Deputy Privacy Policy
Last updated: June 15, 2026
This policy describes what information Deputy collects, how we use it, who we share it with, and the choices you have. We wrote it in plain language; if something seems unclear, tell us at privacy@deputy.ccand we'll fix it.
1. What we collect
The categories of information we collect:
- Account data: email, name, profile photo (if you provide one), and the authentication tokens your identity provider (Google, Apple, email/password) issues us.
- Organization data: your organization membership, role, and the metadata associated with pages or threads you belong to.
- User Content:text you type, voice recordings you submit, pages you create or edit, messages you exchange with Deputy (“Ask” / “Tell” interactions), and escalation threads with teammates.
- Integration data: when you connect Slack or Google Drive, information those services make available to Deputy subject to your authorizations there.
- Device & service metadata: push notification tokens, app version, platform, and timestamps of events we need to operate the Service (login, request rate limits, etc.).
- Payment data:handled exclusively by Stripe. We receive only subscription state (active, past due, canceled) — never your full card number.
2. How we use it
- To provide the Service — capture, transcribe, index, and respond to your requests.
- To send notifications you asked for (push, optional Slack).
- To secure accounts and prevent abuse (rate limits, idempotency, fraud signals).
- To bill paid plans via Stripe.
- To improve the Service (aggregate, de-identified analysis; never individual profiling for ads).
We do not sell your personal information. We do not use your User Content to train third-party general AI models.
3. Processors we rely on
Deputy is built on a stack of trusted service providers (“processors”) that handle data on our behalf under contractual obligations to keep it confidential and to use it only for the functions we request:
- Firebase / Google Cloud — authentication, Firestore database, hosting, Cloud Functions, Cloud Messaging.
- Pinecone — vector index for semantic search over your pages.
- OpenAI — voice transcription (its audio transcription API). Requests are sent with our organization key; under our agreement, OpenAI does not use these inputs to train public models.
- Google Gemini — AI question-answering and reconciliation, and the text-to-speech that voices Deputy’s spoken narration in meetings. Same training-opt-out arrangement.
- Stripe — payments + subscription management.
- Slack, Google Drive — only when you connect them, and only for the scopes shown at connect time.
- Recall.ai — when you invite Deputy to a meeting, Recall’s bot joins the call (Google Meet, Zoom, Microsoft Teams) and captures audio, video, and a transcript on our behalf. Recall hosts the recording briefly; we copy it into our own storage for your plan’s retention window (see retention below).
- Expo — for push notifications on mobile (we send the token and payload; Expo relays to APNs/FCM).
4. Where data lives
Primary data is stored in Google Cloud regions we select (today, US-central). Some processors (e.g. OpenAI, Gemini) may process data in additional regions per their own infrastructure. If you are in a region that requires data residency guarantees beyond this, contact us before creating an account.
5. How long we keep it
- Account + User Content: for as long as your account exists. Deleting your account removes this within 30 days from active systems and within 90 days from backups.
- Meeting recordings:when recording persistence is enabled, meeting audio and video copied into our storage are retained for the window your organization’s admin sets, up to your plan’s maximum (currently up to 7 days on Free, 30 days on Pro, and 1 year on Max/Team). Recordings are deleted when they pass that retention window, when you delete the meeting, or within a 30-day grace period after a downgrade — and, like all your content, when you delete your account.
- Meeting transcripts:retained per your organization’s transcript-retention setting (default 30 days), after which the transcript text is purged.
- Operational logs (requests, errors): up to 90 days.
- Billing records: retained per tax / accounting requirements (typically 7 years).
- Idempotency tokens: 24 hours (used to safely retry mobile uploads).
6. Your rights
You can:
- Access and export your data on request.
- Correct inaccurate profile or page content directly in the app.
- Delete your account in Settings → Delete account (mobile) or by emailing us.
- Object to processing or restrict specific uses. Residents of the EU/UK have additional rights under GDPR; residents of California have additional rights under the CCPA. To exercise any of these, email privacy@deputy.cc.
7. Security
We use industry-standard safeguards: encryption in transit (HTTPS / TLS) and at rest where our providers offer it, scoped service accounts, least-privilege database access, and regular reviews. No system is perfectly secure; if you suspect an issue, please report it to security@deputy.cc.
8. AI assistant connections (Deputy MCP server)
Deputy lets you connect a third-party AI assistant (such as Claude or ChatGPT) to your Deputy workspace as a custom connector, using the Model Context Protocol (MCP). When you connect an assistant, you authorize it through a standard OAuth 2.1 flow and choose which organization’s data it may read.
What a connected assistant can read
A connected assistant can read only the Deputy data you yourself are entitled to, in the organization you selected: your meetings and speaker-labeled transcripts, the action items and commitments you own or host, and the knowledge-base content you can already see — the organization’s shared knowledge plus your own knowledge pages. It cannot read another organization’s data, other users’ private pages, or your billing and account settings.
What it cannot do
The connector is read-only. A connected assistant cannot change, add, or delete anything in Deputy, and it cannot act on your behalf. It is granted a read-only scope, and no write operations are exposed.
How access is scoped and secured
Access is granted per organization and per assistant. Access tokens are short-lived and bound to the Deputy connector; refresh tokens are encrypted at rest. Deputy never forwards your assistant’s token to any other service, and requests are rate-limited to guard against abuse.
Retention and revocation
A record of each connection (the assistant’s name, its verified domain, the scopes granted, and when it was last used) is stored so you can review it. You can revoke any assistant’s access at any time from your Deputy settings; revocation takes effect promptly and the assistant can no longer read your data. Connection records are removed when you delete your account.
9. Walkthrough Q&A
When someone shares a recorded walkthrough or presentation with you, you can raise your hand and ask Deputy a question about it. This section describes what that keeps.
Questions and answers
Your question and Deputy’s answer are transcribed and saved for the person who shared the walkthrough. They appear in that person’s Questions list and on the recording itself, so a later viewer may see the exchange. Treat a question you ask on a shared link as visible to the person who shared it.
Voice
On a walkthrough shared with anyone who has the link, your voice is never recorded — only the transcript of what was said is kept. On a walkthrough limited to a signed-in organization, the live exchange is captured in full, voice and transcript, and can be replayed by other people in that organization.
In both cases the live audio itself travels from your device directly to Google’s Gemini Live service, which generates Deputy’s spoken reply. That connection is made by your browser or app, not by our servers, and we do not receive or retain the raw audio of it.
Email addresses of visitors
If you ask a question without signing in, we ask for your email address first. We use it to tell the person who shared the walkthrough who asked, and to reach you if they answer. It is shown to that person only — never to other viewers of the same link, who see your question attributed to “Someone”.
How long we keep it
Questions, answers, any captured voice, and a visitor’s email address are kept until the walkthrough is deleted or the organization that owns it deletes its account, whichever comes first — then they are removed on the schedule in section 5.
10. Children
The Service is not intended for children under 13 (or 16 where local law sets a higher threshold). We do not knowingly collect data from children.
11. Changes
We'll post updates to this policy here and, for material changes, notify account owners by email or in-app.
12. Contact
Privacy questions, access/deletion requests, or security reports: privacy@deputy.cc.