Privacy Policy
Select your launch country to view the matching country-specific privacy and terms references.
Select your launch country
If you have not signed up yet, choose your launch country to view the matching policy context.
1. Data We Collect
This policy applies to account holders, website visitors, and people who participate in a meeting recorded or processed by Chai. Personal data means information that identifies, relates to, describes, or can reasonably be linked to a person. Meeting audio and a person's voice may be personal data even when a name or other obvious identifier has been removed.
Account data: email address, name, identity provider identifiers, country selection, locale, transcript language, consent timestamp, and accepted terms version.
Calendar and meeting data: connected provider, calendar email, meeting titles, URLs, start and end times, platform, participants, Recall bot identifiers, transcript text, audio file metadata, object storage keys, and user controls.
Product analytics data: page views, interaction events, agent question text and generation metadata, session replay metadata, device/browser metadata, and approximate location derived from network information.
Meeting content may include personal, sensitive, confidential, privileged, or proprietary information supplied by users and participants. We collect information from account holders and participants, from connected identity, calendar, conferencing, and collaboration services, automatically from use of Chai, and from service providers that help us operate and secure the product.
2. Google User Data
When you connect Google Calendar, Chai collects and processes only the Google user data needed to provide the calendar-connected recording features: Google account email, OAuth tokens, calendar connection identifiers, meeting titles, meeting URLs, start and end times, platform details, and participant or attendee metadata needed to identify meetings.
Chai uses Google user data only to connect your calendar, find meetings you asked Chai to record, schedule visible meeting bots, show meeting records, support calendar disconnect, deletion, and export requests, maintain security, debug service issues, and improve user-facing calendar and recording functionality.
The use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
Chai does not sell, license, transfer, disclose, or make Google user data available to third parties for advertising, data brokerage, information resale, credit or lending decisions, unrelated analytics, third-party AI model training, or dataset licensing.
Service providers may process Google user data only as needed to operate or improve Chai's user-facing features, under Chai's instructions. These providers include infrastructure, calendar, hosting, database, security, analytics, and error-monitoring processors used to run the product.
3. How We Use Data, AI, and Derived Data
We use data to authenticate users; connect calendars and integrations; schedule and operate visible meeting bots; record, transcribe, separate speakers, summarize, search, analyze, and play back meetings; answer questions; generate requested outputs; communicate with users and participants; provide support; process rights requests; secure and monitor the service; prevent abuse; comply with law; and establish, exercise, or defend legal claims.
Subject to applicable law, required notice or consent, user controls, and our contracts, we may use eligible meeting content and other data to research, develop, test, evaluate, improve, customize, market, and commercialize Chai and related products and services; create annotations, labels, features, embeddings, statistics, benchmarks, datasets, and other derived information; and train, fine-tune, test, or evaluate artificial-intelligence and machine-learning systems. A provider that processes personal data for these purposes must act on Chai's instructions and may not use it for an independent purpose unless the affected person separately authorizes that use.
We may retain and use aggregated or deidentified information for any lawful purpose, including research, analytics, product development, AI training and evaluation, and commercialization, and may retain it for as long as it remains deidentified. We do not use meeting content to make decisions that produce legal or similarly significant effects about participants.
For Arabic, Hindi, and Urdu transcription, Chai requests Deepgram transcription through Recall.ai using the Deepgram credential configured in Recall.
4. Storage and Security
Chai uses a visible meeting bot and may provide in-meeting text, visual, or other recording notices. Recording and consent laws vary. Account holders must use Chai only when authorized, give all notices required by law or agreement, and obtain any required consent from every participant before recording or secondary processing begins. Chai-provided notices supplement, but do not replace, the account holder's obligations.
Where Chai intends to use meeting content for AI training or derive data for licensing or sale, Chai will provide or require clear notice of that secondary use and an opportunity to decline where required. Chai will obtain affirmative consent from each participant when applicable law requires it. This Privacy Policy is a disclosure of practices and does not by itself constitute a participant's consent or grant rights the account holder does not have.
Meeting audio and transcript files are stored in Cloudflare R2. R2 storage region: Cloudflare R2 automatic global storage region for this deployment. The app uses signed URLs for playback and does not make the R2 bucket public.
The source Recall audio artifact is stored as raw bytes without decode, resample, transcode, normalization, or re-encoding. Stored audio rows include checksum metadata when ingestion verifies the object.
We use administrative, technical, and organizational safeguards designed to protect information. No method of storage or transmission is completely secure, and we cannot guarantee absolute security. Information may be processed in the United States and other countries where Chai or its providers operate, using legally required transfer safeguards where applicable.
