Legal

Privacy Policy

Last updated: June 1, 2026

1.Introduction

tahro ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how tahro, Inc. collects, uses, discloses, and safeguards your personal information when you use our video conferencing, team workspace, business email, whiteboard, and AI collaboration platform (collectively, the "Service").

By accessing or using the Service, you agree to the collection and use of information in accordance with this policy. If you disagree with any part of this policy, please discontinue use of the Service.

This policy applies to all users of tahro, including free, Pro, and Enterprise plan subscribers, and to guests who join meetings without a tahro account.

2.Information We Collect

We collect several categories of information to provide and improve the Service:

Account Information: When you register, we collect your full name, email address, password (stored as a cryptographic hash), and optional profile photo. Organization administrators who subscribe to paid plans also provide company name and billing contact details.

Usage Data: We automatically collect information about how you interact with the Service, including meeting duration and participant counts, features used, device type and operating system, browser type and version, IP address (used for geolocation at the country level only), and session timestamps.

Video and Audio Data: During meetings, video and audio streams are transmitted between participants using end-to-end encrypted WebRTC connections. We do not record, store, or process your video or audio unless the verified meeting host explicitly activates the recording feature. When recording is enabled, all participants are notified and must consent before the session begins.

Whiteboard and Workspace Content: Text, drawings, uploaded files, and chat messages created within your workspace are stored on our servers to enable real-time collaboration and persistence.

AI-Generated Data: When AI features are enabled (transcription, summaries, action items), audio is processed by our AI pipeline. Transcripts and summaries are stored in your account and accessible only to meeting participants.

Billing Information: Payments are processed through Stripe, Inc. We do not store full credit card numbers or payment card data on our servers. We receive a transaction token and the last four digits of your card for reference purposes.

Cookies and Local Storage: See Section 9 for full details on our use of cookies and tracking technologies.

3.How We Use Information

We use the information we collect for the following purposes:

Providing the Service: To authenticate your identity, deliver meeting functionality, sync workspace data in real time, process payments, and send transactional emails (meeting invitations, password resets, billing receipts).

Improving the Service: Aggregated, anonymized usage data helps us identify bugs, optimize performance, and prioritize new features. We do not use individual user data to train AI models without explicit consent.

Safety and Security: We monitor for fraudulent activity, abuse, and violations of our Acceptable Use Policy. IP addresses and session data may be reviewed in response to security incidents.

Customer Support: When you contact our support team, we access relevant account and usage data to diagnose and resolve your issue.

Communications: We may send you product announcements, security alerts, and update notifications. You can opt out of non-essential communications at any time from your account settings or by clicking the unsubscribe link in any email.

Legal Obligations: We process data as required by applicable law, including responding to valid legal process such as court orders and government requests.

4.Information Sharing

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We share information only in the following limited circumstances:

Service Providers: We share data with trusted third-party vendors who perform services on our behalf, including Stripe (payment processing), Amazon Web Services (cloud hosting and storage), Cloudflare (CDN and DDoS protection), and third-party AI model providers for transcription and summarization. These providers are contractually bound to use your data only to perform services for us and may not use it for their own purposes.

Within Your Organization: Workspace administrators have access to workspace member lists, usage statistics, and content created within the workspace. Meeting hosts have access to participant information and AI-generated transcripts from their meetings.

Business Transfers: If tahro is acquired by or merges with another company, your information may be transferred as part of that transaction. We will notify you via email and a prominent in-app notice before your data is transferred and becomes subject to a different privacy policy.

Legal Requirements: We may disclose your information if required by law, subpoena, or other legal process, or when we believe in good faith that disclosure is necessary to protect the rights, property, or safety of tahro, our users, or the public.

With Your Consent: We may share your information in any other circumstances with your explicit consent.

5.Data Retention

We retain your personal information for as long as your account is active or as needed to provide you the Service. Specifically:

Active Accounts: Account data, workspace content, and usage history are retained for the duration of your account. You may delete specific content at any time.

Meeting Recordings and Transcripts: Recordings and AI transcripts are retained for 90 days on Pro plans and 1 year on Business and Enterprise plans. You may delete individual recordings at any time.

