By Convo Team • Published December 15, 2025 • Last updated December 15, 2025

Convo captures audio locally on your device with no bot in the call. Audio is sent only to our transcription provider, which deletes it after processing and never trains on it. Your data is encrypted with AES-256, Convo is GDPR compliant, and you can delete your data anytime from Settings.

Data privacy and security

Updated May 16th, 2026

Convo takes data privacy and security seriously. Learn how we protect your conversations and what controls you have over your data.

What data does Convo collect?

Conversation audio

Convo processes real-time audio from your meetings to provide AI assistance. Audio is not permanently stored unless you explicitly choose to save it.

Meeting transcripts

Text transcriptions are created for AI analysis and stored in your Convo account, where you can delete them anytime.

Participant information

Names, email addresses, and professional information of meeting participants for context and insights.

Meeting metadata

Date, time, duration, and platform information for organizing and analyzing meeting patterns.

How we protect your data

Encryption

  • • AES-256 encryption at rest
  • • TLS 1.3 encryption in transit
  • • Audio deleted by our transcription provider after processing

Access controls

  • • Role-based access control
  • • Multi-factor authentication
  • • Regular access audits

Infrastructure

  • • Secure cloud data centers
  • • 24/7 security monitoring
  • • Regular penetration testing

Compliance

  • • GDPR compliant
  • • AES-256 encryption at rest and in transit
  • • Local on-device audio capture; no bot joins the call

Your privacy controls

Data retention

Your data stays in your Convo account until you remove it:

  • Delete anytime: Remove individual meetings whenever you want
  • Forget all: Wipe everything Convo Memory has learned about your contacts
  • Account deletion: All associated data is removed within 30 days of closing your account

Consent

Because no bot joins the call, obtaining consent is in your hands, just as it is when you take notes. A quick mention at the start is the recommended practice:

  • Let participants know you take notes with an AI assistant
  • Required in all-party-consent regions (e.g. Germany, several US states)
  • See our guide on recording laws by region

Data export and deletion

You have complete control over your data:

  • Export all your data in standard formats
  • Delete specific meetings or all data
  • Request data deletion via support
  • Automatic deletion upon account closure

Regional data handling

Data residency

Your data is processed and stored in secure facilities:

  • • Data is stored in secure US data centers
  • • Audio is processed by our transcription provider, then deleted
  • Enterprise: contact us to discuss specific data residency needs

GDPR compliance

Convo is fully GDPR compliant and respects your data rights:

Right to access

View all personal data we have about you

Right to rectification

Correct any inaccurate personal information

Right to erasure

Delete your personal data permanently

Right to portability

Export your data in standard formats

Configuring privacy settings

  1. Open your privacy controls - Go to Settings > Memory. This is where Convo's data controls live.
  2. Turn Convo Memory on or off - Use the master toggle to control whether Convo builds memory across your conversations.
  3. Forget everything - Use "Forget all" to wipe everything Convo has learned about your contacts. Your transcripts and summaries stay untouched.
  4. Know where your data lives - Audio is captured locally on your device. No bot joins your calls and nothing is streamed to a third party.

Security best practices

For individuals:

  • • Use strong, unique passwords for your Convo account
  • • Enable two-factor authentication
  • • Regularly review your meeting history and delete sensitive data
  • • Only share meeting insights with authorized team members
  • • Keep the Convo app updated

For organizations:

  • • Establish clear data handling policies
  • • Train team members on consent requirements
  • • Regularly audit data access and usage
  • • Set up appropriate retention policies
  • • Monitor compliance with your industry regulations

Incident response

In the unlikely event of a security incident:

  • We detect and respond to incidents within 15 minutes
  • Affected customers are notified within 72 hours
  • Detailed incident reports are provided
  • We work with authorities as required by law
  • Post-incident reviews improve our security measures

Third-party integrations

When you connect Convo with other services:

  • We only share data necessary for the integration to function
  • Third-party services must meet our security standards
  • You can revoke integration permissions at any time
  • We maintain audit logs of all data sharing

Questions about privacy? Our privacy team is available to answer questions about data handling, compliance, or security. Contact us at privacy@itsconvo.com.

Related resources

Sources & References

  • AES-256 Encryption - NIST Guidelines
  • GDPR Compliance Standards
  • Data Protection Best Practices

Still need help? Ask AI about this topic