# Unifies Privacy Policy Canonical: https://unifies.ai/privacy **Effective date:** September 2, 2026 This Privacy Policy explains how **Unifies AI, Inc.** ("**Unifies**", "we", "us"), a Delaware corporation, collects, uses, and protects personal data. Unifies plays two roles: - **Processor** for content processed on behalf of our business customers — meeting transcripts, analysis derived from them, workspace member records imported from connected tools, and per-person execution records. For that content, the customer that runs the workspace is the controller, and our Data Processing Addendum at unifies.ai/dpa governs. If you are a meeting participant or workspace member and want to exercise rights over that content, Section 8 explains the route. - **Controller** for our own operations — accounts, sign-in, billing, support, telemetry, and website visits. ## 1. Data we process ### 1.1 Account data (we are the controller) - Name, work email, profile photo, timezone, and OAuth identifiers from your sign-in provider. **Signing in with Google currently requests calendar access (used for meeting-scheduling features) together with your profile and email.** - Sign-in and session records: one-time code challenges, session tokens (stored hashed), device information, and IP address. - Billing contact details (name, email) and subscription state. **Payment-card details are collected and held by Stripe; they never reach Unifies systems.** - Support and legal correspondence you send us. - The version of the Terms of Service you accepted by signing in, and when you first accepted it. ### 1.2 Customer workspace content (we are the processor) - **Meeting transcripts**: when a workspace directs our bot into a meeting, it transcribes the conversation as it happens — participants' names, speaker labels, and what is said. **We store no audio or video of a meeting**; our capture provider processes the audio only to produce the transcript (see the subprocessors page). - **Derived analysis**: summaries, decisions, commitments with source quotes and timestamps, speaker attributions, task drafts, and receipts. - **Workspace member records** imported from the project tool an admin connects: names, email addresses, avatars, and roles — including for people who have not signed up to Unifies. - **Calendar and scheduling data** for meetings scheduled through Unifies, including attendee email addresses. - **Forwarded and connected messages**: where your workspace uses capture sources beyond meetings (such as forwarding an email to its workspace capture address), the forwarded content — sender, subject, and message body — is processed the same way as meeting content. - **Connected-account credentials**: OAuth tokens for services the workspace connects, stored encrypted at the application layer. ### 1.3 Per-person execution records (we are the processor) Unifies derives, for each workspace member, a record of the commitments attributed to them and a follow-through standing computed from those commitments. - **Purpose:** showing a workspace its own follow-through, per person, with source evidence attached. - **Inputs:** AI speaker attribution over meeting transcripts, task deliveries into the workspace's project tool, and the completion status that tool reports back. - **Visibility:** the person themselves, workspace owners and admins, and the person's manager where configured. No standing is shown below a minimum evidence sample. - **Human review:** every number opens into its source receipts; attributions can be contested on any receipt and reassigned by a workspace admin. Unifies makes no automated decisions about employment; how the employer uses these records is the employer's responsibility as controller. ### 1.4 Telemetry and diagnostics (we are the controller) - **First-party product events**: we record counts of product actions (for example, "a receipt was shared" or "an invite was sent") tied to your account, sent only to our own servers. This is operational telemetry, not third-party analytics. - **Product analytics (PostHog)**: disabled unless you opt in through the cookie banner, and only active if we have enabled the analytics integration in the product. Events carry identifiers and metadata, never transcript or message text. - **Error monitoring (Sentry)**: if enabled in the product, error reports are scrubbed of tokens and sensitive fields before transmission, and any session-replay capability will remain off or consent-gated. See the Cookie Policy at unifies.ai/cookies for the current state of both integrations. - Standard server logs (requests, timestamps, status codes) for security and debugging. - **Shared-link views**: when someone opens a receipt link you shared or a verification page, we increment that link's view count and record the time of the latest view. We do not record who opened it. ### 1.5 Website inquiries and waitlist (we are the controller) - **Waitlist**: if you join the waitlist on unifies.ai, we store your email address, the page you joined from, the time, the integration you asked for (if you named one), and the IP address the request came from, which we keep for abuse prevention. We use this to send you one email when the product opens and, if you asked for an integration, one when it lands. Every waitlist email carries an unsubscribe link. - **Contact form**: messages sent through unifies.ai/contact — your name, email address, and message, with the request IP address — are stored so we can reply, and are forwarded to the founder's mailbox. ## 2. Sources We collect personal data: directly from you (sign-up, settings, support, the waitlist and contact forms); from your workspace's admins and members (invites, meeting scheduling); from meetings our bot is directed into; from third-party services your workspace connects (sign-in providers, calendars, meeting platforms, project tools); and from payment processing (Stripe). ## 3. Purposes and legal bases