5. Personal Data Sales, Deidentified Data, and Sharing
Chai does not sell or license meeting content that remains personal data, or direct identifiers, to third parties for their independent use. This restriction includes raw or reasonably identifiable voice recordings, transcripts containing personal data, participant identities, contact information, and data that a recipient could reasonably link to a person. Removing direct identifiers alone does not make audio or a transcript deidentified.
Chai may disclose, license, sell, or otherwise commercialize aggregated or deidentified data—including eligible audio, transcripts, annotations, labels, statistics, benchmarks, datasets, and derived information—for any lawful purpose, including third-party AI model training, testing, evaluation, research, and product development. Eligibility is subject to applicable consent, deletion, exclusion, opt-out, and export checks. We treat data as deidentified only when it cannot reasonably be used to identify or be linked to a person under applicable law.
When Chai relies on deidentification, Chai will take reasonable measures to prevent identification, publicly commit not to attempt to reidentify the data, and require recipients by contract not to reidentify it or combine it with other information to identify a person. Eligible commercial data excludes Google user data and data derived from Google API scopes, including Google account email, OAuth tokens, Google Calendar event metadata, meeting URLs, event titles, attendees, and calendar-derived records.
We disclose personal data to providers that operate the product, including WorkOS, Supabase, Recall.ai, Deepgram through Recall, Cloudflare R2, Groq, PostHog, Sentry, Vercel, Resend, and connected identity, calendar, conferencing, and collaboration providers. They may process personal data only to provide contracted services, under Chai's instructions and applicable restrictions.
We may also disclose data at your direction; to authorized users or meeting participants as part of the service; to comply with law or valid legal process; to investigate fraud, abuse, security incidents, or threats to rights and safety; to enforce agreements or protect legal claims; and in connection with a financing, merger, acquisition, reorganization, or sale of assets, subject to applicable confidentiality and notice requirements.
6. Choices, Retention, and Rights
You can exclude meetings from future licensing eligibility, delete recordings, disconnect calendars, export available data, change available AI-training choices, request participant deletion at /remove-me, withdraw consent, or delete your account from settings. Depending on where you live, you may also have rights to access, correct, delete, or obtain a portable copy of personal data; object to or restrict certain processing; opt out of a qualifying sale, sharing, targeted advertising, or profiling; and appeal a denied request.
We retain personal data for as long as reasonably necessary for the purposes described here, including providing the service, maintaining security, resolving disputes, complying with law, and enforcing agreements. Disconnecting a calendar stops future access but does not itself delete existing meeting content. Deletion removes available Chai-controlled personal data through active deletion workflows, subject to limited backups, security and consent records, legal holds, and other lawful exceptions.
A deletion, exclusion, opt-out, or withdrawal applies to personal data and future uses under Chai's control. It may not apply to data that was already lawfully deidentified so it can no longer reasonably be linked to a person, to aggregated results, or to models and other derived outputs that do not contain personal data, unless applicable law requires otherwise.
We may verify identity, meeting participation, and an agent's authority before completing a request. Chai will not discriminate against a person for exercising an applicable privacy right. Questions, requests, appeals, recording objections, or Grievance Officer notices can be sent to hello@meetingchai.com.
7. Cookies, Analytics, and Advertising
Chai uses necessary cookies and local storage for authentication, security, language, time zone, consent, and core service operation. With your consent where required, Chai also uses measurement technologies such as PostHog and marketing technologies such as Google Ads and OpenAI Ads. You can accept, reject, or later change nonessential categories through Privacy settings.
Marketing and measurement partners may receive limited website and conversion data, such as cookie identifiers, page activity, registration completion, or calendar-connection completion. Some laws may call this targeted advertising, sharing, or a sale. Chai does not disclose meeting content, calendar event contents, OAuth tokens, or Google user data for advertising.
8. Children, Biometrics, Policy Changes, and Contact
Chai is not directed to children under 13, and users must not use Chai to record children or collect sensitive or regulated information unless they have all authority, notices, consents, and safeguards required by law.
Chai does not currently create voiceprints or facial templates to identify or verify a person through biometric recognition. Transcription, speaker labeling, and separating participant audio are used to organize meeting content, not to establish biometric identity. Before materially changing these practices, Chai will update this policy and provide any notice or obtain any consent required by law.
We may update this policy to reflect changes in the service, law, or our practices. We will update the date on this page and provide additional notice or obtain consent when required for a material change. Questions, privacy requests, recording objections, and security reports may be sent to hello@meetingchai.com.