Skip to content
  • CompanyOS
  • Meeting
  • How it works
  • Pricing
  • Story
ENVI
Start free

Legal

Privacy Policy

Last updated: July 15, 2026

Anby is an AI-native operating platform. To do that well we handle a lot of content your team produces — OKRs, meeting transcripts, decisions, knowledge. This page explains in plain language what we collect, why we need it, how long we keep it, and what you can do with it.

1. Information we collect

We only collect what we need to run the product. Broadly, that falls into three buckets:

  • Account information — name, email, workspace, role, password hash, and billing details when you subscribe. We collect this when you sign up or invite teammates.
  • Workspace content — everything you and your team create inside Anby: OKRs, meeting recordings and transcripts, knowledge base entries, decisions, action items, comments, integration data you connect (Jira, Slack, Google, etc.).
  • Usage and technical data — device information, IP address, browser, product analytics events (which features are used, error logs), and Anby Coin consumption logs.

We do not buy personal data from brokers, and we do not use tracking pixels from third-party advertisers.

2. How we use information

We use the information above to:

  • Provide and operate the product — store your content, run AI actions, deliver notifications, bill your workspace.
  • Keep the service safe — detect abuse, prevent fraud, comply with legal obligations.
  • Improve the product — aggregate analytics, debug errors, and understand which features actually help.
  • Communicate with you — service updates, security notices, product changelogs, and (if you opt in) occasional product marketing.

We do not train public or third-party AI models on your workspace content. Your team's content is used to serve your workspace — not to improve any model that benefits other customers without your consent.

3. Google Workspace data — how we access, use, and share it

If you connect a Google account to Anby Meeting — to sign in and/or to link your Google Calendar — Anby accesses a limited set of Google Workspace data. This section explains exactly what we access, why, and which third parties receive it.

What we access, and the scopes we request:

  • Sign-in (userinfo.email, userinfo.profile) — your Google account email and basic profile, used to create and authenticate your Anby account.
  • Google Calendar, only if you connect it (calendar.events, calendar.calendarlist.readonly) — your calendar events and the list of calendars you can write to. This includes event titles, start and end times, attendee email addresses, and Google Meet links. We use it to detect which meetings to record and to create or update events with Meet links on your behalf.
  • Google Meet recordings — the audio and video of the Google Meet calls you choose to record, and the transcripts and summaries derived from them.

We request offline access so we can keep your calendar in sync. The resulting Google refresh token is stored encrypted (AES-256) and you can revoke it at any time.

Who we share Google user data with. We share Google user data only with the service providers needed to deliver the recording, transcription, and summarization features you ask for. We do not sell Google user data, and we never share it for advertising. Specifically:

  • Recall.ai — our calendar-sync and meeting-recording provider. To sync your calendar and join the meetings you choose to record, we transmit your Google Calendar OAuth credentials (including the refresh token) and calendar event data (titles, times, attendee emails, Google Meet links) to Recall.ai, which records the Google Meet calls you schedule for recording.
  • Cloudflare R2 — encrypted object storage where the meeting audio and video recordings are kept.
  • ElevenLabs — the speech-to-text provider that transcribes the meeting audio.
  • OpenAI — the large language model provider that generates the meeting summary from the transcript. OpenAI processes this content solely to produce your summary and is contractually barred from using it to train its models.
  • n8n — our workflow-automation layer that orchestrates the recording → transcription → summary pipeline; meeting audio and transcripts pass through it in transit.

Our analytics provider (PostHog) and email provider (Resend) receive only derived, non-content metadata — for example the AI system prompt and model output, or the email address we send your summary to — never your raw Google Calendar data or meeting transcripts.

Limited Use. Anby's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google Workspace data — or any data derived from it, such as recordings, transcripts, or summaries — to develop, improve, or train generalized or non-personalized AI/ML models. Humans do not read your Google data except (a) with your explicit consent (for example, support you request), (b) where necessary for security or to comply with applicable law, or (c) where the data has been aggregated and anonymized.

Revoking access. You can disconnect Google Calendar at any time from Anby (Settings → Calendar), which deletes the stored refresh token and instructs Recall.ai to remove the synced calendar. You can also revoke Anby's access directly from your Google Account permissions.

4. AI processing and sub-processors

Anby's AI features run on large language model providers (currently Anthropic and OpenAI). When your team uses an AI action — for example asking God Brain a question or summarizing a meeting — relevant content is sent to these providers to generate the response. These providers are contractually bound to:

  • Not retain your content beyond what's needed to generate the response.
  • Not use your content to train their models.
  • Apply the same security standards as our own infrastructure.

