Privacy Policy
Effective Date: July 9, 2026
In short:
- ArcGlass analyzes customer conversations (messages, emails, tickets, meetings) that your organization connects to the platform. Your organization owns that content and controls it. We process it only to provide the Services.
- We do not sell personal information, we do not show ads, and we do not use your content to train generalized AI models. Our AI providers are contractually prohibited from doing so too.
- The ArcGlass Listen desktop app transcribes meetings on your device. Audio never leaves your device. Uploading transcripts to your ArcGlass workspace is optional and requires your explicit consent.
- You can request access, correction, deletion, or export of your personal information at any time at privacy@arcglass.io.
This Privacy Policy describes how ArcGlass, Inc. ("ArcGlass," "we," "our," or
"us") collects, uses, discloses, and protects information in connection with:
- our websites, including arcglass.io (the "Website"),
- our web application at console.arcglass.io (the "Platform"),
- our downloadable desktop application, ArcGlass Listen (the "Listen App"), and
- related services, integrations, and support (together, the "Services").
If you or your organization has entered into a separate written agreement with
ArcGlass (for example, an enterprise agreement or a data processing agreement),
that agreement governs to the extent it conflicts with this Privacy Policy.
1. Our Role: When We Act as Controller and When as Processor
ArcGlass is a business-to-business service. It matters who decides why and how
personal information is processed:
-
Customer Content (ArcGlass as processor / service provider).
"Customer Content" means the conversations, emails, support tickets, chat
messages, meeting recordings, transcripts, calendar details, documents,
files, and other data that a customer organization (the "Customer")
submits to the Services or authorizes the Services to collect from its
connected data sources. The Customer decides which sources to connect and
what to analyze. For Customer Content, the Customer is the data controller
(or "business" under US state privacy laws) and ArcGlass processes the
data as a processor / service provider, only on the Customer's
instructions.
-
Account, billing, usage, and Website data (ArcGlass as
controller). For the personal information described in Sections
2.1 and 2.5 (for example, your account profile, payment records, product
usage data, and Website visits), ArcGlass determines the purposes and
means of processing and acts as the data controller.
If you appeared in a conversation or meeting analyzed by a Customer's
ArcGlass workspace but do not have an ArcGlass account (for example,
you emailed a company that uses ArcGlass, or attended a meeting that a
Customer recorded), the Customer, not ArcGlass, controls that data. Please
direct privacy requests about that content to the organization that ran the
meeting or owns the mailbox, channel, or account. We will assist that
organization in honoring your request, and you can always reach us at
privacy@arcglass.io.
2. Information We Collect
2.1 Information You Provide to Us
- Account information: When you sign in with Google, Microsoft, or GitHub, we receive your name, email address, and profile image from that identity provider; we never receive or store your identity provider password. If you instead create an account with an email address and password, we store that password only in salted, hashed form. We also collect your organization name, role, and workspace settings you configure.
- Payment information: Payments are processed by Stripe. We receive and store billing records (plan, invoices, payment status, billing contact) but not full payment card numbers.
- Communications: Messages you send us for support, feedback (including through in-product feedback tools), or sales inquiries.
- Files you upload: Transcripts, email files, chat exports, images, audio files, and other documents you upload for analysis. These are Customer Content.
2.2 Customer Content from Connected Sources
When a Customer administrator connects a data source, the Services collect the
content that the Customer authorizes through that source's permissions
(typically via OAuth or admin-granted access). Depending on which integrations
the Customer enables, this can include:
- Messaging platforms: Slack, Microsoft Teams, Google Chat, Discord (channel messages, threads, participant names, timestamps, reactions).
- Email: Gmail and Microsoft Outlook / Microsoft 365 mailboxes, including via Google Workspace domain-wide delegation or Microsoft 365 admin consent where the Customer's administrator sets it up (message content, senders, recipients, subjects, threading metadata).
- Support and ticketing: Zendesk, Freshdesk, Intercom, ServiceNow, and similar tools.
- Meetings: Transcripts and recordings from Zoom, Google Meet, Gong, Chorus, Fireflies, Granola, and meeting share links; uploads from the Listen App; and recordings made by the ArcGlass meeting notetaker (Section 2.3).
- Calendars: Event titles, descriptions, times, organizers, and attendee lists from connected Google and Microsoft calendars, used to match meetings, schedule the notetaker, and enrich analysis.
