KONVOO

LEGAL · PRIVACY

Privacy Policy

Konvoo sits in your meetings, so this document matters more than most. Here is exactly what we collect, who else touches it, what we do with anything we receive from Google, how long we hold it, and how to make us delete it.

Effective
30 August 2026
Last updated
30 August 2026
Applies to
konvoo.in and the Konvoo apps

The short version

Orientation only. The numbered sections below are the document, and where the two differ the sections govern.

  • 01

    Your meetings stay yours

    We do not sell your data and we do not use your meeting content to train AI models, ours or anyone else's.

  • 02

    Recording is never hidden

    A Konvoo agent joins as a visible participant. Nobody is recorded by something they cannot see in the room.

  • 03

    Every vendor named

    Section 8 lists each subprocessor by name, what it handles and where it runs, rather than referring vaguely to trusted partners.

  • 04

    Deletion, with one carve-out

    Delete meetings or the whole account whenever you like. Billing and audit records survive, and section 10 explains exactly why.

Contents16 sections
  1. 01Who we are and what this covers
  2. 02The waitlist on this site
  3. 03What we collect
  4. 04Meeting recordings and transcripts
  5. 05How we use it, and on what basis
  6. 06AI processing and model training
  7. 07Google API data and Limited Use
  8. 08Who else processes your data
  9. 09International transfers
  10. 10How long we keep things
  11. 11Your rights, and how to use them
  12. 12How we protect it
  13. 13Cookies and local storage
  14. 14Children
  15. 15Changes to this policy
  16. 16Contacting us

01Who we are and what this covers#

Konvoo is an AI meeting assistant. It joins your calls, produces live transcripts, summaries and action items, and through the assistant we call Orbit it can carry out follow-up work such as drafting an email or creating a task, always behind a confirmation step you control.

This policy is issued by [ TO BE COMPLETED: registered company name ], trading as Konvoo, registered at [ TO BE COMPLETED: registered office address ] under company number [ TO BE COMPLETED: company registration number ]. It covers konvoo.in, the Konvoo web application, the desktop app, and every API and integration we operate.

Where you use Konvoo through an employer or an organisation account, that organisation decides what is recorded and who may see it. In data protection terms they are the controller and we act as their processor. This policy still describes what we do with the data, and requests about access or deletion may need to go through them first.

02The waitlist on this site#

This section is about konvoo.in as it stands today, not about the product. It is short because the waitlist is small.

  • What it collects. The email address you type into the form. Stored next to it: the time you signed up, the line your browser sends about itself, meaning which browser and which device, and the page you arrived from if your browser mentioned one. That is the whole list. There is no account, no password, no payment details and no advertising profile on this site.
  • What it is used for. A note confirming you are on the list, and a second note when Konvoo is ready to let people in. If you write to us, we use it to write back. We do not sell it, we do not add it to a newsletter, and we do not send marketing to it.
  • Where it is kept. In a spreadsheet in a Google account we control, written to by a small script. The site is hosted by Vercel, which keeps the usual server logs. Both notes go out through our email provider. All three are listed in section 8.
  • How to get it removed. Email privacy@konvoo.in from the address you signed up with and say so. We delete the row. There is no form to fill in and you do not have to give a reason.

03What we collect#

Information you give us

  • Account details. Name, email address, password hash or the identifier from the social provider you signed in with, and your avatar if you set one.
  • Organisation and bubble membership. Which workspaces and bubbles you belong to, your role in them, and the invitations you send or accept.
  • Billing details. Your plan, seat count and invoice history. Card numbers are entered directly with our merchant of record and never reach our servers.
  • What you write to us. Support conversations and anything you attach to them.

Information generated by using Konvoo

  • Meeting content. Recordings, transcripts, captions, summaries, action items, notebooks and highlights. Section 4 covers this in detail.
  • Usage and diagnostics. Pages viewed, features used, AI credits consumed, error reports and performance traces.
  • Device and connection data. IP address, browser and operating system, and approximate location derived from the IP address. We use these for security, rate limiting and abuse prevention.
  • Connected accounts. When you link a calendar, mailbox or task tool, the access tokens and the specific records the integration needs. We request the narrowest scope that makes the feature work. Section 7 covers Google connections specifically.

