Privacy Policy
Effective date: 19 August 2026
Concerto Labs (the "Company") operates The CEO Staff (the "Service", including the website theceostaff.com and the desktop app for macOS and Windows) in compliance with the Personal Information Protection Act of the Republic of Korea ("PIPA") and other applicable laws. In order to process personal data lawfully and keep it secure, the Company establishes and discloses this Privacy Policy pursuant to Article 30 of PIPA.
The CEO Staff is a desktop app that recognises what the other party says during a video meeting in real time, supplies a script you can read aloud, and produces a summary report once the meeting ends. It is currently available on macOS and Windows, and the features offered may differ by operating system. Because of what the Service does, it handles information that can be sensitive — meeting audio and the content of conversations — so the Company sets out its principles for that material separately in Article 5.
In short
Meeting content — audio, transcripts, reports, knowledge base and so on — is stored, as a rule, only on your device.The exception is where you use the meeting-record sharing feature: the summary, transcript and participant details of that record are then stored on the Company's servers. Recordings are never uploaded to the servers under any circumstances. Revoking a share also deletes what was stored (Article 5(2)).The Company does not use your conversations to train AI models.The Company does not sell personal data for money. The website does carry a Meta pixel for measuring advertising performance; in regions where prior consent is required it runs only with consent (Article 10). The desktop app contains no advertising or tracking technology.Notifying meeting participants about recording and transcription, and obtaining their consent, is your responsibility (Article 5(4)).For paid plans, the Company does not store full card numbers or card security codes; withdrawal and refunds follow the Paid Service Withdrawal, Cancellation and Refund Policy.
Article 1 (Scope)
① This Policy applies to all of the following.
- Visiting the website (theceostaff.com) and registering interest in the beta test
- Sending and receiving invitations, and signing up and logging in
- Use of the desktop app (macOS and Windows) (meeting sessions, knowledge base, rehearsal, reports, meeting-record sharing and so on)
- Viewing the meeting-record web viewer (theceostaff.com/r/)
- Customer support and notices
② Where the Company enters into a separate agreement with a corporate customer and processes the personal data of that customer's staff on its instructions, the corporate customer is the controller and the Company acts as a processor. In that case the corporate customer's privacy policy takes precedence.
③ This Policy does not apply to external sites and services linked from the Service; please review the policies of those operators.
④ The Service may offer paid subscriptions in three-month or one-year terms, together with additional paid products. Withdrawal of subscription, cancellation and refunds for paid services are governed by the Paid Service Withdrawal, Cancellation and Refund Policy.
Article 2 (Definitions)
The terms used in this Policy have the meanings below; terms not defined here follow PIPA and related legislation.
- "Personal data" means information about a living individual that identifies that individual — such as a name, email address or voice — including information that identifies the individual when readily combined with other information.
- "Data subject" means the individual identifiable by the information processed, and in this Policy includes users who access, register interest in, sign up for or use the Service, as well as third parties who take part in a user's meeting.
- "User" means a person who has entered into a service agreement with the Company and uses the Service.
- "Meeting content" means audio processed while the user uses the Service, its transcript, translations, summaries and reports, and the knowledge base, FAQ and Memory entries the user has registered — that is, everything the user supplies or the Service generates.
- "Processor" means a party entrusted by the Company with processing personal data on its behalf.
- "Overseas transfer" means providing, entrusting or storing personal data outside the Republic of Korea.
Article 3 (Purposes of processing)
The Company processes personal data for the purposes below and does not use it for any other purpose. Where a purpose changes, the Company takes the necessary steps, such as obtaining separate consent under Article 18 of PIPA.
