Privacy Policy
Effective date: September 28, 2026
1. Overview
Greg is an AI meeting notetaker (“we”, “us”). This policy explains what data we collect when you use Greg, how we use it, who processes it on our behalf, and the choices you have. For anything not covered here, contact hello@getgreg.io.
2. Data we collect
- Account data — your email address, name, and password (stored hashed).
- Meeting content — meeting audio captured by the notetaker bot or uploaded by you, the transcripts produced from it, and the AI-generated summaries, action items, and analysis derived from those transcripts.
- Calendar metadata — if you connect Google Calendar: event titles, times, attendee lists, and meeting links, used to schedule the bot.
- Usage and billing data — credit consumption, plan information, and basic product usage needed to operate and improve the Service.
3. How we use data
We use your data to provide the Service: joining and recording the meetings you choose, transcribing them, generating summaries, delivering notifications, syncing notes to integrations you connect, and billing. We do not sell your personal data or your meeting content, and we do not use your meeting content to train Greg's own models. Whether a subprocessor trains on data sent to its API depends on that provider's terms and account configuration. Those terms are not certified on this page. A control-by-control description for security review is at /security.
4. Subprocessors
We use a small set of service providers to deliver specific parts of the product. Each receives only the data needed for its function:
- Recall.ai — meeting bots that join Google Meet, Zoom, and Microsoft Teams, and transcription of those bot recordings.
- AssemblyAI — speech-to-text for uploaded and browser-recorded audio. Not used for bot meetings.
- OpenRouter — primary path for summaries, extraction, and the assistant. The default model is DeepSeek, reached through OpenRouter.
- Anthropic — fallback when OpenRouter is unavailable, and a pinned path for a Claude re-run. A workspace admin can turn this fallback off.
- OpenAI — when a workspace stores its own key, or when that workspace and the process both leave the platform task router on. An admin can turn the platform router off.
- Google Gemini — embeddings for search, and realtime voice, unless an admin turns Gemini off for the workspace. Not used for summaries.
- Twilio — SMS, WhatsApp, and phone calls when those channels are turned on.
- Stripe — payment processing. We never store your full card details.
- Resend — transactional email, such as meeting-summary notifications.
- Google APIs — calendar, and Gmail when those scopes were granted. Our use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Microsoft — Outlook calendar and mail when a member connects Microsoft 365. Sign-in is a separate grant.
5. Storage and retention
Meetings stay in the workspace until someone deletes them, unless an admin sets a retention period in Settings → Security. That purge removes the meeting, its local audio, and its search index from Greg, and asks Recall.ai and AssemblyAI to delete their copies when Greg has an id for that copy. A missing id is recorded as unavailable. A restored backup can contain a meeting deleted after the snapshot until the deletion ledger is reapplied. Public clip links expire (30 days unless an admin changes that, or turns off external sharing). Deleting your account from Settings → Account removes you and returns deletion job ids. If you are the only member, it also removes the workspace's meetings from Greg. If you share a workspace, your private meetings are removed and the workspace's other meetings stay. If you cannot sign in, email hello@getgreg.io.
6. Sharing
We share data only with the subprocessors listed above, with integrations you explicitly connect (such as your CRM, Slack, Asana, Google Docs, or Zapier), within your own workspace, and where required by law. We never sell your data.
7. Security
Traffic uses HTTPS. Session cookies are httpOnly and, in production, Secure. Provider tokens stored by Greg are encrypted with AES-256-GCM when the credential encryption key is configured; production refuses to start without that key and without a separate backup encryption key. Meeting audio and transcripts are not encrypted by the application itself. Backup archives produced by the backup script are. Greg is not SOC 2, ISO 27001, or HIPAA certified. If we learn of a breach affecting your data, we will notify you as required by law. Details are on the security page.
8. Your rights
You can access and export your meeting content from within the product, and correct your account details in settings. Delete your account from Settings → Account on the website or in the iOS app. To exercise other access or correction rights — or to ask any privacy question — email hello@getgreg.io. Depending on where you live, you may have additional rights under local law (such as the GDPR or CCPA), and we will honor valid requests.
9. Cookies
Greg uses a single session cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.
10. Changes to this policy
If we make material changes to this policy, we will notify you by email or an in-app notice before the changes take effect. The effective date at the top of this page always reflects the current version.