Privacy Policy
Version 0.0.9 — effective 8 September 2026
This Privacy Policy explains how personal data is processed when you visit our website, use the 1nsight desktop application and platform, or take part in a conversation that a 1nsight user records. It is written to comply with the EU General Data Protection Regulation (GDPR / DSGVO) and the German Federal Data Protection Act (BDSG).
1. Controller and contact
The controller responsible for the processing described here is:
Franco Noack Theresienstr. 138, 80333 München, Germany Email: franco.noack@1nsight.ai
Full contact details are set out in our Imprint.
We have not appointed a Data Protection Officer. We will appoint one and name their contact here if and when we become required to do so under Art. 37 GDPR / § 38 BDSG.
2. Who this notice is for, and the roles we act in
Three groups of people are affected by our processing:
Website visitors: people who browse our website. Account and product users: members of an organisation that uses 1nsight, for example the person who installs the desktop application and signs in. Call participants: people who take part in a conversation that a 1nsight user records, including external counterparties who never installed our software. For this group we process data that was not obtained from you directly (Art. 14 GDPR), and this notice is the information we provide to you. The source of that data is the 1nsight user, and their organisation, who recorded the conversation; your contact identity is matched from the meeting organiser's calendar invitation.
As controller for our own website, account sign-up, and the operation and security of the service. This includes limited technical data about the operation of our own software — for example whether the desktop application is running, signed in and correctly permitted on a device. That is service data we process for our own purposes of operating, securing and supporting the service; it contains no conversation content, no meeting titles or links, and no user identifier. As a processor (Art. 28 GDPR) for the content an organisation captures with 1nsight, namely recordings, transcripts, calendar metadata and product-usage events about that organisation's own users and counterparties. In that case the organisation is the controller: it decides which conversations to record and is responsible for having a lawful basis and for informing participants. We process such content only on that organisation's documented instructions and under a data-processing agreement.
3. Categories of personal data we process
Context: Website access; Data: Server-log data your browser transmits automatically (IP address, date and time, requested URL, referrer, user agent), used transiently for delivery and security. Context: Account; Data: Sign-in identity from Google (name and email address, via OpenID Connect openid email profile only; we do not access your mailbox), organisation, and the chosen recording region. Context: Calendar; Data: Read live from your primary Google Calendar (scope calendar.readonly) and minimised on our server to the event title, start and end time, meeting join URL, and attendees (name, email, organiser flag, RSVP status, external flag). A calendar event is stored as part of your organisation's record when it is a meeting with someone outside your organisation, whether or not it was recorded — that is what lets the product show who you have met. Events with no external participant, and events still in the future, are read to display your calendar but are not added to the record. Context: Call recordings and transcripts; Data: Audio of the conversation, the transcript (verbatim text with word-level timing), and the identities of participants (matched to calendar invitees). See §4 for the two recording modes. Context: Product and behavioural events; Data: If your organisation embeds our product SDK: interaction occurrences (which control was used, as events; input values are masked and never captured). These are attributed only to a company domain that your organisation asserts — we store no user identifier, no device identifier, no session identifier and no cookie, so an occurrence cannot be traced to a person or a device. Your IP address is never stored. We do not record session replay. Context: App updates; Data: When you run the desktop application, it periodically contacts our update endpoint (downloads.1nsight.ai) to check for a newer or security-critical version: on launch, on window focus (at most once every ten minutes), and about every six hours in the background. Each check transmits only your IP address and your device's CPU architecture (for example arm64 or x64), used transiently to serve the correct build and for security. Your application version is evaluated on your device and is not transmitted. No account identifier, device identifier, cookie or authentication token is sent, and the check is not linked to you or to any captured data. Turning off automatic updates in Settings stops optional-update downloads; a security kill-switch check still runs. Context: App operation; Data: Whether the desktop application is running, its version and release channel, the operating system version and processor architecture, whether it is signed in, the status of the macOS permissions it needs to work (microphone, screen recording, accessibility, full disk access), that a meeting was detected or could not be matched to a calendar entry, and that a technical fault occurred — recorded as one of a fixed set of categories, never as its message or stack trace. Keyed to your organisation and to the same device identifier the updater already uses; no new identifier is stored on your device for this purpose. No conversation content, no meeting titles or links, and no user identifier. Retained for 30 days. Context: Waiting list; Data: If you ask to be notified when the desktop application is available for a platform we do not yet support, we store the email address you enter and which platform you asked for. Nothing else — no name, no company, no marketing profile. Context: LinkedIn conversations; Data: Where a member connects their own LinkedIn account, the direct messages in that account's inbox: the message text, the date, and the name, LinkedIn profile URL and — where the member's own LinkedIn connections export contains it — the email address of the people in each conversation. Only conversations the member replied to or started themselves are stored. A message from someone the member never answered is never imported and no record of that person is created. Sponsored InMail (LinkedIn's paid advertising messages) is discarded before anything else is read. A conversation is stored as one entry per day it was active, so the record shows when the exchange happened rather than collapsing years into one date. Context: Other content you choose to capture; Data: Conversation and note content is free-form, so a recording, transcript or imported note may contain any personal data a participant chooses to say or write, including data about third parties. We do not seek such data, and it is processed on behalf of, and on the instructions of, the organisation that captured it.
