Privacy Policy

Last updated: August 19, 2026

Who we are

Bookedt, Ltd. ("we", "us") is a corporation registered in Delaware, USA. We make Bookedt, a meeting assistant. This policy explains what data we collect, why, and what we do with it. Questions? Email us at support@bookedt.io.

What we collect

  • Your account: your name, email address, and password (stored hashed — we cannot read it). If you sign in with Google, we get your name, email, and profile picture from Google.
  • What you put in: leads, contacts, notes, tasks, and campaign content you create or upload.
  • Your meetings (Bookedt): if you record a meeting, we process the audio to create a transcript, a summary, and follow-up notes, and then we delete the recording — see “Recording and consent” below. We also read the meeting title and attendee list from your calendar so we know who the meeting was with.
  • Connections you set up: when you connect a CRM (like HubSpot, Pipedrive, or Close), a chat tool (like Slack or Google Chat), or your calendar, we store the keys needed to talk to those tools. These keys are stored encrypted.
  • Basic usage data: logs of what happened in the product (for example, "a sync ran"), used to keep the service working and debug problems.
  • Bookings made through booking pages: if you book a meeting through someone's bookedt.io link, we store the name, email, timezone, any answers you type into the form, and the meeting time — so the meeting can be created, confirmed, reminded about, rescheduled, or canceled. This data is shown to the host you booked with. To have it removed, use the opt-out form below.
  • Who you are, when you book: we send the email address you typed into a booking form to our enrichment provider (FullEnrich) to look up your job title and your company's industry and rough size, and we show that to the host alongside your booking — so they know who they are about to meet. We send the email address only, never your form answers, and we look you up once rather than repeatedly. If the host has connected a CRM, they may have your details saved into it. The same opt-out form below removes this.

How we use it

  • To run the product: sync meetings and contacts to the CRM you connect, prepare meeting briefs, and send hand-off cards to the chat tool you connect.
  • To improve reliability and fix bugs.
  • To email you about your account or the service.

We never sell your data and we do not show ads. When Bookedt posts a card to Slack or Google Chat, the card contains only the task and a link — never meeting content. The full brief stays behind Bookedt sign-in.

AI processing

Transcripts, summaries, and briefs are created with the help of AI providers — currently Deepgram for transcription, with Groq as a fallback, and Anthropic for summaries. They process your data only to provide the service to us, and none of them may train their models on it. Anthropic and Groq are barred by contract; Deepgram allows training by default, so we send every request opted out. See our security page for the detail.

AI output can contain mistakes — the product always shows it to a human for review and never sends anything to your customers on its own.

Google user data

If you connect a Google account, here is exactly what we access and why:

  • Google sign-in: your name, email, and profile picture — to create and identify your account.
  • Google Calendar: your free/busy times — to suggest meeting slots; events we create at your request (with invites and a Meet link); and the title and attendees of meetings you record — so briefs and CRM records are attached to the right people.
  • Google Chat: if you connect a space, we post mention cards to that space.

Our use of Google user data follows the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as needed to provide the features above, we do not use it for advertising, and we do not use it to train AI models.

Who we share data with

We use a small number of service providers to run the product:

  • Hosting and databases: Vercel, Railway, Neon, and Supabase.
  • AI: Deepgram and Groq (transcription) and Anthropic (summaries), as described above.
  • Contact enrichment: FullEnrich, to find business contact details for people you are meeting with, and to identify people who book a meeting through your booking page. How that works, and how to opt out, is set out in where our data comes from.
  • The tools you connect: your CRM, calendar, and chat tool receive the data needed to do what you asked (for example, a meeting note synced to your CRM).

These providers may only use your data to provide their service to us.

Recording and consent

Bookedt records a meeting only when someone on that call chooses to start it. No bot joins the call, so nothing appears in the meeting that the other participants have not already seen.

Recording laws differ by country and by US state, and they are strict. In at least thirteen US states — California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Oregon, Pennsylvania and Washington — you generally need everyparticipant's agreement, or at minimum their knowledge, before you record. The exact rule varies, and so does whether breaking it is a civil or a criminal matter. Oregon's rule applies specifically to video calls. Several of these states let the person you recorded sue you directly.

If you or your customers offer services to people in the EU, EEA or UK, the GDPR is likely to apply to the recording wherever your company is based — it treats a voice recording as personal data. Getting any of this wrong carries real financial and, in some states, criminal consequences.

This list is a starting point, not legal advice, and it is not exhaustive. Check your own jurisdiction and your participants'.

So, plainly: if you start a recording, you are responsible for telling everyone on the call that it is being recorded and for getting whatever consent your law requires — before you start. Say it out loud at the top of the call. If anyone objects, do not record. Bookedt cannot obtain that consent for you and does not try to.

You are the controller of the transcripts and summaries we generate. We store and process them on your behalf, and you decide how long to keep them — delete a meeting and its transcript and summary go with it.

A transcript also records when each thing was said, and separates the voices on the call, so a summary can point back to the moment a claim came from instead of asking you to take its word for it. Separating voices is not the same as recognising them: we group speech by speaker within a single call, and we do not build voiceprints or try to identify anyone by the sound of their voice — not across calls, not anywhere. The timings live with the transcript and under the same rules: delete the meeting and they go with it.

The recording itself is different: we do not keep it. The audio exists for one reason, to produce the transcript, so once the transcript is written we delete the recording — normally within about a day, the margin we leave for a transcription that has to be retried. Nothing in Bookedt ever plays a recording back: there is no player, no download, and no way to share one. The one exception is audio we could not transcribe at all — we keep that while we work out why, and you can ask us to delete it at any time.

If you were recorded by one of our customers and you want that recording gone, ask them first — it is theirs. You can also tell us and we will pass the request on and remove what we are able to.

Security

Data moves over encrypted connections (TLS). Passwords are hashed. API keys, tokens, and webhook URLs are encrypted at rest. Access to production systems is limited to people who need it.

How long we keep data, and how to delete it

Meeting recordings are deleted once we have transcribed them, normally within about a day — the transcript and summary are what remain. Everything else we keep while your account is active. If you delete a connection, its keys are removed. To delete your account and its data, email support@bookedt.io and we will remove it within one month, except for records we must keep by law.

Do Not Track, and tracking generally

Some browsers send a “Do Not Track” signal. There is no agreed standard for how a website should answer one, and we do not currently respond to them. What we can tell you is the thing the signal is actually about: we do not track you across other websites, and we do not let anyone else do it through our site. We run no advertising trackers and no analytics trackers — no Google Analytics, no tag manager, no pixels. The only cookies we set are the ones that keep you signed in.

Your rights

You can ask us to show you the data we hold about you, correct it, export it, or delete it. The quickest way is the opt-out and data request form — you do not need an account, and we action requests within one month. You can also email support@bookedt.io.

If you are in the EU/EEA or UK, these are your GDPR rights and you may also complain to your local data protection authority. If you are a California resident, the same form is how you exercise your CCPA rights, including the right to opt out of any “sale” or sharing of your information — though we do not sell personal information at all.

Children

Our products are for business use and are not intended for anyone under 16.

Changes to this policy

If we change this policy in a meaningful way, we will update this page and the date at the top, and for significant changes we will tell you by email or in the product.