Privacy Policy

Last updated 6 October 2026

Mayah records your meetings, turns them into text, and builds on what it finds. This policy says what is collected, where it goes, how long it is kept, and who can read it.

The short version

  • Meeting audio and screen images are not retained, and never reach Mayah. They go from your Mac straight to the AI provider you configured, under your own key, to be turned into text — and are discarded after that.
  • Meeting transcripts and derived data do reach Mayah’s servers on the paid tier, and so does code from the coding agent if you turn it on. Mayah engineers can read all of it to diagnose faults and improve the product.
  • AI processing uses your own API key. Your prompts go directly to the AI provider you configured — from your Mac, and from your phone if you pair one, including your voice when you talk to Mayah there. They do not pass through us.
  • Mayah also sends us usage measurements — counts, durations and outcomes. This is how we find out that a feature is failing. They record what happened, not what was said. The text of the questions you ask is the one exception — it is on by default, and you can turn it off.

What stays on your device

Mayah keeps no recording of your meeting. Audio and screen images are held only long enough to be turned into text — sent to the AI provider you configured, under your own API key — and are then discarded. No audio or video file is retained, and none of it ever reaches Mayah.

What stays here is the text and what Mayah builds from it: your transcripts, the cards and memory drawn from them, and the voice profiles you name.

The AI provider key you enter is never sent to Mayah. It is stored on your Mac and goes directly from there to the AI provider you chose. If you pair your phone, it is copied to the phone by scanning a QR code shown on your Mac — it does not pass through our servers on the way.

Your phone talks to your AI provider directly too. When you talk to Mayah on your phone, your voice is streamed live from the phone to Google’s Gemini — or to OpenAI, if that is the provider you chose — under your own key, and the spoken replies come back the same way. When the phone reads your briefing aloud, or answers a question from it while your Mac is not responding, it sends the question and the briefing text it needs to that provider as well. This does not pass through us: it goes from your phone to the provider, under their terms.

Slack connects by OAuth, so its token is issued to our servers rather than to your Mac. We keep it so the connection keeps working, we can read it, and it gives access to the Slack workspace you connected. Disconnecting Slack, from Settings, deletes it from our servers.

When Mayah reads a web page for you

This is off until you turn it on in Settings. When it is on and a question needs a web page, Mayah opens the page in its own window of your Chrome, signed in as you, and reads it. It asks you before it opens a site you have not allowed before, and it never opens email, banking, password managers or admin consoles.

To read the page, Mayah sends screenshots of that window to Google’s Gemini, under your own Google key. It also sends your question and a list of the tabs you have open in Chrome, shortened so that a site you have not allowed appears only as its address, with no page name. This goes from your Mac to Google, not through us, under Google’s terms. It happens whichever AI provider you chose for the rest of Mayah.

Your Mac keeps a record of each run: the screenshots, which can include anything visible on those pages, the steps taken, the pages visited, and the answer. It is kept for 7 days, and only for your last 20 runs, and it is not sent to us. What reaches us is the answer you hear on your phone, stored with your other questions and answers as described below.

When Mayah does coding work for you

This is off until you turn it on in Settings. When it is on, you can ask Mayah, from your phone or at your desk, to do a small piece of coding work. Mayah does it on your Mac, in its own copy of your repository or in a new project, using your own AI key like the rest of Mayah’s AI processing. That AI traffic goes from your Mac to the provider, not through us.

So that your phone can follow the work, some of it passes through our servers. That is what you asked for, the ticket number and its summary, Mayah’s plan, and each step of the work: the sources it checked, the commands it ran, the changed lines of code, its questions and your answers, any command it asks you to approve, and its final summary.

We keep this for 30 days, like your phone conversations with Mayah, and then delete it. The question-text switch described below does not cover these records: your phone needs them to follow the work, so whenever you use the coding agent they are kept for those 30 days whatever that switch is set to.

What Mayah can see

On the paid tier, your meeting transcripts and everything derived from them — summaries, cards, extracted entities, corrections, and the memory Mayah builds about your work — are synced to our servers so that features like the mobile app can answer questions when your laptop is closed.

That includes the questions you ask Mayah on your phone and the answers it gives you: both are stored on our servers. Your phone does not talk to your Mac directly, which is why we hold them. The recent turns of the conversation are stored with them as context. Deleting an individual meeting does not remove them, because they are not filed against a meeting — but the question and answer text is now erased automatically 30 days after the exchange finishes. We keep the timing of the exchange after that, which records how quickly your Mac answered and contains none of what was said. You can still ask us to delete everything sooner.

When you talk to Mayah by voice on your phone, we also store that conversation. While you talk, your phone sends us the conversation so far: what you said, word for word as it was transcribed, what the voice said back, and any answer it gave you from your cached briefing when your Mac did not respond. We keep it to find out why a spoken answer went wrong. Your conversation with Mayah on your phone is erased within 30 days, and you can stop us keeping it by turning off the question-text switch described below. This does not apply to your meeting transcripts, which are kept until you delete the meeting.

When your Mac answers a question from your phone, we also keep a record of how it found the answer: the pages it opened and the searches it ran, and the start of what each one returned. It is stored with the question and the answer, to find out why an answer went wrong, and erased within 30 days. The question-text switch described below covers it too: while that switch is off, we discard this record when it arrives.

You can report a problem with a voice conversation from your phone, and add a note if you want to. A report tells us which conversation to look at, and Mayah engineers then read it: the report and your note, the transcript of that conversation, the record of how your Mac answered, and any coding work it started. Each time an engineer opens a conversation, that access is logged. We keep the report and your note for 30 days. You can report a problem with the question-text switch off, but then we hold no transcript of that conversation and no record of how your Mac answered, so there is less for us to go on.

