Synopsist

Privacy Policy

Effective date: June 9, 2026 · Last updated: August 15, 2026

Synopsist ("we", "our", or "us"), a product of Mestor Technologies LLC, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our AI-powered executive summary platform at synopsist.ai.

1. Information We Collect

We collect the following categories of information:

  • Account information: Your name, email address, firm name, and password (stored as a secure hash).
  • Meeting transcripts and notes: Text content you upload manually, or that is automatically retrieved when you connect a supported meeting platform — Google Meet (via real-time push notifications from the Google Workspace Events API, with transcripts processed automatically when the meeting ends), Zoom (via recording webhook), Microsoft Teams (via Microsoft Graph webhook), or Webex (via meeting transcript webhook). The full text content of these files is read and sent to our AI provider to generate summaries.
  • Connected meeting platform account data: If you connect Google, Zoom, Microsoft, or Webex, we store OAuth access and refresh tokens to retrieve transcripts on your behalf. For Google, we use the Workspace Events API to receive push notifications when a meeting ends, then process the transcript automatically. If you configure cloud storage output, we also write branded PDF and DOCX files to the Google Drive folder you designate. For Zoom, Microsoft Teams, and Webex, we receive a webhook notification when a transcript becomes available and retrieve only that specific transcript — we do not browse your broader account or recordings. If you configure OneDrive as a cloud storage output destination, we write branded PDF and DOCX files to the OneDrive folder you designate.
  • Calendar data (optional): If you separately connect your Google Calendar or Microsoft Calendar in Integrations, we read the start time and meeting link of your upcoming events so we can automatically schedule an AI notetaker for meetings on a platform you've opted into. This is a distinct, optional connection from the meeting-platform connections above — see Section 5.
  • Payment information: Billing is handled entirely by Stripe. We do not store credit card numbers or payment details on our servers.
  • Usage data: Summary count, account activity, and session information for security and product improvement purposes.

2. How We Use Your Information

  • To generate AI-powered executive summaries from your meeting transcripts and notes.
  • To automatically detect and process new meeting transcripts from your connected platforms (Google Meet via Workspace Events API push notifications, Zoom, Microsoft Teams, and Webex).
  • To upload branded PDF and DOCX summary files to your designated Google Drive or OneDrive folder, if you have configured cloud storage output in Integrations.
  • To deliver summaries and notifications via email, including DOCX and PDF attachments.
  • To process payments and manage your subscription.
  • To authenticate your account and maintain security.
  • To improve and maintain the platform.

3. Google Account Access — Scope and Limitations

Google API Services — Limited Use Compliance

The use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

When you connect your Google account, Synopsist is granted permission to access Google Meet activity and Google Drive. We limit this access as follows:

  • We subscribe to the Google Workspace Events API to receive a real-time push notification when one of your Google Meet meetings ends. We do not poll or monitor your account continuously.
  • Upon receiving a meeting-end notification, we retrieve only the transcript file associated with that meeting from your Google Drive.
  • We read the full text content of the transcript solely to generate your executive summary.
  • If you configure a Cloud Storage Output folder for Google Meet in Integrations, we write branded PDF and DOCX files to that specific folder only. We do not access any other folders.
  • We do not modify, delete, move, or share any of your existing Drive files.
  • Synopsist platform administrators may view transcript retrieval logs and manually trigger summary generation for specific meetings. This is done solely for support and operational purposes.
  • We request only the meetings.space.readonly and drive.file scopes, plus your basic profile and email address. drive.file limits us to files you have opened with or created through Synopsist — we cannot browse or read the rest of your Drive.
  • You can disconnect at any time from your Security settings or directly from your Google Account permissions page. Disconnecting deletes your stored OAuth tokens, cancels the Workspace Events subscription immediately, and revokes Synopsist's authorization with Google once no other Google connection on your account is still using it.

Synopsist does not use Google user data to train AI models, serve advertising, or share with third parties beyond what is necessary to generate your summary. Our AI provider (Anthropic) processes transcript text solely to return a summary response and does not use it to train generalized models. Synopsist's use of Google user data is limited strictly to the purposes described in this policy.

4. Zoom, Microsoft Teams & Webex Access — Scope and Limitations

When you connect a Zoom, Microsoft Teams, or Webex account, Synopsist's access is limited as follows:

  • We receive a webhook notification from the platform only when a meeting transcript becomes available.
  • We retrieve only that specific transcript — we do not browse, list, or access any other meetings, recordings, files, calendar entries, or account data.
  • We read the full text content of the transcript solely to generate your executive summary.
  • We do not modify, delete, or share any data within your Zoom, Microsoft, or Webex account.
  • You can revoke our access at any time from your Security settings page, or directly from the platform's own connected-app permissions page. Revoking access deletes your stored OAuth tokens immediately.

