Flocci Technologies Open dashboard

Where your meetings actually live

Direct answer

What happens to a Donna recording? Audio and screen video are captured server-side and compressed on the machine running Donna. Audio chunks go to speech recognition and the transcript to analysis; both return, and the recording, transcript and report stay on that machine and its database. On a private deployment nothing about your meetings is stored by a notetaker vendor at all.

The data path, step by step

01

Capture

A real Chromium browser driven by Playwright joins the call as a visible participant. Audio and screen video captured server-side, compressed after the call — the file is born on the server you run.

02

Transcription

Audio is split into size-checked chunks and transcribed. Chunks leave for the speech-recognition service and nothing else does; the resulting transcript is written to your database with real speaker names.

03

Analysis

Two passes: facts and commitments are extracted first, then the report is written through the chosen lens. The transcript is what travels; the recording never does.

04

Storage and delivery

Your own database on your server; reports as Markdown; recordings on your disk. Delivery is explicit — the dashboard, an optional email, a share link you mint, or an export you download.

Visibility is a design constraint, not a setting

Donna joins as a named participant a host admits. There is no covert mode, no silent recorder, and no way to attend a meeting nobody could see her in. She also leaves on her own: She leaves on her own: four end-of-call signals, a roster read that does not count other vendors’ notetakers as humans, and a silence backstop — which matters more than it sounds, because a notetaker that stays in an empty room is still recording it.

Sharing, deliberately narrow

A report leaves the room only when you send it. Share links carry an unguessable token, always serve the latest version of that lens, are revocable, and are excluded from search engines by both a page-level directive and an HTTP header. Exports are files you hold. Email delivery goes to named recipients you type. Nothing is published anywhere by default.

What we do not claim

No certification badges appear on this page, because certifications you have not completed are not a security posture. What is true is architectural and checkable: the recording never leaves the machine you run, the only external calls are transcription and analysis, the dashboard is behind sign-in and noindexed, and on a private deployment there is no vendor copy of anything. If you need a compliance questionnaire filled in honestly, ask us and we will answer it line by line rather than pointing at a badge.

Questions, answered straight

Do you train models on our meetings?

No. Meeting content is processed to produce your transcript and your report, and that is the whole purpose. On a private deployment the question is moot — the data is in your database, reached by your keys.

Who inside our organisation can read a report?

Whoever you allow: meetings belong to their owner, org workspaces scope a team’s meetings to that org, and everything else is behind sign-in. Sharing outside is always an explicit act — a link, an email or an export.

What about the recording of a meeting somebody objects to?

Remove the bot for that call, and delete the meeting if one was made. On your own deployment deletion is a file and a row, not a support request.

Is a self-hosted notetaker automatically compliant?

No. It removes a third-party processor and a cross-border transfer from your assessment, which makes the remaining work tractable — but consent, retention, access control and deletion are still a programme you have to run.

Put Donna in your next meeting

Access is open — sign in with your Google account and she’s in your dashboard in minutes. Rolling out to a whole team, or want a hand with the server setup? We’re glad to help.