Privacy Policy
Last updated: July 23, 2026
Who we are
Pilaut ("we") provides a meeting agent that joins Google Meet calls on your behalf and answers questions in the meeting chat using data you connect. Contact: [email protected].
Information we collect
- Account information. When you sign in with Google we receive your email address and name to create and secure your account.
- Google Calendar data. If you connect your calendar, we access your events in read-only mode (scope
calendar.events.readonly) for a single purpose: listing your upcoming meetings so you can choose which ones the agent joins. We never modify events, and we never access Gmail or any other Google data. - Connected app credentials. API keys or tokens you provide for your own systems (e.g. Stripe, Zendesk) are encrypted at rest (AES-256-GCM envelope encryption) and used solely to answer the questions you configure.
- Meeting chat messages. The agent processes chat messages from meetings it is invited to, and responds only when explicitly mentioned. Questions and answers are logged so you can audit what the agent said.
- Meeting transcripts. Used only to generate your post-meeting summary email, then discarded. Transcripts are never stored.
- Early access form. Email, company and tools you submit to request access.
Google API Services — Limited Use disclosure
Pilaut's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Calendar data is used only to display your upcoming meetings inside Pilaut; it is never sold, never used for advertising, and never transferred except as necessary to provide the feature or comply with the law.
How we use information
To provide the service: joining the meetings you choose, answering when mentioned, sending your meeting notes, and operating your account. We do not sell personal data and we do not use your data to train AI models.
Service providers
We rely on a small set of processors to operate: Recall.ai (meeting bot infrastructure), Anthropic (language model that formats answers), DigitalOcean (hosting) and Google (authentication and calendar). Each receives only what is necessary for its function.
Retention and deletion
Configuration and activity logs are retained while your account is active. You can delete connected apps, documents and credentials at any time from the panel. To delete your account and all associated data, write to [email protected] and we will complete the deletion within 30 days.
Security
Data in transit is encrypted with TLS. Credentials are encrypted at rest and never displayed again after saving. Access to production systems is restricted to the operator.
Changes
We will post any changes to this policy on this page and update the date above.