- Receiving beta registrations and reviewing invitations: verifying applicants, assessing fit, managing the invitation queue, sending invitation emails
- Sign-up and account management: identity verification (email confirmation), keeping sessions signed in, account security, preventing duplicate and fraudulent registration
- Operating the invitation programme: issuing, delivering and expiring invitations, granting and reconciling rewards (free usage credits) for inviters and joiners
- Providing the Service: real-time speech recognition, answer script generation, translation and interpretation, summaries and meeting reports, storing and searching the knowledge base, FAQ and Memory, meeting rehearsal
- Sharing meeting records: creating the web share link for a record at the user's request, managing access rights, emailing the link to participants, and processing revocation of a share
- Usage management: granting, consuming and expiring free usage credits
- Customer support and notices: responding to enquiries, onboarding support, sending essential notices such as incidents and policy changes
- Service improvement and statistics: statistical analysis such as feature-level usage and error diagnosis (pseudonymised or aggregated as a matter of principle)
- Preventing misuse and complying with the law: detecting abuse and fraudulent credit acquisition, handling disputes, meeting statutory obligations
- Marketing messages (with separate consent): information about new features, events and promotions
- Measuring advertising performance: measuring what users who arrive through an advertisement do — visits to the website, downloads and the like — analysing advertising efficiency and building advertising audiences
- Paid service payment and refunds: payment for subscriptions and additional products, management of recurring payments, payment confirmation, issuing receipts, processing withdrawal, cancellation and refunds, preventing fraudulent payments and handling payment-related disputes
Article 4 (Categories of personal data processed and how it is collected)
① Beta registration (registering interest)
| Type | Items | How collected | Purpose |
|---|---|---|---|
| Required | Email address | Entered in the registration form | Sending the invitation email |
| Optional | Name, job role, main meeting type, average meetings per month, whether meetings are in a foreign language, reason for requesting an invitation | Entered in the registration form | Assessing fit for invitation and managing the queue |
| Generated automatically | Whether consent was given and when | Recorded automatically on submission | Evidence of consent |
| Collected automatically | Registration language, country of access (country code), operating system | Collected automatically on submission | Understanding demand by region and environment, preparing for launch |
You can register without providing the optional items, although there may then be less information available for the invitation review.
② Sign-up and invitations
| Type | Items | How collected |
|---|---|---|
| Required | Email address, password (stored encrypted), name, phone number | Entered in the sign-up form |
| Social login | Email address, name, profile image URL, social account identifier | Supplied by the authentication provider, such as Google |
| Optional | Profile image, organisation and job title | Entered directly |
| Invitations | Email address of the invitee, history of issue, delivery, use and expiry | Entered and sent by the user |
| Credits | Credit balance, reason granted, consumption history, founding-member status | Generated automatically within the Service |
Phone number: stored converted to international format (E.164, without hyphens), and used only for essential account notices and for identity checks and contact during customer support. It is not used for marketing without separate consent.
Note when sending invitations: entering a third party's email address to send an invitation amounts to providing that third party's personal data to the Company. You must obtain that person's consent in advance. The Company uses the address only to send the invitation and confirm the outcome, and destroys it without delay once the invitation has expired or gone unused.
③ Use of the Service (meeting content)
As a rule, meeting content is stored only inside the user's device. The Company's servers and its external AI and speech-recognition providers are involved only as a transient processing path that produces a result and returns it to the user's screen.
By way of exception, where a user uses the meeting-record sharing feature, a snapshot of that record is stored on the Company's servers. The details are set out in Article 5(2).
| Type | Items | How collected | Where stored |
|---|---|---|---|
| Audio | The user's microphone input and the other party's audio played on the user's device (only while the user has a session running) | Collected only where the user has explicitly granted the microphone access and system audio capture permissions required by the operating system | Not stored (passes through for real-time recognition only) |
| Recordings | Combined session recording (where the user uses the recording feature) | Generated automatically during the session | Stored only on the user's device |
| Text | Transcripts of the above audio, translations, and metadata such as speaking times and talk ratio | Generated automatically by the Service | Stored only on the user's device |
| Generated output | Answer scripts, live summaries, meeting reports, automatically extracted "Memory" items (positions, decisions, commitments) | Generated automatically by the Service | Stored only on the user's device |
| Material registered by the user | Knowledge base documents (uploaded txt/md/pdf/docx files and documents written in the Service), FAQ, folder and tag information | Registered by the user | Stored only on the user's device |
| Information about meeting counterparts | Name, organisation, job title, notes on disposition and public-information research results for the companies and people the user has registered | Entered by the user, or searched and summarised from public web information at the user's request | Stored only on the user's device |
| Shared meeting records | Title, structured summary, timeline entries, speaker names and transcript (elapsed time from the start of the meeting) of the shared record, the share link identifier and the access scope setting | Created where the user runs the sharing feature | Stored on the Company's servers |
| Participant details | Email addresses and names of participants entered by the user, and the history of links sent | Entered directly by the user | Stored on the Company's servers |
Recordings are not included in the snapshot that is shared. Times in the transcript are also stored only as elapsed time from the start of the meeting, not as absolute timestamps.
