Security & your data

Last updated: July 30, 2026 · Coommit is operated by TAAO Inc.

The short version. Your rooms are private and reachable only by link or invitation. Files you upload are stored in private buckets that have no public address. Coommit never trains any model on your content — and when Echo talks to an AI provider, which provider and under whose terms is a choice you make and can see. You can delete a room, a recording, or your whole account yourself.

Where your data lives

Coommit runs entirely on Google Cloud. The application runs on Cloud Run, your content is stored in Cloud SQL (PostgreSQL) and Cloud Storage, and Google encrypts data at rest across those services by default. We don't run servers of our own anywhere else.

We're a US company (Delaware) serving customers on both sides of the Atlantic, and our infrastructure spans US and EU regions. If the exact storage region matters for your compliance review, ask us and we'll tell you precisely which region your workspace sits in rather than guess in a marketing page.

Encryption

What this is not: Coommit is not end-to-end encrypted. Live audio and video pass through our media servers, which have to decrypt them to route the call and to run transcription. Anyone who tells you a browser-based meeting tool with recording and AI features is end-to-end encrypted is either wrong or selling you something. We'd rather say it plainly.

Who can get into your room

Your documents and our AI

This is the part people ask about most, so here it is in full.

Audio, transcripts and recordings

WhatStored?Notes
Live meeting audioNoStreamed for transcription as the call happens; the audio itself is not written to storage.
Text transcriptYesKept with the room so you can search and reuse what was said. Room owners can turn transcription off entirely.
RecordingsYes, if you recordOnly when someone starts a recording. Stored in a private bucket; you can delete them (see the retention note below on what "delete" guarantees).
Canvas, files, chatYesThat's the product — a room that remembers. Files sit in private buckets served through short-lived signed links, never a public URL.

How long we keep things

We keep your content for as long as you keep it. There is no automatic expiry today — we'd rather tell you that than publish a retention promise our servers don't enforce. What that means in practice:

One limit, stated plainly — and it applies to all three of those. Deleting removes the record immediately and completely: nothing is listable, no link works, no account can reach it. What we cannot yet promise is that the underlying file has been erased from cloud storage in the same instant. Our delete paths ask the storage layer to remove the object, but they do not block on it or retry, so a transient storage error can leave a blob behind with nothing pointing at it. Unreachable is not the same as erased, and we would rather write that sentence than let you assume the stronger one.

If you need certified erasure of stored files — a GDPR request, an end-of-engagement clause, a client audit — email hello@coommit.com and we will do it by hand and confirm it to you in writing. A durable purge queue with retries, and automatic retention limits, are both on the fix list; when they ship we will say so here, with the numbers.

Who else touches your data

Always in the path:

WhoWhat they get
Google CloudHosting, database, file storage, speech-to-text and text-to-speech. Effectively everything, because it is our infrastructure.
MeteredTURN relay servers for WebRTC. Relays call media when a direct path is blocked by a firewall.
ResendTransactional email — your address and the contents of the email itself.
SentryError reports: stack traces, browser and page context.
PostHogProduct analytics — which features get used, tied to your account id. Not your canvas, not your transcripts.
StripePayments. Card details go to Stripe and never to us.

Only when you opt in:

We don't sell data to anyone, and we don't run advertising networks on your content. If you spot something in the product that implies a vendor we haven't listed here, tell us — that is a bug in this page and we want to fix it.

What we don't claim

Coommit is a young product from a small team, and the fastest way to lose your trust would be to imply otherwise.

  • We are not SOC 2, ISO 27001, or HIPAA certified. We haven't started those audits.
  • We are not end-to-end encrypted, for the reasons above.
  • We do not yet offer customer-managed encryption keys or a signed DPA with named sub-processor SLAs. If your procurement process requires one, talk to us — we'd rather have that conversation than have you assume.

If any of these is a blocker for you, tell us. Knowing which one actually stops a deal is more useful to us than a badge on a page.

Found a security problem?

Please tell us before you tell anyone else, and we'll work with you. Write to security@coommit.com — details and preferred languages are in our security.txt. We don't run a paid bounty programme yet, but we do credit people who help us.

Questions

Anything not answered here: hello@coommit.com. See also our Terms of Service.

← Back to Coommit