1.Who we are and what this covers
Who we are
MediaSFU, based in Edmonton, Alberta, Canada, is responsible for the personal information described in this policy. It covers the MediaSFU website, dashboard, APIs, SDKs and apps (the "Service").
Two roles
For our own customers and website visitors, MediaSFU decides how personal information is used and is responsible for it.
For information about our customers' end users, meeting participants, callers and contacts, MediaSFU processes it on the customer's behalf and under the customer's instructions. The customer's own privacy notice applies, and requests about that information should go to the customer first. We will help them respond.
2.Information we collect
Account information
Name, email address, username, organization, account settings and API keys.
Billing information
Billing contact details, plan and purchase history, transaction IDs, invoices and tax or business details. Card and payment details are handled by Stripe and PayPal. MediaSFU does not store full card numbers.
Usage and technical information
IP address, browser and device details, sign-in and API request logs, and usage measurements such as minutes, participants and rooms. We use these for billing, security and reliability.
Rooms and meetings
- Participants: we create a signed access token from the display name you send. We do not attach other identifiers to it.
- Live media: audio, video and screen sharing are relayed in real time and are not written to disk.
- Messages: not saved for Chat, Webinar or Conference rooms. They are saved for Broadcast rooms only when message history is enabled.
- Recordings: made only when recording is enabled. Completed recordings stay in MediaSFU staging for 72 hours and are then deleted, or they are delivered to storage you configure.
Calling and contacts
MediaSFU does not sell or issue phone numbers. We store the numbers you connect, and the contacts and campaign lists you add, such as names, numbers, emails, company details, notes and do-not-call preferences. We also keep call metadata such as call counts, last-called times and durations.
Full call logs are not kept by default. Limited summaries and operational events are stored only when you enable telephony support logging.
AI features
- Translation, voice agents and vision agents: when you enable them, audio, video and transcripts are sent to the providers configured in your pipeline, such as speech-to-text, language-model and voice services, only to deliver the feature.
- Web agents in MediaSFU widgets: session logs are kept by design, so you and your support team can follow conversations. You can delete them from your dashboard, or leave the feature off.
- Custom agents you build with our SDKs: MediaSFU does not log their conversation content unless you add logging yourself.
Support and communications
Messages, tickets and questions you send us, including questions to the Ask MediaSFU assistant on our website.
Cookies and similar storage
Our website uses essential cookies and local storage to keep you signed in, protect sessions and remember preferences, including your cookie choice.
We also use Google Analytics to understand how the website is used, such as which pages are visited, how visitors arrive, and their device type and approximate location. Its cookies are _ga (a random visitor ID, kept up to two years) and _ga_M72BD91GHM (session state). In the EU, the UK and Switzerland, they are set only after you select Accept; elsewhere they are on by default and you can turn them off. Choosing Essential only also removes them. Change your choice at any time with Cookie settings in the website footer.
We use no advertising cookies. Stripe and PayPal may set fraud-prevention cookies on checkout pages, and embedded videos load in YouTube's privacy-enhanced mode.
3.How we use information
Purposes
- to provide, operate and maintain the Service;
- to process payments and keep accurate billing records;
- to secure accounts and detect fraud, abuse and misuse;
- to provide support and send service, security and billing notices;
- to improve reliability and performance, using usage data in aggregated form where we can; and
- to meet legal, tax and accounting obligations.
What we do not do
We do not sell personal information, and we do not build advertising profiles.
Consent and legal bases
We rely on your consent, which may be implied where the use is obvious and reasonable, as Canadian privacy law allows. Where the EU or UK GDPR applies, our legal bases are performing our contract with you, our legitimate interests in running a secure and reliable service, compliance with law, and consent where we ask for it.
4.Service providers and sharing
Service providers
We share information only with providers that help us run the Service, under contracts that limit their use of it:
- Amazon Web Services: hosting and infrastructure;
- Stripe and PayPal: payment processing;
- Google Analytics: website usage measurement, as your cookie choice allows;
- email delivery providers: account and service emails;
- AI model providers: to power MediaSFU's own assistant and live demos, limited to what you submit to them; and
- providers you configure in your own pipelines, which act under your instructions and their own terms.
Other disclosures
We disclose information when the law requires it, to protect people or the Service from harm, or as part of a merger or acquisition, under equivalent protections. We never sell personal information.
5.Where information is stored
The Service is hosted on Amazon Web Services, primarily in the United States. Information may therefore be stored and processed outside your province or country, where it is subject to local law, including lawful access by authorities there. We use contractual and technical safeguards to protect it wherever it is processed.
6.How long we keep it
- Account information: while your account is open, and then for as long as needed to close it out and resolve any outstanding issues.
- Billing records: as long as tax and accounting law requires. In Canada, this is generally six years.
- Security and sign-in logs: only as long as needed to detect and investigate suspicious activity.
- Recordings: 72 hours in MediaSFU staging, unless delivered to your own storage.
- Logs you enable, such as web agent sessions and telephony support logs: until you delete them or close your account.
When information is no longer needed, we delete it or make it anonymous.
7.Security
We protect information with safeguards suited to its sensitivity. These include encryption in transit (HTTPS for our website and APIs, and encrypted media for WebRTC sessions), access controls and scoped API credentials. No system is perfectly secure. If a breach creates a real risk of significant harm, we will notify affected people and authorities as the law requires. Report security concerns to support@mediasfu.com.
8.Your rights and choices
Your rights
You can ask to access, correct, export or delete your personal information, and to withdraw consent. Where GDPR applies, you can also object to or restrict processing. Many records, including web agent and telephony logs, can be deleted directly from your dashboard, and you can change your analytics choice at any time with Cookie settings in the website footer.
How to ask
Email support@mediasfu.com. We may need to verify your identity, and we respond within 30 days. If your request is about information a MediaSFU customer holds about you, we will refer it to that customer.
Complaints
If you are not satisfied with our response, you can contact the Office of the Information and Privacy Commissioner of Alberta, the Office of the Privacy Commissioner of Canada, or your local data protection authority.
9.Children
The Service is intended for adults, and we do not knowingly collect information from children. Customers who use MediaSFU in education or family products are responsible for obtaining any consent their users need.
10.Changes to this policy
We will post updates here with a new version and effective date, and give notice of material changes by email or in the dashboard. Past versions are summarized in the change history below. Billing, credit and refund rules are in the Terms of Service.
11.Contact
For questions about this policy or your information, contact the MediaSFU privacy team at support@mediasfu.com. Our address is MediaSFU, Edmonton, Alberta, Canada.
Change history
| Version | Date | What changed |
|---|---|---|
| 3.0 | September 27, 2026 | Rewritten as numbered sections. Added our two roles, cookies and Google Analytics with a consent choice, calling and contacts data, service providers, storage location, retention periods, and your rights and how to exercise them. |
| 2.3 | June 17, 2026 | Updated billing data, AI agent and telephony logging terms. |