Privacy Policy
This policy explains what personal data Meet IDBSD, operated by PT. Indonesia Bisnis Digital ("we"), processes and why.
1. What we process
- Display name. The name you type when joining a meeting. It is shown to the other participants.
- Chat messages and whiteboard drawings. Stored on our server so late joiners can see them. They are deleted up to 24 hours after the meeting becomes empty, or immediately when the host ends the meeting.
- Audio and video. Not recorded and not stored. They are sent between participants' browsers (end-to-end encrypted with DTLS-SRTP). If a direct connection is impossible they pass through our relay server, which cannot decrypt them.
- Google account data, only if you sign in with Google. Your name, email address and Google account identifier (the "sub" value). We request only the openid, email and profile scopes. We do not access your contacts, calendar, files or any other Google data.
- Audit log. Security-relevant events (sign-ins, administrator changes, meetings created or ended, participants admitted or removed) with the time, your IP address, your display name and, if signed in, your email address. Audit entries are kept for 90 days.
- IP address. Used for rate limiting and recorded in the audit log.
2. Cookies and local storage
- A session cookie keeps you signed in. It is strictly necessary and is deleted when you sign out or it expires.
- Your browser's local storage remembers your display name and, for hosts, a token that lets you reclaim the host role.
- We use no advertising or analytics cookies and no third-party trackers.
3. Why we process it
To run meetings, to keep the service secure and prevent abuse, and to keep an accountable record of administrative actions. If you sign in with Google, we process your account data to identify you and to apply access rules.
4. Sharing
We do not sell personal data. When you sign in, Google processes the sign-in request under its own privacy policy. Our hosting and network providers may process technical data needed to deliver the service. We disclose data if the law requires it.
5. Google API Services User Data Policy
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google account information only to authenticate you and to show your name; we do not transfer it to others, use it for advertising or use it to train models.
6. Retention and deletion
Retention periods are stated above. To ask for access to, correction or deletion of your data, contact dionipe.net@gmail.com. Audit entries needed to protect the security of the service may be kept for the stated period.
7. Security
Connections can be protected with HTTPS, sign-in sessions use secure cookies, secrets are stored with restricted file permissions, and the audit log is tamper-evident. No system is perfectly secure.
8. Children
The service is not directed at children, and you should not use it to collect data about them.
9. Changes
We may update this policy. The date of the latest change is shown at the top of the page.
10. Contact
dionipe.net@gmail.com