Privacy Policy

Information we collect#

The first part below covers this marketing website; the rest covers the product.

Through this website#

The marketing website does not ask you to submit personal information directly. It links to the Attentive download; GitHub handles that download under its own privacy notice.

We collect basic, privacy-preserving usage analytics (page views, referrers, country, device type) via Vercel Analytics. This is aggregated and cookieless — we do not use tracking cookies or build advertising profiles.

If you email us, Google Workspace processes your message. Before July 13, 2026, the public page also offered a waitlist form. A legacy endpoint remains available for older clients; if it receives a submission, we collect the submitted name, email address, company, optional role, and message, store them in Neon, and send a notification through Resend. These submissions are retained only as described under Data retention and deletion. To request deletion, email privacy@asterialabs.ai or founders@asterialabs.ai.

Account data#

When you sign up for the product we collect your name, email address, and authentication credentials. Authentication is handled by Clerk, our sign-in provider (browser) — Clerk processes your name, email, and session data on our behalf. The Attentive desktop app authenticates with a separate session token that is stored in the macOS Keychain on your machine, stored only as a cryptographic hash (SHA-256) on our servers, expires automatically after 90 days, and can be revoked from the dashboard at any time.

Meeting audio and transcripts#

Attentive’s desktop app can capture your sales calls (microphone and system audio) to produce a live transcript. This is the most sensitive thing we do, so it is gated carefully:

  • Nothing captures without explicit consent. Before the app will capture anything — even when you click “record” yourself — you must first read and acknowledge a recording-consent disclosure in the app.
  • The default is ask-every-time. By default, every detected meeting shows a prompt and records only if you explicitly say yes for that call.
  • Automatic capture requires a double opt-in. Capture can only ever start without a per-call click when both (a) a workspace admin has set the workspace recording policy to “auto-record with disclosure” and (b) you have set your own machine’s capture preference to automatic — in addition to the consent acknowledgement above. If any of these is missing or cannot be verified, the app falls back to asking. Recording-policy changes are recorded in the workspace audit log.
  • Consent guidance is built in. The product ships plain-language guidance on one-party vs. all-party consent laws and provides a disclosure snippet for calendar invites. You are responsible for complying with the recording-consent laws that apply to your calls (see our Terms of Service).

What is captured and kept:

  • Capture is configured audio-only — no video is recorded.
  • Audio is captured only to produce your transcript. It is processed transiently for transcription by Recall.ai, a disclosed subprocessor, and handled under Recall.ai’s data processing terms. Attentive does not retain or store recordings — we persist transcript text only, and there is no recording playback anywhere in the product.

We also store data derived from transcripts: meeting summaries, follow-ups, suggested guidance (including source references when applicable), and proposed “memories” (per-account facts). Proposed memories are never used until a person in your workspace explicitly approves them.

Knowledge documents#

You (or your integrations, below) can upload documents — product guides, security FAQs, implementation docs. We store the files and an indexed, searchable version of their text (including vector embeddings) so Attentive can retrieve answers from them.

Connected integrations#

You can optionally connect third-party tools (Google Calendar, Google Drive, Notion, HubSpot, Confluence, Salesforce, GitHub, Gong). These are data sources you authorize — we access them only after you explicitly connect them, only with the permissions shown on the provider’s consent screen, and you can disconnect them at any time. What we pull in (calendar events, documents you choose, CRM contacts, past call records) is stored in your workspace like any other knowledge. OAuth tokens and API keys for integrations are encrypted at the application layer (AES-256-GCM) before being stored. For Gong, you paste your own API keys, which we encrypt the same way and use for read-only access to historical calls.

Google user data#

This section covers data received from Google APIs specifically.

