Privacy Policy

Last updated: August 2026

AgreeLoop stores meeting minutes, contacts, and workspace data in Supabase (EU region). Voice capture records audio on your device and uploads it to our servers, which forward it to OpenAI to be transcribed. The recording on your device is deleted as soon as transcription finishes. We never store the audio itself — it is held in memory only while in transit, and is never written to our database or to any file storage.

Scanning a business card works the same way. The photo you take or choose is uploaded to our servers and forwarded to OpenAI to read the name, title, company, phone, and email off it. Only those five fields are returned, and only the ones you keep are saved to your contact. We never store the photo — like audio, it is held in memory only while in transit and is never written to our database or to any file storage.

What we collect

AI processing

OpenAI is our AI provider. Your audio is sent to OpenAI to be transcribed, the resulting transcript is sent to OpenAI to be structured into a minute, and a business-card photo is sent to OpenAI to have the contact details read off it.

OpenAI retains API inputs and outputs for up to 30 days for abuse monitoring before deleting them, and processes API traffic primarily on US infrastructure. So while your records are stored in the EU, your audio, your minute text, and any business-card photo you scan are processed outside that region and are held briefly by OpenAI before deletion.

Your content is not used to train models, and that rests on two things rather than our word alone. The OpenAI API does not train on data sent through it unless an organisation explicitly opts in, and AgreeLoop keeps every provider data-sharing option — input/output, feedback, and evaluation or fine-tuning — switched off on all our projects.

Email delivery

We send email through Resend. Three kinds of message go through it, and they carry different amounts of your content.

Recipient verification codes carry only the code. Notifications to a sender when their counterparty responds carry that counterparty’s name and what they did — confirmed, agreed, or suggested a change — but no part of the record itself.

The weekly manager digest carries more, and we would rather say so plainly than let you find out from an inbox. It is sent to a company workspace’s owners, admins and managers, and it lists the records sealed in the period: the workspace name, the dates the period covers, how many records were sealed and how many are still awaiting a counterparty, and for each record its title, who wrote it, and the date it was sealed. Where a record has no title, the digest falls back to the opening of its summary, so a line of the minute text itself can appear. The digest links to the console rather than to individual records, so no per-record link is left sitting in a mailbox — but the titles and any fallback summary text do sit in Resend’s logs and in the recipients’ mailboxes, and they are replicated wherever that email is forwarded.

A manager can switch the digest off for their workspace at any time in the workspace settings, which stops it being generated at all.

Who can read a record inside a company workspace

An official record filed into a company workspace belongs to that company, and the workspace’s owners, admins and managers can open it and read it in full — the summary, the key points, the decisions, the action items and any follow-ups. This is the same standard model a CRM uses: your own work is private from your peers, and visible upward to the people accountable for it. Other members of the workspace cannot read a record they did not write.

Two things are deliberately outside that. The raw dictation a record was generated from is never shown — it is what you said before you reviewed and edited it, so the record you approved is what the workspace sees, not the draft behind it. And a record in your personal workspace is not visible to a company manager at all, under any role.

What we do not do

Contact

Questions: privacy@agreeloop.app