Privacy Policy — Zoom Meeting Manager

Last updated: 7 August 2026

Zoom Meeting Manager is provided by Carla Berkers Consulting Limited, which is the data controller for the information described here. References to "the author" below mean Carla Berkers Consulting Limited.

Registered in England and Wales, company number 12156763. Registered office: 11 Hazel Lane, Skelmersdale, Lancashire, England, WN8 6UN.

For anything in this policy — including a request to see or delete what is held about you — contact zmm@scott.hu.

Where your data lives

Your meeting data — recordings, transcripts, and the analysis made from them — resides on Zoom, on Google Drive, and on your own device. None of it is ever sent to the author without your specific, proactive consent (for example, pressing the button that sends an error report — see the Support section below).

The application runs on the computer it is installed on. During the normal course of usage, it contacts the author for exactly one purpose: to check whether your subscription is active. That check is described in full below, and it carries nothing about your meetings.

No meeting data is provided to the author unless you report an issue — and then only whatever you choose to include in that report.

What the app touches, and where it goes

Data Where it comes from Where it goes
Zoom cloud recordings, transcripts, chat logs Your Zoom account Downloaded to your device, uploaded to your Google Drive
Meeting analysis (actions, decisions, segments) Generated from your transcripts Your Google Sheets, in your Drive
Transcript text for analysis Your device Sent to the Anthropic API to produce the analysis
Zoom access and refresh tokens Zoom authorisation Stored encrypted on your device only
Google access and refresh tokens Google sign-in Stored on your device only
Your Google sign-in (name, email) Google Held in a local session on your device
Anthropic API key You Stored encrypted on your device only
Your email address Your Google sign-in Sent to the licence server to check your subscription
Name, billing address, card details You, at checkout Held by Paddle, our payment provider. The author never receives card details.

The services in the right-hand column are ones you already use directly: Zoom holds your recordings, Google Drive holds your files, and Anthropic processes transcript text you send for analysis under your own API key.

The licence check

Subscriptions have to be verified somewhere the user cannot edit, so the app asks a licence server operated by the author whether your account is entitled to run.

What is sent: your email address, as verified by your Google sign-in, and the application version. Because it is an ordinary internet request, the server also sees your IP address and the time of the request, and records them in its logs.

What is not sent: nothing about your meetings. No recordings, no transcripts, no titles, no participant names, no summaries, no file names, and none of your Zoom, Google, or Anthropic credentials.

When it happens: when the app starts, and periodically while it runs. If the check cannot be reached, the app keeps working for a grace period so a dropped connection does not interrupt you mid-meeting.

What this reveals. The check is not analytics: it is not used to study how you use the app, and it carries no meeting content. It does mean that a request arriving from your address tells the author that your account ran the app at that time.

Licence-check logs are kept for 30 days and then deleted.

Payment

Payments are handled by Paddle, which acts as the merchant of record — the legal seller for your purchase. When you subscribe you are contracting with Paddle, and your card details are entered on Paddle's own checkout, not in this application.

The author never sees, receives, or stores your card number. What the author receives from Paddle is confirmation that a subscription exists for your email address, and the country used for tax purposes.

Paddle's handling of your payment data is governed by their own privacy policy at https://www.paddle.com/legal/privacy.

Zoom authorisation

The app uses Zoom's public-client OAuth with PKCE. It holds no Zoom client secret. When you connect your Zoom account:

Requested scopes:

user:read:user
cloud_recording:read:list_user_recordings

Downloading a recording needs no scope of its own — the listing response carries a download link, and the same token authorises the download.

Google authorisation

Signing in with Google is also what grants the app access to Drive. It asks for the narrowest scopes that work:

Scope What it actually allows
openid, userinfo.email Your email address, so the app knows who is signed in and can check your subscription
drive.file See, edit, create and delete only files this app created — not the rest of your Drive
tasks (only if you turn on Google Tasks) Create and manage your Google Tasks

On drive.file. Google's consent screen words this as "see, edit, create, and delete", which reads alarmingly. The object of that sentence is only files this app made. It cannot list, open, or touch anything else in your Drive — including files you created yourself, and including the folder you might have made by hand. The app needs more than "create" because it re-reads the transcript it uploaded in order to analyse it, checks whether a file already exists so re-runs do not duplicate work, and writes results back into its own spreadsheets.

The app does not request auth/drive (every file in your Drive) or auth/spreadsheets (every spreadsheet you own).

On tasks. Google offers no per-task equivalent of drive.file — the scope covers all your tasks or none. The app therefore never asks for it during normal sign-in. It is requested only if you switch Google Tasks on in Settings, which shows you a separate consent screen at that moment. Switching the feature back off stops the app using it, and you can withdraw the permission itself at any time at myaccount.google.com/permissions.

If you never turn Google Tasks on, the app never asks for access to your tasks and never touches them.

Deleting your data

Most of it is yours, and as far as this app is concerned it stays that way:

Two things the author does hold, and how to remove them:

Because the author holds no copy of your meeting data, there is nothing there for the author to delete on your behalf.

Support

Problems, questions, and data requests: zmm@scott.hu.

If you report a problem, please send only what is needed to diagnose it. Log files may contain meeting titles and dates; they do not contain recordings, transcript text, or credentials. Review anything you attach before sending it — whatever you send is what the author sees, and nothing more.

The app also has a Send error report button in Settings. It does nothing until you press it. Pressing it sends the app's recent log files, your account email address, the app version, your platform, your subscription state, and any note you type, which are delivered to the author as an email so the problem can be looked into alongside the copy of the app it concerns. Your recordings and transcripts are never included; meeting names may appear in the logs, along with lines the processing printed about them — the Show report button displays exactly what would be sent, before anything is. Credentials are never included. To have a submitted report deleted, email the address above.

Changes

This policy may change. The date at the top of this page shows when it was last updated, and the current version is always the one published here.


© Carla Berkers Consulting 2026