Privacy Policy
Last updated: 27 September 2026
Yaumiyya is a meeting-notes app operated by Atoll Mind. It turns meeting audio into transcripts, summaries and action items. This policy explains what we collect, what happens to your audio, and how we use data from your Google account if you sign in with Google.
The assistant, letter drafts and payment notifications
Atoll Mind Model is the name of our AI experience in Yaumiyya. When you ask Ask Yaumiyya a question, it is sent through our server to our AI processing service to answer it, and recent turns may be sent again to understand follow-up questions. The assistant does not record or play audio. Question counts are stored to account for usage and prevent abuse. Your questions and the assistant’s answers are not saved to your account: the conversation is kept in the browser tab you asked it in, and is gone when that tab is closed.
When you ask the assistant to draft a letter or email, what you type — your description, any message you paste in to reply to, and the recipient and signature details — is sent through our server to our AI processing service to write the draft. If you choose a meeting, its title, date and summary are sent too, with its minutes if it has them or otherwise the beginning of its transcript. Drafts are not saved on our servers: the draft is returned to your browser and kept only in that browser tab until you close it or sign out, and your signature details are remembered only on your device until you sign out. We store a count of drafts to apply the monthly allowance. Only paste messages you are allowed to share with a processing service.
Bank-transfer slips are stored privately for administrator review. Telegram alerts notify the operator that a review is pending and include a review ID and an authenticated admin link. We do not include your slip image, email or payment reference in those alerts. Telegram processes the notification under its own policies.
Third-party processing services may retain content under their service policies and our service arrangements. Atoll Mind does not train its own models on your meeting content. For questions about processing partners, retention or handling of sensitive recordings, contact our privacy team before uploading.
The Library
Documents you add to the Library — policies, manuals, reports and the like — are stored privately with our cloud hosting service, on servers in Asia-Pacific. To make them searchable, their text is read on our servers and split into passages, and each passage is sent to our AI processing service to be turned into a search index (an “embedding”). A scanned PDF, or one typed in an older Thaana font, is instead read page by page by our AI processing service. When you ask a question, the passages that best match it are sent with your question to write the answer.
A document you add is visible only to you unless you choose “My team”, which lets the people on your plan read it and ask about it; they stop seeing it if they or you leave the plan. Deleting a document deletes its file, its text and its index at once, and Delete my data deletes every document you added. We keep a count of pages read each month to apply your plan’s limit. Only add documents you are allowed to share with a processing service.
Sharing from a meeting
The Share buttons hand the text on screen — a summary, transcript, action list or insights, or a follow-up email, action list or decision register built from the minutes — to the app you choose, such as WhatsApp, Viber, Telegram, your email app or your device’s share sheet. Yaumiyya does not send it anywhere itself. For WhatsApp and Telegram the text travels in the link to their website as soon as you choose them, before you pick a chat; from there it is handled under that app’s policies and by whoever you send it to. If a message is too long for the app, the full text is also placed on your clipboard.
Dictionary lookups
Dictionary lookups run on Yaumiyya’s own servers against a local Dhivehi dictionary corpus. We do not send your search word, account identity, or meeting notes to a third-party dictionary API for these lookups. Word definitions may be temporarily cached to make repeat searches faster.
Error reports and usage analytics
To keep Yaumiyya working and to improve it, we use two services. Sentry, on servers in the EU (Germany), receives a report when something breaks in the app or on our servers: the kind of error, a shortened error message, where in our code it happened, your browser and operating system, and the address of the page with any meeting or invitation ID replaced by a placeholder. PostHog, on servers in the United States, receives usage analytics: which pages are opened, with the same IDs removed, and counts of actions such as uploading a meeting or generating minutes. PostHog links these to a random identifier kept in your browser (a cookie and local storage) and, once you sign in, to your account’s internal ID — never your name or email address. If your browser sends Do Not Track, no analytics are sent.
Neither service receives your meeting content — no audio, transcripts, minutes, summaries, action items, meeting titles, names, email addresses or file names. Error reports are filtered before they leave to remove anything that looks like a transcript line, Dhivehi text or an email address. There is no session replay or screen recording, both services are reached through our own domain, and we configure both not to keep your IP address. We use them only to keep the service reliable and to improve it, not for advertising, and we do not sell this data.
1. Who we are
Yaumiyya is operated by Atoll Mind, Maldives. For any privacy question, contact yaumiyya@atollmind.online.
2. What we collect
- • Account details — your email address, and a display name if you set one.
- • Meeting content — the audio you record, capture from a call on your computer, or upload, the audio Yaumiyya records when you send it to join an online meeting, and the transcript, summary, action items and tasks made from it.
- • Usage records — how many minutes you have transcribed, and how many assistant questions, letter drafts and minutes edits you have used, so we can apply usage limits and credit balances.
- • Trial record — a one-way hash of your email address, normalised (lower case, without a “+” suffix and, for Gmail, without dots), so the free trial is given once per person. Your address itself is not stored in it, it is used for nothing else, and it is kept after an account is deleted so the trial cannot be repeated.