Where the GDPR or UK GDPR applies and we act as controller: | Purpose | Legal basis | |---|---| | Providing and administering accounts, workspaces, and billing | Contract (Art. 6(1)(b)) | | Securing the Service (session control, abuse and fraud prevention, audit logging) | Legitimate interests (Art. 6(1)(f)) — keeping the Service and its records secure | | Account email: sign-in codes, invitations, product notifications and the weekly digest (notification and digest emails are on by default, with opt-outs in Settings) | Contract; legitimate interests — keeping you informed about your own workspace | | First-party product telemetry and debugging | Legitimate interests — operating and improving the Service | | Optional product analytics | Consent (cookie banner) | | Support and legal correspondence | Legitimate interests; legal obligation | | Waitlist: one email when the product opens, and one about an integration you asked for | Consent (joining the list); withdraw by unsubscribing | | Contact-form inquiries | Legitimate interests — answering the people who write to us | | Tax, accounting, and legal compliance | Legal obligation | Meeting recap emails and similar messages that carry workspace content are sent as part of the Service on your workspace's behalf (processor role). For workspace content we process as a processor, we act on the documented instructions of the customer (given through the Service's controls), and the customer is responsible for its own legal basis — including the basis for recording meetings. ## 4. Meeting-recording transparency Our bot joins a meeting only when a workspace directs it there (by scheduling a meeting in Unifies or pasting a meeting link). It appears in the meeting platform's participant list while present. **Its display name is the meeting title chosen by the organizer followed by "— Unifies", and where the platform allows it (Google Meet, Zoom, Microsoft Teams) the bot posts a chat message on joining saying it is transcribing at the organizer's request; the bot does not announce itself by voice.** The workspace customer is responsible for notifying participants and obtaining any consents required in their jurisdictions; participants who do not consent should raise it with the meeting organizer or leave the meeting. ## 5. Disclosures of personal data We disclose personal data only to: - **Subprocessors** that help us run the Service — hosting (Google Cloud), meeting capture and transcription (Recall.ai), AI analysis (OpenAI), email delivery (Resend), and payments (Stripe). The current list, with the categories each receives and its region, is maintained at unifies.ai/subprocessors. - **Services your workspace connects**, at your workspace's direction — for example, task fields written into ClickUp or Linear, or calendar events created in Google Calendar. Those providers are independent of Unifies. - **Recipients you choose**, when you share a receipt link, send an invite, or configure outbound webhooks. At your workspace's direction, meeting recap emails containing the meeting summary and action items are sent to the meeting owner and the active members of its space. - **Professional advisers, and authorities where required by law.** If we receive a law-enforcement demand for customer workspace content, we will redirect the requester to the customer and notify the customer unless legally prohibited. - **A successor entity** in a merger, acquisition, or asset sale, under confidentiality obligations and with notice. **We do not sell personal information, and we do not share it for cross-context behavioral advertising.** We load no third-party advertising or tracking scripts. ## 6. International transfers The Service is operated from, and offered in, the **United States**; personal data is processed and stored in the United States (Google Cloud, us-central1 region). Where we collect personal data directly from you, that collection is not an onward transfer. Where our customers transfer personal data to us from the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (incorporated into our DPA), the UK International Data Transfer Addendum, and Swiss adaptations, together with the technical and organizational measures described in the DPA. A copy of the applicable clauses is available via the DPA at unifies.ai/dpa. ## 7. Retention | Data | Retention | |---|---| | Meeting transcripts and derived search embeddings | Per your workspace's retention window (default 365 days, minimum 30), then automatically deleted daily. | | Meeting audio and video | Not stored. The bot transcribes in real time; no recording is made. | | Sign-in IP addresses on sessions | Removed after 90 days. | | Archived assistant/chat threads | Deleted 30 days after archiving. | | Account data | For the life of the account; deleted through the account-deletion flow (Section 8). | | Workspace content after workspace closure | Held 30 days (so the workspace can be reopened or exported), then permanently purged. | | Billing and tax records | As required by law. | | Waitlist signups | Until you unsubscribe or ask us to delete them; an unsubscribed address is kept only as a suppression record so we do not email it again. The request IP address stays with the row. | | Contact-form messages | Until you ask us to delete them. | | Security audit log | For the life of the workspace, to preserve the tamper-evident chain. | | Database backups | Expire on a rolling schedule (currently up to 7 daily snapshots plus a point-in-time-recovery log window). Deletions reach live systems through the deletion flows described in this policy and age out of backups as that schedule elapses. | ## 8. Your rights If you are in the EEA, the UK, or a US state with a comprehensive privacy law (including California, Virginia, Colorado, Connecticut, and Utah), you have rights over your personal data — access, correction, deletion, portability, objection/restriction, and the right not to face discrimination for exercising them. We honor these rights as follows: - **Access / portability.