art. 16 GDPR), erase (Art. 17 GDPR), restrict processing of (Art. 18 GDPR), and receive a portable copy of (Art. 20 GDPR) your data, as well as to object to processing (Art. 21 GDPR). You may withdraw any consent given at any time with effect for the future (Art. 7(3) GDPR).
To exercise these rights, please contact hello@withmo.io. We will respond within one month.
17. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany.
18. SSL/TLS Encryption
All connections to our platform are encrypted exclusively via HTTPS/TLS.
19. Changes to This Privacy Policy
We will update this privacy policy whenever changes to our data processing or the applicable law make it necessary. The version most recently published on this page always applies.