- Project, CRM, and knowledge tools: Jira, GitHub, GitLab, Azure DevOps, Confluence, Notion, Google Drive / Docs / Sheets, Dropbox, Amazon S3, and similar sources the Customer connects.
- Public sources: Publicly available pages or posts (for example, community forums or public social posts) that the Customer directs the Services to analyze.
Customer Content routinely contains personal information about the Customer's
own personnel, customers, and other conversation participants, such as names,
email addresses, opinions, and anything else said in a conversation. The
Customer is responsible for ensuring it has the right to connect each source
(see Section 8).
2.3 Meeting Recordings and the ArcGlass Notetaker
At a Customer's direction, ArcGlass can send a notetaker bot to join a video
meeting (for example, on Zoom or Google Meet). The notetaker joins visibly as
a named participant, records the meeting audio, and the Services transcribe
and analyze it. We use Recall.ai as our infrastructure provider for the
notetaker. The Customer and the meeting host are responsible for providing any
legally required notice to participants and obtaining any required consents
before recording (see Section 8). Audio files you upload directly to the
Platform for transcription are handled the same way as other Customer Content.
2.4 The ArcGlass Listen App
The Listen App is designed to be private by default:
- On-device processing: Audio capture, transcription, and speaker attribution run locally on your computer. Meeting audio is not sent to ArcGlass or any third party. Transcripts and temporary audio session files are stored locally on your device under your control.
- Optional upload, off by default: If you explicitly enable transcript upload, the Listen App sends completed meeting transcripts (and, if available, matched calendar event details such as the meeting title, time, organizer, and attendees) to your organization's ArcGlass workspace over an encrypted, certificate-pinned connection. Raw audio is never uploaded. Uploaded transcripts become Customer Content in your organization's workspace.
- Calendar access (optional): With your permission, the Listen App reads your device calendar and, if you signed in with Google or Microsoft, your provider calendar, solely to show your upcoming meetings and to attach the matching event's details to a recording.
- Software updates: The Listen App periodically checks our release server for updates. An update check sends standard web request data (such as your IP address and app version) and installs an update only after you approve it.
- Diagnostics: Crash-recovery snapshots and logs are stored locally on your device. The Listen App's upload log records upload status and never contains transcript text.
2.5 Information We Collect Automatically
- Usage data: Features used, pages viewed, actions taken in the Platform, pipeline run activity, and similar interaction data.
- Device and log data: IP address, browser type, operating system, timestamps, referring URLs, and server request logs.
- AI usage records: Operational metadata about AI processing (such as which feature ran, token counts, duration, and cost), which we use for billing, capacity, and abuse prevention.
- Cookies and similar technologies: See Section 10.
3. How We Use Information
- Provide the Services: Ingest, transcribe, analyze, summarize, and organize Customer Content; detect signals (such as sentiment, topics, intent, and requested actions); generate reports and insights; and carry out the automations the Customer configures (for example, creating a Jira ticket or sending a Slack notification).
- Operate accounts and billing: Authenticate users, manage organizations and permissions, process payments, and send transactional messages (such as receipts, digests the Customer configures, and service notices).
- Support: Respond to requests and troubleshoot issues. Where troubleshooting requires our authorized personnel to view a Customer's workspace, that access is limited, logged, and used only to resolve the issue.
- Secure and improve the Services: Monitor for fraud, abuse, and security incidents; debug; and analyze usage patterns to improve features. We use aggregated or de-identified data for analytics, and we do not attempt to re-identify it.
- Communicate: Send product updates and marketing where permitted; you can opt out of marketing at any time.
- Comply with law: Meet legal, tax, accounting, and regulatory obligations, and enforce our agreements.
We do not sell personal information, we do not share it for cross-context
behavioral advertising, and we do not use Customer Content for advertising of
any kind.
4. AI Processing and Model Training
The Services use large language models and other machine learning systems to
analyze Customer Content. This processing is performed by ArcGlass systems and
by enterprise AI services acting on our behalf, currently including Google
Cloud Vertex AI, Microsoft Azure OpenAI Service, and Groq.
- We do not train, fine-tune, or build generalized AI or foundation models using Customer Content.
- Our AI providers are contractually prohibited from using Customer Content to train or improve their models. They process content solely to return results to us. Providers may retain content transiently for abuse prevention in accordance with their enterprise terms.
- Derived data stays in your workspace. Embeddings, classifications, summaries, and knowledge-graph data generated from Customer Content are scoped to the Customer's workspace and used only to provide the Services to that Customer.