④ Information collected automatically
| Items | Purpose |
|---|---|
| Access logs (time of access, request path, response code), browser type when using the website, app version when using the app, operating system, country code of access | Service operation, incident diagnosis, security |
| IP address after login | Detecting unauthorised account access (kept for 90 days) |
| Usage records (feature usage counts, session length, tokens used, error events) | Credit deduction, statistics, quality improvement |
| Information collected by the advertising pixel (page view events, browser and device information, IP address, Meta cookie identifier) | Measuring advertising performance (in regions where prior consent is required, collected only with consent) |
| Cookies and similar technologies | See Article 10 |
⑤ Data minimisation
- The Company collects no unique identifiers whatsoever, such as resident registration numbers or passport numbers.
- The Company does not set out to collect sensitive data such as political opinions, health, sex life, genetic data or criminal records. Because such material may naturally arise in a user's meeting, the Company applies the enhanced safeguards in Article 5 to meeting content as a whole.
- The Company does not create or store biometric data such as voiceprints for speaker identification. Speakers are distinguished only by processing separate audio channels (your microphone / the other party's sound).
- The Company does not keep its own record of website visitors' IP addresses; for country of access it records only the country code in the request header (for example KR).
⑥ Paid service payment and refunds
| Type | Items | How collected | Purpose |
|---|---|---|---|
| Payment data | Payment method type, order number, payment approval number, amounts and dates of payment, cancellation and refund, subscription product, subscription term, recurring payment status | Supplied by the payment gateway during payment and refund | Payment confirmation, managing recurring payments, cancelling payments and issuing refunds |
| Refund data | Reason for the refund request, history of request, approval and processing, refund amount | Entered by the user and generated automatically within the Service | Processing withdrawal, cancellation and refunds, and addressing misuse |
| For cash refunds | Account holder, bank name, account number | Entered by the user where a refund cannot be made to the original payment method | Paying the refund |
Details of the payment method — card number, expiry date, card security code and the like — are handled directly by the payment gateway. The Company does not store full card numbers or card security codes.
⑦ App download
| Type | Items | How collected | Purpose |
|---|---|---|---|
| Required | Phone number | Entered in the download form | Confirming the download and contacting you with usage guidance |
The phone number is stored converted to international format (E.164, without hyphens) and is not used for marketing without separate consent.
Article 5 (Special provisions on meeting content)
Meeting content captures conversations between the user and the other party and so needs particular protection. The Company observes the following principles.
① As a rule, meeting content is stored only on the user's device (local-first design)
- Recordings, transcripts, translations, answer scripts, summaries and reports, Memory items, the knowledge base and FAQ, and information about meeting counterparts are held in the app's own data area on the user's device, encrypted per account. Unless the meeting-record sharing in paragraph 2 is used, none of it is transmitted to or stored on the Company's servers, and the Company can neither hold nor read it.
- The Company's servers and its external providers are involved only as a transient processing path that generates a result and returns it to the user's screen. The audio stream for real-time speech recognition is sent to the speech-recognition provider only while the session runs and is not stored; text for generating answers and summaries is sent to the AI provider, and processing ends when the result is returned (Article 12). Where live meeting notes are switched on, the speech in each interval is also sent to the AI provider at regular intervals during the meeting so that a summary can be generated. What is sent is processed and finished together with the return of the result, and is not stored.
- Please note: because meeting content exists only on your device, it cannot be recovered in the following cases.
- You delete the app together with its app data
- You reset or replace your device
- The operating system's credential store (the macOS keychain, the Windows Data Protection API and the like) is damaged or reset and the encryption key can no longer be read
- You sign in from another device (synchronisation across devices is not supported)
- You sign in with a different account (data is stored separately per account)
The encryption key that opens the account's data is tied to the protected area of that device's operating system, so copying the data files alone to another device does not allow them to be decrypted. This is deliberate, so that someone who takes the files cannot read them. The Company holds no backup and therefore cannot help with recovery. Please save important reports and documents separately using the download function in the Service.
② Processing when a meeting record is shared (an exception to local-first)
- When a user uses the meeting-record sharing feature, the title, structured summary, timeline entries, speaker names, participant email addresses and names, and transcript of that record are stored on the Company's servers as a snapshot. This is so that participants who do not use the app can open the record through a web link. The email sent to participants contains only the title of the record, the viewing link and any note the user has written; it does not contain the record itself.
