Trust & security

What Cadenva does with your meetings — and what it never does.

The questions a company asks before it puts a meeting through someone else's software, answered from the code that runs the service.

Reviewed September 2026Applies to cadenva.com and the Cadenva app

No bot joins your meeting

Cadenva is never a participant in your call. It reads a recording you upload, a transcript you paste, audio captured in your own browser, or a transcript Google Meet already produced.

Nothing reaches a calendar unapproved

A person confirms the wording, the owner and the date before any event is written. There is no setting that turns that off.

Recordings are deleted after processing

Raw audio is released as soon as a meeting reaches a finished state, whether it succeeded or failed. The transcript and the commitments stay in your workspace.

Your content never trains a model

Not ours, and not a provider's. The transcription and extraction provider processes API content under terms that prohibit training on it.

01Does a bot join calls?

No. Nobody in your meeting sees a Cadenva attendee, because there is none. Cadenva reads a meeting one of four ways, and all four begin with an act of yours: you upload a recording, you paste a transcript, you start a capture that records audio in your own browser, or — if you have separately turned it on — Cadenva imports a transcript that Google Meet had already produced for a meeting you chose to capture.

Cadenva cannot start a recording or a transcription inside Google Meet, and cannot change a Meet setting: the only Meet permission it ever requests is read-only. If Google Meet produced no transcript, nothing is imported.

02What Cadenva stores

Raw audio is an input, not a record. Everything of value survives it, and it does not survive processing.

Raw audio

Deleted once the meeting reaches a finished state — completed, failed or errored. A sweep at service start releases anything an interrupted run left behind, so a crash delays the deletion rather than cancelling it.

Transcripts

Kept in your workspace, with the per-line timestamps and speaker names the source provided. They are what the commitments are checked against, so they are not cleared at the end of a session.

Commitments

The action, the owner, the date, the status, and the passage of the transcript each one came from — the evidence is stored with the commitment so a person can always see why Cadenva read it that way.

Calendar data

Not mirrored. Upcoming events are fetched from your provider when you open the app and are not written to our database. What is stored is the identifier and link of events Cadenva itself created, so it can update or remove them later.

Account data

Email address, password hash, workspace membership, and the email and display name of the calendar account you connected.

Billing data

Handled by Stripe. Cadenva stores the Stripe customer and subscription identifiers and the subscription’s status, which is what decides your plan. Card numbers never reach Cadenva. See Privacy.

03Does the AI act on its own?

No. What the model produces is a proposal, and a proposal cannot reach your calendar. Before an event is written, a person has to confirm the commitment itself, confirm the date they were shown or supply a different one, and confirm that nothing is blocking it. A request that merely echoes back the date Cadenva extracted does not count as confirmation, because a client can echo a value without a person ever having looked at it.

This is a property of the server, not of the screen. The rule lives in one function that every execution path calls, and the one code path that was ever built to approve items in bulk is both switched off by default and refused by that same rule if it is switched on — it cannot supply the human authority the rule requires, so it writes nothing.

04Calendar authorisation

What is requested

Connecting Google Calendar asks for one calendar permission — reading and writing events, which Google does not split into two — plus your Google email and basic profile so the app can show which account is connected. Read-only access to Google Meet transcripts is a separate, optional permission that is requested only if you turn that feature on; you can decline it and keep using Calendar. Microsoft Calendar asks for the equivalent read-and-write calendar permission and your basic profile. No Google Drive permission of any kind is ever requested.

One connection per workspace

A calendar connection belongs to the workspace, not to the person who made it. A workspace has at most one Google connection and at most one Microsoft connection, so every event approved by anyone in that workspace is written to that one connected account. This matters if several people share a workspace, and it is the reason the connected account should be one the team means to write to.

When a calendar write fails

Cadenva records what it actually knows. A write is marked verified only when it was confirmed with the provider; when the provider could not be reached or answered ambiguously, the result is recorded as unknown rather than reported as success. You are told which it was, and a failed write does not silently drop a commitment — the commitment stays in your workspace and can be tried again.

