Deewan
Sign in

Privacy Policy

Last updated October 3, 2026

What we collect to run Deewan, where it is stored, who helps us process it, and the choices you have. In short: we collect what the service needs, we don't sell data, and meetings are end-to-end encrypted.

01Who we are

Deewan ("we", "us") provides video meetings, rooms and workspaces at deewan.io. For anything in this policy, contact support@deewan.io.

02What we collect

Account details: your name, email address, a securely hashed password, your chosen avatar or uploaded photo, and your language.

Workspace details: organizations, teams, members, roles, invitations, rooms, room settings and scheduled meetings.

Security and service records: sign-in sessions (device type, IP address, times), rate-limit counters and delivery status of the emails we send.

Guests who join a meeting without an account give only a display name. We keep a random guest id in a cookie for up to 12 hours so a reconnect keeps their place.

Meetings are not recorded unless a host starts a recording, which everyone in the meeting is shown. Otherwise audio, video, screen shares, chat, reactions and webinar questions are relayed live and are not stored.

If you connect Google or Microsoft: your name and email address from that account, and — only if you connect a calendar or export attendance — access to your calendar events or to spreadsheets Deewan creates for you (see “Google and Microsoft accounts” below).

Attendance: for each meeting, who joined (display name, and whether they had an account or were a guest) and when they joined and left. Hosts, and people they allow, can see it and export it.

Connection quality: during a meeting, your browser or app measures its own connection every 30 seconds — latency, jitter, packet loss and bitrate, never what is said or shown — and the averages are kept with your attendance record. For meetings run through the Deewan API, the developer whose app created the meeting can see these numbers, to help diagnose a bad connection.

Booking pages: when someone books a meeting through a Deewan booking link, we collect their name, email address, any notes, and their answers to the questions the link's creator chose to ask (for example a phone number or company). These go to the creator and are stored with the booking. The creator decides what to ask and is responsible for asking only what they need.

Payments for API credit: the billing name, email and address you enter (your card's bank uses them to verify the payment), the amount, and the result HyperPay reports — including the card brand and last four digits. Card numbers, expiry dates and security codes are entered on HyperPay's form and never reach Deewan.

Developers using our API: a log of each API request (time, method, path, status, duration, IP address and user agent — never request or response bodies), used for security, rate-limiting and the developer's own usage dashboard. People who join a meeting through a developer's link are identified to us only by a one-way hash of the developer's own user id, plus the display name the developer sends.

03End-to-end encryption

Meeting audio, video, chat, reactions and webinar questions are encrypted on each participant's device before they are sent. Our media and relay servers only forward encrypted data and cannot read it.

In standard rooms, meeting keys are derived and issued by our application service only to people admitted to that meeting. In rooms set to strict end-to-end encryption, the key is created on a participant's device and shared only between the devices in the meeting; our servers never have it, and features that need it (such as live captions) are not available there.

Recordings are encrypted on the recording host's device before upload. How they are unlocked depends on the room's setting. With recordings set to “participants” (the default for rooms made in Deewan, and always for strict rooms), the key is sealed to the people allowed to watch: we store only the encrypted recording and cannot view it. With recordings set to “workspace” (the default for rooms made through our API), the key is held by Deewan so the workspace's admins and its API can download and play them; Deewan's staff do not view recordings except at the workspace's request, for security, or where the law requires.

Live captions are optional. When someone in a meeting turns them on, a captioning participant operated by Deewan joins the meeting — shown to everyone by a "Captions on" badge — and speech is sent to OpenAI to be transcribed. Transcripts are shown live and are not stored by us.

Background blur and replacement, and voice isolation, run entirely on your device: your camera image and microphone sound are processed in your browser or app before they are encrypted and sent. Pictures you add as your own backgrounds are stored only in your browser and are never uploaded.

04How we use it

To provide the service: signing you in, running meetings, admitting people, sending invitations and showing your workspace.

To keep it secure: detecting abuse, rate-limiting, checking passwords against known breaches (only a partial hash ever leaves our servers), and notifying you of security-relevant changes.

To communicate with you about your account. We don't send marketing email without your consent, and we don't sell or rent personal data.

05Where data is stored and who processes it

Database: Supabase (PostgreSQL), hosted in Frankfurt, Germany (EU).

Application servers, media servers and TURN relay: Amazon Web Services (Lightsail), Frankfurt, Germany (EU).

File storage (profile photos and workspace logos): Cloudflare R2, EU jurisdiction (data stays in the EU).

Transactional email: Amazon Web Services SES, Frankfurt region (EU).

Encrypted meeting recordings, only when a host records: Cloudflare R2, EU jurisdiction.

Live captions, only when turned on: OpenAI.

Sign-in and calendar connections, only if you use them: Google and Microsoft.

Card payments for API credit, only if you top up: HyperPay (card details go to HyperPay directly).

Each processor handles data only to provide its part of the service, under its own security and data-processing terms.

06Google and Microsoft accounts

You can sign in with Google or Microsoft, and connect Google Calendar or Outlook Calendar. When you sign in, Deewan receives only your name and email address. When you connect a calendar, Deewan asks for permission to manage calendar events, and uses it only to add, update and remove your Deewan meetings in your calendar and to show your calendar's events inside Deewan to you. When you export attendance, Deewan asks for permission to create files in your Google Drive and only writes the spreadsheet you asked for.

Deewan's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google or Microsoft data for advertising, do not sell it, do not use it to train AI models, and do not let people read it except with your permission, for security, or where the law requires.

Access tokens are stored encrypted (AES-256-GCM). You can disconnect at any time from Settings, or from your Google or Microsoft account settings; disconnecting deletes the stored tokens.

07Cookies and local storage

Essential cookies keep you signed in (session and a short-lived session cache), remember your language, hold a guest's seat in a meeting, and let the email-confirmation page notice when you've confirmed. They are required for the service to work.

Your consent choice is stored in a cookie so we don't ask again.

When you choose light or dark mode, that preference is kept in a cookie. People who join through a developer's API link get a short-lived signed cookie (up to 12 hours) that keeps their seat in that one meeting.

Your browser also stores device preferences locally — microphone, camera and speaker choices, meeting defaults, background choice, your own background pictures, and sound effects. These never leave your device.

We do not use advertising or cross-site tracking cookies. If we ever add optional analytics, we will ask first through the cookie notice.

08How long we keep it

Account and workspace data are kept while your account exists. When you delete your account, your personal data is removed from our systems, except where we must keep limited records to meet legal or security obligations.

Sign-in sessions expire after 7 days of inactivity. Email verification and password-reset links expire within 24 hours and 15 minutes respectively.

Payment and credit records are kept as financial records, including after a workspace is deleted, for as long as the law requires.

API request logs are deleted after 90 days. Attendance and bookings are kept while the room, booking link or workspace they belong to exists, and are deleted with it, or when the account that owns it is deleted.

09Your choices and rights

You can update your name, avatar, email and password, see and sign out your devices, and delete your account from Settings at any time.

Depending on where you live, you may have the right to access, correct, export or erase your data, or to object to or restrict processing. Write to support@deewan.io and we will respond within 30 days.

10Children

Deewan is not directed at children under 13. Schools and organizations that invite younger users are responsible for obtaining the consent required where they operate.

11Changes

If we change this policy in a meaningful way, we will update the date above and let account holders know by email or in the product before the change takes effect.