04Meeting recordings and transcripts#

This is the most sensitive category of data we hold, so it gets its own section rather than a line in a list.

When a meeting runs with Konvoo, the agent is present as a visible participant. Audio and video are captured through our video infrastructure provider, transcribed, and then processed to produce the summary, action items and analytics for that meeting. Participants can see the agent in the room and in the participant list for the duration.

Meeting content is visible to the people in the meeting and to members of the bubble or organisation it belongs to, according to the permissions set there. It is not published, indexed, or made available to anyone outside that boundary unless you deliberately share it.

You can delete a recording, a transcript or an entire meeting at any time from the meeting page. Deletion removes it from the application immediately and from our backups within 30 days.

05How we use it, and on what basis#

Where the GDPR, the UK GDPR or a comparable law applies, we need a lawful basis for each purpose. Ours are:

Purposes for processing personal data and the lawful basis for each
PurposeLawful basis
Telling you when Konvoo launches, if you joined the waitlistConsent, withdrawable at any time
Running meetings, producing transcripts, summaries and action itemsPerformance of the contract
Executing follow-up actions you approve through the assistantPerformance of the contract
Taking payment, managing subscriptions and metering AI creditsPerformance of the contract
Keeping accounts secure, preventing abuse and rate limitingLegitimate interest in protecting the service
Diagnosing errors and improving reliability and performanceLegitimate interest in a service that works
Answering support and sales enquiriesLegitimate interest, or steps taken before entering a contract
Keeping audit, tax and accounting recordsLegal obligation

We do not carry out automated decision-making that produces a legal or similarly significant effect on you. The assistant proposes; a person approves.

06AI processing and model training#

Producing a summary means sending transcript text to a third-party model provider. We are specific about what that involves, because vague answers here are the main reason security reviews stall.

  • What is sent. Transcript text and the prompt built around it. Audio and video are not sent to the language model. They are handled by the video infrastructure provider that produced the transcript.
  • Training. Your content is not used to train our models or our providers' models. We use API tiers that exclude submitted data from training by default.
  • Retention at the provider. Providers may hold request data briefly for abuse monitoring, then delete it. They do not retain it as a long-term store.
  • Accuracy. Transcripts and summaries are generated by machine and will sometimes be wrong. Misattributed speech, an action item nobody agreed to, a name spelled four ways. Treat AI output as a draft, especially before acting on it.

The assistant can take real actions such as sending an email, creating a task, or updating a record in a connected tool. Every such action passes through a confirmation step first. We designed it that way so that a model mistake stays a bad suggestion rather than becoming a sent email.

07Google API data and Limited Use#

Konvoo can connect to a Google account so that the product can do the work you asked it to do: know when a meeting is and who is in it, and send a follow-up once you have approved it. This section says what happens to anything we receive from Google in the course of that.

We request the narrowest scopes that make the connected feature work, and we ask for them at the point you turn the feature on rather than up front. You can revoke a connection at any time from your Konvoo integration settings or from your Google account permissions. When you do, we stop exchanging data immediately and delete the tokens.

In practice that commitment means all four of the following, and we state them separately so none of them can be read as implied:

  • We use Google user data only to provide or improve the features you connected it for.
  • We do not transfer Google user data to anyone except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition after telling you about it.
  • We do not use Google user data to serve advertising of any kind, including retargeting and personalised advertising.
  • We do not allow humans to read Google user data, unless we have your explicit consent for specific messages, it is necessary for security purposes such as investigating a bug or an abuse report, to comply with applicable law, or the data has been aggregated and anonymised so it no longer identifies anyone.

