Private Vault

We can’t read your meetings.Not won’t — can’t.

Most tools promise not to look. That is a policy. Private Vault removes the ability — that is a property of the math. Meeting titles, transcripts, notes, and AI chat are encrypted on your device before they are saved. What we store is ciphertext. Anyone who breaks into our servers gets noise where your meetings should be.

Last updated July 2026 · Required to use Observer

01 How it works

Encryption you can explain in a minute

01

Your vault passphrase stays on your device

Private Vault uses a passphrase you choose in the Observer app — separate from signing in. That passphrase never leaves your device. Observer turns it into a key on your device (scrypt), then uses that key to unlock your data. Your normal Observer login still works as usual.

02

One data key, locked two ways

Your device creates a random data key that encrypts meeting content with AES-256-GCM. That key is stored on our servers only in locked form: once locked with your passphrase-derived key, and once with your recovery key. We can store the locked boxes. We cannot open them.

03

A recovery key, shown once

When you enable Private Vault, Observer shows a recovery key exactly once and asks you to save it. It is the only other way into your encrypted meetings if you forget your passphrase. We do not keep a copy — if we did, the promise above would be theater.

02 What we can and cannot see

At rest, your words stay sealed

We cannot see

  • Meeting titles — even the list of what your meetings were about
  • Transcripts — every utterance saved to your account
  • Meeting notes — summaries and takeaways
  • AI chat — questions you asked and answers you got

Observer also does not store raw audio recordings.

We do retain

  • Your email address — how you sign in
  • Usage metering — minutes and request counts (numbers, not words)
  • Timestamps and durations — when meetings happened and how long they ran
  • Meeting IDs and routine sync metadata
  • Instructions you configure for AI — needed to generate answers

Metering is numbers, not words — it keeps plans and free trial fair.

03 AI processing, honestly

Your words leave the vault only to be processed

Live answers, transcription, and note generation need readable text for a moment. An AI model cannot work on ciphertext, and we will not pretend otherwise.

When you use those features, Observer decrypts only what is needed on your device, then sends that content to our API and AI/speech providers over a secure, encrypted connection for that request. Our notes endpoint is built to hold that data in memory only: it does not write meeting titles or notes to our database, does not log the words, and answers with an X-Observer-No-Store response header — a machine-readable signal that this request was not persisted. After generation, your device encrypts the result again before saving.

Providers process data under contracts that prohibit training on your content. See our Subprocessors page.

We do not claim “end-to-end encrypted AI.” What we claim — and stand behind — is zero-access storage and transient processing: your content is stored sealed, and processed only briefly, never kept as readable meeting text on Observer systems.

04 Honest limits

What Private Vault does not promise

While AI or transcription is running, content must be readable briefly to those services.

If someone has access to your unlocked computer while Private Vault is enabled, they may be able to view your meetings in the app — like any other signed-in desktop app. Encryption protects what leaves your device and what sits in our database, not a shared computer session.

Meetings created before Private Vault was required may still exist as older plaintext rows until replaced; new meetings are encrypted.

05 Questions you should ask

Straight answers

What if I lose my passphrase?

Your recovery key gets you back in: open Private Vault → Manage, choose Recover with recovery key, and set a new passphrase. If you lose both the passphrase and the recovery key, previously encrypted meeting content cannot be recovered — by you or by us. There is no support ticket that can undo the math. That is intentional.

Why isn’t the AI path end-to-end encrypted?

Because it cannot be, and we will not pretend otherwise. A transcription engine needs to hear the audio; a language model needs to read the words. What we control is everything around that moment: decryption happens on your device, processing is transient, our notes path never stores meeting words, and results are encrypted again before saving. If another cloud meeting tool tells you everything is end-to-end encrypted, ask them how their AI reads your transcript.

Does Observer store my audio?

No. Audio is processed in real time for transcription and is not kept as a recording in your account. The durable record is the encrypted transcript, notes, and AI chat.

Do I have to unlock Private Vault every time I open the app?

No — not while you stay signed in on the same device. Once Private Vault is enabled, Observer can keep it unlocked across launches using your device’s secure storage, so you do not type your vault passphrase every time you open the app. You do need to unlock again after you sign out and sign back in, and on any new device. Starting a meeting still requires Private Vault to be enabled on that device.

Need clarity?

Questions about meeting privacy?

Email us anytime if you want clarity on how Observer stores or processes meeting content. Also see our Privacy Policy, Private Vault help, and Subprocessors.

[email protected]