AI-generated outputs (transcripts, summaries, classifications, suggested
actions) are automated and may contain errors. They are provided to help your
team review conversations, not as a verbatim record or professional advice.
5. Google and Microsoft API Data
ArcGlass's use and transfer to any other app of information received from
Google APIs will adhere to the
Google API Services User Data Policy,
including the Limited Use requirements.
In particular, for data obtained through Google Workspace APIs (such as Gmail, Google Calendar, and Google Drive):
- We use it only to provide and improve user-facing features of the Services that are visible to you and your organization.
- We do not use it to develop, improve, or train generalized artificial intelligence or machine learning models.
- We do not sell it, and we do not use or transfer it for serving advertisements.
- Humans do not read it except with your explicit permission, where necessary for security or legal compliance, or where the data has been aggregated and anonymized.
Data obtained through Microsoft APIs (such as Microsoft Graph for Outlook,
Teams, and Microsoft 365 calendars) is used under the same restrictions: only
to provide the features your organization enables, never for advertising, and
never to train generalized AI models. Access is granted by your organization's
administrator and can be revoked at any time in your Google or Microsoft admin
console, which stops further collection.
6. How We Share Information
6.1 Within Your Organization
The Services are collaborative. Customer Content, analysis results, and
activity within a workspace are visible to the Customer's administrators and
to authorized users according to the permissions the Customer configures.
Your organization's administrators control the workspace and its data.
6.2 At the Customer's Direction
When the Customer configures automations or integrations, we send data to the
third-party systems the Customer chooses (for example, creating a ticket in
Jira or Zendesk, posting to Slack or Discord, updating a CRM, or sending an
email through the Customer's configured sender). Those systems are governed by
their own terms and privacy policies.
6.3 Service Providers (Subprocessors)
We use a small number of vendors to operate the Services. They may process
personal information only to perform services for us, under contracts that
require confidentiality, security, and (for Customer Content) a prohibition on
AI training. Our current providers include:
| Provider |
Purpose |
Location |
| Google Cloud Platform | Hosting, database, storage, AI inference (Vertex AI) | United States |
| Microsoft Azure | AI inference (Azure OpenAI Service) | United States |
| Groq | AI inference | United States |
| Render | Hosting for auxiliary services | United States |
| Cloudflare | Content delivery, TLS, network security | Global |
| Stripe | Payment processing | United States |
| Twilio SendGrid | Transactional email delivery | United States |
| Recall.ai | Meeting notetaker infrastructure | United States (region configurable) |
| GitHub | Listen App release hosting and update delivery | United States |
| Google Analytics | Website and Platform analytics (only with your cookie consent) | United States |
| Discord | Internal operations alerting (website traffic notifications, product feedback) | United States |
We may update this list as the Services evolve. Customers with a data
processing agreement will be notified of subprocessor changes as described in
that agreement.
6.4 Legal and Safety
We may disclose information if we believe in good faith that disclosure is
required by law, regulation, legal process, or governmental request, or is
necessary to protect the rights, property, or safety of ArcGlass, our users,
or the public. Where legally permitted, we will notify the affected Customer
before disclosing Customer Content in response to legal process.
6.5 Business Transfers
If ArcGlass is involved in a merger, acquisition, financing, reorganization,
or sale of assets, information may be transferred as part of that transaction,
subject to this Privacy Policy's commitments. We will notify you of any
transaction that changes how your personal information is handled.
6.6 With Consent
We share information for other purposes only with consent.
7. Recording Laws and Consent
Laws in many jurisdictions (including "all-party consent" states such as
California and Washington, and many countries) require notice to, or consent
from, some or all participants before a conversation or meeting is recorded or
transcribed. Customers and users who record, connect, or upload conversations
are solely responsible for complying with these laws, including providing any
required notices and obtaining any required consents before using the
notetaker, the Listen App, or any other recording feature. ArcGlass does not
and cannot verify that consent was obtained for any particular conversation.
8. Customer Responsibilities
Each Customer is responsible for:
- having the legal right and authority to connect each data source and to submit Customer Content to the Services,
- providing any privacy notices to, and obtaining any consents from, its own personnel, customers, and conversation participants that applicable law requires,
- configuring retention, access, and integration settings appropriately, and
- responding to privacy requests from individuals whose data appears in its Customer Content (we provide tools and assistance for this).