What we request and why. Attentive requests the narrowest Google scopes that support its features:

ScopeWhat it allowsWhat we use it for
calendar.events.readonlyRead-only access to your calendar events (not your full calendar settings)Showing your upcoming meetings, matching them to accounts by attendee email, and preparing pre-call briefs
drive.fileAccess only to the specific files you pick in the Google file picker — not your whole DriveSyncing the documents you explicitly choose into your workspace knowledge
gmail.readonlyRead-only access to your Gmail messages and threads — Attentive cannot send, modify, or delete any emailMatching your email threads with an account’s contacts and surfacing them as account-scoped knowledge during your calls (email signatures and quoted reply chains are stripped)

How Google data is used and stored. Calendar events, picked Drive files, and email threads matched to your accounts are stored in your workspace (on Neon, our US-hosted database, and Vercel Blob for files), under the same workspace isolation, encryption, and deletion controls as everything else. Google OAuth tokens are stored AES-256-GCM encrypted. Google data is used solely to provide the user-facing features above — briefs, meeting-account matching, and answers retrieved from the documents and email threads tied to your accounts — and for no other purpose.

Limited Use disclosure. Attentive’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • We only use Google user data to provide or improve the user-facing features described above, which are visible and prominent in Attentive’s interface.
  • We do not transfer Google user data to third parties except to the subprocessors that operate those features on our behalf (listed on our subprocessor page), for security purposes (for example, investigating abuse), to comply with applicable law, or as part of a merger, acquisition, or sale of assets after obtaining explicit prior consent from you.
  • We do not use Google user data for serving advertisements (including retargeting, personalized, or interest-based advertising), and we do not sell it to data brokers or information resellers.
  • We do not use Google user data to determine credit-worthiness or for lending purposes.
  • No humans at Asteria Labs read your Google user data unless (a) we have obtained and documented your explicit consent to view specific data, (b) it is necessary for security purposes (for example, investigating a bug or abuse), (c) it is necessary to comply with applicable law, or (d) the data is aggregated and anonymized and used for internal operations.
  • We do not use Google user data to create, train, or improve generalized AI or machine-learning models. Google data is only ever passed as context to our AI provider to generate your briefs and answers, under API terms that do not permit training on it.

Revoking access. You can disconnect Google from Attentive’s integration settings at any time, and you can also revoke Attentive’s access from your Google security settings. Disconnecting stops all further access; previously synced content remains in your workspace until you delete it.

Usage and error data#

  • Operational logs. Our servers log request timing, errors, and audit events (e.g. settings changes, member and integration changes) to run and secure the service. Logs may include your IP address.
  • Error monitoring (Sentry). We use Sentry for crash and error reporting in the web app and desktop app. Every error report passes through a scrubber before it leaves the app: request bodies, headers, cookies, and query strings are removed; URLs are stripped to their path; the only user identifier kept is an internal user ID; and fields that could carry call or knowledge content (transcripts, queries, answers, document text, emails, tokens) are redacted by name at any depth — anything the scrubber can’t inspect is dropped rather than sent. What Sentry does receive is stack traces, app version, and these scrubbed technical details. Transcript, query, and knowledge content never leaves the app in error reports. We do not use third-party advertising or marketing analytics trackers in the product.

Payment data#

During our closed beta, billing is arranged directly with each customer. We never store full card numbers ourselves. When self-serve billing launches, the payment processor will be named on our subprocessor page before it processes any customer data.

How we use information#

We use the data above to:

  • run Attentive: pre-call briefs, live transcription, real-time sales guidance, note-taking, manual search, post-call summaries, and account memory;
  • keep your workspace secure: authentication, audit logging, abuse prevention;
  • operate and improve the service: debugging (with the scrubbing described above), latency and quality measurement;
  • communicate with you about the service.

