Privacy

Privacy Policy

Caspi is built to be discreet by default. This policy explains what we collect, how meeting data is handled, and the control you keep over it.

Last updated: July 20, 2026

Caspi is a product of Garcini Media Inc. ("Garcini Media," "we," "our," "us"), a company incorporated in the Province of Québec, Canada. We build a discreet assistant that listens to your meetings in real time. Privacy is the entire point of the product, and this policy explains what we process and the control you keep.

1. What we process

  • Meeting audio & transcripts. While a meeting is running, audio is transcribed in real time to power your live recap, suggested questions and chat.
  • Saved meetings. Only the meetings you choose to keep are stored in your private meeting memory for later recall.
  • Account & connection data. The email you sign up with and encrypted tokens for the tools you connect (Linear, Notion, Slack, and others).
  • Google user data. If you connect a Google account or Google Workspace account, Caspi may access the specific Google data you authorize through Google OAuth, including your Google account identifier, email address, basic profile information, Gmail message metadata and message content, Google Drive file metadata and supported file content from Drive, Docs, Sheets and Slides, and Google Calendar event details such as titles, descriptions, times, locations, organizers, attendees, response status and meeting links. Caspi accesses this data only for the connected Google services you choose to enable.

2. How we use it

  • To transcribe your meetings and power live recap, suggested questions and chat.
  • To create tasks, notes and follow-ups in the tools you connect.
  • To use Google user data only for the user-facing Caspi features you request, such as showing relevant calendar context, preparing for upcoming meetings, answering your questions with context from Gmail, Drive, Docs, Sheets, Slides and Calendar, drafting follow-ups, creating Google Docs, and creating Google Calendar events that you approve.
  • To provide support when you contact us.
  • To keep the service secure and prevent abuse.

3. Google API data use

Caspi's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We request Google permissions only when they are needed for a visible Caspi feature and only after you authorize access through Google OAuth.

  • Data accessed. Depending on the permissions you grant, Caspi may access your Google account identifier, email address, basic profile information, Gmail messages and headers, Google Drive file names, file metadata, sharing-related metadata returned by Google APIs, supported Drive file content, Google Docs, Sheets and Slides content exported through Drive, and Google Calendar event details including event title, description, location, meeting link, organizer, attendee emails, RSVP status, start time and end time.
  • Data usage. We use Google user data to provide and improve the Caspi features shown to you in the product, including surfacing meeting context, preparing briefs for upcoming meetings, answering your questions, checking whether discussed work already exists, drafting meeting notes or follow-ups, creating Google Docs, and creating Google Calendar events only when you request or approve that action.
  • Google feature details. Gmail access is read-only: Caspi can list, search and read messages, but does not send, modify, archive, label or delete Gmail messages. Drive access is used to find, list, preview and read relevant files; Caspi creates or edits Google Docs only after you approve a document action. Calendar access is used to read events for scheduling, meeting preparation and calendar views, and to create follow-up events that you approve; Caspi does not delete calendar events.
  • Data sharing. We do not sell Google user data. We do not transfer Google user data to advertising platforms, data brokers, information resellers, credit-worthiness services, or personalized advertising providers. We share Google user data only with service providers that help us operate Caspi, process data securely on our behalf, and deliver the user-facing features you requested, or when required for security, legal compliance, or a business transfer with required user notice or consent.
  • Human access. Garcini Media personnel do not read your Google user data unless you give us explicit permission for support, it is necessary to investigate security or abuse, or it is required by law.
  • AI/ML training. We do not use Google user data to train generalized AI or machine learning models. We do not transfer raw or derived Google Workspace API user data to third-party AI or ML services for the purpose of training generalized models. When AI processing is used to provide a Caspi feature you requested, it is limited to producing that user-facing result and is not used to train a generalized model.

4. What we never do

  • We never sell your data.
  • We never use your meeting content to train models.
  • We never use Google user data for advertising or retargeting.
  • We never sell, rent or transfer Google user data to advertisers, data brokers, information resellers, credit-worthiness services or similar third parties.
  • We never use raw or derived Google Workspace API user data to train generalized AI or machine learning models.
  • We never use Google user data for lending, credit eligibility, ad targeting, user profiling for advertising, or any other prohibited use under the Google API Services User Data Policy.
  • We never show the Caspi panel to other participants - it is hidden from screen sharing and screen capture.
  • We never track you across other websites or apps - this site uses no advertising cookies or third-party analytics trackers.

5. Data retention & deletion

Meeting audio is processed in real time to generate your transcript and is not retained afterwards unless you choose to save the meeting. Saved meetings, transcripts and connection tokens are kept until you delete them or close your account.

Google OAuth tokens are retained only while your Google connection is active. Google user data that Caspi stores as part of saved meetings, notes, drafts, or workspace memory is retained until you delete the relevant item, disconnect Google, or close your account. When you disconnect Google, we revoke or delete the stored Google connection tokens and stop accessing new Google user data.

You can delete a saved meeting, disconnect a tool, or delete your account at any time from Settings, or by emailing privacy@caspi.io. Deleting your account erases the associated data within 30 days, except for limited records we must keep to comply with tax, accounting or other legal obligations.

6. Storage & security

Saved meetings and embeddings are stored in your own workspace. Integration tokens are encrypted at rest, and data is encrypted in transit. Access to production systems is limited to authorized personnel bound by confidentiality obligations.

Google OAuth tokens and Google user data are protected using encryption in transit and at rest, access controls, least-privilege internal access, logging where appropriate, and operational safeguards designed to prevent unauthorized access, disclosure, alteration, or destruction.

7. Third-party processors & international transfers

To transcribe and reason over meetings, audio and text are processed by our AI model providers solely to deliver the feature you requested. These providers are contractually bound not to train on your data. Some processors may be located outside Canada, including in the United States or the European Union. Where your data crosses borders, we rely on contractual and security safeguards to protect it to a standard consistent with Québec's privacy legislation and Canada's federal privacy law (PIPEDA).

8. Children's privacy

Caspi is not directed to children, and you must be at least 16 years old to use it. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact privacy@caspi.io and we will delete it.

9. Your rights

Depending on where you live, you may have rights under Québec's privacy legislation, Canada's PIPEDA, the EU/UK GDPR, or the California CCPA, including the right to access, correct, port or delete your data, and to withdraw consent. To exercise any of these rights, contact privacy@caspi.io; we will respond within the timeframe required by applicable law. If you are not satisfied with our response, you may lodge a complaint with your local data protection authority, such as Québec's Commission d'accès à l'information.

10. Changes to this policy

We may update this policy as Caspi evolves. If we make material changes, we will update the date above and, where required, notify you directly, such as by email or in-app notice.

11. Contact

Garcini Media Inc. is the organization responsible for the personal information described in this policy. To reach the person accountable for its protection, or to exercise any of the rights above:

Garcini Media Inc. (operator of Caspi)
Province of Québec, Canada
Email: privacy@caspi.io
Website: https://caspi.io