9. Data Security
We apply technical and organizational measures appropriate to the sensitivity of the data we handle, including:
- encryption in transit (TLS 1.2 or higher) and encryption at rest for databases and file storage,
- certificate-pinned connections for Listen App uploads,
- logical tenant isolation: every record is scoped to the owning organization, and cross-organization access is denied by default,
- authentication on protected routes, role-based access within workspaces, and audited, limited support access,
- verification of signatures on inbound webhooks from integrated providers, and
- a coordinated vulnerability disclosure program.
No method of transmission or storage is completely secure, and we cannot
guarantee absolute security. If we learn of a breach affecting your personal
information, we will notify you and the relevant authorities as required by
applicable law.
10. Cookies and Analytics
- Platform (console.arcglass.io): We use strictly necessary cookies and browser storage to keep you signed in and to remember workspace preferences. With your consent, we also use Google Analytics to understand how the Platform is used so we can improve it; if you decline, analytics cookies are not set, and you can change your choice at any time under Settings, Privacy. The Platform does not use advertising cookies.
- Website (arcglass.io): We use Google Analytics to understand Website traffic, and only after you accept analytics cookies through our consent banner; if you decline, analytics cookies are not set. We also record basic, first-party page view data (page viewed, referring page, browser type, and approximate location at country level) for traffic measurement, delivered to our internal operations channel.
You can withdraw cookie consent by clearing your browser storage for the
Website, and you can control cookies through your browser settings.
11. Data Retention and Deletion
- Customer Content: Retained for as long as the Customer's workspace is active or as the Customer directs. Customers can delete conversations, sources, or their entire workspace. When a workspace is terminated, we delete or de-identify Customer Content within 30 days of a verified deletion request, except where law requires longer retention.
- Account information: Retained while your account is active and deleted or de-identified within 30 days of a verified account deletion request.
- Billing records and audit logs: Retained as required for tax, accounting, security, and legal compliance.
- Backups: Deleted data ages out of encrypted backups on a rolling basis within 90 days.
- Listen App local data: Transcripts and audio session files on your device are yours; deleting them is under your control and takes effect immediately.
12. Your Rights and Choices
Depending on where you live, you may have the right to access, correct,
delete, or export your personal information, to restrict or object to certain
processing, and to withdraw consent. To exercise these rights, contact
privacy@arcglass.io. We will verify
your request and respond within the timeframe required by applicable law. We
will not discriminate against you for exercising your rights.
If your data was processed as part of a Customer's workspace, we may refer
your request to that Customer, as they control that data (see Section 1).
12.1 European Economic Area, United Kingdom, and Switzerland (GDPR)
Our legal bases for processing are: performance of a contract (providing the
Services), legitimate interests (securing and improving the Services,
measuring Website traffic, business communications), consent (marketing,
analytics cookies, optional features such as Listen App uploads), and legal
obligations. You have the rights of access, rectification, erasure,
restriction, portability, and objection, the right to withdraw consent at any
time, and the right to lodge a complaint with your supervisory authority.
12.2 California and Other US States
We do not sell personal information and have not done so in the preceding 12
months, and we do not share personal information for cross-context behavioral
advertising. California residents have the rights to know, access, correct,
delete, and port their personal information, to limit use of sensitive
personal information (we use it only to provide the Services), and to
non-discrimination. You may use an authorized agent to submit requests, and
you may appeal a denial by replying to our decision. The categories of
personal information we collect, the sources, purposes, and disclosures are
described in Sections 2, 3, and 6.
13. International Data Transfers
We are based in the United States and process data there. If you use the
Services from outside the United States, your information will be transferred
to the United States and other countries where our providers operate. Where
required, we rely on appropriate safeguards for cross-border transfers,
including the European Commission's Standard Contractual Clauses and the UK
Addendum, which are incorporated into our data processing agreement.
14. Children's Privacy
The Services are business tools and are not directed to children under 16. We
do not knowingly collect personal information from children under 16. If you
believe a child has provided us personal information, contact us and we will
delete it promptly.
15. Third-Party Links and Services
The Services link to and interoperate with third-party websites and services.
This Privacy Policy does not apply to them, and we are not responsible for
their privacy practices. Review the privacy policies of any third-party
service you connect or visit.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated
policy on this page and update the effective date above. For material changes,
we will provide additional notice, such as an email to workspace
administrators or an in-product notice, before the changes take effect.
17. Contact Us