//

Trust & Security

Security and privacy, documented.

Earmark captures meetings without adding a bot, does not retain raw meeting audio, and does not use customer content to train its models. This page documents the data flow, retention choices, subprocessors, controls, and current compliance status.

Last updated: October 8, 2026. Statements on this page describe the product as of this date. Availability that changes is called out below in Compliance and enterprise status.

//

At a glance

Four promises we keep by default

Botless capture

Audio is captured on your device. Nothing joins your call, and other participants aren’t notified by Earmark.

No raw audio retained

Audio is streamed for transcription and never written to disk or stored by Earmark.

No training on your content

Earmark doesn’t train AI models on your meetings, transcripts, or artifacts.

Private by default

Meetings are visible only to the person who created them, even within a workspace.

//

Data flow

How your meeting data moves

Every meeting follows the same path from your device to the outputs you create.

Your device

Mic + system audio

AssemblyAI

Real-time transcription (US)

Earmark backend

Convex (US)

AI model provider

OpenAI or Anthropic

1

Capture

The Earmark app captures your microphone (web and desktop) and system audio (desktop only). Audio stays in memory only long enough to be streamed.

2

Transcription

Audio is streamed to AssemblyAI over a secure WebSocket (wss://streaming.assemblyai.com, port 443). AssemblyAI returns transcript text in real time.

3

Storage

For saved meetings, transcript text is stored in your workspace on Convex. For temporary meetings, it isn’t saved to Earmark’s servers.

4

Generation

When you create a task, Earmark sends your prompt, meeting context, and relevant transcript text to the selected AI model provider. The resulting artifact is returned to your meeting.

5

Sync

Your apps receive updates over an encrypted realtime connection.

//

Lifecycle

Data by lifecycle stage

Stage

Audio

Transcript

Artifacts & pins

Where it lives

During capture

Held in memory and streamed

Created in real time

Created on request

Your device, AssemblyAI (in transit), Convex

After the meeting (saved)

Not stored

Stored in your workspace

Stored in your workspace

Convex

After the meeting (temporary)

Not stored

Not saved to Earmark’s servers

Not saved to Earmark’s servers

Your device, that session only

Local transcript file (desktop)

Not stored

Markdown file on your device, if enabled

Not included

Your device

After deletion

Not stored

Recoverable for 30 days, then purged

Recoverable for 30 days, then purged. Pins removed immediately.

Convex, then removed

//

Handling

Audio, transcripts, and outputs

Audio

Earmark never writes meeting audio to disk or uploads it to storage. On macOS, the ‘Screen & System Audio Recording’ permission is used only to capture audio — Earmark doesn’t record or store screen content.

Transcripts

Transcripts from saved meetings are stored in your workspace and indexed so you can search your own meetings. Desktop users can also save a Markdown copy locally, on by default and toggled in Settings › Personalization › Meeting files.

AI outputs

Artifacts, titles, and answers send only what the task needs: your prompt, meeting context (title, attendees, your role and bio, and company vision), and relevant transcript text. Artifacts from saved meetings are stored with the meeting.

Model training policy

Earmark does not train AI models on your meeting data, transcripts, pins, or artifacts. Your content is processed only to produce your outputs and is never shared with other customers.

//

Encryption

Encrypted in transit and at rest

Layer

Protection

In transit

TLS for all traffic between your device, Earmark, and subprocessors (HTTPS and WSS on port 443).

At rest

Encrypted by our infrastructure providers.

//

Isolation

Tenant and workspace isolation

Between workspaces: each workspace’s data is logically separated from every other workspace.

Within a workspace: meeting content is private to the person who created it. Members, including admins, can’t view each other’s meetings, transcripts, pins, or artifacts.

Shared within a workspace: workspace name, logo, company description, transcription language, policies, and the member directory (names and email addresses).

//

Retention

Retention and temporary mode

Data

Retention

Raw audio

Never stored.

Saved meetings

Kept until you delete them.

Temporary meetings

Not saved to Earmark’s servers. Audio and transcript text are still processed by our transcription and AI providers while the meeting runs.

Deleted meetings

Recoverable from Recently deleted for 30 days, then permanently purged with all associated data (transcript, tasks, artifacts, participants).

