Last updated 3 August 2026
For account, website, support and marketing data, Groundery is the controller: we decide why and how it is processed, and this policy is the notice for it.
For the material you upload and everything derived from it (“Customer Content”), Groundery is a processor: you decide what goes in and why, and we process it on your instructions to run the service. Where that content contains personal data — the voices, faces and names of the people in your recordings — you are the controller, and you are responsible for the notices and consents described in clause 4 of the Terms. A data processing agreement is available on request.
Account data. Name, work email, organization, workspace role, and authentication metadata (sign-in times, method, IP address of the session), handled through Clerk. We never see or store your password.
Access request data. If you use the request form: your name, work email, organization, and what you told us you publish. We use it to evaluate and respond to the request, and to contact you about a pilot.
Customer Content. The audio, video, transcripts, documents and brand assets you upload, and everything the pipeline derives from them — transcripts with word timings, speaker labels, selected moments, research summaries with their sources and images, rendered clips, audiograms, articles and story packages.
Usage data. Pages viewed, features used, content hours processed, job outcomes and errors, plus standard server logs (IP address, user agent, timestamps). Product analytics run through Vercel Analytics, which is cookieless and does not build a cross-site profile of you.
Communications. Emails and messages you send us, and our replies.
Customer Content is never used to train, fine-tune, or evaluate any machine-learning model — ours or a vendor’s. Our AI subprocessors are engaged under terms that prohibit training on data we send them, and we use zero-retention processing where a provider offers it.
What we do learn from is operational metadata: how long a step took, whether it failed, how many content hours a workspace processed. That tells us where the pipeline is slow or brittle without anyone reading your material.
Running the pipeline means analyzing the people who appear in what you upload. Specifically, Melioda separates speakers and attributes lines to them; labels a speaker by name where the recording itself makes the name available; samples frames and asks a vision model how many people are visible together, so a clip can be framed or cropped correctly; and looks up public figures and organizations mentioned in the material against open-web sources.
We do not create biometric templates, do not perform facial recognition against any identity database, and do not match people across recordings or across workspaces. Frame analysis counts and locates people in a shot; it does not identify them.
We use the vendors below, each under a written agreement limiting them to processing on our instructions. We do not sell personal data, and we do not disclose it to anyone else except where the law requires it — in which case we will tell you unless we are barred from doing so.
Research lookups are the one step that reaches outside this list: to find context for a name or a claim, the research provider queries the open web and returns pages, sources and images from third-party sites. The query carries the entity and a short piece of surrounding context from your material — never the whole recording or transcript.
We will give notice before adding a subprocessor that processes Customer Content, and this list is the record of who they are.
Data is encrypted in transit (TLS) and at rest. Media lives in private object storage and is reachable only through signed URLs that expire; nothing is served from a public bucket. Access is scoped to a workspace and enforced on every request. Internal access to production is limited to the people who need it, is logged, and is used for operating the service — not for reading your material. No system is perfectly secure; if a breach affects your personal data we will notify you and, where required, the relevant authority without undue delay.
Melioda runs on infrastructure in the United States, and the vendors in clause 7 process data there and, in some cases, in other countries where they operate. Where personal data protected by EU or UK law is transferred out of those regions, the transfer is covered by the European Commission’s Standard Contractual Clauses (with the UK Addendum where applicable) or another lawful transfer mechanism.
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal data; to object to or restrict certain processing; and to withdraw consent you previously gave. If you are in the EEA or UK you also have the right to complain to your supervisory authority. If you are in California, you have the rights to know, delete, and correct, and the right not to be discriminated against for exercising them — and note that we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and have not in the preceding twelve months.
Write to hi@groundery.com and we will respond within 30 days. If your request concerns material uploaded by one of our customers — for example you were recorded in an interview — we will refer you to that customer, who controls it, and support them in responding.
We set only what the product needs: session and authentication cookies from Clerk that keep you signed in and protect against request forgery, and a small number of preference cookies. Product analytics are cookieless. We run no advertising cookies, no third-party trackers, and no cross-site profiling, so there is no consent banner to dismiss.
Melioda is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 18 as a user of the service. Recordings you upload may of course feature people of any age; handling that lawfully is your responsibility as controller of that material.
We will post any change here and move the “last updated” date. For material changes affecting how Customer Content is processed, we will give at least 30 days’ notice to workspace administrators by email before it takes effect.
Groundery — privacy questions, data requests, and data processing agreements: hi@groundery.com.