You open your video call app every day without a second thought. Click the link, grant the camera and microphone permission you granted months ago, and you're in. But behind that friendly "Join Meeting" button is a long list of decisions your provider made about your data—decisions you probably never saw, let alone agreed to on purpose.
Most people think about video-call privacy exactly twice: the day they install the app, and the day something goes wrong. In between, the app is quietly making choices on your behalf—how long it keeps a record of who you spoke to, whether your "private" recording sits behind a public link, whether a new AI note-taker is being trained on your quarterly planning call right now. None of these choices show up in the interface you actually see. They live three menus deep in a settings panel, or four thousand words into a privacy policy nobody reads end to end.
This matters more than it used to. Video calls have quietly become the place where the most sensitive conversations in our lives happen: performance reviews, therapy sessions, board meetings, custody hearings, first dates, layoff notices, medical consultations. A chat app leak exposes messages. A video-call leak can expose someone's face, voice, home, and the exact words they used in a moment they believed was private. The stakes are simply higher, and the audit trail is longer than most people assume.
This isn't a lecture on paranoia, and it isn't an argument that every video app is secretly malicious. Most providers are not acting in bad faith—they're optimizing for convenience, adoption, and increasingly AI features, and privacy defaults quietly lose out to those priorities unless someone forces the trade-off into the open. This is a five-minute, checklist-style audit you can run on any app you already use—Zoom, Teams, Google Meet, WebEx, or anything else—right now, before your next call.
How to use this checklist
Each item below takes about 30 seconds to check. Open your video app's privacy settings or policy page in another tab, work through the boxes in order, and tally your checkmarks at the end. Score yourself using the key at the bottom. If you manage an app for a team or company, run this once per quarter—vendors change defaults quietly, often through a routine "feature update" that gets almost no press coverage.
The Checklist
Ten questions. Five minutes. Zero fluff.
1. End-to-end encryption—on by default, not buried in a toggle
Ask: Is my call encrypted end-to-end, or only "encrypted in transit" to the provider's servers?
"Encrypted in transit" often means the provider itself can still decrypt and inspect your audio, video, or chat on its own servers, even though nobody outside the company can. True end-to-end encryption means the keys never leave participants' devices—not the provider, not a cloud server in between, not a support engineer troubleshooting a ticket. The difference sounds technical, but it's really a question of who you're trusting: the math, or the company's internal policies and employee access controls.
2. Meeting metadata retention
Ask: How long does the app keep records of who met with whom, when, and for how long—even if the content itself isn't stored?
Metadata (attendee lists, timestamps, IP addresses, device info) can reveal sensitive relationships and patterns even without a single word of the conversation being recorded. Knowing that a job seeker had a 45-minute call with a competitor's HR line every Tuesday for a month tells a story all on its own—no transcript required. Metadata is often kept far longer than call content because it's cheap to store and useful for product analytics, which means it frequently outlives the policy language written about it.
3. Third-party data sharing
Ask: Does the app share analytics, attendee emails, or usage data with advertising or data-broker partners?
Many "free" video tools subsidize costs by sharing behavioral data with ad-tech partners, data brokers, or affiliated products in the same corporate family. This is usually disclosed somewhere, but rarely in plain language, and almost never with a simple way to opt out without downgrading your account or losing features.
4. Recording storage and access controls
Ask: Where are cloud recordings stored, who inside the company can access them, and can I set my own expiration date?
A recording is a permanent, searchable transcript of a conversation people expected to be temporary. Weak access controls or indefinite storage turn a routine meeting into a long-term liability—the kind that surfaces years later in a lawsuit, a data breach, or a simple misdirected sharing link. The safest recordings are the ones with a built-in expiration date, so the decision to keep something forever has to be made on purpose, not by default.
5. AI meeting assistants and training data
Ask: If the app offers AI note-taking or summarization, is my meeting content ever used to train models—the vendor's or a third party's?
AI features are the newest and least transparent leak point in video calling today. Many tools quietly opt every meeting into model training unless you dig into an admin console to opt out, and the opt-out is often controlled at the organization level, meaning an individual employee has no way to protect their own calls even if they want to. Ask specifically whether training is opt-in or opt-out, and whether that answer changes for free versus paid accounts.
6. Device and OS-level permissions
Ask: What can the app access on my device beyond the camera and mic—contacts, calendar, files, location?
Permission creep is easy to miss because the prompt appears once, during install, and is rarely revisited. A video app rarely needs your full contact list, file system, or precise location to run a call—those permissions typically exist to power a convenience feature (like "find coworkers automatically") that most people never use, and could be requested only when that specific feature is turned on.
