Twin2.me
Privacy policy
Last updated: 2026-09-24
Twin2.me builds a "twin": an assistant that answers in your voice, from the
material you give it. This policy covers what we collect, what for, who we
share it with and how long we keep it. The
meeting assistant has its own section, because it
records conversations with more people in them than you.
Who is responsible
Twin2.me is the data controller. Write to us any time at
info@twin2.me, which is also the channel
for exercising your rights.
What we collect, and what for
- Your account. Name and email, plus your profile photo if
you sign in with Google. They come from Google or Microsoft when you sign
in with them, or you type them yourself if you sign in with email and
password. For the password we store only an scrypt hash, from which the
password cannot be recovered. And, to stop anyone guessing passwords, we
note how many times each email address and each IP address fails to sign
in, and delete that within a day.
- The material you upload — files, recordings, links,
whatever you connect from your clouds and your apps — to build your twin.
It is yours and you can delete it.
- Your calendar, if you connect it. See below.
- The audio of meetings you send the assistant to. See
below.
- Minimal telemetry about product use (what failed, how
long it took, how many tokens an answer cost). It is not shown to anyone
outside the team and is not used to profile you.
We use no analytics or advertising cookies, and the public pages load nothing
from a third-party domain: no fonts, no measurement tags, no social widgets.
There is no profiling and no automated decision-making about you.
Your calendar
If you connect Google Calendar or Outlook, we do it through OAuth and with a
consent separate from signing in: you can use Twin2.me without connecting any
calendar.
- What we read. Only your primary calendar, and at three
moments:
- When you open Calendario in Twin2.me, the events in
the range you are looking at (a week, a month or, at most, a year),
private ones included: title, time, whether it has a video call, your
response and how many guests there are. Only to show them to you on
that screen: they are not stored.
- When you ask your twin about your schedule in Hablar, the events in
the range you ask for (31 days at most), only for that answer: those
are not stored either.
- If your plan includes the meeting assistant, every few minutes, the
events for the next 24 hours: title, start and end time, who organises
it, who is invited (name and email), and the text where the video-call
link usually lives. The assistant skips events marked
private and never stores them.
- What for. To show you your schedule, so your twin can
organise your day and, with the assistant, to know which meeting to join
and at what time, and to put a name to who is speaking in the
transcript.
- What we write. Two things. We add the assistant's
email to the guest list of the meetings you mark, and remove it if you
change your mind. This is done without notifying the other guests, and we
touch nothing else on the event. It is what lets the assistant join without
somebody having to admit it by hand. And, only on Google Calendar and only
when you press «Hacer» on a card in Hablar, we create on your primary
calendar the events you asked your twin to add: with no guests and without
notifying anyone.
- What we store. For each meeting the assistant is going to
join: the title,
the time, who is invited, and the join link encrypted — it carries
the room password, so it never leaves through our API and never appears in
a log. Your calendar tokens are stored encrypted with AES-256-GCM.
- Disconnecting. When you disconnect a calendar, meetings
that have not started yet are cancelled and the permission is revoked.
Whatever already reached your material stays, because it is yours, and you
can delete it from there.
Twin2.me's use of information received from Google APIs will adhere to the
Google
API Services User Data Policy, including the Limited Use requirements.
Specifically: we do not sell that data, do not use it for advertising, do not
use it to train models, and no human reads it unless you ask us to in order
to resolve an issue or the law requires it.
The meeting assistant
If your plan includes it and you switch it on for a specific meeting, a
twinme-branded assistant joins that video call, records the
audio and leaves the transcript in your material. Here is what it
does and what it does not:
- It announces itself. It joins under a name that says
what it is, and posts a message in the meeting chat saying that it is
recording and for whom. On Zoom it also triggers the platform's own
recording indicator, which cannot be suppressed.
- Audio only. It does not record video, does not record
screen sharing, and does not speak.
- The audio is deleted. It is transcribed and, as soon as
the transcript is ready, the audio file is erased: what
remains is the text. We do not keep both.
- Other people in the room are protected. The transcript
enters your material as a private source; what other people said does not
reach the search index or your twin's answers except after a leak filter
and a quarantine that you resolve, not an operator of ours. Third parties'
full names are blocked.
- The minutes are for you. From the transcript we draw a
summary, what was left to do —and who took it on— and what mattered, even
if you were not there. You see them in Calendar and we email them to you,
which you can turn off in Settings. Nobody else receives them, they do not
feed what your twin tells other people, and removing the meeting from your
material removes them.
- Your twin does your tasks. If the minutes say you have
to do something that is done in an app you connected —sending an email,
scheduling, creating a document—, your twin does it in your name with that
app and tells you in Twin2.me. Anything that moves money, and anything past
a few actions per task, per meeting and per day, is left for you to
approve. It works from what was said in the meeting, including what other
people said. You can turn it off in Settings.
- What we do not control. The organisation hosting the
meeting can stop the assistant from joining. That is not a failure: it is
their decision, and we respect it.
Recording a conversation is your responsibility. In many
places the law requires notifying everyone on the call, and in some it
requires their express consent. The assistant gives notice on its own — its
name and a chat message — but that does not replace you: you are the
one who switches recording on, and you are the one answerable for having
whatever permission your jurisdiction requires. If someone in the
room objects, ask the host to remove the assistant and delete the meeting
from your material.
Who we share it with
We do not sell or rent your data, and we do not use it for advertising. To
operate we rely on these processors, and on nothing else:
- Amazon Web Services (United States): the server, the
database, file storage, the emails we send you and the meeting
assistant.
- Deepgram and Groq: transcribe the audio. They receive
the audio file and return the text. Meeting audio goes to Deepgram
only.
- Language-model providers — today DeepSeek and Groq — to
distil your material and answer. If you connect your own AI account,
traffic goes to yours and not to ours.
- OpenAI: lets your search index match by meaning and not
only by words. It receives the text that enters the index and the
questions people ask your twin, and returns numbers. It never receives
your original files.
- Composio: connects the apps you link, such as Gmail,
Google Docs or Notion. It holds the permission for each one, and
everything we touch in them goes through it: what we bring into your
material, and what your twin reads or does when you ask it to in Hablar —
anything it writes, only after you approve it. It does not store the
content of those calls.
- Google Workspace: our email, and the account the
assistant uses to join Google Meet. When you send it to a Meet meeting,
the invitation — title, time, guests and link — reaches that
account.
None of them trains models on your material. If that ever changed, this page
would change first.
How long
- Your material, while you have an account or until you
delete it. Deleting a source deletes it for real, file included.
- A meeting's audio, until the transcript is ready. After
that it does not exist.
- Calendar events that never got recorded are cleaned up
with the rest of the meeting history.
- Your account, until you ask us to delete it. Then
everything hanging off it goes.
How we protect it
- No model is trained on your data. A twin has no weights:
it is your corpus, your distilled voice and your persona specification on
top of a model that does not change. There is no model trained on you.
- Your original files are not indexed and a query does not
touch them. Only what is marked publishable enters the search index.
- Your cloud and calendar permissions are stored encrypted
with AES-256-GCM, and so are meeting links, because they carry the room
password.
- Your files do not pass through our server: they upload
straight to storage with a signed, single-use permission.
Your rights
You can know, update, rectify and delete your data, withdraw your
authorisation and request proof of it, and complain to the Superintendencia
de Industria y Comercio (Colombian Law 1581 of 2012 and Decree 1074 of 2015).
If you are in the European Union you also have the rights of access,
rectification, erasure, restriction, portability and objection (GDPR articles
15 to 22) and to complain to your supervisory authority. Write to
info@twin2.me and we will answer.