Privacy Policy

Last updated: October 4, 2026

Introduction

KlayPod ("we," "our," or "us"), operated by Kartik Vyas as an individual developer, is committed to protecting your privacy. This Privacy Policy explains how your personal information is collected, used, and disclosed by KlayPod.

This Privacy Policy applies to our website, and its associated subdomains (collectively, our "Service") alongside our application, KlayPod. By accessing or using our Service, you signify that you have read, understood, and agree to our collection, storage, use, and disclosure of your personal information as described in this Privacy Policy and our Terms of Service.

Jira and Confluence (Atlassian) data

When an organization admin connects Jira or Confluence, we store: the Atlassian site name and address; the connecting admin's Atlassian account ID and email; Atlassian account IDs, display names and emails of Jira users so they can be matched to KlayPod members; and synced issue content (titles, descriptions, statuses, comments and their author names). Access tokens are stored encrypted and never shown in the browser.

We use this data only to sync work between Jira/Confluence and KlayPod for that organization. We never sell it or use it for advertising.

Every week we report the Atlassian accounts we hold to Atlassian's Personal Data Reporting API. When Atlassian tells us an account is closed, we erase that person's name and email and show "Former user" instead. When an organization disconnects Jira or Confluence, we delete the stored Atlassian names and emails for that connection within 24 hours; the KlayPod tasks remain.

To ask for deletion of your data, email kartik.dvyas@gmail.com from the address on your account. We respond within 30 days.

Google User Data

KlayPod integrates with Google services (Google Calendar, Google Drive, Google Sheets, Google Docs, and Google Sign-In) to provide our AI meeting note-taker and export features. When you connect your Google account, we request access to specific data using the following OAuth scopes:

  • openid, userinfo.email: To authenticate you and identify your account by your primary Google email address.
  • https://www.googleapis.com/auth/calendar.events: To read your upcoming calendar events so we can display them in the "Upcoming Meetings" dashboard, detect video conference links (Google Meet, Zoom, Microsoft Teams), and allow our AI note-taker bot to auto-join meetings you have enabled auto-join for.
  • https://www.googleapis.com/auth/drive.file: To create new Google Sheets and Google Docs in your Drive when you choose "Export in a new Sheet/Doc", and to read or update only those individual files that you explicitly select through the Google Picker. KlayPod never requests broad access to your Drive, Sheets or Docs — it can only see the specific files it created or that you picked.

KlayPod does not request the restricted or sensitive scopes drive.readonly, drive, documents, or spreadsheets. All Docs and Sheets functionality (reading an open document, answering questions in it, exporting tasks and meeting notes, and two-way sheet sync) operates entirely under the per-file drive.file scope, granted file-by-file by the user through the Google Picker.

How we use Google user data

  • Display your upcoming meetings inside KlayPod.
  • Detect video conference links so our note-taker can join at the scheduled time when you opt in.
  • Store the meeting title, start/end time, and conference link for meetings you elect to record, so we can join and label the recording correctly.
  • Write your projects, tasks, and meeting notes into the Google Sheets or Google Docs you explicitly choose to export to, and read back edits in synced sheets to keep both sides up to date.
  • Create new spreadsheets or documents in your Drive only when you request an export. We never browse, read, or modify other files in your Drive.

How we store and protect Google user data

  • OAuth access and refresh tokens are stored encrypted at rest in our secure database (Supabase) and are never exposed to the client browser.
  • Calendar event data is read live from Google and cached only briefly (up to 7 days) to power the Upcoming Meetings view.
  • All traffic between your browser, our servers, and Google is transmitted over HTTPS/TLS.

How we share Google user data

We do not sell, rent, or share Google user data with third parties for advertising or marketing purposes. We share limited data only with the following subprocessors strictly to deliver the Service you requested:

  • Recall.ai — receives the meeting join URL and title so the note-taker bot can join and record the meeting you enabled.
  • OpenAI / Google Gemini — receive meeting transcripts to generate summaries and action items. Providers are contractually prohibited from using this data to train their models.
  • Supabase — hosts our encrypted database and authentication service.
  • Resend — sends transactional email (reminders, notifications).

Google API Services Limited Use Disclosure

KlayPod's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use Google user data to provide or improve user-facing features that are prominent in the KlayPod interface.
  • We do not transfer Google user data to third parties except as necessary to provide or improve those features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
  • We do not use Google user data for serving advertisements.
  • We do not allow humans to read Google user data unless we have your affirmative agreement for specific messages, doing so is necessary for security purposes (such as investigating abuse), to comply with applicable law, or for internal operations where the data has been aggregated and anonymized.

Revoking access and deleting Google user data

You can disconnect your Google account at any time from Settings → Calendars in KlayPod, which deletes the stored OAuth tokens and cached calendar data. You can also revoke KlayPod's access directly from your Google Account permissions page. To request full deletion of all associated data, email kartik.dvyas@gmail.com.

