← CEO Assistant

CEO Assistant

Privacy Policy

Effective date and last updated: October 2, 2026

CEO Assistant uses connected Telegram chats and Google Calendar to provide reports, create events and Meet links, and transcribe and summarize meetings. The service operator’s support and privacy contact is ralphquite@gmail.com.

1. Data accessed and its purpose

With your Google OAuth permission, we access your account email, calendar identifier and timezone, authorization credentials, and event information, including titles, descriptions, dates, participants, status, and Meet links. This enables calendar connection, event creation, meeting synchronization, recording, and meeting history. Authorization includes account identification, calendar events, calendar-list reading, and free/busy access. The current scheduling flow does not check availability.

We also process Telegram account and chat metadata, text and captions from activated work chats, plain texts from the owner’s selected Business private chats, user requests, and generated reports. Private text collection starts with the authorized Business connection and continues until disabled; URLs are removed before private texts are stored. Meeting recording processes audio, transcripts, speaker labels, and timestamps. The optional Meet extension processes device identity, meeting links, and session status to control recording. These data support the service’s user-facing features.

2. Data sharing

  • Google: account authorization, Calendar events, and Meet links.
  • Vercel and Neon: application hosting and data storage.
  • Attendee: calendar synchronization, recording, and transcription. The connected Google refresh credential and application OAuth credentials are shared with Attendee to maintain the calendar connection.
  • OpenAI: relevant messages, requests, and transcript excerpts for interpretation and summaries; meeting transcription also uses OpenAI through Attendee. Responses API storage is disabled, but provider service and abuse-monitoring retention may apply.
  • Telegram and authorized recipients: reports and transcripts are delivered to the owner and explicitly authorized users or integration operators; invitations and meeting links may be delivered to intended participants.

Providers may process data outside your country under their applicable data policies.

3. Google data and Limited Use

Our use and transfer of Google API data follows the Google API Services User Data Policy, including Limited Use. Google data is used only for the described calendar and meeting features. Provider transfers support these features with authorization, security, or legal requirements. We do not sell Google data, use it for advertising, or use it to train generalized AI models. Human access requires your permission or a security or legal need, except permitted aggregated internal operations.

4. Storage, protection, and retention

Access is restricted to authorized users. Stored Google refresh credentials and private Business message texts are encrypted. Application logs exclude message text, transcripts, and credentials. Hosting providers process limited technical and operational information needed to operate and protect the service.

Work messages follow the configured retention policy: 365 days by default, with other periods or no automatic expiry configurable by the owner. Private Business texts expire after 1–28 days, default 28, and are removed by scheduled cleanup. Meeting transcripts are retained for six calendar months by default, configurable to a longer period, or deleted earlier at an authorized user’s request. We request deletion of Attendee recording data after processing. Calendar credentials are removed on disconnection. Summaries, meeting metadata, and necessary security records may remain; provider retention and backups may delay physical deletion.

5. Consent, disconnection, and deletion

You can disable chat collection, disconnect Telegram Business, disconnect Calendar through /calendar, or revoke access in your Google Account connections. Meeting controls allow you to stop recording and delete a stored transcript. Revoking access stops future authorized access; it does not automatically erase previous results, source events, or copies already delivered to recipients.

Contact ralphquite@gmail.com to request access, correction, or deletion of your data. We may verify your authority before acting. Changes to the use of Google data will be disclosed here and require renewed consent where required. See the Terms of Service for account and recording permissions.

Privacy PolicyTerms of Service
ralphquite@gmail.com