Skip to main content
Privacy settings

Full control over how meetings are recorded, how participants are informed, and how long data is stored. Tailor Sally to your organization's privacy and compliance requirements.

This section covers the settings you can configure inside Sally. Changing them is up to owners and admins, members cannot. For background on hosting, certifications, subprocessors, and DPAs, see Privacy & Security.

What you'll find in this section​


Your data. Your control.​

Sally processes meeting data (including audio, transcripts, and summaries) on behalf of your organization. Under the GDPR, your company acts as the data controller, while Sally operates as the data processor in accordance with Art. 28 GDPR.

Here's what that means in practice:

  • Germany hosting: Meeting content, transcripts and metadata are stored and processed exclusively in Germany at Hetzner. No data ever leaves the EU.
  • Own LLM in Germany: AI processing runs on Sally's own language model, operated end-to-end in our own infrastructure in Germany. No external AI providers are involved, so meeting content never leaves our systems.
  • No AI training: Your data is never used to train or improve language models. This is guaranteed both contractually and technically.
  • Retention you define: You decide how long meeting data is stored. Automatic deletion ensures data is removed after the period you set.
  • Participant consent: Sally supports opt-in and opt-out consent workflows so you can meet your notification obligations under the GDPR.
  • Data Processing Agreement: A GDPR-compliant DPA under Art. 28 is available for every customer.
Want to learn more?

For full details on hosting, certifications, subprocessors, and how to request a DPA, visit our Privacy & Security section.