** Request an export in **Settings → You → Account & security**; when it is ready we notify you by email and you download the archive from the same Settings screen (single-use link, expires 24 hours after issuance). - **Erasure.** **Settings → You → Account & security → Delete account** erases the transcripts and search embeddings of meetings your account created, removes your sessions and connected accounts, and deletes your profile. Receipts that documented your workspace's work remain with the workspace, with your name replaced by "Deleted user"; audit-log entries are pseudonymized (your email is replaced with a hash) to preserve the log's integrity. What you said in other meetings in your workspace may remain in their transcripts, which your workspace controls and can delete. We also instruct our subprocessors to delete residual copies they hold for us. We confirm completion by email. - **Correction.** Edit your name, photo, and timezone in **Settings → You → Profile**; contest a commitment attribution on the receipt itself. - **Objection / restriction, and anything else:** email **legal@unifies.ai**. We respond within the time applicable law requires; if we deny a request, you may appeal by replying to our response, and a different person will review the appeal. - **Automated decision-making.** Unifies makes no solely automated decisions about you that produce legal or similarly significant effects. Automatic task creation can be disabled per workspace by an admin (Workspace settings). - **Complaints.** You may lodge a complaint with your supervisory authority (EEA/UK) or state attorney general (US). **Right to object, stated separately (GDPR Art. 21):** where we process your personal data on legitimate interests, you may object at any time on grounds relating to your particular situation, and we will stop unless we demonstrate compelling legitimate grounds. Where processing is based on consent (analytics), you may withdraw consent at any time — via the cookie banner or the "Manage cookie preferences" control in the footer of our legal pages — without affecting processing before withdrawal. **Meeting participants and workspace members in a customer's workspace:** for content we process on a customer's behalf, please direct your request to that customer (the workspace's owner/admins) — they control it, and we assist them as processor. If you contact us directly, we will acknowledge your request and forward it to the customer. **Managing email.** Product-notification and weekly-digest emails are on by default and can be turned off in **Settings → You → Notifications**. Sign-in codes, security notices, and billing receipts are service messages that accompany an active account. We do not send marketing email to account holders. If you joined the waitlist, you will receive one email when the product opens (and, if you asked for an integration, one when it lands); every waitlist email carries an unsubscribe link. **California and other US state privacy notice.** In the last 12 months we have collected these categories of personal information (sources: Section 2; purposes: Section 3; disclosures: Section 5, to service providers only): **identifiers** (name, email, account identifiers); **commercial information** (subscription and billing records); **internet or other electronic activity** (product events, logs, device/session data); **audio information** (meeting speech, held only as transcripts — collected at the direction of our business customers); **professional information** (workspace role and work records such as commitments and standings). We do **not** sell personal information or share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months; we use sensitive personal information (such as the contents of communications) only to provide the Service, consistent with CCPA regulations. We do not use or disclose personal information for purposes incompatible with this policy, and we do not discriminate for exercising rights. To exercise California/state rights, use the in-product flows above or email legal@unifies.ai; we verify requests against your account email, and authorized agents may submit requests with proof of authorization. ## 9. Cookies and similar technologies We use a small set of first-party cookies and browser storage: essential cookies for sign-in and security, and — only if you opt in via the cookie banner — analytics. Details, including a full table and how to change your choice, are in the Cookie Policy at unifies.ai/cookies. ## 10. Security We protect personal data with measures that include TLS encryption in transit, encryption at rest with cloud-provider managed keys plus application-layer encryption for stored OAuth tokens, workspace-scoped authorization enforced and tested on the server, short-lived rotating sessions, hashed credentials, a tamper-evident hash-chained audit log verified daily, automated scrubbing of sensitive fields at telemetry egress points, and daily database backups with point-in-time recovery. Our security posture — including what we do **not** yet claim — is described at unifies.ai/security. No method of transmission or storage is completely secure. ## 11. Children Unifies is a business product not directed to children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact legal@unifies.ai. ## 12. Changes to this policy We may update this policy as the Service or the law changes. For material changes we will give at least 30 days' notice by email to workspace owners or in-product. The current version, with its effective date, is always at unifies.ai/privacy. ## 13. Contact **Unifies AI, Inc.** 131 Continental Dr, Suite 305, Newark, DE 19713, United States Privacy requests: **legal@unifies.ai** · Security: **security@unifies.ai** (see also unifies.ai/.well-known/security.txt) --- *© 2026 Unifies AI, Inc.*