- • Shared credit pool records — if you join somebody’s plan, or add someone to yours, we hold who is in whose pool, the name or address shown on that membership, any monthly limit set on it, and, against each credit charged, which member’s work it paid for. That last record is what lets a plan owner see how many credits each person used. It is a count, and it names no meeting.
- • Shared meeting records — if you share one of your meetings with your plan, or with someone on it, we hold which meeting, which plan, who you shared it with and when. Nothing is copied: the record is a permission, and deleting it ends the access the same moment.
- • Notification settings — which kinds of in-app notification you switched off, and which one you last saw, so the bell can show what is new.
- • Payment records — when you buy credits, a plan or an extra hour, the reference and amount of your payment and the transfer slip you upload, held privately for an administrator to verify. We keep a transfer slip for five years after it is checked, as a financial record, and then delete it; the record of the payment itself stays with your credit history. We never see or store your card details.
- • Contract records — if your organization is served by a contract rather than paying in the app, we hold the purchase-order reference the contract is invoiced against, the term and terms agreed, and a record of every call-off made under it. Because a contract is invoiced in arrears, that reference is stored on the account and is shown beside each call-off on your credit activity, so the invoice can be matched to what was supplied. It is a reference your organization issued to us, not a payment instrument.
3. Signing in with Google
If you choose “Continue with Google”, Google shares your name, email address and profile picture with us. We use them for one purpose only: to create and identify your Yaumiyya account and to show who is signed in.
We do not request access to your Gmail, Drive, Contacts, Calendar or any other Google service, and we never post anything to your Google account. You can revoke Yaumiyya's access at any time from your Google account permissions page.
Limited Use: Yaumiyya's use and transfer of information received through Google sign-in adheres to the Google User Data Policy, including its Limited Use requirements. We do not sell Google user data, use it for advertising, or use it to train AI models.
4. Audio storage and deletion
Uploaded audio is deleted as soon as its transcript is saved. We use audio only to produce the transcript and do not keep it on our servers afterwards. If processing fails before a transcript exists, the audio is kept in private storage for about an hour so you can retry, and is then deleted. Deleting a meeting removes its audio and notes; if a deletion attempt fails, it is retried automatically.
The app may also keep a copy of the audio on your own device so you can play the meeting back. That playback copy stays in your browser, and you can remove it at any time from Settings.
5. Capturing a call on your computer
Your screen is never recorded. When you capture a call running on your computer, the browser asks you to choose a screen before it will share that computer’s sound. Yaumiyya drops the screen as soon as the browser allows, which on almost every browser is the moment it is handed over; where one will not give up the sound without it, the screen stays shared and is still never read. Either way no image of it is drawn, stored, uploaded or sent anywhere, and only sound is recorded. Your browser still shows its own sharing indicator for as long as the capture runs, because it cannot tell what we do with what it gave us.
What that sound contains is whatever your computer is playing, which is the meeting and also anything else making noise at the time. Your microphone is a separate recording and you can turn it off before you start. The audio that results is treated exactly like any other recording, including being deleted from our servers as soon as its transcript is saved.
6. Sending Yaumiyya to an online meeting
When you paste a Zoom, Google Meet, Microsoft Teams or Webex link, Yaumiyya joins the call as a visible, named participant that everyone in the meeting can see and that someone has to admit. It records the call’s mixed audio only — not video, and no image of anyone’s screen.
That recording is made and held by our meeting-recording provider, Recall.ai, on servers in Asia-Pacific (Tokyo) — not on your device, and not in our own storage. We delete the provider’s copy as soon as the transcript is saved. If processing fails, it is kept there for about an hour so the meeting can be retried, and is then deleted. The provider handles it under its own policies and our service agreement with it.
This records other people, including people who do not use Yaumiyya and have no agreement with us. You are responsible for any notice or consent your organisation, your jurisdiction or the meeting service requires before recording them.
7. How your content is processed
To produce your transcript, summary, assistant answers and letter drafts, your audio and text are sent to third-party AI processing services and handled under their service policies.
We do not sell your data, and we do not use your meetings to train our own models.
8. Who can see your meetings
No other user can see your data. Every meeting, transcript, summary and task is tied to your account and access is enforced in the database itself (row-level security), not just hidden in the interface.
Two exceptions you should know about: the app operator can access account data where necessary to run the service — for support, verifying a payment, or investigating abuse — and our servers necessarily process your content to produce your notes. The service is not end-to-end encrypted, so please do not upload material you would not be comfortable with the operator being able to access.
If your credits come from somebody else’s plan, that does not change. A plan owner pays for what the people they added transcribe, ask and draft, and what they are shown in return is a number: how many credits each member spent this month, the name or address on that membership, and any limit they set on it. They never see your meetings unless you share one with them — not the audio, the transcripts, the summaries, the action items, the titles, the dates or your questions to the assistant. Joining a pool shares nothing, and paying for one grants nothing: every meeting stays private to whoever recorded it until that person decides otherwise. The same is true the other way: you cannot see the owner’s meetings, or any other member’s, unless they share one with you. You can leave the pool at any time from Settings, and leaving is separate from deleting your data — doing one does not do the other.
