Skip to content
LynkkGet started free

Legal

Privacy Policy

Last updated: August 6, 2026

This Privacy Policy explains how Lynkk (“Lynkk”, “we”, “us”, or “our”) collects, uses, shares, and protects your information when you use our applications, websites, and services (the “Service”). We aim to collect only what we need to make the Service work for you. Section 1 covers Google user data specifically, including what we access, how we use it, who we share it with, how we protect it, and how long we keep it.

1. Google user data and Limited Use

This section applies to all data Lynkk receives from Google APIs (“Google user data”), and to any aggregated, anonymized, or derived data we produce from it. Where this section is more specific than the rest of this Policy, this section governs Google user data.

1.1 What Google user data we access

Lynkk accesses Google user data only after you connect your Google account, and only through the OAuth scopes you grant. Those scopes, and the exact data each one gives us, are:

  • Google Calendar, read (https://www.googleapis.com/auth/calendar.readonly): your calendar list, and your calendar events, including each event's title, description, start and end time, time zone, location, conferencing (Google Meet) link, recurrence, organizer, attendee names and email addresses, and response status.
  • Google Calendar, write (https://www.googleapis.com/auth/calendar.events): the ability to create or update calendar events. We use it only for the specific events you ask us to create or change, with the title, time, guests, and Meet link you confirm.
  • Sign-in and basic profile (openid, https://www.googleapis.com/auth/userinfo.email, https://www.googleapis.com/auth/userinfo.profile): your Google account identifier, email address, name, and profile picture.

We also store the OAuth access and refresh tokens Google issues for your connection, so the features you enabled keep working without asking you to sign in again.

We do not request or access Gmail, Google Drive, Google Docs, Google Sheets, Google Slides, Google Tasks, Google Chat, Google Contacts, or Google Photos data, and we do not access any Google data outside the scopes listed above.

1.2 How we use Google user data

We use Google user data only to provide and improve the user-facing features you turned on:

  • Showing your schedule: displaying your upcoming and past meetings inside Lynkk so you can see your day.
  • Sending the notetaker bot: using an event's conferencing link and start time to join the calls you selected, at the right moment.
  • Matching and labelling notes: linking a recording to the meeting it came from, and using the event title and attendee list to name and attribute the resulting note.
  • Meeting preparation: producing a brief for an upcoming meeting from the event's title, description, time, and guest list, together with your related past notes.
  • Answering your questions: responding when you ask Lynkk about your own schedule or meetings in chat or by voice.
  • Creating events you ask for: scheduling or updating a calendar event when you request it. We show you the exact event before it is created and act only after you confirm. We never write to your Google account without that confirmation.
  • Identifying your account: using sign-in and profile data to link your Google account to your Lynkk account and to show which account is connected.

We do not use Google user data, raw or derived, for advertising or ad targeting, for credit, lending, insurance, employment, or eligibility decisions, for building profiles to sell, or for any purpose unrelated to the features above.

1.3 Who we share, transfer, or disclose Google user data to

We do not sell Google user data, and we do not transfer it to data brokers, advertising networks, or information resellers. We share it only in these situations:

  • With you, and with anyone you explicitly share a note or meeting with from inside the Service.
  • With service providers who process it on our behalf, under contract, only to deliver the features described above, and only to the extent each one needs. These are: our cloud infrastructure provider (hosting, database, and file storage); MeetingBaas (the notetaker bot, which receives the meeting link and join time so it can join the call you selected); Anthropic (the AI model that writes your meeting brief, summary, and chat answers, which receives the event details needed for that specific request); and Cohere (embeddings for search over your own notes, where a note may contain calendar-derived text such as a meeting title or attendee name).
  • When the law requires it, or where disclosure is necessary to investigate fraud or abuse, enforce our Terms, or protect the rights, property, or safety of our users or the public.
  • In a business transfer, such as a merger, acquisition, or sale of assets, in which case the successor remains bound by this Policy for Google user data, and we will notify you before your data becomes subject to a different policy.

No Lynkk employee or contractor reads your Google user data, except with your explicit consent (for example when you ask for support and authorize it), where it is necessary for security purposes such as investigating abuse, where the law requires it, or where the data has been aggregated and anonymized so it no longer identifies you.

1.4 AI and machine learning: Limited Use compliance

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Lynkk does not use Google user data, whether raw, aggregated, anonymized, or derived, to develop, improve, or train generalized or foundational artificial intelligence or machine learning models, our own or anyone else's. We do not transfer Google user data to any third party that would use it for that purpose.

The AI providers that can receive Google user data are Anthropic (Claude models, used to generate meeting briefs, summaries, action items, and chat and voice answers) and Cohere (embeddings, used only to power search over your own notes). We call both directly over their paid, commercial APIs from our own infrastructure. Their API terms prohibit training on customer data, and we do not opt in to any model-improvement or data-sharing program. Data is sent only to answer the specific request you triggered, and the output is returned to you.

We do not route Google user data through AI aggregators, gateways, or model hubs, and we do not send it to consumer AI chat products. We do not operate self-hosted or offline models on Google user data. If we ever add an AI provider or route that can receive Google user data, we will update this section before doing so, and the Limited Use requirements above will continue to apply.

Our speech-to-text providers (Deepgram and AssemblyAI) process the audio you record. They do not receive Google user data.

