Your meetings, your data

Private by design.
Never used to train AI.

Meetings are among the most sensitive things a company records. Peaflow treats them that way — isolated per workspace, access-controlled at the database, and never fed into model training.

🔒

Tenant isolation

Every row is scoped to your workspace and enforced by database row-level security — one customer can never read or write another's meetings.

🗝️

Access-controlled storage

OAuth tokens and recordings are held server-side only, behind deny-by-default policies. Recordings are served through short-lived signed links.

✍️

Signed webhooks

Every inbound event — meeting, billing — is signature-verified and idempotent, so nothing forged or replayed is ever processed.

👋

Transparent consent

The notetaker appears in the participant list and the host admits it — everyone in the call can see it's recording.

🚫

No training on your data

Your transcripts and recordings are used to serve you — summaries, search, recaps — and never to train foundation models.

🗑️

Retention you control

Set how long recordings are kept, delete any meeting on demand, and account deletion anonymises your data rather than orphaning it.

Security questions

Where is my data stored?

In managed Postgres (Supabase) with row-level security, and recordings in Cloudflare R2 accessed through short-lived signed URLs. Peaflow never relies on a meeting provider's storage as the permanent copy.

Can other companies see my meetings?

No. Isolation is enforced at the database with a membership check on every read and write. We regularly run second-tenant attack tests against production to prove it.

Do you train AI on my meetings?

No. Your content is used only to generate your own summaries, answers and recaps.

How is billing secured?

Payments run through Polar with signature-verified, idempotent webhooks. Card details never touch Peaflow's servers.

Meeting intelligence you can trust.

Private by default — from the first recording.