Privacy Policy
Effective date: 19 August 2026.
1. General
This Policy explains what personal data is processed when you use Plancy services, including Plancy Meetings — a service that records and transcribes video meetings.
The data controller is Arkhitekturny Portal LLC (OGRN 1237700594779, INN 9709098730), address: 10/2 Nizhnyaya Syromyatnicheskaya street, Moscow, 105120, Russian Federation.
Processing is carried out under Russian Federal Law No. 152-FZ of 27 July 2006 "On Personal Data". All data is stored and processed within the Russian Federation.
By using the service you confirm that you accept this Policy. If you do not agree with it, please do not use the service.
2. What data we process
Account data. Name, email address, organization identifier. Used for sign-in, access control and service communication.
Meeting data. The meeting audio recording, its transcript with speaker labels, the summary and action items, meeting titles and times, participant lists and the meeting link. This data is created only for meetings the user explicitly sends to recording or selects for automatic recording from a connected calendar.
Connected account data. When you connect Zoom, Google Calendar or Yandex Calendar, the service stores your user identifier in that external service and a refresh token. Passwords for external services are never requested and never stored.
Technical data. Browser and device information, request paths, timestamps and error records. Used for troubleshooting and abuse prevention.
3. Data obtained from Zoom
This section describes the data you grant access to when you connect a Zoom account.
The application requests the following scopes:
- View a user (
user:read:user) — called once, at connection time, to read your Zoom user identifier. No other profile field is read or stored. - View a user's token (
user:read:token) — called when a recording starts, so the bot can join a meeting you host. - View a meeting local recording join token (
meeting:read:local_recording_token) — called when a recording starts, so the meeting is not interrupted by a permission prompt. - View a user's Zoom Access Key (
user:read:zak) — required by Zoom for applications that use the Meeting SDK. Our code never calls the ZAK endpoint and never stores a ZAK.
Of everything obtained, only the Zoom user identifier and the OAuth refresh token are stored. Access tokens, on-behalf-of tokens and local recording join tokens are never persisted: they are requested at the moment a recording starts and exist only in process memory.
The bot joins as an ordinary participant under a clearly recognisable name. The host and all participants can always see that the bot is present.
4. Purposes of processing
- Providing service features: recording, transcription, summaries and search across meetings.
- Identifying users and separating access to an organization's data.
- Notifying users when a summary is ready and about other service events.
- Troubleshooting, keeping the service available and secure.
- Performing the contract with the customer organization and complying with the law.
5. Sharing with third parties
Meeting data is shared with processors solely to deliver the service:
- Speech recognition provider — receives the audio recording to produce a transcript.
- Language model provider — receives the transcript to produce a summary and action items.
Processors do not use the data for their own purposes. Data is not shared with anyone else, except where required by the law of the Russian Federation.
6. Storage and protection
Data is stored on servers located in the Russian Federation. We apply:
- transport encryption (TLS 1.2 or above) for all data exchanged over the internet;
- AES-256-GCM encryption of external service refresh tokens before they are written to the database;
- access separation: an organization's data is available only to its own users;
- restricted employee access to meeting content.
Tokens and other secrets are never written to service logs.
7. Retention
Meeting and account data is retained until it is deleted by the user or the organization, until consent is withdrawn, or until the contract with the organization ends.
Disconnecting a linked account (Zoom or a calendar) immediately deletes the stored refresh token and the external user identifier.
8. Your rights
You may request information about the processing of your data, ask for it to be corrected, blocked or deleted, and withdraw your consent. Send such requests to the address in the "Contacts" section.
You can delete an individual meeting record or disconnect an external account yourself in the service interface.
9. Cookies
The service uses cookies that are necessary for sign-in and for storing user preferences. You can manage them in your browser settings; disabling them may break the service.
10. Changes to this Policy
We may update this Policy. The current version is always available at plancy.ru/policy. Material changes are communicated separately.
11. Contacts
Personal data enquiries: info@plancy.ru
Zoom integration enquiries: sergey.leskov@stemps.ru
Postal address: 10/2 Nizhnyaya Syromyatnicheskaya street, Moscow, 105120, Russian Federation.