Your consent before we record. Recording a meeting is the point at which your audio and its transcript are shared with these AI service providers, so we ask for it explicitly first. Before your first recording, Anby shows a consent screen that states what is sent (the meeting audio and video, and the transcript derived from it), names the providers that receive it — Recall.ai (capture), ElevenLabs (transcription), and OpenAI (summaries) — and links here. No meeting data leaves your device until you agree, and you can decline and use the rest of the app without recording.

We also use infrastructure providers for hosting (AWS), analytics (PostHog and Google Analytics), email (Resend), and error monitoring (Sentry). A current list of sub-processors is available on request at privacy@anby.ai.

5. Third-party AI connectors

You can connect Anby to third-party AI assistants — for example Claude — through our MCP connector. When you authorize such a connector, it can read the workspace data within the scope you grant (the Anby Meeting connector is read-only: meetings, transcripts, summaries, and tasks you participate in, scoped to your tenant). It cannot create, modify, or delete anything.

Once content reaches that assistant, the assistant's handling of it is governed by its own privacy terms, not this policy. Access is per-user and tenant-scoped, and you can revoke it at any time from the assistant's connector settings or from your Anby account — after which the connector can no longer reach your data.

6. Data retention

While your workspace is active, we keep your content as long as you want it. Deleting content from within Anby removes it from active systems immediately; encrypted backups are purged on a rolling 30-day schedule.

If your workspace is cancelled, we retain your data for 30 days in case you want to reactivate, then permanently delete it. You can request immediate deletion at any time.

Some aggregated, non-identifying analytics (e.g., "X% of teams use feature Y") may be kept indefinitely.

7. Data export and portability

You can export every piece of content in your workspace at any time via the Anby API or via our MCP server. No lock-in, no "enterprise upgrade" to get your own data back.

Workspace admins can also trigger a full workspace archive (JSON + attachments) from the Settings page. Large archives are delivered by email link within 24 hours.

8. Security

Our baseline:

  • All data in transit is encrypted via TLS 1.2+.
  • All data at rest is encrypted (AES-256).
  • Workspace data is isolated at the database-schema level per tenant.
  • Access to production systems is limited to engineers on duty, requires 2FA, and is audit-logged.
  • We run regular internal security reviews and respond to responsible-disclosure reports at security@anby.ai.

No service is perfectly secure. If we ever detect a breach affecting your workspace, we'll notify you and your workspace admins without undue delay.

9. Your rights

Depending on where you live, you may have rights to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Export your data in a machine-readable format.
  • Delete your data.
  • Object to or restrict certain types of processing.

You can exercise any of these rights by writing to privacy@anby.ai. We'll respond within 30 days. If you're a team member in a workspace you don't own, some requests may need to be coordinated with your workspace admin.

10. International transfers

Anby is operated globally. Your data may be processed in data centers outside your country. Where required by law (GDPR, UK data protection, etc.), we use standard contractual clauses and equivalent safeguards to protect international transfers.

11. Children's privacy

Anby is not directed to children under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data about a child, please contact us and we'll delete it.

12. Changes to this policy

We may update this policy as the product evolves. Material changes (new categories of data, new sub-processors, significant changes to retention) will be announced via product in-app notification and/or email at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

Questions?

Write to us at privacy@anby.ai. For general inquiries, silver@anby.ai reaches a real human — usually same-day.

Anby

CompanyOS for AI-native operators. Sense work, validate concerns, and choose the next best operating move from real company signal.

Start with 14 days of Pro, for free.

Deploy AI Meeting first. Let CompanyOS build your operating picture from real work — nothing to configure.

Start for free

Platform

  • How it works
  • Pricing
  • Story

CompanyOS

  • CompanyOS
  • Insights
  • Concerns
  • Onboarding

AI Meeting

  • AI Meeting
  • Meeting summaries
  • Action items
  • Transcript intelligence

Connectors

  • Google Calendar
  • Zoom
  • Slack
  • Notion
  • Jira

Resources

  • AI Readiness Assessment
  • Design Partner Program
  • Our Story
  • Knowledge walks out
  • Strategy Monday gap
  • Tool fatigue
  • silver@anby.ai

Legal

  • Privacy
  • Terms
  • Security posture
  • Public mocks only
© 2026 Anby. Organization intelligence for real work.
ENVI
PrivacyTerms