Privacy policy
September 24, 2026 version
Geremy.ai, an artificial intelligence application for creating minutes and analyzing meetings, attaches the utmost importance to the protection of privacy and personal data. This privacy policy explains how we collect, use, disclose, process and protect the personal information of Geremy.ai users.
Geremy.ai is a service provided by Stellar Quantum SAS – Hamadryade Bât. 2, 55 allée Camille Claudel, 84000 Avignon, France.
Collecting and using information
1. Audio recording and consent
When using Geremy.ai to record meetings, the Customer is responsible for informing all participants and, where applicable, for obtaining their consent, for the recording and transcription of their voices and statements. It is up to the Customer to determine the legal basis applicable to its context: performance of the contract, legitimate interest, task carried out in the public interest, or consent.
2. Processing audio recordings
- Audio recordings are transferred to Geremy.ai’s servers for automatic transcription.
- Audio recordings are automatically deleted once the report has been produced, within four hours.
- Voice is processed solely for transcription purposes and is not stored.
3. Data use and artificial intelligence
- Your data is never used to train AI models.
- We have set up a permanent opt-out with all our AI suppliers, with active monitoring to maintain this guarantee.
- Each account is isolated: no processing accesses the data of another account, and no meeting is shared between users. The history search and task tracking features apply exclusively to your own meetings.
4. User account creation and management
We need certain information to create your account:
- Your first and last name: to identify you
- Your e-mail address: to contact you and enable you to log in
- Your telephone number (optional): to contact you
- Your company name (for business accounts): to personalize your experience
5. Creating and managing reports
When you create a report, we record:
- Contents of the report
- Creation date and time: to organize your reports
The user can enter optional additional information (objectives, agenda, list of participants) to enhance the report. This information can be modified or deleted at any time.
6. Service support
To help you if you have any problems, we use:
- Your first and last name: to identify you
- Your e-mail and telephone number: to contact you
- Your payment details (if you have a paying account): to manage your subscription
7. Statistical analysis and customization
- Information on using the application
- Application performance data
- User preferences and usage history
Data storage and security
- Our servers are hosted in the European Union, in France. An encrypted copy of backups is kept in a second region of the Union.
- Data encryption in transit (TLS 1.2 minimum, TLS 1.3 preferred) and at rest (AES-256).
- Regular, secure backups.
- HTTP Strict Transport Security (HSTS) and Content Security Policy (CSP).
- Role-based access control (principle of least privilege).
Data retention and deletion
Deletion on request
The Customer may at any time request the permanent deletion of his Account and all his data (reports, preferences, profile information), through either of two channels:
- from the customer area: the request is confirmed via a validation link sent by e-mail; permanent deletion takes place within one week of validation. This period is a security measure allowing a fraudulent or accidental request to be cancelled;
- via support: the request is handled and the deletion carried out within 72 hours.
Deleting a report or content from the customer area results in its erasure from our production servers within a maximum of twenty-four hours.
Default retention times
- Account data and reports: stored for the entire period of use of the Service, then two (2) years after the end of the trial period or subscription. At the end of this period, definitive deletion after prior notice of thirty (30) days.
- Audio recordings: automatically deleted within four hours of the report being produced.
- Connection data (logs): 12 months maximum.
- Billing data: stored in compliance with legal accounting and tax requirements.
Confidentiality
Stellar Quantum undertakes to:
- Keep secret all information received from the Customer;
- Not disclose confidential information to a third party, except upon judicial requisition;
- Use this information only to perform the Service.
This obligation remains in effect during and after the term of use of the Service. All Stellar Quantum personnel are bound by a contractual obligation of confidentiality.
Data transfer and disclosure
Meeting content — recordings, transcripts and reports — is processed exclusively within the European Union and is not disclosed to any third party, except as required by law.
Our own processing — billing and management of the commercial relationship — relies on service providers established in the European Union, which have no access to any meeting content.
Disclosure on court order
In the event of a request from a competent judicial authority (rogatory commission, examining magistrate, public prosecutor, judicial police, or foreign order via international mutual assistance), Stellar Quantum will:
- Verify the legitimacy of the request
- Limit communication to what is strictly required
- Inform the Customer in advance, unless prohibited by law (secrecy of the investigation)
- Keep track of the request
User rights
You have the following rights concerning your personal data:
- Right of access, rectification and deletion
- Right to limitation of processing and portability
- Right to object
- Right not to be subject to an automated individual decision
- Right to set directives regarding the fate of your data after your death (Article 85 of the French Informatique et Libertés Act)
You may request the permanent deletion of your Account and all your data at any time, through either of the two channels described above, with the exception of billing data, which is retained in accordance with legal obligations.
