Privacy Policy
Last updated: 01 Feb 2025
1. Scope & Definitions
This Policy applies to: (a) the Minute Minder Chrome extension; (b) the Minute Minder web app/dashboard and APIs; and (c) our public website and support channels.
Personal Data means any information that identifies or can reasonably be linked to an identified or identifiable person. Usage Data means de‑identified or pseudonymous technical data about how features are used (e.g., when a timer starts) that does not include meeting content.
We do not collect or process meeting content such as audio, video, screen shares, captions, chat messages, or transcript text.
2. Information We Collect
2.1 Account & Authentication
Google Sign‑In data: your Google account email and a unique user ID via Chrome Identity/OAuth to create and secure your account, enforce licenses/teams, and sync your preferences.
Team/Org metadata: seat assignments, role (e.g., admin/member), and plan tier.
2.2 Calendar Metadata (read‑only, with consent)
To calibrate meeting timers and reminders, and only after you grant consent, we may request read‑only access to limited Google Calendar fields such as:
Event start/end time and duration;
Event title and Google Meet link (if available).
We do not access email content, Drive files, or other Google products via this connection.
2.3 Preferences & Configuration
Reminder templates (e.g., halftime, 10‑minute, 5‑minute, overtime), messages, and sound on/off;
Overlay position/size, theme, and other UI settings;
Notification opt‑in/out.
2.4 In‑Meeting Ephemeral State (Extension)
To ensure reminders fire at the correct time and survive page reloads, the extension may store small pieces of ephemeral state such as:
Timer start timestamp, scheduled reminder timestamps;
Whether overtime mode is active.
This state is cleared automatically when the timer stops or the tab is closed.
2.5 Billing
Payments are processed by our payment provider (e.g., Stripe). We receive and store limited billing metadata (e.g., subscription status, plan, seat count) but do not store full payment card numbers.
2.6 Support & Communications
If you contact us, we collect the information you provide (e.g., email, message content, attachments) to respond and keep records for compliance and training.
2.7 Device & Technical
We may collect technical data such as browser type/version, OS, extension version, language, time zone, and diagnostic logs (e.g., error codes) to maintain and secure the Services.
3. How We Use Information
Provide the core functionality: show an in‑meeting timer, schedule alarms, and display optional OS notifications so meetings stay on time.
Sync settings and teams: remember your reminder templates and apply org‑level defaults.
Measure and improve: aggregate usage metrics (e.g., reminders fired, meetings on‑time) to improve reliability and UX.
Security and abuse prevention: detect fraud, misuse, or violations of our terms; protect the integrity of the Services.
Support: respond to your requests and provide product updates or service notices.
Compliance: meet legal, regulatory, and contractual obligations (e.g., tax, accounting, response to lawful requests).
4. Analytics & Telemetry
Minute Minder uses analytics to understand feature adoption and reliability. Analytics data is designed to be pseudonymous and excludes meeting content.
What analytics may record
Feature events (e.g., timer started/stopped; reminders scheduled/fired; notifications displayed or dismissed);
Counts and durations (e.g., number of meetings with Minute Minder active; on‑time vs. overrun sessions);
Performance and reliability (e.g., load times, error rates, service‑worker wakeups);
Technical context (browser/OS, extension/app version, locale, time zone).
Controls
Where required by law, we will ask for consent before placing analytics cookies or writing analytics identifiers.
You may be able to manage analytics preferences in the app settings. If you need an account‑level opt‑out, email support@minuteminder.io.
We do not sell or share Personal Data for cross‑context behavioral advertising.
5. Legal Bases (EEA/UK)
Where the GDPR/UK GDPR applies, we process Personal Data under these legal bases:
Performance of a contract: to provide the Services you request.
Legitimate interests: to secure, maintain, and improve the Services, to measure usage, and to prevent abuse (balanced against your rights).
Consent: for optional analytics or where local law requires consent (e.g., certain cookies) and for connecting Google Calendar.
Legal obligations: to comply with applicable laws, regulations, and lawful requests.
7. Data Retention
Account data is kept while your account is active and for a reasonable period thereafter for recordkeeping, unless you request deletion.
Ephemeral meeting state stored by the extension is cleared when the timer stops or the tab closes.
Analytics & logs are kept for as long as needed to provide, secure, and improve the Services and to meet legal obligations; we aim to minimize retention.
You may request deletion at any time (see Your Choices & Rights).
8. Security
We implement technical and organizational measures designed to protect information, including encryption in transit (TLS), access controls, least‑privilege design in the extension (no audio/video capture, no remote code execution), and vendor due diligence. No method of transmission or storage is 100% secure; you use the Services at your own risk, but we work continuously to improve our safeguards.
9. Your Choices & Rights
9.1 Access, Correction, Deletion
You can access or update many settings in the app. You may also request a copy of your Personal Data, ask us to correct it, or request deletion by emailing support@minuteminder.io.
9.2 Revoke Google Access
You can revoke Minute Minder's access to your Google account at any time via your Google Account permissions page. After revocation, some features (e.g., calendar‑based reminders) will no longer function.
9.3 Cookies & Local Storage
You can manage cookies through your browser settings. Where required by law, we will ask for consent before setting analytics cookies. The extension uses Chrome storage to remember preferences; you can reset it from the extension settings or by reinstalling.
9.4 EEA/UK/California
If you are in the EEA/UK, you may have additional rights under GDPR/UK GDPR (e.g., portability, restriction, objection, and the right to lodge a complaint with a supervisory authority). California residents may have rights under the CCPA/CPRA (e.g., know/access, delete, correct). We do not sell Personal Data.
10. International Transfers
Your information may be processed in countries other than your own. Where applicable, we use appropriate safeguards for cross‑border transfers (e.g., Standard Contractual Clauses) and require our processors to do the same.
11. Children's Privacy
The Services are not directed to children under 13 (or under 16 in the EEA/UK). We do not knowingly collect Personal Data from children in these age groups. If you believe a child has provided Personal Data, please contact us and we will take appropriate steps to delete it.
12. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will post the updated version and adjust the "Last updated" date. Your continued use of the Services after changes become effective signifies your acceptance.
13. How to Contact Us
For privacy inquiries, data access/deletion requests, or questions about this Policy, email support@minuteminder.io.
14. Chrome Extension Permissions Disclosure
For transparency, the extension uses the following Chrome permissions strictly to provide its single purpose—time management in Google Meet:
activeTab — to inject the in‑meeting timer into the active Google Meet tab after you activate Minute Minder.
alarms — to schedule meeting reminders reliably (halftime, 10‑minute, 5‑minute, overtime).
notifications — to optionally show OS‑level reminders if the Meet tab is not focused.
scripting — to inject packaged content scripts/CSS solely on
https://meet.google.com/*.storage — to save your preferences and small pieces of ephemeral meeting state.
identity / identity.email — to sign in with Google and associate your license/team.
Host permissions — limited to
https://meet.google.com/*and our API domain(s) as needed; optional Google APIs for Calendar (read‑only) with your consent.
We do not collect or store meeting audio/video/chat, and we do not execute remotely hosted code.