The 30-day recovery window is fixed. Custom retention periods aren’t available yet.

Workspace admins can require temporary mode for every new meeting in Settings › Workspace › Temporary meetings. Members can’t override it.

//

Access

Authentication and administration

Earmark uses Clerk for authentication. Sign in with an email verification code, Google, or Microsoft. Review active sessions and revoke one or all of them from Settings › Security.

Role

Capabilities

Admin

Manage members and roles; edit workspace name, logo, and company description; set transcription language; require temporary mode; manage billing; and delete the workspace.

Member

Create meetings, generate artifacts, and use all core features.

Admin rights don’t grant access to other members’ meeting content.

//

Subprocessors

Who processes your data

Provider

Purpose

Data received

AssemblyAI

Real-time transcription

Meeting audio

OpenAI

AI outputs

Prompts, meeting context, transcript text

Anthropic

AI outputs

Prompts, meeting context, transcript text

Convex

Database and realtime backend

Meetings, transcripts, artifacts, workspace data

Clerk

Authentication

Name, email, workspace membership, calendar connection tokens

Vercel

Hosting

Application requests

Google Calendar / Microsoft Graph

Calendar sync (desktop, when connected)

Calendar events, read-only

PostHog

Product analytics

Usage events, name, email; session recordings with all text masked

Sentry

Error monitoring

Error reports, name, email; session replays with text masked

Better Stack

Logging

Application logs

Stripe

Payments

Billing details, entered directly with Stripe

ToDesktop

Desktop app delivery

App installs and updates

Vimeo

Product tour video

Standard video embed requests

Processing is US-based. Transcription uses AssemblyAI’s default (US) streaming endpoint. We update this list when subprocessors change. For a copy for your vendor review, email support@tryearmark.com.

//

Incidents

Incident response

If we confirm a security incident affecting your data, we will notify affected workspace owners by email without undue delay — and share what happened, what data was involved, and what we’re doing about it.

To report a vulnerability or suspected incident, email support@tryearmark.com. Please include steps to reproduce, and avoid accessing other users’ data.

//

Your controls

Deletion and export

Action

Who

What happens

Delete a meeting

Meeting owner

Moves to Recently deleted with its transcript, tasks, artifacts, and participants. Restorable for 30 days, then purged by a daily job.

Delete a pin

Pin creator

Removed immediately. Can’t be restored.

Delete your account

You, in Settings › Security

Your meetings and data are removed and purged after 30 days.

Delete a workspace

Admin

All meetings are removed and purged after 30 days. Requires typing the workspace name to confirm.

Export a meeting

Meeting owner

Download transcript, artifacts, and details as Markdown. You can also combine all open meeting windows into one file.

Bulk export isn’t available yet. Contact support if you need help exporting many meetings.

//

Enterprise

Security reviews and custom terms

We support security reviews, vendor questionnaires, and custom terms for teams evaluating Earmark.

//

Status

Compliance and enterprise status

Status as of October 8, 2026. “Not available” means the control isn’t offered today — ask us about timing.

Control

Status

Owner

Reviewed

SOC 2 report

In progress

Security

2026-10-08

GDPR and DPA

In progress

Legal

2026-10-08

SAML / OIDC SSO

Available

Engineering

2026-10-08

SCIM provisioning

Not available

Engineering

2026-10-08

Enforced multi-factor authentication

Not available

Engineering

2026-10-08

Audit logs

Available

Engineering

2026-10-08

Data residency

Not available — processing is US-based

Engineering

2026-10-08

Custom retention periods

Not available — 30-day window is fixed

Engineering

2026-10-08

Bulk data export

Available

Engineering

2026-10-08

Uptime SLA

Available

Engineering

2026-10-08

Public status page

Available

Engineering

2026-10-08

No training on customer content

Available

Engineering

2026-10-08

No raw audio retention

Available

Engineering

2026-10-08

Workspace-enforced temporary mode

Available

Engineering

2026-10-08

Encryption in transit (TLS)

Available

Engineering

2026-10-08

Still have a security question?

Book a review or send your questionnaire — we’ll walk through architecture, data handling, and your requirements.