- Recordings are not part of what is shared and are never stored on the Company's servers under any circumstances.
- Times recorded in the transcript are stored only as elapsed time from the start of the meeting, not as absolute timestamps.
- Users may choose whether the share is open to "anyone with the link" or to "participants only".
- Users may revoke a share at any time. Revoking deletes the snapshot stored on the server, and links already sent can no longer be used to gain access.
- Where a user enters participants' email addresses in order to send the link, this amounts to providing a third party's personal data to the Company. The user must tell those participants in advance that the record is being shared and obtain any consent required.
- The Company uses the participant email addresses it receives only to send the link to the record and to confirm the result.
- If the sharing feature is not used, the meeting record never leaves the user's device.
③ Not used to train AI models
The Company does not use your audio, transcripts, knowledge base or reports to train or fine-tune artificial intelligence models. The Company's contracts with the external AI providers it uses (Article 12) likewise stipulate that the data is not used for model training.
④ Your responsibility to notify and obtain consent
- Processing the other party's audio begins with the user's own choice and action, and the Company processes it on the user's instructions.
- Before any recording or transcription takes place, you are responsible for informing meeting participants and obtaining any consent required by the law that applies to you. Korea's Protection of Communications Secrets Act prohibits recording by someone who is not a party to the conversation, and some countries and states — California in the United States, for example — require the consent of every participant (all-party consent).
- The Company is not liable for disputes arising from a user's failure to meet this obligation, and may restrict use of the Service where unlawful use is established.
⑤ Access control
- Because unshared meeting content is stored only on the user's device, Company personnel cannot read it. Even where the Company needs to inspect meeting content for technical support or incident response, access is impossible unless the user supplies the material directly. Snapshots shared under paragraph 2 are, however, stored on the Company's servers and are therefore technically accessible. The Company grants access to the smallest possible number of people, records and manages access history, and does not read them for any purpose other than incident response and compliance with legal obligations.
- Where a user provides part of their meeting content to the Company in the course of an enquiry or error report, the Company uses it solely to handle that enquiry and destroys it without delay once handling is complete. In such cases the time, reason and identity of access are logged and kept for one year.
- For information held on the Company's servers, such as account data, access rights are granted to the minimum number of people and access history is logged and managed.
⑥ Deletion controls
- Users can delete individual sessions (recording, transcript, report), knowledge base documents, Memory items and knowledge base folders themselves at any time within the Service.
- Deleting the app together with its app data destroys all meeting content immediately.
- Because unshared meeting content is not held on the Company's servers, no separate deletion request to the Company is required.
- A shared meeting record is deleted from the server when the share is revoked within the Service. Where revocation is difficult, deletion may be requested through the contact point in Article 14.
⑦ Information about meeting counterparts (third parties)
- Where a user registers a counterpart's name, organisation or disposition in the knowledge base, or requests public-information research, the Company processes it on the user's instructions. Users must satisfy themselves that collecting and using that information is lawful.
- Public-information research searches and summarises only information published on the internet; the Company does not build a separate database of individuals.
- A third party who was a meeting counterpart may request access to or deletion of information about themselves through the contact point in Article 14. The Company will pass the request to the user holding that information and support its handling.
Article 6 (Processing and retention periods)
① The Company processes and retains personal data within the period required by law or the period consented to by the data subject.
| Type | Retention period |
|---|---|
| Beta registration data | Destroyed without delay once the purpose is met by sending the invitation, and in any event within 1 year of collection |
| App download data (phone number) | Destroyed without delay once the purpose is met, and in any event within 1 year of collection |
| Member data | Destroyed without delay on account closure |
| Invitation history | 90 days after the invitation expires or is used |
| Credit history | 1 year from the date credits expire (granting, reconciliation and dispute handling) |
| Meeting content that has not been shared (recordings, transcripts, reports, Memory, knowledge base, FAQ) | Not held by the Company (stored only on the user's device and kept there until the user deletes it) |
| Shared meeting record snapshots | Until the user revokes the share or closes their account. Destroyed without delay on revocation |
| Participant email addresses and link-sending history | Destroyed without delay when a share is revoked or the account is closed |
| Access logs for meeting-record share links | 90 days |
| Service usage logs | 1 year |
| Information collected by the advertising pixel | Retained by Meta under its own policy; the Company keeps no separate record in a form that identifies an individual user |
| Access and security logs (including IP after login) | 90 days |
| Records on contracts and withdrawal of subscription | 5 years under the Act on the Consumer Protection in Electronic Commerce |
| Records on payment and the supply of services | 5 years under the Act on the Consumer Protection in Electronic Commerce |
| Records on consumer complaints and dispute handling | 3 years under the Act on the Consumer Protection in Electronic Commerce |
| Refund account details | Destroyed without delay once the refund is complete; where retention is required by law, held separately for that period |
| Marketing consent records | Until consent is withdrawn |
② The Company may, after prior notice, make dormant or destroy the account of a user who has not used the Service for a year or more.