We do not capture biometric data or voiceprints, and we do not access email content.
4. Recording and consent
Recording the non-public spoken word without consent is a criminal offence under § 201 of the German Criminal Code (Strafgesetzbuch, StGB). Obtaining that consent is the responsibility of the organisation operating the recording, and the service does not verify it.
Who is responsible. 1nsight records on the instruction of the organisation using it. The service does not ask participants for consent and does not verify that consent has been obtained. The recording organisation is the controller for the content of its recordings and is responsible for establishing a lawful basis and for giving any notice its jurisdiction requires. Recording modes. Local mode is the default: the desktop application records the meeting audio (microphone and system audio) as a mixed mono audio file with no video, which is then transcribed through our transcription pipeline, and the meeting platform shows the other participants nothing. In bot mode, a clearly named notetaker bot visibly joins the meeting and is visible to everyone in it; the audio (and, depending on configuration, video) and its transcription are handled by our recording provider. The mode is set once for the whole organisation by an administrator. Controls. An individual call can be marked "Don't record" before it starts, and a recording in progress can be stopped. Recordings and their transcripts can be deleted at any time, and per-class retention windows can be set by an administrator. Audit. We keep an append-only record of erasures, deletions and retention changes, as evidence of how data has been handled.
For the content of a recording we act as processor, and the GDPR lawful basis is the recording organisation's, typically the consent of participants (Art. 6 (1)(a) GDPR). Lawfulness under § 201 StGB (confidentiality of the spoken word) is likewise established by the recording organisation and not by the service. Where processing is based on consent, it may be withdrawn at any time with effect for the future (see §10).
5. Purposes and legal bases
Processing: Delivering and securing the website; Legal basis: Legitimate interest in operating and securing the site (Art. 6 (1)(f) GDPR). Processing: Checking for and delivering application updates; Legal basis: Legitimate interest in software security and integrity, namely keeping installed applications current and being able to withdraw a known-bad release (Art. 6 (1)(f) GDPR); balanced by an IP-and-architecture-only check with no profiling, no identifiers and no account linkage, documented in our legitimate-interest assessment. Processing: Account creation and providing the service; Legal basis: Performance of a contract and pre-contractual steps (Art. 6 (1)(b) GDPR). Processing: Reading your calendar to schedule and attach recordings; Legal basis: Performance of the contract, that is, providing the service you signed in for (Art. 6 (1)(b) GDPR). Processing: Recording and transcribing conversations; Legal basis: Consent of participants (Art. 6 (1)(a) GDPR); we act as processor (Art. 28 GDPR) for the organisation, which is responsible for obtaining that consent and for § 201 StGB lawfulness. Processing: Product and behavioural analytics (masked, occurrence-only); Legal basis: Legitimate interest, documented in our legitimate-interest assessment (Art. 6 (1)(f) GDPR); balanced by mask-by-default capture, no cookies, no IP storage, and the absence of any user, device or session identifier. Processing: Operating and supporting our own software (app operation); Legal basis: Legitimate interest in operating, securing and supporting the software we supply (Art. 6 (1)(f) GDPR), documented in our legitimate-interest assessment; balanced by a closed list of technical signals with no conversation content and no user identifier, no new identifier stored on your device, 30-day retention, and no use for evaluating individuals. Processing: Notifying you that a platform you asked for is available; Legal basis: Consent, given by submitting your address to the waiting list (Art. 6 (1)(a) GDPR); withdrawable at any time by asking us to remove you. Processing: Importing a connected LinkedIn account's conversations; Legal basis: Legitimate interest in maintaining a record of business conversations the organisation has itself had with a counterparty (Art. 6 (1)(f) GDPR), documented in our legitimate-interest assessment. Nothing is recorded and no consent is inherited: the counterparty agreed to LinkedIn holding their message, not to us. The balance rests on the import being reciprocal or self-initiated — an unanswered message from a stranger never enters the record, so a person only appears where a business exchange actually took place — on advertising messages being discarded, on the member choosing the period to import and being able to exclude individual conversations before anything is written, and on any person in an imported conversation being erasable on request. Processing: Complying with legal obligations; Legal basis: Compliance with a legal obligation (Art. 6 (1)(c) GDPR).
