See what Groundnote controls, what you configure, and where data can go.
Groundnote is self-hosted software. This document distinguishes built product controls, deployment responsibilities, optional external providers, tested operating procedures, and current limitations.
Document control
Owner: Groundnote · Effective: 4 September 2026 · Last reviewed: 4 September 2026 · Next scheduled review: 4 December 2026
Change history: Version 1.0 publishes the initial deployment, provider, data-flow, backup, incident-response, and feature-status account.
Data-flow overview
1. Capture
Recording, upload, pasted transcript, Microsoft Graph import, or configured Recall.ai bot.
2. Process
Local transcription and Ollama can keep processing inside the deployment. Configured cloud providers create egress.
3. Store and review
SQLite or PostgreSQL stores records under operator-controlled infrastructure and access settings.
4. Connect
Users may send selected outcomes through webhooks, SMTP, work trackers, calendar, or other enabled services.
Text equivalent: Meeting content first enters a customer-operated Groundnote instance. Local processing paths are available. If an operator enables an external capture, transcription, AI, calendar, notification, email, billing, or work-tracking service, the selected data leaves the deployment for that provider. Groundnote stores and presents the resulting records, while users review outcomes and initiate supported outbound actions.
Hosting and storage responsibilities
| Component | Groundnote provides | Operator is responsible for |
|---|---|---|
| Application | Self-hosted web server and desktop application options | Host security, updates, availability, capacity, and network controls |
| Transport | Application endpoints | TLS termination and reverse-proxy configuration |
| Database | SQLite default or PostgreSQL configuration | Storage location, access, backup, restore, and infrastructure encryption |
| Fortress profile | PostgreSQL, local Whisper, local Ollama, and cloud-transcription refusal configuration | Explicit deployment and verification; it is not the default mode |
| Desktop | Windows and macOS application builds | Endpoint security and acceptance of current unsigned-build warnings |
Groundnote does not currently publish a high-availability or clustered deployment claim. Bring-your-own cloud object storage is excluded from this public matrix until end-to-end support is verified.
AI model and processing matrix
| Provider | Path | Data and responsibility |
|---|---|---|
| Ollama | Local analysis | Prompts and outputs stay on operator infrastructure when Ollama is local. |
| Local Whisper | Local transcription | Audio is processed by the installed local binary and model. |
| OpenAI | Optional cloud analysis or transcription | Selected content leaves the deployment under the customer's account and provider terms. |
| Anthropic | Optional cloud analysis | Selected prompts leave the deployment under the customer's account and provider terms. |
| Google Gemini | Optional cloud analysis | Selected prompts leave the deployment under the customer's account and provider terms. |
| AWS Bedrock | Optional cloud analysis | Selected prompts use the customer's AWS configuration, region, and provider terms. |
Customer-data training statement: Groundnote does not currently publish a contractual promise covering every configured provider's model-training behavior. Local models avoid external AI-provider transfer. For cloud providers, customers must review and configure the provider account, product terms, retention, and data-use controls appropriate to their deployment.
External provider register
| Provider or service | Purpose and data | Optionality and caveat |
|---|---|---|
| Microsoft Graph | User identity, calendar events, meeting metadata, and available Teams transcripts | Optional per-user OAuth; transcript permissions may require tenant approval. |
| Google Calendar | Calendar events and meeting context | Optional per-user OAuth; no direct transcript import. |
| Recall.ai | Meeting URL, bot configuration, capture, and processed transcript | Optional external bot; provider region and terms apply. |
| Slack or Teams webhooks | Selected meeting digest | Optional outbound notification to a configured webhook. |
| Jira, Asana, Linear, ClickUp | Selected task details and returned external reference | Optional outbound work tracking; capabilities vary by connector. |
| SMTP server | Selected outbound email content and recipients | Optional; operator supplies and governs the mail service. |
| Stripe | Subscription and payment-related data | Optional billing configuration; not required for core self-hosted use. |
| Hugging Face | Model download credentials for optional diarization | Optional model acquisition path; meeting content need not be sent for inference. |
Processing region, retention, and subprocessor details can vary with customer-selected accounts and provider configuration. Request the current deployment-specific data-flow review before procurement.
Backup, recovery, and incidents
Groundnote includes deployment and scheduled backup scripts for the documented production pattern. The restore runbook validates backup contents, stops the application, replaces data, restarts services, and verifies application identity and health. Actual recovery point depends on the operator's backup schedule; actual recovery time depends on infrastructure, data size, and testing.
Health endpoints, a public status view, application error logs, and hash-chained audit records support operational review. Operators remain responsible for monitoring, escalation, incident handling, notification duties, and credential rotation in their environment. Suspected Groundnote vulnerabilities can be reported through support@groundnote.com.au without including secrets or private meeting content in the initial message.
Feature-status legend
- Available: implemented and suitable for current product description.
- Requires configuration: implemented, but an operator, account, credential, provider, or deployment setting is needed.
- Beta or verification pending: implemented code exists, but production workflow testing or assurance is incomplete.
- Planned: not available and not suitable for current capability claims.
Available: source-linked outcomes, confidence states, hash-chained audit records, legal hold, retention controls.
Requires configuration: OIDC, MFA per account, cloud AI, local Whisper, Recall.ai, webhooks, SMTP, calendars, work trackers, fortress profile, SQLite encryption.
Beta or verification pending: evidence attachments, approval workflow, timeline and audit-pack UI, live identity-provider testing.
Planned or unavailable: SCIM auto-deprovisioning, organisation-enforced MFA, independent certification, and public high-availability architecture.
Assurance limitations
Groundnote is not SOC 2 certified, ISO 27001 certified, HIPAA certified, or independently penetration-tested as of this review. Controls do not make a customer deployment compliant by themselves. Verify product behavior, infrastructure, contracts, provider terms, and operating procedures against your requirements.