Article 7 (Destruction of personal data)
① Where personal data becomes unnecessary — because the retention period has passed or the purpose has been achieved — the Company destroys it without delay.
② Personal data stored electronically is permanently deleted by a method that prevents recovery or reconstruction; paper documents are shredded or incinerated.
③ Personal data that must be retained under other legislation is stored and managed in a separate database or a different storage location.
Article 8 (Provision to third parties)
① The Company processes personal data only within the purposes set out in Article 3, and provides it to third parties only with the data subject's consent or where Articles 17 and 18 of PIPA otherwise apply, such as under a specific provision of law.
② The Company currently does not provide personal data to third parties. The following are exceptions.
- Where a state authority, such as an investigative agency, makes a lawful request following statutory procedure
- Where personal data must be transferred as part of a merger or business transfer (in which case the fact and the user's rights are notified in advance)
③ The Company does not sell personal data for money. However, information passed to Meta through the advertising pixel in Article 10 may count as a "sale" or "share" of personal data under some US state privacy laws. You can refuse this at any time from "Cookie settings" at the bottom of the website (Article 18(2)).
④ The Company reviews the statutory requirements and procedure for any request for information from an investigative agency, and notifies the affected user unless prohibited by law.
Article 9 (Entrustment of processing)
① To provide the Service smoothly, the Company entrusts part of its personal data processing to external providers.
| Processor | Entrusted work | Country where data is stored |
|---|---|---|
| Supabase, Inc. | Authentication and operation of the database of accounts, invitations and credits, storage of meeting records shared by users and provision of web access to them, and sending of meeting-record share links by email | Republic of Korea (Seoul region, ap-northeast-2) |
| Korea PortOne Co., Ltd. (PortOne) | Payment for subscriptions and additional products, recurring payments, payment cancellation and refund processing | Republic of Korea |
② Of the processors above, Supabase, Inc. stores personal data in a region inside Korea, but as the company is headquartered abroad, access from outside Korea may occur during technical support and incident response. The Company sets out this and other overseas transfers in Article 12.
③ Other overseas processors are listed in Article 12.
④ When concluding an entrustment agreement, the Company sets out in writing — as required by Article 26 of PIPA — the prohibition on processing beyond the stated purpose, security measures, restrictions on sub-processing, management and supervision and liability for damages, and supervises whether the processor handles personal data securely.
⑤ Any change to the entrusted work or the processor is disclosed through this Policy without delay.
Article 10 (Automatic collection devices and how to refuse them)
① The Company uses the following cookies and similar technologies.
| Type | Purpose | Effect of refusal |
|---|---|---|
| Essential cookies | Keeping the login session, security (CSRF protection) | The Service cannot be used |
Functional cookies (such as tcs-locale) | Remembering your language, keeping interface state | Settings are not retained |
Marketing cookies (the Meta pixel's _fbp and the like) | Measuring advertising performance and building advertising audiences | Advertising performance is not counted; use of the Service is unaffected |
② For users in regions where prior consent is required (the EU, EEA, the United Kingdom, Switzerland and Brazil), cookies other than essential cookies are stored only with consent. Marketing scripts are not even downloaded before consent is given. You can change your choice at any time from "Cookie settings" at the bottom of the website.
③ You can refuse or delete cookies through your web browser settings.
④ The Company does not use web analytics tools. To measure advertising performance it uses the Meta pixel (Meta Platforms, Inc.) on the website only, in order to see whether someone who saw an advertisement visited the website or went on to download, and to build advertising audiences. Meeting content, meeting records and account information are never passed to the advertising provider.
⑤ The desktop app contains no cookies or tracking technologies for advertising or analytics whatsoever. The pixel in paragraph 4 exists only on the website. It stores only the app settings the user has chosen — display language, session presets, prompter scripts and the like — inside the device, and this information is not transmitted to the Company's servers.
