Privacy policy
Last updated: August 2026
Sindo is a relationship memory for business partnerships. To do its job it processes communication data that you and your team explicitly connect. This policy explains what we collect, how we use it, where it is stored, and who it is shared with — with specific detail for data we receive from Google.
What we collect
We only collect data from sources you connect, scoped to your workspace:
- Google Calendar (read-only) — see the dedicated section below.
- Meeting recordings and transcripts captured by our notetaker bot when it is invited to a meeting.
- Slack — direct messages, private channels, and Slack Connect channels that you assign to a partner.
- Telegram — direct messages and group chats you connect.
- Connected meeting notes from Granola, when you enable that integration.
- Content you add — uploaded documents, links, and Notion content.
- Contact identities inferred from these communications, and public information about partner companies (such as their website).
- Account details you sign up with (name, email) via our authentication provider, Clerk.
Gmail is a separate, legacy integration that is not part of Sindo's current Google authorization. New Google connections request Google Calendar access only.
Google Calendar data
When you connect a Google account, Sindo requests read-only access to your Google Calendar. We want to be specific about how that data is handled:
What we access. Through the Google Calendar API we read your upcoming calendar events, including each event's title, description, location, and start/end times; the attendees' names, email addresses, and response status; meeting and source links; and the Google account identity (email address) used to connect. Connecting also creates OAuth access and refresh tokens.
How we use it. We use Google Calendar data solely to provide Sindo's features to your workspace: detecting which meetings relate to your partners, building partner timelines, scheduling the notetaker for meetings you choose, and generating summaries and answers about your partnerships.
How we store it. OAuth access and refresh tokens are stored in Sindo's database, encrypted at rest by our infrastructure provider and accessible only to Sindo's server-side systems. Calendar event content is generally read live from Google at request time and is not permanently stored, with one exception: details of meetings you schedule for or process with the notetaker are retained as part of your workspace history (see Storage, retention, and deletion).
How we share it. Google Calendar data may be shown to other authorized members of your Sindo workspace (see Sharing within your workspace), and is processed by the subprocessors listed below. We never sell it, never use it for advertising, and never use it to train AI models, and we exclude it from the aggregate, de-identified layer described below. Sindo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Sharing within your workspace
Sindo is a multi-member product. Calendar connections are combined across the members of a workspace, so a partner-related meeting sourced from one member's connected calendar may be displayed to other authorized members of the same workspace. Your conversations, documents, and the identities in them are never shared across different customer workspaces (see “Aggregate, de-identified insights” below for the one narrow exception, which contains none of that content). Private sources such as your direct messages remain visible only to you unless you explicitly share them.
How we use your data
We use connected data to provide Sindo's features to your workspace: building timelines, resolving contact identities, and generating AI summaries and answers. Your content is used for your workspace and nothing else. AI processing uses Anthropic's Claude models. By default, Anthropic does not use Sindo's API inputs or outputs to train its models, and Sindo does not opt in to model training. We never sell your data, never use it for advertising, and never share it with third parties beyond the subprocessors needed to run the service. The one use that reaches beyond your workspace is the aggregate, de-identified layer described next.
Aggregate, de-identified insights
Sindo may compute aggregate, de-identified insights derived across workspaces — benchmarks and product intelligence. Data received from Google APIs is excluded from this layer entirely. These insights never contain your conversations, your documents, your names, your counterparties' names, or anything that could identify you or the people you work with, and patterns true of only a small number of workspaces are suppressed rather than published. Anything that would use signal capable of identifying your workspace or a counterparty requires your explicit opt-in, per feature, and is off by default; should any such computation exist, a single setting will remove your workspace from all of it. No computation of this kind runs today — these are the constraints it would run under. The binding version of these commitments is in our terms of service.
Subprocessors
We share data only with the service providers required to operate Sindo:
- Vercel — application hosting.
- Supabase — database and storage.
- Clerk — authentication and workspace membership.
- Anthropic — AI summaries and answers.
- Recall.ai — meeting notetaker bot and transcription.
Connected sources you pull data from— such as Google Calendar, Slack, Telegram, and Granola — are not subprocessors; they are your own accounts that you authorize Sindo to read. They are described under “What we collect” above.
Storage, retention, and deletion
Data lives in your workspace for as long as your workspace exists. A few specifics worth being clear about:
- Disconnecting a source (for example, a Google account) stops all future collection from it immediately and revokes the stored tokens.
- Disconnecting does not delete data already imported. Meetings, transcripts, and summaries created before you disconnected remain in your workspace history until you delete the workspace or ask us to remove them.
- Removing a conversation from a partner room detaches it from that room; the underlying history may remain in your workspace unless you delete it.
- Deleting your workspace removes all associated data from our systems, including any derived contributions attributable to your workspace, which stop feeding future aggregate computation.
To delete your workspace, or to request deletion of specific imported data separately from disconnecting a source, email oren@sindo.io. We complete deletion within 30 days and confirm in writing.
Contact
Questions about this policy: oren@sindo.io.