← Back to Trunked

Privacy

Privacy policy

Trunked is a desktop app that records calls you are in and turns them into notes you can search and ask questions about. This policy covers the Trunked website at trunked.ai, the Trunked desktop app for macOS and Windows, and the Trunked API at api.trunked.ai. It explains what we collect, how we use it, who we share it with, how we protect it, and how long we keep it.

Summary

  • We collect your account details, the calls you choose to record, and the transcripts and notes made from them.
  • If you connect Google Calendar, we read your upcoming events so the app can show them and remind you to record. We do not copy your calendar into a database.
  • We do not sell your data, and we do not use your meeting content or your Google user data for advertising.
  • We use your recordings, transcripts and notes only to provide the features you request, maintain the service and meet legal obligations.
  • You can delete your account data at any time, in the app or by writing to us.

What we collect

Account information. Your email address, and your name and profile picture when you sign in with Google or Microsoft. If you sign in with a one-time email code, we store your email address only. We also store the answer you give to the question about what you do for work, if you answer it.

Recordings and meeting content.Audio captured from your microphone and your computer's audio output during calls you start, the transcripts made from that audio, the notes you write, the notes our AI generates, meeting titles, the names and email addresses of participants you or your calendar supply, the folders you file meetings in, and the questions you ask our chat about your meetings.

Calendar information. Only if you connect a calendar. See Google user data below.

Usage and diagnostics. Page views, presses, feature usage, app version, operating system, referring campaign parameters, IP address, crash and error reports, and session replays. Session replay in the app and on the shared note page masks every input and every text node, so your notes, transcripts, chats, participant names and sign-in codes are never recorded in a replay.

Support messages. What you write to us in the in-app support chat, which runs on Crisp.

Google user data

This section describes what Trunked does with data obtained through Google APIs.

What Google user data we access

Sign-in with Google (scopes openid, email, profile): your Google account identifier, email address, name and profile picture. We use this to create and identify your Trunked account.

Google Calendar (scope https://www.googleapis.com/auth/calendar.readonly), requested only when you choose to connect a calendar, and never as part of signing in:

  • Your calendar list: each calendar's identifier, name and colour. The identifier of your primary calendar is your Google account email address.
  • Events in the next seven days on the calendars you have not hidden: event identifier, title, start and end time, location, description, conferencing links such as Google Meet, Zoom or Microsoft Teams, attendee names and email addresses, and your own response status so declined meetings can be left out.

The access is read-only. Trunked cannot create, change or delete anything in your Google Calendar.

How we use Google user data

  • To show your upcoming meetings in the app and the menu bar.
  • To alert you shortly before a meeting starts, so you can decide whether to record it.
  • To open the meeting's conferencing link when you start a recording from that event.
  • To fill in the meeting's title and participant list when you start a recording from that event.

We use Google user data only to provide and improve these user-facing features. We do not use it for advertising, targeting, profiling, credit or lending decisions, or resale.

What we store

Calendar reads are live. Each read asks Google for the next seven days, answers the app, and is discarded. We keep no events table, no sync tokens and no calendar webhooks, and we run no background calendar sync.

The exception is a meeting you record from a calendar event. That meeting record in your library keeps the event identifier, the event title as the meeting title, and the attendee names and email addresses as the meeting's participants. That copy sits in your own library and is removed when you delete the meeting or your account.

Your Google OAuth tokens are stored encrypted in our database, so the app can read your calendar without sending you back to a browser each time.

Who we share Google user data with

We do not sell Google user data. We do not transfer it to third parties for advertising, data brokerage, information resale, credit assessment or unrelated purposes. We share it only with the service providers that run Trunked on our behalf, under contracts that limit them to processing it for us:

  • Vercel (United States) hosts the API that reads your calendar and serves the app.
  • Neon (United States) hosts the database that stores your encrypted OAuth tokens, and the title and participants of any meeting you recorded from an event.
  • Vercel AI Gateway and Google Gemini process the meeting record when you ask Trunked to write notes or answer a question about a meeting. If that meeting came from a calendar event, its title and participant names are part of what is processed. This happens only to produce your requested notes and answers.

We do not send calendar content to our analytics or advertising tools. Analytics records only that a calendar was connected and which provider it was.

We disclose data when the law requires it. If Trunked is involved in a merger or acquisition, this policy continues to apply to transferred data until you are given notice of a change.

How we protect Google user data

Google user data is encrypted in transit using HTTPS with TLS. Google OAuth tokens and stored event details are encrypted at rest. Database access is scoped to the account that owns the data, and access to production systems is limited to the people who need it to run the service.

How long we keep Google user data, and how to remove it

  • Calendar reads are not retained. Nothing from a read is written to storage.
  • OAuth tokens are kept until you disconnect the calendar, delete your account data, or revoke access in your Google Account.
  • Event details attached to a meeting you recorded are kept until you delete that meeting or your account data.

You can remove Google user data in these ways:

  • Disconnect the calendar in Trunked settings.
  • Revoke Trunked's access at myaccount.google.com/permissions.
  • Delete your account data in Trunked settings, or write to team@trunked.ai. Deleting your account data deletes your stored OAuth tokens and provider connections, your sessions, your contacts directory, your folders, your chats and your share links, and blanks the content of your meetings. We complete deletion requests within 30 days.