Article 11 (Automated decisions and AI processing)
① The Service analyses conversations with artificial intelligence to generate answer scripts, summaries and reports. These are reference material that assists the user; the Company does not use them to make automated decisions with legal or similarly significant effects on the user.
② Generated output may be inaccurate, so the user must make the final check and judgement.
③ The Company does not carry out automated decision-making through profiling.
Article 12 (Overseas transfer of personal data)
① To the extent necessary to provide the Service, and pursuant to Article 28-8(1)3 of PIPA (entrustment or storage of personal data for the conclusion and performance of a contract with the data subject), the Company transfers personal data overseas (entrustment and storage) as follows.
| Recipient (contact) | Country | Items transferred | Timing and method | Purpose and retention period |
|---|---|---|---|---|
| OpenAI, L.L.C. (privacy@openai.com / 1455 3rd Street, San Francisco, CA 94158, USA) | United States | Meeting transcripts, the speech in each interval to be summarised for live meeting notes, extracts from the knowledge base, FAQ and Memory, research cues about people (name, company, title) | Sent over the network when generating answers, judgements, translations, live summaries, interval summaries for live meeting notes, reports, rehearsals and web searches | Generative AI inference. Processing ends when the result is returned and the Company does not instruct separate storage. Not used for model training |
| Soniox, Inc. (privacy@soniox.com / 1045 Helm Ln, Foster City, CA 94404, USA) | United States | Meeting audio stream | Streamed in real time while the session runs | Real-time speech recognition (STT). Real-time requests are processed immediately without storage and are not used to improve models |
| Supabase, Inc. (privacy@supabase.io / 970 Toa Payoh North, Singapore) | Storage: Republic of Korea (Seoul region) / company location: Singapore and United States | Email address, password hash, name, phone number, profile image URL, session token, invitation and credit history, snapshots of meeting records shared by the user (title, summary, timeline entries, speaker names, participant email addresses, transcript) (recordings are not included) | Sent over the network on sign-up and login, and at the moment the user shares a meeting record | Authentication and account database, and storage of shared meeting records with web access to them. Data is stored in the Korean region; access from outside Korea may occur during technical support and incident response. Retention as in Article 6 |
| Resend, Inc. (privacy@resend.com) | United States | Recipient email address, subject and body, send and receipt history, when a record is shared, the title of the record, the share link and any note entered by the user | Sent over the network when invitation and notice emails are sent, and at the moment the user asks for a meeting-record share email to be sent | Transactional email delivery and sending of meeting-record share links. Send logs are retained under the provider's policy |
| Netlify, Inc. (privacy@netlify.com / 512 2nd Street, San Francisco, CA 94107, USA) | United States | Communication data generated while serving website requests (access records such as IP address) | Sent automatically on access | Web hosting and request handling. The Company does not itself collect or store these access records |
| Google LLC (data-access-requests@google.com / 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) | United States | Beta registration data (email address, consent and time, registration language, country of access, operating system), account data on social login | Sent over the network on registration and social login | Storing and managing registrations (Google Sheets), social login authentication. Retention as in Article 6 |
| Telegram FZ-LLC (support: https://telegram.org/support) | United Arab Emirates | Registration data contained in new-registration alerts (email address and the like) | Sent over the network on registration | Delivering new-registration alerts to the operators. Retention as in Article 6 |
| Meta Platforms, Inc. (privacy@meta.com / 1 Meta Way, Menlo Park, CA 94025, USA) · for users in the EEA and the UK, Meta Platforms Ireland Ltd. | United States (via Ireland for EEA and UK users) | Website page view events, browser and device information, IP address, Meta cookie identifier | Sent automatically when the website is visited. In regions where prior consent is required, sent only with consent | Measuring advertising performance and building advertising audiences. Meeting content, meeting records and account information are not sent. Retention follows Meta's policy |
| Adobe Inc. (DPO@adobe.com / enquiry form at adobe.com/privacy) | United States | Access information the browser sends automatically when loading web fonts (IP address, browser information) | Sent automatically on access (use.typekit.net) | Web font delivery. The Company does not collect or store this information |
| ProspectOne Sp. z o.o. (operator of jsDelivr) (d@jsdelivr.com / ul. Królewska 65A, 30-081 Kraków, Poland) | Poland | Access information the browser sends automatically when loading static resources (IP address, browser information) | Sent automatically on access (cdn.jsdelivr.net) | Static file delivery via an open-source CDN. The Company does not collect or store this information |
② Session recordings are not transferred to any of the providers above.