Definitions and Key Terms

For this Privacy Policy:

  • Cookie: A small amount of data generated by a website and saved by your web browser. It is used to identify your browser, provide analytics, and remember information about you such as your language preference or login information.
  • Company: When this policy mentions "Company," "we," "us," or "our," it refers to KlayPod, that is responsible for your information under this Privacy Policy.
  • Country: Where KlayPod or the owners/founders of KlayPod are based, in this case is India.
  • Device: Any internet-connected device such as a phone, tablet, computer, or any other device that can be used to visit KlayPod and use the services.
  • Personal Data: Any information that directly, indirectly, or in connection with other information allows for the identification of a natural person.
  • Service: Refers to the application or the website or both.
  • Third-party service: Refers to advertisers, contest sponsors, promotional and marketing partners, and others who provide our content or whose products or services we think may interest you.
  • User: A person who uses our service. Users correspond to the subject of Personal Data.

Information We Collect

Our primary goals in collecting information are to provide and improve our Service, to administer your use of the Service, and to enable you to enjoy and easily navigate our Service.

Personal Data

While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you ("Personal Data"). Personally identifiable information may include, but is not limited to:

  • Email address
  • First name and last name
  • Usage Data

Usage Data

We may also collect information that your browser sends whenever you visit our Service or when you access the Service by or through any device ("Usage Data"). This Usage Data may include information such as your computer's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers, and other diagnostic data.

How We Use Your Information

We use the information we collect in various ways, including to:

  • Provide, operate, and maintain our Service
  • Improve, personalize, and expand our Service
  • Understand and analyze how you use our Service
  • Develop new products, services, features, and functionality
  • Communicate with you, either directly or through one of our partners, to provide you with updates and other information relating to the Service
  • Send you emails regarding your account or task management
  • Find and prevent fraud

What Data We Store

KlayPod processes and stores the following categories of data to deliver its features:

  • Audio notes: Audio files you record via push-to-talk or hands-free mode, stored in our private encrypted storage.
  • Meeting recordings: Video and audio from meetings joined by our AI note-taker bot. Video is downloaded from our recording provider (Recall.ai) and archived in our private storage after processing.
  • Transcripts: Full text transcripts of your audio notes and meeting recordings, stored as structured text in our database.
  • AI summaries and action items: Generated summaries, key points, and action items extracted from transcripts, stored in our database.
  • Tasks and projects: Your task lists, projects, long projects, and associated metadata (due dates, priorities, assignees).
  • Calendar data: Upcoming meeting titles, times, and conference links fetched from your connected Google Calendar.
  • Account data: Your email address, authentication tokens (encrypted), and workspace membership.

AI Training — Our Commitment

We never use your content to train AI models. Your recordings, transcripts, AI summaries, action items, tasks, and notes are used solely to deliver the features you requested — never to improve our models or anyone else's.

  • We do not train, fine-tune, or evaluate any AI model on your audio, video, transcripts, summaries, or notes.
  • Our AI vendors (OpenAI, Google Gemini) process your content under zero-data-retention terms: the content is used only to generate your response and is not retained by the vendor or used for their model training.
  • We do not sell, rent, or share your content with advertisers, data brokers, or third parties for any purpose other than delivering the Service.
  • Aggregate, non-content usage metrics (e.g., number of meetings, total minutes, storage used) may be used for billing, capacity planning, and product improvement — but never the content itself.

Data Retention — You Are in Control

You choose how long we keep your data, in Settings → Privacy. Separate retention windows can be set for media (audio/video), transcripts, and AI summaries — from 1 day up to "keep until I delete it."

  • Audio notes: Stored in our private encrypted storage and deleted after your retention window expires (default: 30 days). The audio file is removed from storage; the database row (with transcript and summary) is preserved.
  • Meeting video: Downloaded from our recording provider after processing and archived in our private storage. Deleted after your retention window expires (default: 30 days). The vendor's copy is purged within 24 hours of the call.
  • Transcripts: Kept indefinitely by default so you can always reference your notes. You can set a shorter retention window in Settings → Privacy.
  • AI summaries and action items: Kept indefinitely by default. You can set a shorter retention window or delete them at any time.
  • Immediate media deletion: You can enable "Delete media immediately after processing" to have audio and video removed the moment your transcript and summary are generated, retaining only the text.
  • Google Calendar event data: Read live from Google; cached only as long as needed to power the Upcoming Meetings view.
  • Account data: Retained while your account is active. Upon account deletion, all associated data — including audio, video, transcripts, and summaries — is purged within 30 days.

An automated daily purge job enforces your retention settings, removing expired files from both the database and file storage.

Administrator Access & Audit Log

Like every hosted service, our operations team holds server-level credentials that can technically reach stored content. We are transparent about this rather than claiming an encryption guarantee we cannot enforce.

