Privacy Policy
Last updated 1 August 2026
This explains what One Click Jitsi collects, why, and what it never sees. It is written to be checked against the product rather than to cover us, so where something is a limitation we say so.
The short version
We store what is needed to run your account and your deployments: your email, your cloud credentials (encrypted), and the settings and status of the servers you create. We never receive your meeting audio, video, recordings or transcripts. Those are produced by your server and stored in your own cloud account, which we have no standing access to.
What we collect
- Account details: your verified email address and an optional display name. New accounts use Google or a one-time email link, so we do not ask you to create a password.
- Cloud credentials: the access key and secret for the cloud account you connect. These are encrypted at rest in our database and are used only to run deployments you ask for.
- Deployment records: the name, region, instance size, domain, feature settings and status of each server you create, plus the addresses of the instances so the dashboard can reach them.
- Deployment logs: the console output of each deployment run, kept for seven days so you can review a run after it finishes, then deleted automatically.
- Billing details: your plan and its expiry. Card and payment details are handled entirely by our payment processor and never reach our servers.
- Operational email: notifications you have enabled about deployments finishing, failing, or needing attention.
What we never collect
- Meeting audio and video. Media flows between participants and your own server. It does not pass through us.
- Recordings. Your server uploads them directly to an S3 bucket in your cloud account, using an instance role scoped to that bucket. We hold no copy and no credentials for it.
- Transcripts. Same path as recordings. With Vosk, the speech model runs on your own instance and the audio never leaves it.
- Participant identities, chat messages, or anything else that happens inside a meeting.
When you open recordings in the dashboard, your browser fetches them using a short-lived link we generate with your own credentials. The files do not pass through our servers.
Website analytics
On the public website we record which pages are visited and the path through them, for example whether someone reads the home page before signing in. We keep the page, the referring site's host, a device and browser class, and a country when our network edge provides one. Because this sets no cookie and never stores your actual IP address, it runs without a separate consent choice, the same basis privacy-first analytics tools rely on.
We do not store your IP address. It is reduced the moment it arrives: the final part is zeroed so it points at a network rather than a person, and a separate salted, non-reversible hash lets us count unique visitors without keeping the address itself. No tracking cookie is set, and we never record analytics from inside the signed-in dashboard.
What we do with your cloud credentials
They are used to run the deployments, changes and teardowns that you initiate, and for nothing else. We do not use them to inspect unrelated resources in your account, and we do not share them.
You can remove a stored connection at any time from the dashboard, which deletes the encrypted credential. You can also revoke the key in your cloud provider's console, which takes effect immediately regardless of anything on our side. We recommend keys scoped to only the permissions the deploy form lists.
Where your data lives
You choose the region for each deployment, so your servers, recordings and transcripts stay in the jurisdiction you select. We do not copy or replicate them elsewhere.
Our own platform data (accounts, deployment records, logs) is stored on infrastructure we operate. If you need a specific data residency arrangement for the platform itself, contact us before signing up so we can tell you honestly whether we can meet it.
Third parties we rely on
- Your cloud provider, currently AWS, which you contract with directly and which bills you directly.
- Razorpay, for payments. They receive the details needed to take payment; we receive only the result.
- An email provider, for the notifications you enable and for one-time sign-in and account-security emails.
- Google Cloud Speech-to-Text, only if you explicitly choose it for transcription. In that case meeting audio is sent from your server to Google under your own Google Cloud account, not ours. The self-hosted Vosk option avoids this entirely.
We do not sell your data, and we do not use it to train anything.
Retention and deletion
- Deployment logs are deleted automatically after seven days.
- Deleting a cloud connection deletes the stored credential.
- Destroying a deployment removes the resources from your cloud account; the record of it remains in your dashboard until you delete it.
- Ask us to delete your account and we will remove your account data. Anything in your own cloud account stays yours and is unaffected, which also means you should tear down deployments first if you want them gone.
Your rights
You can access, correct, export or delete your account data. Write to us at our contact page and we will respond. If you are in a jurisdiction with statutory rights over your personal data, such as the UK, EU or India, those rights apply and this policy is not intended to limit them.
Security
Credentials are encrypted at rest. Traffic to the platform is served over HTTPS. Each deployment gets its own SSH key, which is generated for that deployment and used only to configure it.
No system is perfectly secure, and we would rather say that than imply otherwise. If you find a vulnerability, please report it through our contact page and we will work with you on it.
Changes
If this policy changes in a way that affects how your data is handled, we will update the date at the top and tell account holders by email rather than changing it quietly.