To exercise these rights: rgpd@geremy.ai or support@geremy.ai
You can also lodge a complaint with the CNIL: www.cnil.fr
RGPD compliance
- Legal basis: Contract performance, legitimate interest (statistics, marketing with right of objection)
- Transfers outside the EU: No data transfers outside the European Union
- Notification of data breaches: to the Customer, in our capacity as processor, within a maximum of 48 hours. For processing for which we are the controller, notification to the supervisory authority within 72 hours.
- Privacy by Design: Applied to application development and operation
- Registers: register of our own processing operations (Article 30.1) and register of the categories of processing activities carried out on behalf of our customers (Article 30.2), kept up to date.
- Impact analysis (AIPD): we provide the data controller with the information necessary to carry it out.
Cookies and similar technologies
Definitions
- Cookie: Small file stored by your browser to save certain information.
- Script: A piece of code executed to ensure the proper functioning of the site.
- Invisible tag: Small invisible element used to track site traffic.
Types of cookies used
- Technical or functional cookies: Ensure the proper functioning of the site and application (no consent required).
- Statistical cookies: We use analytical tools for audience measurement and internal statistical analysis purposes only. This data is not used for advertising purposes, nor is it shared with third parties for commercial purposes.
Cookie management
You can accept or refuse non-essential cookies via the “Manage my cookies” link in the footer, and change your choice at any time. The deactivation of certain cookies may affect the operation of the site. Details of the cookies placed are set out in our Cookie Policy.
Modifications and contact
Geremy.ai reserves the right to modify this policy at any time. Users will be informed of any significant changes.
Data protection contact: rgpd@geremy.ai
Address: Stellar Quantum SAS, Hamadryade Bât. 2, 55 allée Camille Claudel, 84000 Avignon
APPENDIX: Data Processing Agreement (DPA)
In accordance with Article 28 of Regulation (EU) 2016/679 (RGPD)
Preamble
The present agreement is concluded between Stellar Quantum SAS (“Subcontractor”) and the Customer within the meaning of the Terms and Conditions of Sale (“Data Controller”). The Data Controller retains control of the data it processes via the application.
Article 1 – Purpose, duration and termination
Subject: Audio transcription and report generation using artificial intelligence.
Duration: For the entire period of use of the services.
End: At the end of the trial or subscription period, the data is kept for two (2) years to enable the Data Controller to consult the data or take out a new subscription. At the end of this period, the data will be permanently deleted after thirty (30) days’ prior notice.
Before the end of the term, the Data Controller may retrieve its reports using the Service’s export functions; failing this, the data is deleted.
Deletion on request: The Data Controller may request the deletion of his Account and data at any time. Deletion takes place within 72 hours for a request handled by support, or within one week of validation for a request made from the customer area, this period allowing an accidental or fraudulent request to be cancelled. Billing data is kept in accordance with legal accounting and tax obligations.
Article 2 – Processed data
Identification data: surname, first name, e-mail, telephone (optional), SSO data.
Audio recordings: voice, processed solely for transcription purposes and automatically deleted once the report has been produced.
Transcripts and reports generated.
Connection data: logs (12 months maximum).
Persons concerned: Users and participants of recorded meetings.
Article 3 – Subcontractor’s obligations
The Subcontractor undertakes to process the data only in accordance with the instructions of the Data Controller.
The Subcontractor guarantees data confidentiality.
The Subcontractor implements appropriate security measures.
The Subcontractor assists the Data Controller with requests to exercise rights.
The Subcontractor shall notify any data breach within 48 hours.
The Subcontractor deletes the data at the request of the Data Controller — within 72 hours via support, or one week after validation from the customer area — or upon expiry of the two (2) year retention period after the end of the trial period or subscription.
The Subcontractor undertakes never to use the data to train AI models (permanent opt-out, active monitoring).
The Subcontractor guarantees strict partitioning of each account.
The Subcontractor informs the Data Controller if an instruction appears to it to be contrary to the RGPD.
Upon request, the Subcontractor provides its security white paper and the processing description sheet; this communication constitutes demonstration of compliance with the present agreement.
Article 4 – Security
Hosted in the European Union, encryption in transit (TLS 1.2 minimum, TLS 1.3 preferred) and at rest (AES-256), role-based access control, continuous monitoring and regular security testing.
Article 5 – Subsequent subcontractors
The Data Controller generally authorizes the use of subsequent subcontractors. The Subcontractor will inform of any changes.
Article 6 – Transfers
No data transfer outside the European Union.