③ Meeting content is only transmitted and processed transiently in order to generate a result and is not stored by overseas providers. Snapshots of meeting records shared by the user are the exception: they are stored in the Seoul region of the Republic of Korea, and access from outside Korea may occur in the course of the provider's technical support (Article 5(2)).
④ Payment data is not transferred overseas. Payments are processed through a payment gateway inside Korea (Article 9).
⑤ Data subjects may refuse the overseas transfer of their personal data through the contact point in Article 14. However, these transfers are essential to core functions of the Service (speech recognition, AI generation, authentication, data storage), so refusing them may limit or prevent use of the Service.
⑥ Automatic transfers relating to web fonts and CDNs can be blocked through your browser's content-blocking settings, although this may affect how pages are displayed.
⑦ When contracting with overseas processors, the Company applies appropriate safeguards recognised by applicable law, such as standard contractual clauses (SCCs), and secures by contract the prohibition on model training and on use beyond the stated purpose.
Article 13 (Rights of data subjects and legal representatives, and how to exercise them)
① Data subjects may exercise the following rights against the Company at any time.
- Access to how their personal data is processed
- Correction where there is an error
- Deletion
- Suspension of processing
- Withdrawal of consent
- Portability (download) — meeting reports, transcripts and knowledge base entries are stored on your device and can be downloaded directly within the Service.
- Revocation of a shared meeting record — you may revoke it yourself from the sharing management screen in the Service, or request revocation through the contact point in Article 14.
② You may exercise these rights from the settings screen in the Service, or by writing or emailing the contact point in Article 14, and the Company acts within 10 days of receiving the request. As the Company does not hold unshared meeting content, however, access, correction and deletion must be carried out by the user within the Service. Rights may also be exercised through a representative, in which case a power of attorney confirming the delegation must be submitted.
③ You are free to refuse consent to the collection and use of personal data. Refusing consent for required items will limit sign-up and use of the Service. Refusing optional items (such as marketing messages) carries no disadvantage in using the Service.
④ The Company verifies that a person exercising these rights is the data subject or a duly authorised representative.
⑤ Data subjects must exercise their rights without breaching applicable law and must not infringe others' personal data.
⑥ Information that the Act on the Consumer Protection in Electronic Commerce requires to be retained, such as payment and refund records, may fall outside the scope of a deletion or suspension request; where that is the case, the Company will explain the reason.
Article 14 (Privacy officer and access requests)
① The Company has designated the privacy officer below to oversee personal data processing and to handle complaints and remedies for data subjects.
- Privacy officer: Jemin You (COO)
- Contact: hello@theceostaff.com
- Payment and refund enquiries: hello@theceostaff.com
② Data subjects may use the contact above for any enquiry, complaint or request for remedy relating to personal data processing, including requests for access under Article 35 of PIPA. The Company will respond and act in good faith without delay.
Article 15 (Children under 14)
① The Service is not directed at children under 14, and the Company does not collect the personal data of children under 14.
② Where it is established that the personal data of a child under 14 has been collected, the Company destroys it without delay.
Article 16 (Security measures)
Pursuant to Article 29 of PIPA, the Company takes the following measures.
- Administrative measures: establishing and implementing an internal management plan, limiting those who handle personal data to the minimum required to operate the Service, regular training for them, and managing the history of granting, changing and revoking access rights
- Technical measures
- End-to-end encryption in transit (TLS 1.2 or above)
- Encryption of stored data (passwords are one-way hashed; meeting content is encrypted with a per-account AES-256 key, and that key is envelope-encrypted into the operating system's credential store)
- Per-account data isolation and row level security
- Structural removal of leakage risk through a local-first design that keeps unshared meeting content off the servers
- A structure in which payment method details are handled directly by the payment gateway and never stored on the Company's servers
- Retention of access records and protection against tampering
- Intrusion prevention and detection, and regular vulnerability assessments
- Physical measures: personal data is held in domestic facilities of cloud providers with physical security certifications (ISO 27001 / SOC 2 and the like)
- Incident response: in the event of a breach, notifying data subjects and reporting to the authorities within the periods set by law
Article 17 (Remedies for infringement of rights)
To seek redress for infringement of personal data rights, data subjects may apply to the bodies below for dispute resolution or advice. These bodies are separate from the Company; please contact them if you are not satisfied with the Company's own handling of a complaint or remedy, or if you need more detailed help.