Withdrawing access

Disconnecting from inside Cadenva deletes the stored credentials. That does not revoke the grant on the provider’s side, which you can do at any time in your Google or Microsoft account settings. Events Cadenva already created stay in your calendar and are yours to keep or delete.

05Workspaces and teams

A workspace is the unit of both access and separation. Several people can share one — that is how a team uses Cadenva — and everyone in a workspace sees the same meetings, the same commitments and the same source evidence, and can review, correct, approve and schedule any of them. There are no permission levels today: membership is the permission. Decide who belongs in a workspace on that basis.

Between workspaces there is no sharing at all. Every request is checked against the workspace the caller’s session was issued for, and a session for one workspace cannot read or write another’s data even when it asks by name. Calendar credentials, transcripts, commitments and billing state are all held per workspace.

Joining an existing workspace requires that workspace’s own join code, which we mint for you and which is never valid for any other workspace. Adding and removing members is done through us today rather than from a settings screen — write to hello@cadenva.com and we action it. When a member is removed, their membership ends and every session they hold is invalidated immediately, everywhere. Their past work is not rewritten or deleted.

06Infrastructure and providers

Cadenva runs on managed infrastructure and uses a small number of service providers, each named in the Privacy Policy together with exactly what it receives. That list is the authoritative one and is kept in one place deliberately, so it cannot say two different things on two pages.

The properties worth stating here: all traffic runs over HTTPS; calendar credentials are encrypted by the application before they are stored, and the service refuses to start in production without its encryption key; off-site backups are held encrypted by the storage provider and expire automatically about 30 days after they are taken; the backup credential held by the running service can write backups and cannot read, list or delete them. Logs and error reports carry error types, counts and identifiers rather than tokens, transcripts, meeting titles or account emails.

These providers are established outside the EEA, principally in the United States, so operating Cadenva involves an international transfer of the data described in Privacy. The transfer commitment Cadenva makes to a business customer is in the Data Processing Agreement.

07Accounts and access

Accounts are email and password. Passwords are never stored — what is stored is a salted PBKDF2-SHA256 hash at 390,000 iterations, with a fresh random salt per password. A session is a signed token with a 30-day lifetime that we can revoke from our side; signing out revokes it everywhere, on every device, rather than only clearing the browser that asked.

Single sign-on, enforced two-factor authentication and IP-restricted access do not exist in Cadenva today. If your procurement requires any of them, tell us before you buy rather than after.

08Deleting your data

Email hello@cadenva.com and we erase the workspace you name. We confirm and complete deletion from the live service within 48 hours. There is no self-service delete button; this is a request we action, and we would rather say so than imply a control that is not on the screen.

Erasure removes the workspace and everything reachable from it — transcripts, commitments, approvals, stored credentials and any remaining files — and it refuses rather than half-completing if it cannot remove every file first. It is irreversible. Two things it deliberately does not do: it does not delete the user accounts themselves, because a person may belong to other workspaces, and it does not touch events already in your calendar, which are yours. Off-site backups taken before the request still hold earlier copies and cannot have single records cut out of them; they expire on their own schedule, about 30 days after each one is taken.

09Reporting a problem

Report a security or privacy issue to hello@cadenva.com. Write “security” in the subject and it will be read as such. We will acknowledge within one business day. We do not currently run a paid bug bounty, and we will not pretend one exists in order to look larger than we are.

10What we do not claim

Cadenva is a small, young company, and the useful thing to publish is the boundary rather than a longer list of assurances. We hold no ISO 27001 certificate and no SOC 2 report. No third-party penetration test has been performed. There is no security operations centre and no dedicated security staff. We offer no contractual uptime guarantee — the Terms say the service is provided as-is, and that is the real commitment, not a marketing softening of one.

Everything on this page describes the service as it is built today. If a question you need answered is not here, ask it at hello@cadenva.com and we will answer it directly, including when the answer is no.