6. AI-assisted analysis and automated processing
Parts of the service are AI-assisted. We disclose this in line with Art. 13 GDPR and the transparency principle of the EU AI Act (Regulation (EU) 2024/1689).
AI-generated content. Transcripts are produced by an automated speech-to-text model. Where enabled, conversation summaries, key points, action items and, in our analysis layer, relationship or stance signals about business contacts are generated by a large language model. This content is machine-generated and may be inaccurate or incomplete; it supports human judgement and does not replace it. No training on your data. We do not use your conversations, transcripts or personal data to train or improve AI or machine-learning models, and our processors are instructed not to. For transcription this is enforced technically on every request (Deepgram training opt-out); for AI analysis (AWS Bedrock) and bot-mode transcription, the no-training commitment rests on the provider's contractual terms and defaults. Safeguards. Our analysis is text-only, with no inference of emotion from voice and no biometric categorisation. We do not seek special categories of personal data (Art. 9 GDPR) and do not build inferences about them; because conversation content is free-form, such data may nonetheless be spoken, in which case it is handled under the same confidentiality, security and retention rules as all other content, and our analysis layer is designed to suppress rather than surface it. A human reviewer remains involved. No solely-automated decisions. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing within the meaning of Art. 22 GDPR.
7. Recipients and sub-processors
We use carefully selected service providers ("processors") who process personal data only on our instructions under Art. 28 GDPR data-processing agreements. The transcription, audio-storage and transcript-analysis functions are configured to run in the EU and fail closed if a non-EU endpoint is set.
Sub-processor: Recall.ai; Purpose: Meeting recording (bot and local upload); Data: Audio (in bot mode, possibly video). In bot mode only, the meeting's join link and its scheduled start time, so the notetaker joins the right call at the right time — no attendee names, email addresses or RSVP status; Region and basis: Region chosen per organisation: EU (eu-central-1) or US (us-west-2); US transfers under the EU SCCs, and the EU-US DPF where the provider is certified. Sub-processor: Deepgram; Purpose: Speech-to-text (local pipeline); Data: Audio converted to transcript text; Region and basis: EU endpoint enforced; per-request training opt-out. Sub-processor: Amazon Web Services (S3); Purpose: Storage of recording audio; Data: Audio files at rest; Region and basis: EU region enforced; encrypted (SSE-KMS). Sub-processor: Amazon Web Services (Bedrock) / Anthropic Claude; Purpose: AI summaries and analysis; Data: Transcript text, and meeting metadata — title, date and the participants a meeting was with; Region and basis: EU region and model enforced in code, which fails closed rather than falling back to another region; no training (contractual). Sub-processor: Supabase (via Lovable Cloud); Purpose: Database, authentication, storage, functions; Data: All account and customer data; Region and basis: Hosted in Switzerland (AWS Europe/Zurich). Switzerland is covered by a European Commission adequacy decision, so this is not a restricted transfer under Chapter V GDPR. Sub-processor: Resend; Purpose: Transactional and authentication email (sign-in, verification codes); Data: Email address; Region and basis: Sending domain in the EU (Ireland); account data stored in the US under SCCs / EU-US DPF. Sub-processor: Google; Purpose: Calendar access (read-only) and sign-in; Data: Calendar metadata; OIDC identity; Region and basis: Google Ireland / Google LLC; EU-US Data Privacy Framework. Sub-processor: Cloudflare; Purpose: Hosting the application-update endpoint (downloads.1nsight.ai, object storage on R2); serving company marks — the small logo shown beside a company in the app, fetched by domain from a first-party endpoint we operate; and relaying real-time update notifications to the desktop app, so a calendar change appears within seconds instead of on a timer; Data: Client IP address, and the request timestamp and path, in transient access logs. For company marks the path contains the company's own domain name; no account, user or organisation identifier is sent. For real-time notifications the app holds an open connection identified only by an opaque value derived cryptographically from your user identifier — it cannot be reversed to identify you without a secret Cloudflare does not hold — plus a timestamp. No calendar content, event titles, attendees, email addresses or organisation identifiers are sent: the notification says only that something changed, and the app then fetches the change from us directly. This relay runs in Cloudflare's EU jurisdiction and stores nothing; Region and basis: Cloudflare Germany GmbH / Cloudflare, Inc.; US transfers under the EU-US Data Privacy Framework and the EU SCCs; logs are minimal and short-lived, and per-request invocation logging is disabled on the mark endpoint so the requesting customer is not recorded alongside the domain.
