HintMint

HintMint

Security

Last Updated: 20-Jul-2026

HintMint is built and operated by RTC LEAGUE, Inc. This page summarizes how we protect the meeting audio, transcripts, and account data you trust us with. For RTC LEAGUE's full corporate security posture, see the RTC LEAGUE Security & Trust Center.

On this page

Data Protection

  • Encryption in transit (TLS 1.2+) and at rest (AES-256) for meeting recordings, transcripts, and account data
  • Role-based access controls limiting internal access to personnel who need it to operate the Services
  • Dedicated workspace isolation for team and enterprise accounts
  • Google user data (name, email, profile photo) is stored under the same encryption standards. Access to it is restricted to authorized personnel and systems, see our Privacy Policy Section 3.3 for detail

Infrastructure Security

  • Firewall protection and intrusion detection systems
  • Regular security audits and assessments

How We Handle Meeting Data

  • HintMint does not listen to, record, or process audio outside of sessions you explicitly initiate
  • Recordings and transcripts are retained for the period set by your plan, then permanently deleted from active systems (backup copies may persist up to 90 days in immutable backup systems)
  • HintMint does not use Customer Data, including meeting recordings and transcriptions, to train AI models without your explicit consent. Enterprise Tier customers have this contractually guaranteed; Free and Pro Tier customers can opt out in writing to support@hintmint.io

Google API Compliance

HintMint's use of Google user data adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request only the minimum OAuth scopes needed to authenticate you, we do not access Gmail, Calendar, Drive, or Contacts data unless you separately authorize a specific integration, and we never use Google user data for advertising. Full detail is in our Privacy Policy, Section 3.

Sub-processors

A current list of the vendors we use to provide the Service, including cloud infrastructure, transcription, and payment processing, is published at hintmint.io/subprocessors.

Compliance

FrameworkStatus
GDPR / UK GDPRData Processing Agreement available, Standard Contractual Clauses used for international transfers
CCPA / CPRA, Nevada Ch. 603AAddressed in our Privacy Policy; HintMint does not sell Personal Information
SOC 2 Type IINot yet attained

Enterprise Documentation

Available under NDA to Enterprise Customers. Contact your account representative or email legal@rtcleague.com:

  • Data Processing Agreement (DPA)
  • Master Services Agreement (MSA)
  • Security Whitepaper
  • Completed Vendor Risk Questionnaire (SIG Lite / CAIQ)

Download and try HintMint for free today

Get Started