Security & privacy

Your workflow.
Your data choices.

Understand what is processed on your device, what reaches an engine provider, and what belongs to the website or Official Cloud service.

Data routes

Review every processing stage

Local engine

The selected stage runs on the device with its installed model. Verify that ASR, translation, and TTS are all local before treating a complete session as local.

Provider API

The relevant audio or text is sent to the service configured for that stage. Review its account, retention, region, and contractual terms.

Hybrid configuration

Each stage may take a different route. A local ASR does not make cloud translation or cloud TTS local; inspect active bindings before use.

Separate services

A desktop engine is one
part of the picture.

A local inference choice does not remove account, licensing, download, or optional cloud-service traffic.

Website and licensing

Account information, orders and device activation support purchasing and license management. They are separate from your chosen translation engine.

Subtitle Bridge · Official Cloud

When the extension uses Official Cloud, task content passes through CrossMeet's service to configured providers. Official Cloud pronunciation assessment is currently disabled; practice recordings are not accepted through that feature.

Knowledge and document tools

Inspect OCR, search-intent, embedding and reranking engines as well as translation. A cloud stage receives the content required to perform that task.

Read the privacy policy ↗
Before sensitive use

Prepare the full workflow

Legal, medical, employment, and confidential business data require an assessment of the full system and every vendor involved.

01

Confirm active engines

Check ASR, translation, TTS, and any knowledge-base or feedback route.

02

Use the provider's real terms

Verify retention, training use, regional processing, access control, and deletion with each provider.

03

Review saved and exported data

Decide how session history, diagnostics, exports, backups, and device access are managed.

04

Test on the target environment

Validate network behavior, permissions, device routing, and failure handling before production use.

Current boundary

No unverified compliance claims

This website does not claim HIPAA, SOC 2, ISO 27001, or equivalent certification, and does not promise a DPA, BAA, NDA, private deployment, or security review until an authorized legal entity and signed scope exist. CrossMeet is not a medical device and does not replace professional risk assessment.

Report a security issue

Send reproducible steps and affected versions. Do not include real customer data, credentials, or sensitive recordings.

security@crossmeet.com

Your next conversation

Start with a clearer understanding.

Explore Free, then add the tools your work needs.