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Privacy Infringement Report Centre (Korea Internet & Security Agency): 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
- National Police Agency: 182 (ecrm.police.go.kr)
Article 18 (Additional provisions for the EU, EEA, UK and other jurisdictions)
① The following applies additionally to data subjects in regions where the GDPR or equivalent law applies.
- Controller: Concerto Labs. Enquiries may be addressed to Jemin You (COO) / hello@theceostaff.com.
- Legal bases for processing
- Sign-up and provision of the Service: performance of a contract (GDPR Article 6(1)(b))
- Processing meeting audio and transcripts: consent (Article 6(1)(a)) and performance of a contract (Article 6(1)(b))
- Payment and refund processing: performance of a contract (Article 6(1)(b)) and compliance with a legal obligation (Article 6(1)(c))
- Security, prevention of misuse and service improvement: the Company's legitimate interests (Article 6(1)(f))
- Marketing messages: consent (Article 6(1)(a))
- Statutory obligations: Article 6(1)(c)
- Additional rights: in addition to the rights in Article 13, you have the rights to restriction, to object and to data portability, and the right to lodge a complaint with the supervisory authority where you live.
- Transfers outside the EEA: appropriate safeguards such as adequacy decisions and standard contractual clauses (SCCs) are applied. The Republic of Korea received an adequacy decision from the European Commission in December 2021.
- Automated decision-making: the Company does not carry out automated decision-making within the meaning of Article 22 of the GDPR.
② For data subjects in regions where US state privacy laws apply, such as California, the Company does not sell personal data for monetary consideration. However, the transfer of information through the Meta pixel in Article 10 may amount to a "sale" of personal data or a "share" for targeted advertising under those laws, and data subjects may opt out from "Cookie settings" at the bottom of the website. The Company also honours a browser's GPC (Global Privacy Control) signal as an opt-out. The rights to access, delete and correct, and not to be discriminated against, are guaranteed as set out in Article 13.
③ This Policy was drawn up with the Korean text as the authoritative version; where a translation differs, the Korean text prevails to the extent that this does not conflict with mandatory local law.
Article 19 (Changes to this Policy)
① Where this Policy is added to, amended or partly removed, the Company gives notice through the website notices or this page at least 7 days before it takes effect (30 days for changes materially affecting data subjects' rights).
② This revision made the following changes.
- Stated that where a user uses the meeting-record sharing feature, the summary, transcript and participant details of that record are stored on the Company's servers (Key points, Articles 3 and 4, Article 5(2))
- Added the retention period for shared meeting records and the way to delete them by revoking the share (Article 6, Article 5(6), Article 13)
- Added the entrustment and overseas transfer arrangements relating to sharing (Articles 9 and 12)
- Restated the Service as a desktop app (macOS and Windows) and aligned storage locations and non-recovery cases with the operating system's credential store (Articles 1, 4, 5(1), 10 and 16)
- Corrected the generative AI provider to match actual use and stated the transfer of interval summaries for live meeting notes (Article 12)
- (Amended 15 August 2026) Added the phone number to the required items collected at sign-up and updated the related overseas-transfer entry (Articles 4 and 12)
- (Amended 15 August 2026) Stated that the phone number is collected when downloading the app (Articles 4 and 6)
- (Amended 19 August 2026) Reflected the introduction of the Meta pixel for measuring advertising performance (Key points, Articles 3, 4, 6, 8, 10, 12 and 18). In regions where prior consent is required the script is not downloaded before consent, and elsewhere it can be refused at any time from "Cookie settings"
As before, recordings are never stored on the Company's servers, and if you do not use the sharing feature your meeting record never leaves your device.
③ Earlier versions of this Policy are available below.
- In force 29 July 2026 – 31 July 2026 (v1, beta registration only): view earlier version
- In force 1 August 2026 – 5 August 2026 (v2, before paid plans): view earlier version
Addendum
This Policy takes effect on 11 August 2026.
This amended Policy (adding the phone number to the items collected) takes effect on 15 August 2026.
This amendment (introduction of the advertising pixel) takes effect on 19 August 2026.