Privacy Policy

Last updated 18 August 2026

1. What we collect

Account details you provide (full name, email address, phone number), authentication data (a hashed password, or an identifier from Google, Facebook or X if you sign in with them), meeting metadata (titles, schedules, participants), attendance records (join and leave times), recordings where enabled, and technical logs including IP address and browser type.

2. Why we use it

To authenticate you, to give you access to the meetings you are assigned to, to run and record meetings, to show attendance to organisers and administrators, to keep an audit trail of administrative actions, and to protect the service against abuse.

3. Passwords

Passwords are never stored in plain text. They are hashed with Argon2id. Password reset links are single-use, time-limited, and stored only as a hash.

4. Recordings

Recordings are stored in Cloudflare R2 object storage and are never publicly accessible. Every playback and download uses a short-lived signed link issued only after a server-side permission check. Administrators can delete recordings, which removes both the stored file and its metadata.

5. Cookies

We use a single essential, HTTP-only session cookie to keep you signed in. We do not use advertising or third-party tracking cookies. Cloudflare Turnstile is used on sign-up and sign-in to block automated abuse.

6. Retention

Account and meeting records are kept while your account is active. Sessions expire automatically. Recording retention can be configured by your administrator; expired recordings are deleted from storage and marked as deleted in the audit trail.

7. Your rights

You can view and correct your profile in the application. For access, export or deletion requests, contact your administrator or privacy@monrq.com.

8. Contact

Privacy questions can be sent to privacy@monrq.com.