Privacy

What we know about you, and why.

The short version

  • There are no advertising or behavioral trackers on this site, and nothing here is sold or shared for marketing. That is why you were not asked to dismiss a cookie banner.
  • Visits are counted without storing anything on your device — no cookie, no identifier, no fingerprint. We can see that a page was viewed and roughly which country it came from. We cannot tell that two visits were the same person.
  • In a meeting, other participants see your display name and your live camera and microphone. That is the point of the room, not a side effect.
  • Recording and saved transcription are off unless deliberately enabled for the meeting. Participants receive a notice before their speech is processed.
  • Our main application services use European servers. Optional caption processing uses ElevenLabs and may take place outside Europe. You can ask us to delete the data we hold.

When you just look at the site

Our servers keep ordinary technical logs, which include your IP address, in order to serve pages and to notice attacks. We also count page views using Vercel Web Analytics, which is a deliberately limited tool: it writes nothing to your browser and keeps no identifier for you, so it can report that a page was visited and roughly from where, but it cannot follow you between visits or across sites.

This is why there is no consent banner. The rule that produces those banners is about storing or reading things on your device, and we do not do that for counting visits.

When you join a meeting

To join a room, you share your display name and live audio and video with the others there. We do not store microphone audio unless recording or saved transcription is enabled. Live captions also send speech to ElevenLabs for processing, even when no transcript is saved; see below.

We do store:

  • Your display name for that meeting. You choose it, it is specific to that meeting, and you can change it while you are there.
  • Chat messages you send. These are kept with the meeting so people can read back. They cannot be edited or unsent.
  • The latest host message addressed to each participant, with its sender and acknowledgment or withdrawal. A newer message replaces it. In the meeting, only its sender and recipient can read it; it is separate from chat. Withdrawing hides the message but does not erase this stored record. We also keep a replaceable hourly delivery count per sender to limit abuse; it is deleted with the account.
  • When you joined and left, along with the kind of device, operating system and browser you used — so we know whether the rooms work on real machines.
  • Faults, when something breaks. If the site fails while you are using it we record what went wrong, on which page, and what kind of browser you were using — so that it can be fixed rather than waiting for somebody to mention it. No page addresses and nothing you typed. Kept for thirty days.
  • How the sound check went. Before you go into a room we check that your microphone works, and we record what the check found — it worked, it was blocked, there was no microphone, it was open but silent — together with your operating system, browser, and the name of the app if the link was opened inside one. It is how we learn how often that goes wrong and on what, instead of hearing about it from the few people who mention it. No sound is recorded. The record is kept against the account you are signed in with — the temporary one a guest link creates for you, or your host account — and against the meeting, so that one person checking three times can be told apart from three people. Only administrators can read it, and it is deleted after thirty days.
  • Connection measurements every thirty seconds: how good the connection was, delay, resolution, lost packets, whether your video stuttered. This is how we tell whether the service is actually any good rather than guessing. It describes your connection, never what was said. Kept for thirty days, then deleted automatically. We also record fixed technical events when the media connection disconnects or reconnects, when you use Leave or Reconnect, when a room move or meeting end closes the connection, and when the meeting page closes or stops using its media connection. These events help explain interrupted calls. They contain no conversation content and are linked to the signed-in account (including temporary guest accounts) and meeting. Only administrators can read them; they are deleted after thirty days.

When a meeting is recorded

Recording is off unless it is deliberately enabled for a meeting. When it is on, you are told before you settle into the room and you have to agree; declining offers you a way out rather than quietly starting the camera. People who arrive late get the same notice, and recording stays visibly indicated while it runs.

Recordings are encrypted before they are stored, and can only be played back by an administrator through a link that expires after two hours. If the purpose changes later — deciding to publish something that was recorded as a private archive — that needs a fresh decision and a fresh agreement, not the original one.

Captions and saved transcripts

During the restricted trial, an administrator-owned meeting can enable live captions and separately choose to save a transcript. Connected participants must acknowledge the processing notice. The worker sends one mixed microphone stream to ElevenLabs, applying the room’s audio rules. You can leave if you do not want your speech processed.

For captions alone, So Many Rooms keeps only the current caption display. When transcript saving is enabled, our worker holds temporary audio and matches speaker activity to inferred names. Successful processing deletes that audio; failed audio is removed after 24 hours by cleanup that runs while the service is running. A hard service crash can lose an unfinished transcript.

Saved transcript text and inferred speaker names are stored with the meeting until its deletion. Only the meeting owner can download the transcript through the application and can then share the downloaded file. Deleting our meeting data does not promise immediate deletion of ElevenLabs’ own logs or retained data, which are governed by its terms and the account configuration.

When you host

Hosting requires an account, so we hold your email address and a password managed by our authentication provider. Administrators can see the email addresses of hosts in the usage figures, because knowing who is running meetings is part of running the service.

What is kept on your device

Only things the site cannot work without, which is why none of them ask permission:

  • A sign-in session, so you are not asked to log in on every page.
  • The last room you joined, so you can get back to it easily.
  • Your camera, microphone and speaker choices, so a meeting does not start by sending your voice to the wrong device.
  • Your language, appearance and home time zone choices, in the functional cookies smr-locale, smr-theme and smr-timezone. They are written only when you make an explicit choice, kept for one year, and never shared as meeting state.
  • The __vdpl cookie, set only while you are in a room. It keeps a long meeting on a single version of the software so that releasing an update does not interrupt you. It is removed when you leave.

Who else handles it

These providers handle data for the service. Their locations and retention arrangements differ:

  • Vercel — the website itself and the visit counting, served from Dublin.
  • Supabase — accounts, meetings, chat and the measurements above, hosted in Ireland.
  • Hetzner — the servers that carry live audio and video, and the encrypted recording storage, in Germany.
  • Zoom or LiveKit Cloud — only if a particular meeting is placed on one of them instead of our own servers, which the host can see.
  • ElevenLabs — optional speech-to-text processing for captions and transcripts through its global API. Speech and text may be processed outside Europe, and ElevenLabs’ own retention terms apply.

A provider’s corporate headquarters and the location where it processes data are different things. In particular, the initial ElevenLabs integration uses its global service; we do not promise EU-only processing or zero vendor retention.

How long we keep it

  • Connection measurements: thirty days, deleted automatically.
  • Meeting records, messages, attendance, recordings and saved transcript text are retained until deletion is requested. Temporary transcription audio follows the shorter cleanup rule described above. We have not yet set maximum periods for the other records; until then, please request deletion.

What you can ask for

If you are in the EU or UK you have the right to see what we hold about you, correct it, have it deleted, take a copy elsewhere, and object to how it is used. You do not need an account to ask — write to us and describe the meeting.

We ask people for a display name rather than a real name, and we do not require an account to attend a meeting, so in many cases the least we know about you is the most we ever knew.

Who to write to

So Many Rooms is operated by Light Connections SAS, a company registered in France (SIREN 810 972 109), which is the data controller for everything described here.

For anything on this page — a copy of your data, a correction, a deletion, or just a question — write to contact@somanyrooms.com.

Because we are established in France, our lead supervisory authority is the CNIL. You are equally entitled to complain to the data protection authority of the country you live in.