Most trust pages list controls an auditor has signed off. We have not been audited, so this page does something different: it describes exactly what happens to your audio, names every third party that sees any part of it, and ends with a list of the things we have not done. Every claim here can be checked in the source.
Updated 18 September 2026Report a vulnerability: trust@freedomwithai.com
Audio leaves your browser over an encrypted WebRTC connection (DTLS-SRTP) to the media server you run. The interpreter receives it only while you are speaking — a voice gate opens on speech and closes on silence.
Speech is recognised, translated and re-spoken in memory; the agent writes no audio to disk and has no database connection. While a room is open it keeps the finished sentences in memory (for “catch me up”) and hands them to the web app, which stores them only for workspace meetings whose transcript setting is on — and discards them otherwise. Audio is never stored.
Each listener receives a separate synthesised track in their own language, over the same encrypted connection. Original audio is carried alongside it so you can duck or raise it.
Anonymous meetings keep nothing afterwards: while one runs, the server holds only display names, chosen languages and waiting-room requests, and deletes them when it ends (or within a day if the end is never reported). Workspace meetings keep a transcript, chat and AI recap only when the workspace policy says so, and everyone in the call sees a “Recap on” badge. Cloud recordings go to the bucket you nominate; local recordings stay on the recording person’s computer. Every recording shows a REC badge and a notice to all participants.
Measured, not asserted: the marketing pages make no third-party requests at all, and a live meeting contacts exactly two external hosts — and only when you use a background effect.
Anonymous meetings leave nothing behind: no account, no transcript, no recording, and the names and languages used to run the call are deleted when it ends. The interpreter itself has no database connection and no filesystem writes — audio exists only in memory, for as long as the sentence takes, and the running transcript it holds for “catch me up” is dropped when the room closes.
The SFU is LiveKit running on your infrastructure. No third-party meeting service sits in the path of the audio.
Background blur and replacement run in your browser with MediaPipe. Video frames are never uploaded for processing.
WebRTC media is DTLS-SRTP. Signalling and the app are served over TLS.
A token grants one room, carries a randomised identity and expires after six hours.
Meeting codes must match a strict pattern; display names are truncated and stripped of control and bidirectional-override characters so they cannot disguise the UI.
Token issuing is capped at 30 requests per minute per client address.
Content-Security-Policy, HSTS, X-Frame-Options: DENY, X-Content-Type-Options, Referrer-Policy, and a Permissions-Policy that grants camera and microphone only to this origin.
Accounts and meeting history live in the Postgres you provide; recordings live in the object store you nominate.
Platform superadmin; workspace owner, admin, host and member; meeting host, co-host, participant and viewer. Every moderation call is authorised on the server from the database, never from what a browser claims.
Passcodes, waiting rooms (knock to join), members-only meetings, locking a meeting in progress, and removal by the host.
Membership, role, branding, policy, recording, moderation and API-key changes are recorded with who, when and from which address.
Passwords are scrypt-hashed; API keys are stored only as SHA-256 hashes and shown once; webhooks are signed with HMAC-SHA256.
Each workspace can delete meetings (transcripts, recaps, chat) automatically after a set number of days.
Providers are configurable per pipeline stage and per language, so this list changes with your configuration. Your hosting provider and your object-storage provider are also subprocessors — but they are yours, chosen by you, and we never see those credentials.
If you need any of these for a procurement review, say so and we will tell you honestly whether it is on the roadmap or simply absent. We would rather lose a deal than claim a certificate we do not hold.
Email trust@freedomwithai.com with steps to reproduce. We will acknowledge within three working days. There is no bounty programme; we will credit you if you want it. Please do not run automated scans against a shared deployment, and never test against a meeting you are not part of.