Privacy Policy
Last updated: September 7, 2026
1. Data Controller
The controller of your personal data is Xivalo (xivalo.com). For any privacy-related enquiry, you can reach us at info@xivalo.ai.
2. Data We Collect
We collect the following categories of personal data:
- Account data: name, email address, and company or organisation.
- Meeting data: audio recordings, transcripts, and AI-generated summaries.
- Usage data: sign-in timestamps, features used, and interaction patterns within the platform.
- Technical data: IP address, browser type, operating system, and device information.
- Payment data: processed securely by Stripe. Xivalo does not store credit card numbers or banking details.
- Google data: if you connect your Google account, we access your name, email address, profile picture, and your Google Calendar events (read-only) in order to sync your meetings with the platform.
3. Legal Basis for Processing
In accordance with Article 6 of the General Data Protection Regulation (GDPR), we process your data on the following bases:
- Performance of a contract: managing your account and providing the service you signed up for.
- Legitimate interest: improving the service, platform security, and fraud prevention.
- Consent: marketing communications, where you have opted in.
4. Purposes of Processing
Your personal data is processed for the following purposes:
- Providing the meeting intelligence service: recording, transcription, and analysis.
- Processing and analysing meetings using artificial intelligence.
- Sending transactional communications related to your account and the service.
- Processing payments and managing billing.
- Improving the quality and security of the platform.
5. Artificial Intelligence Processing
Xivalo uses several artificial intelligence providers, each for a distinct function:
- Deepgram (Nova-3 model): transcription of meeting audio and identification of individual speakers.
- OpenAI: analysis of the transcript (summaries, topics, detected tasks), the conversational assistant, and the generation of vector representations that enable semantic search within your workspace.
- Recall.ai: management of the assistant that joins meetings to record them and, for meetings captured that way, real-time transcription.
This processing takes place under the following conditions:
- Data sent to these providers is processed under a Data Processing Agreement (DPA), in their capacity as processors.
- They do not use data sent through their APIs to train their models, in accordance with their respective data usage policies.
- Recordings and transcripts are stored on AWS servers in Europe (eu-west-3, Paris).
6. Google Data
Xivalo lets you connect your Google account to sync calendar events, schedule automatic meeting recordings and, optionally, prioritise and summarise your mailbox. The following describes how we handle data obtained through Google APIs:
6.1. Data we access
- Basic profile: name, email address, and profile picture of your Google account (scopes:
openid,profile,email). - Calendar events: read-only access to your Google Calendar events (scope:
calendar.events.readonly), including the title, date, time, duration, and attendees of each event. - Gmail messages (optional, only if you connect your mailbox): read-only access to your messages and conversations (scope
gmail.readonly), including senders, recipients, subject, date, and message body. Xivalo never sends, replies to, modifies, or deletes mail in your account.
6.2. How we use this data
- To authenticate your identity and sign you in to the platform.
- To show your upcoming meetings so that you can schedule automatic recordings.
- To associate meeting recordings with the corresponding calendar events.
- To classify your email conversations by priority, summarise them, and detect which ones need a reply, and to show that to you in your Xivalo Inbox.
- To associate those conversations with the contact and company records of your CRM, so that the mail and the meetings you have with each person appear on the same screen.
6.3. Storage and sharing
- Google Calendar data is stored in our database (Amazon RDS in the EU) and refreshed periodically while the connection is active. The credentials used to access your Google account are stored encrypted (AES-256-GCM).
- Recall.ai, our meeting recording provider, acts as a processor and receives: (a) the credential used to access your Google Calendar, which it needs in order to read your events and schedule meeting recordings, and (b) the data of those events. Recall.ai processes this data solely on Xivalo's behalf and according to our instructions.
- OpenAI, our processor, receives the content of your email messages solely to generate the priority, category, and summary shown to you in your Xivalo Inbox. OpenAI does not use this data to train or improve its models. Under its API policy, OpenAI may retain it for up to 30 days for the sole purpose of abuse monitoring, and deletes it afterwards.
- Your mail is stored encrypted (AES-256-GCM) and is private to your user: no other member of your workspace can access it, neither directly nor through the platform's conversational assistant.
- Other than the above and the infrastructure providers required to operate the service (AWS), we do not share data obtained through Google APIs with any other third party.
- We do not use Google data for advertising, market research, or to build user profiles for purposes other than the functionality of the service.
