1. Information We Collect
Types of data gathered during application usageWhen you use Gramola services, we gather specific categories of information necessary to deliver accurate automated meeting transcriptions, action items generation, and workspace collaboration.
Account & Identity Information
We collect your name, business email address, organization name, authentication credentials, and chosen workspace preferences when registering an account.
Conversational & Meeting Input Data
Audio streams, recorded meetings, user-uploaded audio/video files, participant metadata (names, timestamps, screen sharing metadata where permitted), and conversational notes submitted for transcription analysis.
Technical & Operational Telemetry
Device IP addresses, browser specifications, operating system versions, diagnostic log data, and latency statistics required to maintain high transcription fidelity.
2. Audio & Transcription Processing
How conversational streams are converted into actionable notesGramola utilizes advanced deep learning speech-to-text engines and contextual language models to process spoken conversations. Audio data is streamed over TLS 1.3 encrypted connections directly into isolated processing pipelines.
Encryption in Transit
All audio streams and API requests utilize industry-standard TLS 1.3 cryptographic protocols with modern cipher suites.
Encryption at Rest
Transcripts, meeting summaries, and stored audio clips are stored using AES-256 bit encryption in SOC2-compliant data centers.
While we employ defensive measures and rigorous engineering standards, no networked electronic storage or transmission method is entirely immune from potential security vulnerabilities.
3. Zero-Model Training Stance
Our strict commitment regarding proprietary data & AI modelsWe believe your business conversations, client discovery calls, internal standups, and strategy sessions belong exclusively to you. We uphold strict organizational and architectural boundaries:
No General Model Training
Gramola does NOT sell, license, or use your raw audio recordings, transcripts, summaries, or structured conversation insights to train, fine-tune, or improve public foundational AI models.
- Model inference requests are processed in stateless or segregated zero-data-retention environments.
- Enterprise tenants benefit from dedicated tenant isolation and custom retention policies.
- Customer data is never accessible to other customers or third-party advertising vendors.
4. Retention & Erasure Policies
Control how long meeting records and voice files persistWe preserve personal and conversational data only as long as necessary to fulfill user requests, satisfy workspace administration rules, or comply with legal obligations.
| Data Type | Standard Retention | User Control |
|---|
| Raw Audio Streams | Deleted immediately after transcript generation unless auto-archive is activated | Configurable in Workspace Settings |
| Meeting Transcripts & Summaries | Retained for active account duration or until manual deletion | Instant permanent erasure via user dashboard |
| Diagnostic Error Logs | 30 days rolling cycle for infrastructure telemetry | Automated system purge |
When an account is closed or a deletion request is confirmed, all associated conversation transcripts, embeddings, and action lists are purged from active and replica databases within 30 days.
5. Third-Party Service Providers
Vetted infrastructure and processing partnersTo deliver reliable real-time transcription and robust cloud architecture, we partner with specialized infrastructure and computational service vendors. Every vendor undergoes thorough data privacy evaluations and signs strict Data Processing Agreements (DPAs):
Cloud Hosting & Storage
AWS & Google Cloud Platform secure server facilities located in the United States and European Union regions.
Billing & Subscriptions
PCI-DSS Level 1 compliant payment gateways. We never store credit card numbers on Gramola servers.
6. Your Rights & Access Controls
Exercising your GDPR, CCPA/CPRA, and statutory privacy rightsDepending on your geographic location, you hold specific legal rights concerning your personal information:
Right to Access & PortabilityExport your meeting transcripts, summaries, and action checklists in JSON, PDF, or Markdown formats at any time.
Right to Rectification & ErasureModify inaccurate transcript records or request complete deletion of your workspace data history.
Right to Object & Restrict ProcessingWithdraw consent for specific optional integrations, notifications, or diagnostic metrics tracking.
7. Data Protection Office
Direct communication channels for privacy inquiriesIf you have any questions regarding this Privacy Policy, wish to execute data subject requests, or need a signed Data Processing Agreement (DPA) for your enterprise organization, please reach out to our team: