Privacy Policy
Effective 10 October 2026
SmritiOS turns meetings into transcripts, summaries and tracked tasks. That means we handle conversations, so we try to collect only what the product needs and to be plain about it. This policy explains what we collect, why, who helps us process it, and how you can control it.
1. Who we are
SmritiOS (smritios.com) is operated by SmritiOS in India. For the data you put into SmritiOS, we decide why and how it is processed, so we are the "data fiduciary" under India's Digital Personal Data Protection Act, 2023 (the DPDP Act). Contact us at support@smritios.com.
The DPDP Rules were notified in November 2025 and most duties start later in a phased way. We already follow the principles the law sets out: tell you what we collect and why, ask for consent where needed, keep data secure, and let you access, correct and delete it. Until the new rules apply in full, the Information Technology Act, 2000 and its rules also apply.
2. What we collect
- Account details: name, email address and a password (stored only as a salted hash, never in readable form). If you use Google sign-in, we receive your Google account ID, email, name and profile picture.
- Meetings you send us: when you ask the SmritiOS bot to join a call, or upload a recording, we capture the audio and video of that meeting, and create a transcript, summary, decisions and action items from it. We also keep the meeting title, link and time.
- Workspace content: tasks and comments, images you attach to tasks, team channel messages and files, mentions, notifications, and your questions to Ask Smriti with its answers.
- Google Calendar (only if you connect it): the titles, times, meeting links and calendar names of upcoming events from the calendars you choose. See section 4.
- Technical data: device and browser details (such as your user-agent) tied to your sign-in sessions, IP address and error reports, used to keep your session secure and fix bugs.
- Cookies and analytics: see section 9.
We do not ask for payment card details today. When paid plans launch, payments will be handled by a payment provider and we will update this policy.
3. How we use it
- To provide the product: record and transcribe meetings, write summaries and action items, search your workspace and answer your questions.
- To run your account: sign you in, send verification, reset-password and mention emails, and show notifications you asked for.
- To keep the service safe and working: prevent abuse, debug problems and measure reliability.
- To understand how the website is used, but only if you accept analytics cookies.
We do not sell your data, and we do not use your meeting content to train our own AI models.
4. Google user data
This section covers information we receive from Google when you sign in with Google or connect Google Calendar.
- Sign-in: we ask only for basic profile access (your ID, email, name and picture) to create or find your account.
- Calendar (optional, read-only): if you choose "Connect Google Calendar", we ask for read-only access to your calendars. We list your calendars so you can pick which to show, and copy the next 14 days of events from the ones you pick (title, time, link, calendar name) so they appear on your SmritiOS calendar. We never create, change or delete anything in your Google Calendar.
- Bot joins only when you say so: an event is used to send the bot only if you switch on "Smriti bhejo" for that event. It is off by default.
- Who sees it: Google user data is not shared with, sold to or transferred to anyone else. It stays in your workspace and in the hosting and database providers listed in section 5 that store it for us. It is never used for advertising, never sold to data brokers, and never used to make credit or lending decisions.
- No AI training: we do not use Google user data (your profile details or calendar events) to develop, improve or train generalized or non-personalized AI or machine-learning models.
- Storage: events are stored in our database. The refresh token that lets us keep syncing is stored encrypted.
- Stop at any time: choose Disconnect in SmritiOS, or remove SmritiOS at myaccount.google.com/permissions. Disconnecting deletes the stored token and the copied events and revokes our access.
SmritiOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In practice: we use Google user data only to provide the features you see in the app; we do not transfer it to others except to run the service with your consent, for security, or as the law requires; we do not use it for advertising or sell it; and people at SmritiOS do not read it unless you ask us to, it is needed for security or abuse investigation, or the law requires it.
5. Who processes data for us
We use trusted providers to run SmritiOS. They process data on our instructions, only for the purpose listed:
- Google (Gemini): generates summaries, action items, embeddings for search, and Ask Smriti answers from your meeting and workspace text.
- Deepgram and Sarvam AI: turn meeting audio into transcripts, chosen by the language spoken.
- Groq (optional): a second AI opinion when we detect tasks in team chat messages.
- Cloudflare: private object storage for recordings, uploads, channel files and task images.
- DigitalOcean and Contabo: the servers that run the app and the meeting bot.
- A managed cloud database (PostgreSQL) and Redis for application data and background jobs.
- Zoho ZeptoMail: sends our account and notification emails.
- Sentry: collects error reports so we can fix bugs.
- Google Analytics: website statistics, only after you accept analytics cookies.
- Meta (Facebook and Instagram) and LinkedIn: measure how our ads perform on the public website, only after you accept analytics cookies.
Some of these providers are outside India, so your data may be processed in other countries. We share only what a provider needs for its task.
6. Recording meetings and other people
When the bot joins a call, it appears as a participant named "SmritiOS Notetaker". The person who sends the bot is responsible for telling the other participants that the meeting is being recorded and transcribed, and for getting any consent the law or their organisation requires. Recordings, transcripts and summaries are visible to members of the workspace that the meeting belongs to, according to their role. If you were in a meeting and want your voice or words removed, ask the workspace owner, or write to us at support@smritios.com.
8. How long we keep data, and deleting it
We keep your account and workspace content while your account is active. You can delete tasks, meetings and attachments inside the app. To delete your account and the personal data tied to it, write to support@smritios.com; we complete verified requests within 30 days, except where we must keep something by law. Copies in backups are removed as the backups expire. Disconnecting Google Calendar deletes the copied events and the stored token straight away.
How we protect it: connections use HTTPS; passwords are stored hashed; Google Calendar tokens are encrypted; files sit in private storage and are shown through time-limited links; sign-in cookies are not readable by page scripts; and access to workspace content is checked against your workspace membership. No system is perfectly secure. If a breach affects you, we will tell you and the authorities as the law requires.
10. Your rights and how to use them
You can ask us to:
- give you a summary of the personal data we hold about you and how it is processed;
- correct inaccurate or incomplete data (most of it you can edit in the app);
- erase your data;
- withdraw a consent you gave, such as disconnecting Google Calendar or declining analytics cookies;
- nominate someone to exercise your rights if you die or cannot act.
Email support@smritios.com from the address on your account. We reply within 30days. If you are not satisfied, write to the same address marked "Grievance" and we will resolve it; you may also complain to the Data Protection Board of India once it is operating.
11. Children
SmritiOS is for people aged 18 and over. We do not knowingly collect data from children. If you think a child has given us data, write to support@smritios.com and we will delete it.
12. Changes to this policy
If we change what we collect or how we use it, we will update this page and the date above, and tell you in the app or by email for material changes. If we ever want to use Google user data in a new way, we will ask for your consent first.
13. Contact
SmritiOS, India. Email: support@smritios.com. Please put "Privacy" or "Grievance" in the subject.