- We do not use data obtained through Google APIs to create, train, or improve generalised artificial intelligence or machine learning models, including foundation models.
6.4. Revoking access
You can disconnect your Google account at any time from your workspace settings. When you do, we delete the stored access tokens and calendar data. You can also revoke access directly from your Google account.
If you have connected your Gmail mailbox, you can disconnect it at any time from your settings. When you do, we revoke the access on your Google account and permanently and immediately delete every thread, message, and summary we had stored. While the mailbox is connected, each thread is kept for at most 90 days from the date of its last message.
6.5. Compliance with Google's policy
Xivalo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Mailboxes connected over IMAP
Besides Gmail, you can connect to Xivalo a mailbox from any provider that offers IMAP access (for example Hostinger, OVH, IONOS, Zoho, a cPanel host, or Google Workspace through an app password). In that case no Google API and no OAuth grant is involved: Xivalo connects to your mail server with the username and password you give us.
7.1. Data we process
- Access credentials: the email address, the username, the IMAP server and port, and the mailbox password (or app password). The password is stored encrypted (AES-256-GCM) and used only to read your mailbox. It is a different category of data from an OAuth token: it does not expire and cannot be revoked at a provider, so we keep it for as long as the mailbox stays connected.
- Mail content: the same data as for Gmail — senders, recipients, subject, date and body of the messages in your inbox and in your sent folder — with read-only access. Xivalo never sends, replies, moves or deletes mail in your mailbox.
7.2. How we use and share them
Exactly as with Gmail mail (sections 6.2 and 6.3): we classify your conversations by priority, summarise them and link them to your contacts; the content is sent to OpenAI, our processor, only to generate that priority and summary, and is not used to train models; and your mail is private to your user. Access credentials are never shared: they do not leave our infrastructure (AWS, EU) and are not sent to OpenAI or to any other provider.
7.3. Disconnecting and deletion
You can disconnect the mailbox at any time from your settings. When you do, we permanently and immediately delete the password and every stored thread, message and summary. If the server rejects the password, we delete it too and notify you so you can enter it again. Since there is no grant to revoke at your provider, change the password there if you want to be completely sure Xivalo can no longer access the mailbox. While the mailbox is connected, each thread is kept for at most 90 days from the date of its last message.
8. Data Storage
- Database: Amazon RDS (PostgreSQL) in the eu-west-3 region (Paris, France).
- File storage: AWS S3 in a European Union region.
- Encryption: all data is encrypted both at rest and in transit (TLS 1.2+).
9. Data Sharing
We share data only with the following third parties, all necessary to provide the service:
- Google: OAuth authentication and calendar sync. Google data is used exclusively for the functionality described in section 6 and in accordance with the Google API Services User Data Policy.
- OpenAI: transcript analysis, email triage and summarisation, conversational assistant, and semantic search (under a DPA).
- Deepgram: transcription of meeting audio and speaker identification (under a DPA).
- Recall.ai: the assistant that joins meetings to record them, calendar sync, and real-time transcription. It receives the credential used to access your calendar and the data of your events (under a DPA).
- Stripe: payment processing.
- AWS (Amazon Web Services): infrastructure hosting.
- Meta (WhatsApp Business Platform):if your business connects its WhatsApp Business number, the messages your customers send you and the replies sent back to them pass through Meta's infrastructure, which operates the channel. See section 13.
- Meta (Facebook): if you accept marketing cookies, we share browsing data (pages visited, IP address anonymised by Meta, browser user agent) to build custom advertising audiences. Legal basis: consent (Art. 6.1.a GDPR). You may withdraw your consent at any time.
We do not sell personal data to third parties under any circumstances.
10. Data Retention
- Active account: data is retained for as long as the user account remains active.
- Deleted account: data is deleted within a maximum of 30 days of the deletion request.
- Email:90 days from the date of the thread's last message. After that, the threads, messages, and bodies are permanently deleted. Disconnecting the mailbox deletes everything immediately.
- WhatsApp conversations:90 days from the conversation's last message. After that they are permanently deleted, together with the phone number and profile name of whoever wrote in.
- Invoices: retained for 5 years as required by law.
11. Your Rights
Under Articles 15 to 22 of the GDPR, you have the right to:
- Access: request a copy of your personal data.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your data.