For users in the EEA, UK, and other jurisdictions that require a legal basis for processing, this table maps each purpose to its basis:

PurposeData usedLegal basis
Providing the service: briefs, answers, summaries, account memory, searchAccount data, transcripts, knowledge documents, integration contentPerformance of contract
Capturing and transcribing callsMeeting audio (transient) and transcriptsConsent — the in-app acknowledgement plus per-call confirmation or the double opt-in described above; withdrawable at any time
Syncing connected integrations, including GoogleCalendar events, documents you pick, CRM recordsConsent — you connect each integration and can disconnect at any time
Securing the service: authentication, audit logs, abuse preventionAccount data, operational logs, audit eventsLegitimate interests (keeping the service and your data secure); legal obligation where applicable
Improving and debugging the serviceContent-scrubbed error reports and timing telemetryLegitimate interests (running a reliable service without reading your content)
Product accounts and communications about the serviceName, email address, companyPerformance of contract; legitimate interests

Two product principles worth stating in a privacy policy:

  • Guidance can include source references. When Attentive retrieves information from your approved content, it shows the supporting source so a person can evaluate it before relying on the guidance.
  • Nothing is autonomous. Attentive never sends emails, updates your CRM, or commits a “memory” about a customer without a person explicitly approving it.

AI processing — and no training#

Attentive uses two AI providers as subprocessors:

  • Anthropic (Claude models) generates briefs, answers, and summaries. Prompts containing your transcript excerpts, knowledge content, and queries are sent to Anthropic’s API to produce those outputs.
  • Voyage AI produces the embeddings and re-ranking that power search. Document text and search queries are sent to Voyage’s API for that purpose.

Asteria Labs does not train any AI models on customer data, and both providers process this data under commercial API terms that do not permit training their models on it. Your data is used to generate your answers, and for nothing else.

How we share information#

We share personal data only with:

  • Subprocessors — vendors that process data on our behalf to run the website and the service. The current list, with what each one receives and why, is at asterialabs.ai/subprocessors. When the list changes, we update that page and record the change in its dated changelog.
  • Integration providers you connect — when you connect Google, HubSpot, etc., we access those services as authorized by you; we do not push your Attentive data to them except where a feature you invoke explicitly does so with your approval.
  • Legal requirements — if required by law, subpoena, or to protect rights and safety, and only after scrutiny of the request.
  • Corporate transactions — if Asteria Labs is acquired or merges, data may transfer to the successor, which remains bound by this policy; we will notify you first.

We do not sell personal data, and we do not share it with third parties for their own advertising or marketing.

Workspace isolation#

Every piece of customer data in Attentive belongs to exactly one workspace. All data access in the product goes through a workspace-scoped data layer, enforced in code and by automated tests: transcripts, documents, memories, and answers are never shared across workspaces, and one customer’s content can never appear in another customer’s answers.

Data retention and deletion#

  • Self-serve full deletion. Deleting your workspace (Settings) permanently removes all workspace data — uploaded files first, then every database record: transcripts, accounts, contacts, documents, knowledge chunks and embeddings, memories, briefs, reports, cards, audit logs, and user records. This behavior is covered by automated tests.
  • Individual items. You can delete individual documents from the dashboard. Removing a single call’s data is not yet self-serve — email privacy@asterialabs.ai and we will purge it for you within 30 days.
  • Legacy waitlist submissions are kept only while needed to manage early-access requests, or until you ask us to delete them.
  • Retention while your account is active. We retain workspace data for as long as your workspace exists, so your account memory keeps working. We do not currently auto-expire content.
  • After termination. If your subscription or workspace is terminated and you have not already deleted it yourself, we retain workspace data for 30 days so you can export or ask us to restore access, then delete it from our live systems.
  • Backups. Deleted data may persist for a limited time in our infrastructure providers’ encrypted platform backups until those backups age out on the providers’ standard schedules; backups are not used to restore deleted customer data except in disaster recovery.
  • Provider-side retention. Anthropic and Voyage AI retain API data per their standard API retention terms, which do not permit training on it. For call audio, see Meeting audio and transcripts: Attentive persists transcript text only, and audio is handled by Recall.ai under its data processing terms.