1.5 How we protect Google user data

Google user data is protected by the following measures, which are specific to sensitive data and go beyond our general security practices:

  • Encryption in transit: all traffic between your devices, our servers, Google's APIs, and our service providers travels over TLS 1.2 or higher.
  • Encryption at rest: our databases and file storage are encrypted at rest.
  • Additional encryption of credentials: your Google OAuth access and refresh tokens are separately encrypted with AES-256-GCM before being stored, using keys held outside the database, so a copy of the database alone does not yield usable credentials. Keys can be rotated without re-authorizing your account.
  • Access control: every query for Google user data is scoped to the account that owns it. Internal access to production systems is restricted to the small number of personnel who need it, is individually authenticated, and is logged.
  • Least privilege at the source: we request the narrowest Google scopes that support the features we offer, and we store only the calendar fields those features use.
  • Secret handling: API keys and encryption keys are held in the runtime secret store, never in source control, and are not exposed to client applications.
  • Incident response: we monitor for unauthorized access, investigate suspected incidents, and will notify affected users and regulators where the law requires it.

1.6 How long we keep Google user data, and how to delete it

While your connection is active. We keep a mirror of the calendar events relevant to the features you enabled, plus your encrypted OAuth tokens, only for as long as your Google account stays connected. Calendar events that pass out of the window we sync are removed on the next sync.

When you disconnect Google. Disconnecting Google in your Lynkk settings revokes our OAuth tokens with Google (ending our access at Google itself, not only on our side), deletes the stored tokens immediately, deletes the calendar events we mirrored from your account, and stops all syncing. You can also revoke our access at any time from your Google account permissions page, which has the same effect on our ability to reach your data.

Notes from meetings you recorded. If you recorded a meeting, its note and transcript are your own content and stay in your account until you delete them, even after you disconnect Google. Any calendar-derived detail inside such a note (for example the meeting title or an attendee name) is removed when you delete the note.

When you delete your account. Deleting your Lynkk account deletes the associated Google user data, including tokens, mirrored calendar events, and notes, within 30 days, except where we must retain specific records to meet a legal or accounting obligation. Backups are overwritten on a rolling cycle and are purged within 90 days.

Requesting deletion. To request deletion of your Google user data at any time, email us at admin@lynkk.ai and we will action it within 30 days.

1.7 Google API Services User Data Policy

Lynkk's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

2. Information you provide

  • Account information: your name, email address, and authentication details when you sign up or sign in.
  • Your content: audio recordings, uploaded files, transcripts, notes, tags, and the summaries, action items, and decisions generated from them.
  • Meeting and integration data: when you connect a service (such as Google Calendar, Outlook, or Jira), the calendar events, attendees, and related data needed to provide the feature you enabled. For Google, see Section 1.
  • Communications: messages you send us, such as support requests.

3. Information collected automatically

When you use the Service, we collect limited technical and usage data (such as device and app information, log data, and basic feature usage) to operate, secure, and improve the Service.

4. How we use your information

  • provide, maintain, and improve the Service;
  • transcribe your recordings and generate summaries, action items, and search;
  • sync with the integrations you connect and deliver the meeting bot;
  • process payments, prevent fraud, and ensure security;
  • communicate with you about your account and the Service.

5. AI providers and sub-processors

To deliver the Service, we share the minimum necessary content with trusted third-party processors who act on our behalf and process data only to provide their service to us:

  • Speech-to-text: Deepgram and AssemblyAI, to transcribe your audio.
  • AI summaries, extraction, and chat: Anthropic, to generate summaries, action items, decisions, and answers.
  • Search: Cohere, to create the embeddings that power semantic search and related notes.
  • Meeting bot: MeetingBaas, to join online meetings and capture audio.
  • Payments: Paddle, our Merchant of Record, who processes your payment securely. We do not store your full card details.
  • Email and infrastructure: providers such as Resend (transactional email) and our cloud hosting provider.

These processors are bound by contract to use your content only to provide their service to us. We do not permit them to use it to train or improve their own generalized AI or machine learning models. Which of these can receive Google user data, and on what terms, is set out in Section 1.

6. Recording and consent

You are responsible for obtaining any consent required from participants before recording a conversation or using the notetaker bot, as described in our Terms of Service. We process recordings on your instruction to provide the Service to you.

7. How we share information

We do not sell your personal information. We share it only: with the sub-processors listed above; with services you direct us to connect; when required by law or to protect rights and safety; and in connection with a business transfer (such as a merger or acquisition), subject to this Policy.

8. Data retention and deletion

We retain your information for as long as your account is active or as needed to provide the Service. You can delete notes and recordings, and audio retention can be configured in your settings. When you close your account, we delete or de-identify your personal data within 30 days, and purge it from backups within 90 days, except where we must retain it to meet legal obligations. Retention and deletion of Google user data specifically is described in Section 1.6.

9. Security

We use technical and organizational measures (including encryption in transit with TLS, encryption at rest, additional AES-256-GCM encryption of integration credentials, and access controls) to protect your information. No method of transmission or storage is completely secure, but we work to safeguard your data and respond to incidents responsibly. The measures that apply to Google user data are detailed in Section 1.5.

10. Your rights and choices

Depending on your location (for example, under the GDPR or India's DPDP Act), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at admin@lynkk.ai.

11. International data transfers

We and our sub-processors may process your information in countries other than your own, including India and the United States. Where required, we rely on appropriate safeguards for such transfers.

12. Cookies and analytics

We use essential cookies to keep you signed in and to operate the Service, and privacy-friendly analytics to understand aggregate usage. We do not use cookies for cross-site advertising.

13. Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, please contact us so we can remove it.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will update the “Last updated” date above and, for material changes, provide additional notice where appropriate.

15. Contact us

Questions about your privacy or this Policy? Email us at admin@lynkk.ai.