  • Administrative access to customer content (audio, video, transcripts, summaries) is permitted only to operate the service or to resolve a support issue you have raised.
  • Every administrative access is written to an immutable audit log recording who accessed what data, when, and why.
  • You can read that log yourself at any time in Settings → Privacy. Entries cannot be edited or deleted from the application.
  • Our internal cost dashboard exposes usage counts only (number of meetings, total minutes, storage used) — never transcripts, summaries, audio, or notes.
  • We do not listen to your recordings, read your transcripts, or view your summaries unless you explicitly request support that requires it.

Data Storage and Security

We use Supabase as our database and authentication provider. Your data is stored securely on Supabase's servers, which may be located outside of India. Supabase implements industry-standard security measures to protect your information from unauthorized access, alteration, disclosure, or destruction.

OAuth tokens for third-party integrations (such as Google) are encrypted at rest. All traffic between your browser and our servers is transmitted over HTTPS/TLS.

We maintain appropriate administrative, technical, and physical safeguards to protect Personal Data. However, no method of transmission over the Internet or method of electronic storage is 100% secure.

Cookies

We use cookies and similar tracking technologies to track the activity on our Service and hold certain information. Cookies are files with a small amount of data which may include an anonymous unique identifier.

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.

Sub-processors

We engage third-party sub-processors to help deliver KlayPod. These sub-processors have access to customer data only to perform tasks on our behalf, are bound by written data-processing agreements with confidentiality and security obligations, and may not use the data for any other purpose (including training their own models).

Our current sub-processors are:

  • Supabase (AWS, US): Database, authentication, and encrypted file storage.
  • Recall.ai (US): Joins meetings, captures audio/video, and generates transcripts. Receives only the meeting join URL and title.
  • OpenAI (US): AI summarization, action-item extraction, and the voice assistant. Enterprise API with zero data retention — no training on customer data.
  • Google (Gemini, US): AI summarization, chat answers, and recommendations. Enterprise API with zero data retention — no training on customer data.
  • Sarvam AI (India): Optional multilingual transcription and summarization when selected by the workspace admin.
  • Resend (US): Transactional email delivery (reminders, invitations, notifications).
  • Slack Technologies (US): Message delivery for the KlayPod Slack app, where installed.
  • Google Workspace APIs (US): Calendar, Gmail, Docs, and Sheets access, only where the user has explicitly connected their account.
  • Lovable Cloud (US/EU): Application hosting and edge compute.

We notify customers by email at least 30 days before adding a new sub-processor that processes customer content. To subscribe to sub-processor change notices, email kartik.dvyas@gmail.com.

Large Language Model (LLM) Use

KlayPod exposes LLM-powered features to customers, including "Ask KlayPod," meeting summarization, action-item extraction, task recommendations, and the voice assistant.

Models used

OpenAI GPT-5 and GPT-5 mini; OpenAI Realtime (voice); Google Gemini 3 Flash and Gemini 3 Pro; Sarvam AI (optional, for Indic-language transcription and summarization). We do not train, fine-tune, or host our own models.

Data tenancy

KlayPod uses third-party, multi-tenant enterprise LLM APIs; we do not operate a self-hosted model. Every request is scoped to a single workspace: prompts are assembled server-side from that workspace's data only, enforced by row-level security. Customer content is never used to train or improve any vendor's models, is not shared between customers, and is not pooled into any shared index. No customer data is embedded into model weights.

Data residency

Customer data at rest is stored in our Supabase/AWS environment in the United States. LLM inference requests are processed in the United States by OpenAI and Google. Where Sarvam AI is enabled by a workspace admin, those requests are processed in India. Prompts are transmitted over TLS 1.2+ and are not stored by the vendor after the response is returned.

LLM retention settings

Our LLM providers are configured for zero data retention: prompts and completions are processed in memory to generate the response and are not retained for abuse monitoring, human review, or training. KlayPod stores the resulting outputs (summaries, action items, chat answers) in the customer's workspace, subject to the retention windows the customer configures in Settings → Privacy, and deletes them on request or on account deletion within 30 days.

Service Providers

We may employ third-party companies and individuals due to the following reasons:

  • To facilitate our Service;
  • To provide the Service on our behalf;
  • To perform Service-related services; or
  • To assist us in analyzing how our Service is used.

These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

Do Not Track

Please note that we do not alter our Site's data collection and use practices when we see a Do Not Track signal from your browser.

Your Data Protection Rights

Depending on your location and applicable laws, you may have the following rights regarding your personal data:

  • Right to Access: You have the right to request copies of your personal data.
  • Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
  • Right to Erasure: You have the right to request that we erase your personal data, under certain conditions.
  • Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
  • Right to Object to Processing: You have the right to object to our processing of your personal data, under certain conditions.
  • Right to Data Portability: You have the right to request that we transfer the data we've collected to another organization, or directly to you, under certain conditions.

If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us at kartik.dvyas@gmail.com.

Children's Privacy

Our Service does not address anyone under the age of 18 ("Children"). We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your Child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact Us

If you have any questions about this Privacy Policy or wish to request data deletion, please contact us at kartik.dvyas@gmail.com.