Google user data is not used to train our models or any third-party model, which is the same commitment section 6 makes about meeting content. The full policy we are adhering to is published by Google at developers.google.com/terms/api-services-user-data-policy.

Konvoo also connects to Microsoft and Zoom on the same terms. Where those providers publish their own limited-use rules, we follow those too, and the commitments above are the ones we apply to every connected account regardless of provider.

08Who else processes your data#

We use the following subprocessors. Each is bound by a contract that restricts them to processing data on our instructions, and each is listed with what it actually handles rather than a generic category. The list is derived from the services the product genuinely calls, not from a template, because a list nobody can verify fails at the first security questionnaire.

Google is the only one of these processing anything today, because the only thing running on konvoo.in is the waitlist described in section 2. The rest begin processing when the product does.

Subprocessors, their purpose, the data they handle and their processing region
SubprocessorPurposeData handledRegion
GoogleThe pre-launch waitlist store on konvoo.in, and the Workspace mailbox that receives mail you send usWaitlist email address, signup time, browser user agent string, referring page, and anything you write to team@konvoo.inGoogle global infrastructure
Stream (GetStream.io)Video and audio infrastructure, recording, live transcriptionMeeting audio and video, recordings, captions, participant identifiersUnited States
OpenAISummaries, action items, meeting analytics, the Orbit assistantTranscript text and the prompts derived from itUnited States
NeonPrimary application databaseAccount records, meeting metadata, transcripts, summaries, audit logConfigured per deployment, EU or US
VercelApplication hosting, edge delivery, and Blob file storageRequest metadata, uploaded files and exported documentsGlobal edge, primary region per deployment
UpstashRedis for sessions, rate limiting and short-lived stateSession identifiers, request counters, ephemeral tokensConfigured per deployment
Dodo PaymentsMerchant of record for subscriptions and credit purchases: payment, tax and invoicingBilling name, email, billing address, and payment method held by the providerUnited States and EU
StripePayments, subscriptions and invoicing on subscriptions opened on this railBilling name, email, and payment method held by StripeUnited States and EU
LiveblocksReal-time collaboration in the meeting notebookNotebook document content and presence dataUnited States
InngestBackground job orchestration for post-meeting processingJob payloads containing meeting and user identifiersUnited States
SentryError monitoring and performance tracingStack traces, request context, user identifierUnited States
Email delivery providerTransactional email: sign-in links, notifications, follow-ups you approve, and the two waitlist notesRecipient address and message contentPer provider

We may also disclose data where the law requires it, a valid court order for example, or to establish or defend a legal claim. If we are ever compelled to hand over customer data, we will tell the affected customer unless we are legally barred from doing so.

If Konvoo is acquired or merged, data may transfer as part of that transaction. The acquirer remains bound by this policy until you are notified of any change, and a material change gives you the rights set out in section 15.

To be told when this list changes, email privacy@konvoo.in and ask to be added to the subprocessor notification list.

09International transfers#

Several of our subprocessors operate in the United States, so data may be transferred outside your home country and outside the European Economic Area.

Where we transfer personal data out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision covering the destination. Copies of the relevant clauses are available on request from privacy@konvoo.in.

10How long we keep things#

We keep personal data only as long as the purpose it was collected for requires, then delete or anonymise it.

Retention period and legal basis for each category of data
CategoryRetentionBasis
Waitlist email address on konvoo.inUntil Konvoo launches and the launch note is sent, or until you ask us to delete itConsent, withdrawable at any time
Account and profileUntil you delete the accountPerformance of the contract
Meeting recordings, transcripts and summariesUntil you delete them, or the account is deletedPerformance of the contract
Meeting notebooks and highlightsUntil deleted by you or an organisation adminPerformance of the contract
Support and contact correspondence24 months from the last messageLegitimate interest in handling and auditing enquiries
Security and access audit logRetained after account deletion, with an email snapshotLegitimate interest in security and accountability
Credit transactionsRetained after account deletion, with an email snapshotLegitimate interest in dispute resolution
Subscription, invoice and payment recordsRetained for the statutory financial-records periodLegal obligation, tax and accounting

Backups are retained on a rolling 30-day cycle. Data you delete disappears from the live service immediately and ages out of backups within that window.