5. Calendar Access — Scope and Limitations

If you choose to connect your Google Calendar or Microsoft Calendar in Integrations, Synopsist can automatically schedule an AI notetaker to join and record a meeting on your behalf, instead of relying on your meeting platform's own cloud recording. This is a separate, optional connection — it does not happen automatically when you connect Google Meet, Zoom, Microsoft Teams, or Webex above.

  • We request read-only access to calendar events only (Google's calendar.events.readonly scope, or Microsoft's Calendars.Read permission), together with your email address (userinfo.email) so we can show you which account is connected. We cannot create, edit, move, or delete any calendar event, and this narrower events-only permission means we also cannot see your list of calendars, their sharing permissions, or your calendar account settings.
  • We read only the start time and meeting link (for example, a Zoom, Google Meet, Microsoft Teams, or Webex URL) of your upcoming events — not attendee lists, descriptions, attachments, or any other event content.
  • To provide this feature, we share your calendar's OAuth refresh token with our notetaker infrastructure provider, Recall.ai, which watches the calendar directly and schedules the notetaker bot on our behalf. This differs from the integrations above, where Synopsist itself retrieves data via webhook — here, Recall.ai acts on the calendar using access granted specifically for this feature. See Third-Party Service Providers below.
  • A notetaker is scheduled only for a meeting whose platform you have separately turned to "Notetaker" mode in Integrations. If a platform is left on its default ("Silent") setting, we still read that event's meeting link to check it, but do not schedule a bot for it.
  • Disconnecting your calendar (from Integrations) deletes your stored refresh token, cancels any notetaker bots already scheduled for future meetings, tells Recall.ai to stop watching the calendar, and revokes Synopsist's authorization with Google. If you also have Google Meet/Drive connected, that connection keeps working and the authorization is revoked when you disconnect it as well.

6. Third-Party Service Providers

We share data with the following trusted service providers solely to operate the platform:

  • Anthropic: Meeting transcript text is sent to Anthropic's Claude API to generate summaries. Data is processed per Anthropic's privacy policy.
  • Google: OAuth tokens are used to access your Meet Recordings folder on Google Drive, and — if you separately connect Google Calendar — your calendar event times and meeting links. Data is processed per Google's privacy policy.
  • Zoom: OAuth tokens and webhook notifications are used to retrieve meeting transcripts you've authorized. Data is processed per Zoom's privacy policy.
  • Microsoft: OAuth tokens and webhook notifications are used to retrieve Microsoft Teams meeting transcripts you've authorized, and — if you separately connect Microsoft Calendar — your calendar event times and meeting links. Data is processed per Microsoft's privacy policy.
  • Webex (Cisco): OAuth tokens and webhook notifications are used to retrieve Webex meeting transcripts you've authorized. Data is processed per Cisco's privacy policy.
  • Recall.ai: If you use the AI notetaker feature, meeting audio and video is processed by Recall.ai to produce a transcript, which we then use to generate your summary. If you connect a calendar, Recall.ai also receives your calendar's OAuth refresh token so it can watch the calendar and schedule notetaker bots on your behalf, as described in Calendar Access above. Data is processed per Recall.ai's privacy policy.
  • Stripe: Handles all payment processing and subscription management.
  • Resend: Delivers transactional emails (welcome emails, summary notifications, password resets).
  • Neon / PostgreSQL: Secure cloud database for storing your account and summary data.
  • Vercel: Cloud hosting provider for our application.

We do not sell your data to any third party.

7. Data Retention

We retain your account data and summaries for as long as your account is active. If you request account deletion, we will delete your data immediately, except where retention is required by law. OAuth tokens are deleted immediately upon disconnecting any connected meeting platform (Google, Zoom, Microsoft Teams, or Webex) or calendar (Google Calendar or Microsoft Calendar).

8. Data Security

We use industry-standard security practices including encrypted connections (HTTPS/TLS), hashed passwords (bcrypt), and scoped OAuth access. However, no system is 100% secure — please use a strong, unique password for your account.

9. Your Rights

You have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and associated data.
  • Disconnect any connected meeting platform (Google, Zoom, Microsoft Teams, or Webex) or calendar (Google Calendar, Microsoft Calendar) at any time from Integrations or the Security settings page.
  • Export or receive a copy of your summaries.

To exercise these rights, contact us at support@synopsist.ai.

10. Cookies

Synopsist uses browser localStorage (not cookies) to store your authentication token. We do not use third-party tracking cookies or advertising cookies.

11. Children's Privacy

Synopsist is intended for professional use by financial advisors. We do not knowingly collect information from individuals under the age of 18.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notice. Continued use of the platform after changes take effect constitutes acceptance of the updated policy.

13. Contact Us

If you have questions about this Privacy Policy or how your data is handled, please contact us:

Synopsist / Mestor Technologies LLC

Email: support@synopsist.ai