Limited Use

Trunked's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Microsoft calendar data

If you connect an Outlook or Microsoft 365 calendar, we request the Calendars.Read and offline_access scopes and read the same fields for the same purposes, under the same storage, sharing, retention and deletion rules described above for Google Calendar.

How we use your other information

  • To record calls you start, transcribe them, generate notes, name meetings and answer your questions about them.
  • To keep your library available across your devices and to the people you share a folder with.
  • To send you sign-in codes, workspace invitations you asked for, and the install link for the app.
  • To measure which parts of the product are used, diagnose crashes, and measure which marketing campaigns lead to installs.
  • To answer your support messages.
  • To meet legal obligations and to prevent abuse.

Sharing a meeting note produces a secret link. Anyone who has the link can read that note, and the transcript too if you chose to include it. The page is marked so search engines do not index it. Turning the link off deletes it permanently and it never works again.

Who processes your data

We do not sell your data. We share it with the service providers below, who process it on our behalf and only for the purposes we set for them:

  • Vercel (United States): hosting for the website, the API and the AI Gateway.
  • Neon (United States): the Postgres database holding accounts, meetings, notes, transcripts and settings.
  • Amazon Web Services (S3) (United States): storage for recorded audio and app downloads.
  • AssemblyAI (United States): speech to text for your recordings.
  • Google Gemini through Vercel AI Gateway: generating notes and titles, and answering your questions about your meetings.
  • PostHog (United States): product analytics, error reporting and masked session replay.
  • Resend (United States): sign-in codes, invitation and install emails.
  • Crisp (European Union): the in-app support chat.
  • Google Ads and Meta: website and download conversion measurement only. They receive campaign identifiers and a hashed email address for conversion matching. They never receive your recordings, transcripts, notes or calendar.

Trunked is operated from the United States and your data is processed there. Where you are in the European Economic Area, the United Kingdom or Switzerland, transfers rely on the standard contractual clauses our providers maintain.

How we protect your data

  • All traffic between the app, the website and our API runs over HTTPS with TLS.
  • Data in our database and in object storage is encrypted at rest.
  • OAuth tokens for Google and Microsoft are encrypted before they are written to the database.
  • Recorded audio sits in a private bucket with public access blocked and access control lists disabled. It is reachable only through short-lived signed URLs issued to you.
  • Every database query is scoped to the account that owns the row, so one account cannot read another's data. A resource you cannot see answers as if it does not exist.
  • The desktop app seals its session credentials with the operating system keychain before writing them to disk, and holds no password.
  • We use one-time email codes and provider sign-in. There is no password to guess or leak. Stored one-time codes are hashed.
  • Session replay masks every input and every text node, so your content is not captured in recordings of the interface.
  • Access to production systems is limited to the people who need it to run the service.

No service can promise perfect security, but these controls are in place and we review them when the data path changes.

How long we keep data

  • Account information: until you delete your account data.
  • Meetings, transcripts and notes: until you delete the meeting or your account data.
  • Recorded audio: retained in encrypted storage as the original record of the call. Deleting a meeting or your account removes the transcript, notes, title and participants and takes the recording out of the app. Write to us if you need the underlying audio files erased as well.
  • Calendar data: as described in the Google user data section. Reads are not retained.
  • Analytics and error events: retained by PostHog, Google and Meta under their configured retention periods.
  • Support conversations: retained by Crisp until we delete the thread.

When a retention period ends, or when you ask us to delete data, we delete or blank it.

Your rights and choices

Depending on where you live, you can ask us for a copy of your data, ask us to correct it, ask us to delete it, object to a particular use, or ask us to hand it to another service. Delete your account data in Trunked settings, or write to team@trunked.ai. We answer within 30 days and we do not charge for it. If you are in the European Economic Area or the United Kingdom, you can also complain to your data protection authority.

You can clear Trunked site data, use your browser's tracking controls, and use Google and Meta advertising controls to limit measurement.

Trunked is not for children. Do not use it if you are under 16.

Recording responsibly

Trunked records from your computer instead of joining your call as a bot. Recording state is visible in the app while it runs. Trunked does not invite itself to meetings, message participants, or publish your notes. Follow the consent and recording laws that apply to your call, and tell participants when you are required to.

The website

You do not need an account, a password or a payment card to download the app. PostHog measures page visits and which call to action was pressed. Google's ads tag measures verified download and registration conversions. Meta's browser pixel measures page visits and the same presses. A button press is not reported as a completed install.

For attribution we process a sanitized landing URL, campaign parameters, Google click identifiers, Meta click and browser identifiers, IP address, user agent, the location of the download button, and the platform. Only after the download service issues a signed installer URL does the server record a download request. Where an email address is used for conversion matching, it is hashed by Google's tag in your browser and by PostHog before it reaches Meta.

Nothing is carried inside the installer, and the app is not linked to the download that fetched it. This marketing path never receives meeting audio, transcripts, notes or calendar data.

Changes and contact

If the data path changes materially, we update this page before the change reaches the product, and we change the date below. For privacy questions, access requests or deletion requests, contact us at team@trunked.ai.

Last updated: August 13, 2026