Deleted Accounts: When you delete your account, we initiate a deletion process that removes your personal data within 30 days. Backup copies may persist for up to an additional 60 days before being permanently purged from all systems.

Billing Records: We retain transaction records and invoices for 7 years as required by financial regulations, even after account deletion. These records contain only the information necessary for accounting purposes.

Anonymized Data: Anonymized, aggregated data that cannot be used to identify you may be retained indefinitely for product analytics purposes.

6.Your Rights

Depending on your location, you may have the following rights regarding your personal data:

Access: You have the right to request a copy of the personal data we hold about you. You can export much of your data directly from Account Settings → Privacy → Export Data.

Correction: You may update or correct inaccurate personal information at any time from your account settings.

Deletion: You may request deletion of your account and associated personal data. See Section 5 for retention timelines.

Portability: You may request your data in a machine-readable format (JSON or CSV) for transfer to another service.

Objection and Restriction: You may object to or request that we restrict certain processing of your personal data, including processing for direct marketing purposes.

Withdrawal of Consent: Where we rely on your consent to process data (such as AI features), you may withdraw that consent at any time from your settings.

EU/EEA/UK Residents (GDPR): If you are located in the European Economic Area or United Kingdom, you have the rights listed above under the General Data Protection Regulation. You may also lodge a complaint with your local data protection authority.

California Residents (CCPA): California residents have the right to know what personal information we collect and share, the right to opt out of the sale of personal information (we do not sell personal information), and the right to non-discrimination for exercising your rights.

To exercise any of these rights, please contact us at privacy@tahro.io or through your account settings.

7.Security

We implement industry-standard technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.

Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher. Meeting audio and video streams are protected using DTLS-SRTP encryption.

Encryption at Rest: All data stored on our servers is encrypted at rest using AES-256 encryption.

Access Controls: Access to production systems is restricted to authorized personnel through multi-factor authentication and role-based access controls. All access is logged and audited.

Security Audits: We conduct regular third-party security audits and penetration tests. Our infrastructure is hosted on SOC 2 Type II certified data centers.

Incident Response: In the event of a data breach affecting your personal information, we will notify you and the relevant regulatory authorities within 72 hours as required by applicable law.

While we take extensive precautions, no method of electronic transmission or storage is 100% secure. We encourage you to use strong passwords and enable two-factor authentication on your account.

8.Cookies & Tracking

We use cookies and similar tracking technologies to operate the Service and understand how it is used.

Essential Cookies: These are required for the Service to function. They include your authentication session token, CSRF protection tokens, and user preference settings (such as theme). You cannot opt out of essential cookies without disabling your account access.

Analytics Cookies: We use privacy-focused analytics to understand how users interact with tahro. Analytics data is aggregated and anonymized and does not include personally identifying information. We do not use Google Analytics on authenticated pages.

Functional Cookies: These cookies remember your preferences, such as camera and microphone device selections, to improve your experience across sessions.

Third-Party Cookies: Our payment processor Stripe sets cookies for fraud prevention purposes. We do not allow third-party advertising cookies on the Service.

Managing Cookies: You can control cookies through your browser settings. Note that disabling cookies may affect the functionality of the Service. You can also manage cookie preferences at any time via the Cookie Settings link in the site footer.

We do not engage in cross-site tracking, behavioral advertising, or the sale of cookie data to third parties.

9.Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons.

When we make material changes to this policy, we will notify you by email (to the address associated with your account) and by displaying a prominent notice within the Service at least 14 days before the changes take effect.

The "Last updated" date at the top of this page indicates when this policy was most recently revised. We encourage you to review this policy periodically.

Your continued use of the Service after the effective date of an updated Privacy Policy constitutes your acceptance of the revised policy. If you do not agree to the updated policy, you must discontinue your use of the Service and may request account deletion.

Previous versions of this policy are available upon request by contacting privacy@tahro.io.

10.Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: privacy@tahro.io General Support: support@tahro.io

Mailing Address: tahro, Inc. Attn: Privacy Team [Address on file with registered agent]

EU Representative (GDPR): For users in the European Economic Area, our EU data protection representative can be reached at eu-privacy@tahro.io.

We aim to respond to all privacy inquiries within 5 business days. For formal data subject rights requests, we will respond within 30 days as required by applicable law.