11Your rights, and how to use them#

Depending on where you live, you have some or all of the following rights. We apply them to everyone, not only to people whose local law compels it.

  • Access. Get a copy of the personal data we hold about you.
  • Correction. Have inaccurate data fixed. Most profile fields are editable directly in your account settings.
  • Erasure. Have your data deleted, subject to the carve-out described in section 10.
  • Portability. Receive your data in a machine-readable format, or have it sent to another provider where that is technically feasible.
  • Objection and restriction. Object to processing based on legitimate interest, or ask us to pause processing while a dispute is resolved.
  • Withdraw consent. Where processing rests on consent, withdraw it at any time. This does not undo processing already carried out.
  • Complain. Raise a complaint with your local supervisory authority. We would rather you came to us first, but it is your right either way.

To exercise any of these, email privacy@konvoo.in and say which right you are using. We respond within 30 days. We will ask you to verify your identity first. It would be a poor privacy policy that let a stranger download your meeting history by asking politely.

Our contact for data protection matters is [ TO BE COMPLETED: data protection contact ]. Until that is appointed and named here, data protection requests go to the same address as everything else, and they are handled by a person rather than routed into a queue.

12How we protect it#

  • Data is encrypted in transit with TLS and at rest by our storage providers.
  • Access to production data is restricted to staff who need it, and privileged actions are written to an audit log that survives account deletion by design.
  • Two-factor authentication is available on every account. We strongly recommend enabling it, particularly for organisation administrators.
  • Sessions, API tokens and integration credentials are scoped, expire, and can be revoked individually from your account settings.
  • Every user-triggerable endpoint is rate limited, which is as much a data-protection control as a performance one.

No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal data and poses a risk to you, we will notify you and the relevant supervisory authority within the time limits the law sets, which is 72 hours under the GDPR.

Found a vulnerability? Report it to security@konvoo.in. We will not pursue legal action against researchers acting in good faith who give us reasonable time to fix the issue before disclosing it.

13Cookies and local storage#

We keep this deliberately small. This site, konvoo.in, sets no advertising cookies and runs no advertising trackers at all.

  • Essential cookies keep you signed in to the product and protect against cross-site request forgery. The product does not function without them, so they are set without asking.
  • Local storage holds interface preferences and drafts so your work is not lost on a refresh. It stays in your browser.
  • Analytics, where used, is limited to aggregate product usage. We do not run advertising cookies and we do not sell audience data to anyone.

You can clear or block cookies in your browser settings. Blocking the essential ones will sign you out of the product and keep you out.

14Children#

Konvoo is a workplace tool and is not directed at children. You must be at least 16 to hold an account, or older where your country sets a higher age for digital consent. If we learn that we hold data about a child below that age, we will delete it. If you believe a child has created an account or joined the waitlist, tell us at privacy@konvoo.in.

15Changes to this policy#

We update this policy when the product changes, when we add a subprocessor, or when the law moves. The last updated stamp at the top of the page always reflects the current version, and it is set by hand rather than by the build, so it means what it says.

For material changes, meaning a new category of data, a new purpose, or a new subprocessor handling meeting content, we will give you at least 30 days of notice by email or in the application before the change takes effect, so you have time to object or to leave.

16Contacting us#

Privacy questions, data requests and security reports all reach a person at privacy@konvoo.in. Dedicated privacy and security addresses are being set up. Until they exist, this policy publishes the one mailbox that genuinely receives mail rather than an address that would bounce.

You can also read the Terms and Conditions, which cover the agreement itself.

By post: [ TO BE COMPLETED: registered company name ], [ TO BE COMPLETED: registered office address ].

Something here unclear?

Ask before you agree. A real person reads this address, and questions about this document are the ones we most want to get.

team@konvoo.in