Optional third-party sources the organisation already uses
These are not our sub-processors. When an organisation admin connects a source — with that organisation's own API key, or by signing in to their own account and authorising us there — we pull text the organisation or its member already holds in that tool and store it in the organisation's 1nsight workspace. Nothing is sent to the tool. The organisation remains controller of its relationship with it, and the basis differs by source: a call-recording connector rests on the admin's attestation that the recordings were lawfully collected, while a LinkedIn import rests on legitimate interest as set out in §5, because nothing was recorded and no consent is inherited.
Source: Granola; Purpose: Optional connector import of meeting notes; Data: Transcript text and attendee metadata retrieved on sync; Region note: Granola's notes API is US-hosted; each sync is the organisation's outbound call to Granola. Imported text is stored in the organisation's 1nsight workspace region. Source: LinkedIn; Purpose: Optional import of a member's own direct messages, under the EU Digital Markets Act's data-portability right; Data: Message text, dates, and the names and profile URLs of the people in each conversation, retrieved on each sync; Region note: The member authorises us in their own LinkedIn account and may withdraw that authorisation there or in our application at any time. Each sync is our outbound call to LinkedIn on the member's behalf; nothing is sent to LinkedIn beyond the request itself. LinkedIn Ireland Unlimited Company is the controller of the account we read from. Imported text is stored in the organisation's 1nsight workspace region.
The sub-processor table in §7 is our current list of sub-processors. We keep it up to date here and will give notice of additions or replacements to organisations that have a data-processing agreement with us, so they can object.
7a. Google user data — Limited Use
Where you connect a Google account, 1nsight requests no more than four OAuth scopes: openid, email and profile for sign-in, and https://www.googleapis.com/auth/calendar.readonly to read your calendar. (Connecting a calendar on its own requests only the last of these.) We request no permission to write to your calendar, and none to your mailbox, files or any other Google service. What we read and what we retain from your calendar is set out in §3.
1nsight's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
We use Google user data only to provide the features it is requested for, and those features are visible and prominent in the product: showing your meetings, attaching each recording to the meeting it belongs to, and identifying the participants a conversation is with. We do not sell Google user data, and we do not use it for advertising of any kind. We do not transfer Google user data to third parties except as needed to provide those features, for security, or to comply with the law. We hold our own Google credentials and read your calendar directly: your calendar is never connected to our recording provider, and attendee names, email addresses and RSVP status are never disclosed to them. In bot mode only (see §4), we pass that provider the meeting's join link and its scheduled start time, which is what lets the notetaker join the right call at the right time. We do not allow humans to read your Google user data, except with your explicit consent — including a support session you or your organisation has asked us for, which is read-only and logged (see §11) — where it is necessary for security or to comply with the law, or where it has been aggregated and anonymised. We do not use Google user data to create, train or improve any generalised artificial-intelligence or machine-learning model. Calendar-derived participant information is used by our analysis layer only to produce results for the organisation whose calendar it came from, on the EU AI provider named in §7, whose terms commit it not to train on the data (see §6).