This data, including any code, is stored in readable form. It is encrypted in transit and at rest, but we hold the keys, and Mayah engineers can read it. We do this deliberately: diagnosing why an answer was wrong requires seeing the material it was drawn from.

Usage measurements

Mayah sends us measurements about how the product behaved: counts, durations, timings, and fixed labels chosen from short lists. A measurement records that something happened and how long it took, not what was said in it. We collect them because without them we cannot tell a feature that is quietly failing from one nobody uses.

We also collect the text of the questions you ask, unless you turn that off — that is the one exception, and it is on by default. It travels on these same measurements; the separation happens on our servers, not on your Mac, and it is then stored apart with its own deletion clock. It has its own section below.

Each measurement also carries a random identifier for your installation, created on your Mac and not derived from your hardware, and the id of the meeting, card or run it relates to.

If you tell us your role (for example business analyst or engineer, during setup or in Settings → Account), it is stored on your account and each measurement carries it, so we can see how well Mayah works for each kind of role. It is a choice from a fixed list, never free text.

These measurements are kept for 180 days and then deleted.

The text of the questions you ask

This is on by default, and we do not ask you to agree to it — we rely on our legitimate interest in making Mayah work, and we tell you here instead. You can turn it off at any time in Settings → Account. Nothing in this section happens while it is off: your Mac withholds the text rather than sending it for us to discard.

What turning it off does not change: a question you ask on your phone still passes through our servers, because that is the only way your Mac receives it. That copy is described above, with its own 30-day window. The switch here controls the separate copy we keep to diagnose faults, the transcript of your voice conversations with Mayah on your phone, and the record of how your Mac answered each question from your phone: while it is off, we discard that transcript and that record when they arrive. It does not cover the coding agent’s records, which your phone needs to follow the work; they are described above.

What it sends: the words of the question itself, as you typed or said them, and the surface you asked it from — the phone, a card, the live meeting feed. That record holds nothing else: not the answer Mayah gave you, not the transcript it drew on, not the instructions sent to the AI model, and nothing your connected services returned.

Why we collect it. The measurements above can tell us an answer was poorly grounded, but not what was being asked — which is the difference between a retrieval failure and a question Mayah was never built to answer.

Kept for 180 days, then deleted.

What we do with it

We use your content to operate the service, to diagnose faults, and to improve Mayah’s accuracy. Content may be used to evaluate and improve the system in text form only — which means someone here may read your transcripts and the questions you asked, as you wrote or said them, your colleagues’ names included. Raw audio is never used for this, because we never receive it.

We do not sell your data. Your meeting content — transcripts, the questions you ask, Mayah’s answers and what it remembers — is never used for advertising or marketing.

Website analytics and advertising

We count visits to mayah.app’s public pages, and clicks such as signing up or downloading, using Vercel Web Analytics. Vercel Web Analytics uses no cookies and does not track you across days or websites. We also keep our own daily counts of visits, clicks and video plays on each campaign page; those are totals, with nothing about who you are. Nothing inside the Mayah app is counted.

When you arrive from one of our ads or posts, a cookie remembers for 7 days which link brought you, the site you came from, and the ad platform’s click id if the link carried one. If you sign up, we store that on your account, along with your answer to where you heard about Mayah, if you gave one. It tells us which ads and posts bring people who go on to use Mayah.

When you sign up, and when you first pay, we tell X and LinkedIn so they can measure and improve our ads. We send a hashed (SHA-256) copy of your email address, the click id from their ad if you came from one, the time, and for a payment its price. We send nothing about your meetings. If you visit from the European Union, the European Economic Area, the United Kingdom or Switzerland, none of this happens unless you accept it in the cookie banner. Everywhere else it is on unless you opt out. You can change your choice at any time with “Cookie settings” at the bottom of our home page. We also note the campaign you signed up through on your Stripe subscription.

If you ask to be told when the Mayah iPhone app is out, we keep your email address for that alone. We send you one email when the app is on the App Store, and delete your address as it goes out. It is never added to a mailing list.

Your controls

  • Delete any individual meeting. What Mayah learned from it — the notes it keeps about your projects, your work and the people you work with — is not filed against a meeting, and is not removed with it. To have that erased as well, ask us below and we will delete everything we hold about you.
  • Request a copy of what we hold about you, or ask us to delete all of it, by emailing hello@mayah.app.

Recording consent is your responsibility

Recording laws differ by state and country, and in many places every participant must consent before a conversation is recorded. Mayah gives you the technical ability to record; it does not give you the legal right to. You are responsible for obtaining whatever consent applies to your meetings, and for complying with your employer’s own policies.

Mayah does not announce itself to the other people in your meeting. It captures audio from your own Mac rather than joining the call, so it does not appear in the attendee list, and it does not trigger the recording banner that Teams, Zoom or Google Meet show when someone starts one of their own recordings. Nobody in the room is told that Mayah is running. If the people you are meeting with are to know, you have to tell them — and separately from whatever the law where you are requires, we recommend that you do.

Who else is involved

We use Stripe for payments (Stripe receives your billing details; we never see your full card number), Vercel for hosting and website analytics, Neon for our database, X and LinkedIn for measuring our ads (see above), and Google Firebase for the phone app. Firebase Cloud Messaging delivers the phone’s notifications, so we store a push token for your phone. Firebase Realtime Database is how we wake your Mac when you ask your phone a question, so your Mac keeps a connection open to it. Both carry only a reference to the item waiting on our servers, not the question or the answer. Your AI provider receives your prompts directly under your own API key and their terms, not ours.

Where your data lives

Mayah is operated from Australia by BUI Group Pty Ltd. Our hosting, database and notification providers may store data outside Australia, including in the United States.

Complaints

Email hello@mayah.app and we will respond within 30 days. If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.