Sharing one of your meetings. If you are on a plan with more than one seat you can share a meeting you recorded, either with everyone on the plan or with named people on it, from that meeting’s own page. Sharing lets them read it — the transcript, the minutes and the actions — and nothing more: they cannot edit, rename, regenerate or delete anything, they cannot see the recording, which is never shared and is deleted as soon as the transcript is made, and they cannot see what that meeting cost you in credits. No email is sent; the meeting appears in their list, with an in-app notification under their bell unless they have switched those off. You can stop a share at any time on the same page and their access ends that moment, and it stops for as long as the plan goes unpaid — access is worked out afresh on every read, so paying again brings back a share you have not ended. A share never reaches anybody outside the plan: if you leave it, or the person you shared with does, the access ends with the membership and the record of it is deleted.
Putting an action on somebody’s list. On a plan with more than one seat you can assign one of a meeting’s actions to somebody on that plan. Assigning is not sharing, and it does not open the meeting — what the person is given is the action itself: the task, any note on it, the deadline and priority, who assigned it, and the meeting’s title and date so they know what it came out of. They do not get the transcript, the minutes, the summary or anything else of that meeting unless you also share it with them, which is the separate act described above. They can move the action between states and write a note on it, and so can you; nobody else who can read the meeting can change it. They can also confirm they have it, or ask you to clarify it with a short note, and you see that answer on the action. Nothing is emailed to them: the action appears on their Actions page, is counted on its tab, and shows under their bell as an in-app notification unless they have switched those off. You can take it back at any time from the meeting page, and if either of you leaves the plan the action comes back to you unassigned, keeping its state, its note and a record of who had been carrying it.
Approving minutes. You can send a meeting’s minutes to people on your plan to approve. Naming someone as an approver shares the meeting with them to read, as described above, if it is not shared with them already, and that share stays until you stop it. Each approver can approve the minutes or return them with a short note, which you and anybody else who can read the meeting will see. When everyone has approved, we keep a fixed copy of exactly what was approved, with who approved it, when, and a fingerprint of that copy (a short code printed on the PDF and Word file, so anybody holding one can check it was not changed). That copy is kept with the meeting and deleted with it, and while it is the current version its wording cannot be edited.
The decision register. When minutes are approved, each decision in them is kept as a numbered record (for example DEC-2026-0007) with the wording that was approved, who moved and seconded it where the minutes say, and the lines of the transcript it came from. The records are read by exactly the people who can read that meeting, and leave anybody’s register when their access to the meeting ends. The meeting’s owner can mark a decision superseded or revoked, with a note; we keep when that was done. The records are deleted with the meeting.
Meeting series. You can file your meetings into series of your own, such as “Weekly ops”; a series holds only your own meetings and its name is kept until you delete it (the meetings stay). A meeting in a series carries forward what is still open from the earlier ones — their open actions, with who has them and when they are due, and the decisions the last meeting deferred — as a section of its minutes. Anybody who can read that meeting sees that section, including people it is shared with and its approvers, even if they cannot open the earlier meetings themselves; approved minutes keep it as it stood. The name of the series shows on a shared meeting; nothing else about the series does.
Notifications. The bell at the top of the app lists what has happened to your own actions and meetings: an action given to you, a comment on one of yours or one that mentions you, an answer from the person you assigned, progress and changes, reminders around a due date, a transcript or minutes that are ready or failed, a meeting shared with you, minutes sent to you to approve and what happens to them, somebody joining or leaving your team, and credits running low. It is built from the record the app already keeps of what happened (who did what, and when) and shows each line only to the people it concerns, never to the person who did it. Its wording comes from what you can already open, so an action or meeting you no longer have access to is not named. It stays inside the app: no email is sent yet, and nothing is pushed to your phone. Each kind can be switched off in Settings → Notifications; we keep which kinds you switched off and which notification you last saw, and nothing else about them.
9. Where data is stored and for how long
Your account and meeting notes are stored with our cloud hosting service, encrypted at rest, on servers in Asia-Pacific. Traffic between your device and the app is encrypted with HTTPS.
We keep your notes until you delete them. You can permanently delete all of your meetings, transcripts and summaries at any time from Settings → Delete my data, and you can ask us to delete your whole account by emailing us. The one exception is a meeting Yaumiyya joined online: while it is still in the call, or its recording is still being processed (usually within about half an hour of the call ending), the meeting is kept until that finishes; delete it again then, from the meeting page or with Delete my data. You can take Yaumiyya out of a call from the meeting page.
10. Your rights
You can access, correct, export or delete your data. Export is available from any meeting (PDF, DOCX, calendar), deletion from Settings, and anything else by contacting us at the address above. We respond to requests within a reasonable time.
11. Children
Yaumiyya is intended for workplace use and is not directed at children under 13.
12. Changes
We may update this policy; the “last updated” date above shows the current version. Continued use of the app means you accept the latest version.
13. Contact
Questions about this policy? Email yaumiyya@atollmind.online or message +960 794 8580 on WhatsApp.
See also our Terms & disclaimer.