You can disconnect your calendar at any time, in the application's Settings or from your Google Account permissions page. Disconnecting in the application also revokes our access at Google and deletes the stored credential.
8. International data transfers
Our primary database and application platform is hosted in Switzerland, which the European Commission has recognised as providing an adequate level of data protection; transfers there therefore require no additional safeguard. Where a processor processes data outside the EU/EEA and outside an adequacy decision (for example the US recording region, transactional email via Resend, the application-update endpoint hosted by Cloudflare, Google, or — when the organisation connects the Granola connector — Granola's US-hosted notes API on each sync), the transfer is safeguarded under Chapter V GDPR (Art. 44 et seq.) by an EU adequacy decision (including the EU-US Data Privacy Framework where applicable) or the European Commission's Standard Contractual Clauses (SCCs), with supplementary technical measures such as encryption. Our transcription, audio storage and transcript-analysis functions are configured to remain in the EU. Connector and LinkedIn imports store text in the organisation's 1nsight workspace region; they do not send that text to Granola or to LinkedIn — the US hop is the organisation's outbound API call to retrieve notes they already hold there.
9. Retention and deletion
We keep personal data only for as long as necessary for the purposes described here or as required by law, and we delete it on request.
Recording-provider copy. The recording provider's copy of a local upload is deleted automatically after 36 hours. In bot mode, the recording is retained at the provider, per the organisation's recording configuration, until it is ingested and then erased on our side. Product and behavioural events. Retained on fixed windows: raw events approximately 90 days, and derived events and sessions approximately 13 months. Recording audio, transcripts, calendar metadata and contact records. Retained no longer than necessary for the organisation's use of the service, subject to the organisation's configurable retention windows, and deleted on request or on account closure. Waiting list. We keep the address you gave us until we have notified you that the platform you asked for is available, or until you ask us to remove you — whichever comes first. You can ask at any time using the contact in §1, and we do not need a reason. Erasure. On a valid request we delete the recording, its stored audio, the transcript and the associated contact records, and we keep only a minimised record that the erasure took place.
10. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), and data portability (Art. 20), and the right to object (Art. 21) to processing based on legitimate interest. Where processing is based on consent, you may withdraw it at any time with effect for the future (Art. 7 (3)), without affecting the lawfulness of processing before withdrawal.
To exercise your rights, contact franco.noack@1nsight.ai. Where the data was captured by an organisation using 1nsight (and we act as processor), we will forward your request to that organisation as the responsible controller. We respond without undue delay and within one month (Art. 12 (3) GDPR).
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority competent for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach (www.lda.bayern.de).
11. Security
We protect personal data with encryption in transit (TLS throughout) and at rest (AES-256 with KMS-managed keys, where disabling a key cryptographically shreds the associated audio); separation of each organisation's data, enforced in the database itself; role-based access control; encryption of third-party access tokens at rest; region enforcement that fails closed rather than falling back to another region; least-privilege internal access, with support access to a customer's workspace restricted to read-only and recorded; and automated verification of every change before it is released.
We review these measures as the service develops and will update this section as they change. No method of transmission or storage is completely secure; we ask you to tell us at franco.noack@1nsight.ai if you believe your data may be at risk.
12. Cookies and tracking
Our website and product do not use tracking or advertising cookies and do not perform cross-site tracking. The product SDK stores nothing on your device — no cookie, no localStorage entry, no device or session identifier — so § 25 TDDDG, which governs storing information on or reading it from a user's terminal equipment, is not engaged. No IP address is persisted and no fingerprinting is performed.
13. Children
1nsight is a business service and is not directed at children. We do not knowingly process the personal data of minors.
14. Data-processing agreement
Where we process personal data on behalf of an organisation using 1nsight, that processing is governed by a written data-processing agreement under Art. 28 GDPR, covering subject matter and duration, confidentiality, security measures, sub-processors, assistance with data-subject rights, breach notification, deletion or return of data, and audit rights. The agreement is published at Data Processing Agreement and forms part of our Terms of Service, so it applies automatically; a counter-signed copy is available on request at franco.noack@1nsight.ai.
15. Changes to this notice
We may update this notice as the product and our legal setup mature. Material changes will be announced on this page; the current version and effective date are shown at the top.