Legal

Privacy Policy

Last updated: 19 July 2026 · Effective: 19 July 2026

Comsync is a Mac app that records your meetings on your device, transcribes both sides, and turns them into notes, follow-up drafts, and answers you can chat with. This policy explains exactly what data that involves, where it goes, and the controls you have over it. We have written it in plain language on purpose.

01Who we are

Comsync (“Comsync”, “we”, “us”, “our”) is a product of Chaitoj Conversync Private Limited, reachable at comsync.in. For anything in this policy — including questions, requests, and data-deletion — you can reach us at ojasjain@comsync.in. We are the data controller for the information described below. This policy covers the Comsync macOS application and this website, note.comsync.in.

02The data we collect

We collect only what we need to run the service. In practice that is five things:

Google profile

When you sign in with Google, we receive your basic Google profile: your name, email address, and profile picture. We use this to create and identify your account. We never receive or store your Google password — authentication happens on Google's side.

Google Calendar data

With your authorization, we access your Google Calendar in read-only mode to read your upcoming events — so the app can show your next meetings, title a recording from the matching event, and match attendees. We do not create, modify, or delete any events on your calendar.

Meeting audio (for transcription)

When you record a meeting, Comsync captures audio locally on your Mac and relays it in real time, through our backend, to our transcription provider to produce a live transcript. This audio is streamed for processing and is not stored — by us or, per our agreement, retained by the provider for their own purposes. See Audio & transcription.

Meeting content

The output of a meeting — transcripts, AI-generated notes, chat messages and answers, follow-up email drafts, and meeting metadata (such as title, date, and duration) — is stored on our servers and tied to your account so it is available across your devices.

Usage data

We keep basic per-account usage information — counts of meetings and requests, and token counts for AI processing — to operate the service, enforce fair-use and rate limits, and keep the product reliable.

03How we use your data

  • To provide the core product: record, transcribe, generate notes and follow-up drafts, and let you chat with your meetings.
  • To identify your account and keep your data isolated to you.
  • To show your calendar (read-only) so recordings match the right meeting and attendees.
  • To operate and secure the service: apply usage and rate limits, prevent abuse, debug, and keep things running.
  • To communicate with you about your account and support requests.

We do not use your data for advertising, and we do not build cross-site profiles of you.

04Google user data & Limited Use

Comsync's use of Google user data is limited to the purposes described in this policy — signing you in, showing your upcoming meetings and matching attendees, and creating follow-up events you confirm. We request the narrowest scopes needed for those features.

Google Limited Use disclosure

Comsync's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular: we use Google user data only to provide and improve the Comsync features you can see; we do not transfer or sell it to third parties for advertising, market research, or other unrelated purposes; we do not use it for serving ads; and no human reads your Google data except where you explicitly permit it, for security or to comply with applicable law, or as necessary to operate the feature you requested.

05Sub-processors

We rely on a small set of trusted service providers (“sub-processors”) to deliver Comsync. Each receives only the data needed for its specific function, under agreements that require confidentiality and appropriate security. They are:

Sub-processorPurposeData it handles
Google Sign-in (OAuth) and Calendar access Your Google profile and calendar events
Deepgram Speech-to-text transcription Meeting audio, streamed in real time (not stored; model-improvement opt-out applied, so it is not used for training)
Anthropic (Claude API) AI: enhanced notes, follow-up drafts, chat answers Transcripts, your notes, and limited meeting context, sent to generate your output (not used to train models)
Amazon Web Services Cloud hosting and database Your stored account and meeting content (hosted in India — Mumbai region)

We may update this list as the product evolves; material changes will be reflected here with a new “last updated” date.

06Audio & transcription

No bot ever joins your call. Comsync captures the meeting audio on your Mac and streams it, through our backend, to a third-party speech-to-text provider to produce a live transcript. The audio is relayed in real time and not stored by Comsync; what we keep is the resulting text transcript, tied to your account. Transmission is protected in transit (see Security).

07AI processing

To generate enhanced notes, follow-up email drafts, and answers when you chat with your meetings, we send the relevant transcript text and your own notes — and, where useful, limited context such as a meeting's title or an attendee's name — to Anthropic (the Claude API) through our backend, and return the result to you. We use Anthropic's commercial API, under which, per Anthropic's Commercial Terms of Service, your content is not used to train Anthropic's models. It is used only to produce your output.

Speech-to-text transcription is performed by Deepgram. On every request we send Deepgram's model-improvement opt-out (mip_opt_out=true), so your meeting audio is not retained by Deepgram and is not used to train Deepgram's models. Deepgram receives only meeting audio; it never receives your Google Calendar or profile data.

Limited Use — AI & Google data

Our use of raw or derived user data received from Google Workspace APIs (your Calendar data) complies with the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data — including any data derived from it — is never used to create, train, retrain, or improve any generalized or foundational AI/ML model, whether ours or a third party's.

08Where your data is stored

Your account and meeting content are stored in a database on cloud infrastructure located in India (Mumbai region) — that is, your data resides in India. Each user's data is isolated: you can access only your own meetings, notes, and chats. Depending on where you and our sub-processors operate, limited data may be processed in other regions to deliver a feature (for example, transcription or AI generation); where that happens, it is done under appropriate safeguards.

09Security

  • Encryption in transit: all traffic between the app, our backend, and our providers uses HTTPS/TLS.
  • Encrypted secrets at rest: Google refresh tokens are encrypted at rest.
  • Session management: sessions expire (after 90 days) and can be revoked; you can sign out at any time.
  • Per-user isolation: access controls ensure one account cannot reach another's data.

No system is perfectly secure, but we take reasonable, industry-standard measures to protect your information and continually work to improve them.

10Retention & how to delete your data

We keep your account and meeting content for as long as your account is active, so it's available to you across devices. Meeting audio is not retained (it is only relayed for transcription). You are in control:

  • Disconnect Google at any time to revoke our calendar and profile access.
  • Sign out to end your session on a device.
  • Delete your account and data by emailing ojasjain@comsync.in. On request, we delete your stored transcripts, notes, chats, and account data. We may retain limited records where required for legal or security reasons.

11We do not sell your data or train on it

We do not sell your personal information or meeting content, and we do not share it for cross-context behavioural advertising. Your content is not used to train AI models — not ours and not our providers'. Data is shared only with the sub-processors listed above, solely to deliver the features you use.

12Children

Comsync is a workplace productivity tool and is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us data, contact us and we will delete it.

13Changes to this policy

We may update this policy as the product or our providers change. When we do, we'll revise the “last updated” date at the top, and for material changes we'll take reasonable steps to let you know. Continuing to use Comsync after an update means you accept the revised policy.

14Contact us

Questions, requests, or concerns about your privacy? Email ojasjain@comsync.in. We read every message.