Privacy Policy
Last updated 18 August 2026
1. What we collect
Account details you provide (full name, email address, phone number), authentication data (a hashed password, or an identifier from Google, Facebook or X if you sign in with them), meeting metadata (titles, schedules, participants), attendance records (join and leave times), recordings where enabled, and technical logs including IP address and browser type.
2. Why we use it
To authenticate you, to give you access to the meetings you are assigned to, to run and record meetings, to show attendance to organisers and administrators, to keep an audit trail of administrative actions, and to protect the service against abuse.
3. Passwords
Passwords are never stored in plain text. They are hashed with Argon2id. Password reset links are single-use, time-limited, and stored only as a hash.
4. Recordings
Recordings are stored in Cloudflare R2 object storage and are never publicly accessible. Every playback and download uses a short-lived signed link issued only after a server-side permission check. Administrators can delete recordings, which removes both the stored file and its metadata.
5. Cookies
We use a single essential, HTTP-only session cookie to keep you signed in. We do not use advertising or third-party tracking cookies. Cloudflare Turnstile is used on sign-up and sign-in to block automated abuse.
6. Retention
Account and meeting records are kept while your account is active. Sessions expire automatically. Recording retention can be configured by your administrator; expired recordings are deleted from storage and marked as deleted in the audit trail.
7. Your rights
You can view and correct your profile in the application. For access, export or deletion requests, contact your administrator or privacy@monrq.com.
8. Contact
Privacy questions can be sent to privacy@monrq.com.