Security#

  • TLS encryption in transit everywhere; encryption at rest for the database and file storage; integration OAuth tokens and API keys additionally encrypted at the application layer (AES-256-GCM).
  • Desktop session tokens are stored hashed (SHA-256) server-side, expire after 90 days, and are revocable; on your Mac they live in the Keychain.
  • Workspace-scoped data access enforced in a single code path with automated tests.
  • Durable audit logging of sensitive workspace actions.
  • Vulnerability management: dependency scanning, secret scanning, and CI security gates on every change. To report a vulnerability, email security@asterialabs.ai.
  • A SOC 2 readiness program is underway. We do not yet hold a SOC 2 report and do not claim one.

No system is perfectly secure; if a breach affects your data we will notify you without undue delay, consistent with applicable law and our incident-response process.

International data transfers#

Asteria Labs is based in the United States, and our subprocessors process data in the US (see the subprocessor page for regions). If you use Attentive from outside the US — or your call participants and contacts are outside the US — their personal data is transferred to and processed in the US.

For personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (with the UK and Swiss addenda) as the transfer mechanism. Our data processing addendum incorporating them is available to customers on request at privacy@asterialabs.ai.

Your rights#

Attentive is a business tool: for most data in a workspace, our customer (the workspace owner) is the controller and we process it on their behalf as a processor. If you are a call participant or contact whose data appears in a customer’s workspace, that data was provided to us by the customer, not collected from you directly — we will route your request to that customer where required, and help them honor it.

Depending on where you live, you may have rights to:

  • Access the personal data we hold about you, and get a copy;
  • Correct inaccurate data;
  • Delete your data (see Data retention and deletion above — workspace deletion is self-serve and immediate);
  • Object to or restrict certain processing;
  • Port your data to another service;
  • Withdraw consent where processing is based on consent (e.g. disconnect an integration, revoke Google access, decline recording);
  • Not be discriminated against for exercising these rights.

GDPR (EEA/UK). Our lawful bases are set out in the table under How we use information: performance of contract, legitimate interests (security, service improvement with scrubbed telemetry), consent (recording capture, integrations), and legal obligation. Attentive does not make automated decisions about you that produce legal or similarly significant effects. You may lodge a complaint with your supervisory authority.

CCPA/CPRA (California). We do not sell personal information, and we do not “share” it for cross-context behavioral advertising — and have not in the preceding 12 months, so there is no sale or sharing to opt out of. We do not use or disclose sensitive personal information for purposes that require a right to limit. In the last 12 months we collected these categories of personal information:

CategoryExamples in AttentiveDisclosed to
IdentifiersName, email address, company, internal user IDService providers (hosting, authentication, email) on our subprocessor page
Audio, electronic, or similar sensory informationCall audio (transient, consent-gated) and transcriptsService providers (transcription, AI generation, hosting)
Professional or employment-related informationWorkspace roles; accounts, contacts, and CRM records you sync or uploadService providers (hosting, AI generation)
Commercial informationBeta billing arrangementsNot disclosed
Internet or other electronic network activityCookieless aggregate analytics, operational logs, content-scrubbed error reportsService providers (hosting, analytics, error monitoring)
InferencesMeeting summaries and proposed account memories derived from your own content; these stay in your workspaceService providers (hosting, AI generation)

We do not collect precise geolocation. Retention for every category follows Data retention and deletion above. You may exercise access, deletion, and correction rights via the contact below — directly, or through an authorized agent — and we will not discriminate against you for doing so. If we decline a request, you may appeal by replying to our response.

To exercise any right, email privacy@asterialabs.ai (or founders@asterialabs.ai / support@asterialabs.ai). We will verify your request and respond as required by applicable law.

Children#

Attentive is a business product and is not directed at children. Do not use Attentive if you are under 18. We do not knowingly collect data from children under 16; if you believe we have, contact us and we will delete it.

Changes to this policy#

We will post changes here. For material changes we will notify workspace admins by email before the change takes effect.

Contact#

Asteria Labs, Inc.
1395 22nd Street, APT 661, San Francisco, CA 94107, United States
Privacy requests: privacy@asterialabs.ai (or founders@asterialabs.ai / support@asterialabs.ai)
Security reports: security@asterialabs.ai