- Portability: receive your data in a machine-readable format.
- Objection: object to the processing of your data.
- Restriction: restrict processing in certain circumstances.
To exercise any of these rights, contact us at info@xivalo.ai. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
12. Chrome Extension
The Xivalo extension for Google Chrome lets you record Google Meet meetings directly from your browser. The following describes what data it collects and how it handles it:
12.1. Data collected by the extension
- Tab audio and video: the extension captures the audio and video of the Google Meet tab while recording. This content is stored locally in the browser until the recording ends.
- Microphone audio: with your permission, the extension captures your microphone audio so that your voice is included in the recording.
- Meeting data: the meeting title and the participants visible in the Google Meet interface.
- Session data: the extension uses your Xivalo session cookie to authenticate you. It does not store any additional credentials.
12.2. Browser permissions
The extension requests the following Chrome permissions, each required for it to work:
- tabCapture: capture the audio and video of the Google Meet tab for recording.
- offscreen: process and mix the audio tracks (tab + microphone) in the background using the Web Audio API.
- activeTab: interact with the active Google Meet tab to detect meetings and display the recording interface.
- storage: save user preferences (such as the automatic recording option).
- notifications: notify you when a recording starts, ends, or uploads successfully.
- alarms: manage internal timers for the recording state.
12.3. Data handling
- Recording happens locally in your browser. No audio or video is streamed to our servers in real time while recording.
- When the recording ends, the file is uploaded to Xivalo's servers (AWS S3 in the EU) for transcription and AI analysis.
- The extension only activates on
meet.google.compages. It does not access any other website or collect browsing data. - No analytics, tracking, or behavioural data is collected through the extension.
13. WhatsApp Business Data
Xivalo lets a business connect its WhatsApp Business number so that an automated agent answers its customers using the material that business has published inside Xivalo. This feature is off by default and only runs if the business explicitly turns it on.
In this processing, the business connecting its number is the Data Controller and Xivalo acts as a Processor.The data processed belongs to that business's end customers, not to Xivalo.
13.1. Data we receive
- The phone number of the person writing in, in international format, exactly as Meta delivers it.
- That person's WhatsApp profile name, if they make it visible.
- The content of the messagesthey send to the business's number, and of the replies sent back to them.
- The message identifier and timestamp assigned by Meta, which we use to avoid replying twice to the same message.
We do not access the contact list, the business's prior message history, or any other data in the WhatsApp account beyond the above.
13.2. How we use this data
- To generate the reply sent to the customer. The reply is built solely from material the business has marked as published inside Xivalo; if that material does not cover the question, the agent says it does not know rather than improvising.
- To show the business the conversation and, in particular, the questions its material could not answer.
- To meter service usage for billing.
This data is not used to train artificial intelligence models, ours or anyone else's, and is not shared with other Xivalo customers.
13.3. Storage and sharing
- Conversations are stored in our database (Amazon RDS in the European Union) and deleted 90 days after the last message.
- The message content is sent to OpenAI to draft the reply. OpenAI does not use data submitted through its API to train its models.
- The access credential Meta issues for the number is stored encrypted and is never displayed again on any screen.
13.4. Revoking access
The business can turn the agent off or disconnect the number from its Xivalo dashboard at any time, and can also revoke Xivalo's access from its Meta Business account settings. Disconnecting the number deletes the associated conversations.
If you are a customer of a business that uses Xivalo and wish to exercise your rights over the messages you sent it, please contact that business, which is the Data Controller. You may write to us at info@xivalo.ai and we will help you reach them.
14. Cookies
For detailed information about the cookies we use, see our Cookie Policy.
15. International Transfers
Data may be processed in the United States by OpenAI, Deepgram, and Recall.ai, in all cases under Standard Contractual Clauses (SCCs) approved by the European Commission. Primary data storage takes place in the European Union (Paris, France region).
16. Security
We implement technical and organisational measures to protect your data, including:
- TLS encryption on all communications.
- Database encrypted at rest.
- Role-based access controls.
- Periodic security reviews.
17. Minors
The Service is not directed at children under 16. We do not knowingly collect personal data from minors. If you become aware that a minor has provided personal data, contact us so that we can delete it.
18. Changes
We reserve the right to modify this Privacy Policy. Changes will be notified by email at least 30 days before they take effect.
See also our Terms of Service and our Cookie Policy.