Security
How Axelize handles call data: no bot, no audio, no video, and a text transcript you control.
Last updated 2026-09-18
What Axelize reads
The extension runs only on meet.google.com. During a call it reads the text captions Google Meet already renders in your browser and sends them to your workspace as a transcript. That is the whole input. It does not join the meeting as a participant and it does not touch the audio or video stream.
What is never captured
- Meeting audio or video.
- Screen contents, other tabs or other websites.
- Voiceprints or any other biometric data. Nothing is derived from anyone's voice.
- Anything from a call where captions were off. With no captions there is no input.
What is stored
- Transcripts, as text, with the speaker name Google Meet displayed for each line, attached to the meeting record so later calls have the history.
- Account context you create: companies, contacts, products, notes, uploaded files and the web pages you ask Axelize to read.
- Suggestions generated during the call, kept with the meeting.
All of it lives on servers in Helsinki, Finland. The subprocessors page lists every third party that touches it.
A transcript is still a record
Because nothing is recorded, Axelize does not trigger the audio recording policies and biometric rules that a meeting bot does. A stored transcript is still a record of what was said, though, and in some places the law treats transcribing a conversation the same way it treats recording one. Several US states, including California, Illinois and Washington, require every participant to be told. You are on the call, so telling participants is your job. We make it easy: share the participant notice in your invite, or say at the start, "I use an AI assistant that keeps a text transcript of our call." Most people say yes, and the ones who do not have told you something useful.
How the AI sees your data
Suggestions come from Google's Gemini models through the Gemini API on a paid plan. Under that plan Google does not use your data to train its models, and it deletes API inputs and outputs after a limited abuse detection period. Axelize itself never trains on your content and never uses one customer's content to serve another. That is a binding commitment in our terms, not a setting.
Deletion and retention
Delete a meeting and its transcript and suggestions go with it. Delete a company and its files and scraped pages go with it. To delete your whole account, email [email protected] from your sign-in address and it is gone within 30 days. A default retention period, after which a transcript is deleted unless you choose to keep it, is being built and will be announced here.
Infrastructure
- Hosted on Hetzner in Helsinki, on infrastructure we run ourselves.
- TLS 1.2 or higher on every connection, with Cloudflare in front of the app and API.
- Nightly database backups, kept for seven days.
- Server access restricted to authorised personnel over SSH, behind the Hetzner Cloud Firewall.
- Secrets kept out of source control.
Sign-in
You sign in with Google. Axelize asks only for your email address and basic profile, which are the non-sensitive scopes. It does not request access to your calendar, mail or Drive.
Extension permissions
The extension requests tabs to know which Meet call is open, storage to keep captions safe across a page reload, alarms to
retry delivery, and access to meet.google.com only.
What we do not claim
Axelize does not hold a SOC 2 report or an ISO 27001 certificate of its own, and we do not yet encrypt database volumes at rest beyond what the data centre provides. We would rather tell you that than imply otherwise. Both are on the roadmap, along with the retention default above.
Reporting an issue
Email [email protected] with anything you believe is a security problem. We will respond before doing anything else.