7. Waiting rooms, host controls, and unauthorized access
Ask: Can uninvited people join a meeting via guessed or shared links, and is there a waiting room or lock feature enabled by default?
Weak default access controls are how uninvited guests end up on calls—and how sensitive discussions get overheard, screen-recorded, or disrupted entirely. A waiting room that has to be manually switched on for every single meeting is a control that will eventually be forgotten under deadline pressure, which is exactly when it matters most.
8. Data residency and jurisdiction
Ask: Which country or region are my call data and recordings actually stored in, and under whose laws?
Where data physically lives determines which government agencies can legally request access to it, under which legal standard, and often without notifying you or the account holder at all. This matters most for regulated industries—healthcare, legal, finance—but it's relevant to anyone who simply prefers to know, in plain terms, which country's laws govern their conversations.
9. Account deletion and true data erasure
Ask: If I delete my account, is my data actually erased—including backups—or just hidden from my view?
"Deleted" and "de-listed" are not the same thing. Deleting an account typically removes it from your view and the provider's active dashboards, but backups, logs, and analytics copies often persist well past account closure—sometimes for months, sometimes indefinitely, depending on the backup retention schedule buried in an internal policy you'll never see.
10. Plain-language transparency
Ask: Can I find a privacy policy summary that a non-lawyer can actually read in under five minutes?
If a provider can't explain its own data practices simply, that's often a sign the practices themselves wouldn't hold up well in plain English. Clear, short-form privacy communication is usually a signal that a company had to defend those decisions internally before publishing them—vague, legalistic language is frequently what's left after the plain version raised uncomfortable questions.
Frequently Asked Questions
"I don't have anything to hide—does this really apply to me?"
Privacy isn't about hiding wrongdoing; it's about controlling context. A comment that's harmless between two colleagues can read very differently to an employer, an insurer, or a stranger who screenshots it out of context. The goal of this audit isn't secrecy—it's making sure your conversations are seen by the people you intended, for as long as you intended, and not a day longer.
"Can't I just trust the big-name providers because they have more to lose?"
Scale cuts both ways. Larger providers do tend to have more mature security teams, but they also have more business incentive to monetize usage data, more legacy features bolted on over a decade, and more organizational complexity that makes a single, clean privacy answer harder to get. Size is not a reliable proxy for good defaults—read the actual settings instead of assuming a familiar logo means a safe one.
"What if my company chose the video app and I don't control the settings?"
You can still run this audit—just direct the results at your IT or security team instead of your own account settings. Most of these questions (metadata retention, AI training defaults, data residency) are decided once at the organization level, so a single conversation with whoever manages the account can improve the defaults for everyone who uses it, not just you.
"How often should I re-run this checklist?"
Once a quarter is a reasonable cadence for personal use, and every time your organization renews or upgrades a contract for business use. Providers frequently roll out new AI or "smart meeting" features between contract cycles, and those features are exactly where new data-sharing defaults tend to appear first.
Score Yourself
Count your checked boxes out of 10:
- 8–10 checked: Solid. Your app is treating your meetings like they matter.
- 5–7 checked: Mixed bag. You're leaking somewhere—probably metadata, AI training, or recording access.
- 0–4 checked: Time to switch. Your day-to-day conversations are more exposed than you realized.
Why we built Meetingpoint.chat around this checklist
We wrote this audit because we run it against our own product first, not just everyone else's. Meetingpoint.chat was built with end-to-end encryption on by default for every call, clear and finite metadata retention instead of open-ended "as needed" language, no ad-tech data sharing of any kind, opt-in-only AI features that never train on your calls without explicit, revocable consent, waiting rooms and host locks enabled from the first meeting rather than a setting you have to remember, and a plain-language privacy page you can genuinely read over one cup of coffee.
Run this same ten-item checklist on us before you take our word for any of it—we'd rather you check the boxes yourself.
Privacy isn't a feature you bolt on after the fact, and it isn't a marketing line on a homepage—it's a series of small defaults, chosen deliberately, that add up to whether people can actually speak freely on a call. Every checkbox above represents a decision some product team made on your behalf, usually without asking. The five minutes you spend running this audit is five minutes spent taking that decision back.
Run this audit on whatever you're using today, whether that's the tool your company mandated three IT cycles ago or the free app you downloaded for one meeting and never left. If it comes up short on more than a couple of items, that's worth raising with whoever owns the account or simply switching. Meetingpoint.chat was built to pass every item on this list, and we'd rather earn that by holding still while you check.