← OnCallTalk

Privacy Policy

Effective · Last updated · Version 2.0

This policy describes how OnCallTalk (“OnCallTalk”, “we”, “us”) handles information when you use the OnCallTalk Chrome extension and the website at oncalltalk.com (together, the “Service”). It covers what we process, where it goes, how long we keep it, and the choices you have.

At a glance

  • Meeting audio never reaches our servers and is never stored. It streams from your browser directly to our transcription provider over an encrypted connection and is discarded as it is transcribed. No audio file is ever created.
  • Transcripts are never written to our database. Transcript text exists in server memory only for the single request that turns it into a suggestion.
  • We do not sell or share your personal information, and we do not use it for advertising, cross-context behavioural advertising, or credit assessment.
  • Nothing you send us is used to train AI models — not by us, and not by our providers.
  • No cookies, no analytics, no third-party trackers on the website or in the extension.
  • Audio capture runs only while you explicitly start a session and stops the moment you press Stop, close the panel, or leave the meeting tab.

1. Who we are

OnCallTalk is a real-time assistant for Google Meet. It runs in your own Chrome side panel; no bot or additional participant joins your meeting. OnCallTalk is the party responsible for the personal information described in this policy — the “controller”, or the “Data Fiduciary” if you are in India.

You can reach us about anything in this policy at intern01.theelitepoint@gmail.com. That address is also our channel for privacy rights requests and grievances.

2. What we process

2.1 Meeting audio — processed live, never stored

When you press Start on a meeting, the extension captures:

The two are combined into one two-channel stream so the speakers can be told apart, and sent from your browser directly to Gladia, our speech-to-text provider, over an encrypted WebSocket. This audio does not pass through our servers. Our backend only opens the transcription session and hands your browser a short-lived URL to connect to, which is how our provider key stays on the server and out of the extension.

Capture stops immediately when you press Stop, close the side panel, or leave the meeting tab. No audio is written to disk, and no recording file is produced at any point in the Service.

2.2 Transcripts — processed in memory, never stored

The text returned by transcription is sent to our backend, which combines it with your meeting notes and style settings into a single prompt for OpenAI, which generates a suggested reply. The transcript is used to build that one request and is then discarded. We do not write transcripts to our database.

2.3 Operational logs

Our servers keep short technical logs so failures can be diagnosed and abuse investigated. Described precisely rather than generally:

These logs are never used to build a profile of you and are not shared with anyone. They are retained only for as long as they are useful for diagnosing faults and investigating abuse, and are then discarded.

2.4 Information you give us

The following is stored in our database and is visible to you in the extension. All of it is content you author yourself.

Account and content data stored in our database.
Data Why we hold it
Email address To identify your account and sign you in.
Password Held only as a salted bcrypt hash. We never store or transmit your password in readable form and cannot recover it.
Style profile The notes you write about how you like to speak, added to every suggestion prompt.
Example responses The “they said X, I’d say Y” pairs you author to steer the model’s tone.
Meeting preparation Client name, company, background, objective and notes — all typed in by you — plus the status and start and end times of each prepared meeting.

Your meeting notes are free-text fields, and whatever you type there is sent to OpenAI as part of the prompt. Please avoid entering information you would not want processed by a third-party model — payment card numbers, government identifiers, or health details about other people.

2.5 Usage and performance records

We store numeric records that contain no conversation content of any kind: the token count and model name for each suggestion request, so your plan’s monthly limit can be enforced; the latency of each suggestion in milliseconds, so we can monitor quality; your plan and its limit; and the time you last signed in.

2.6 What stays on your own device

Your sign-in tokens and extension preferences are kept in Chrome’s local extension storage on your computer. They are not synced to your Google account and are not readable by us. Signing out or removing the extension clears them.

The website sets no cookies and loads no analytics, tag managers, session recorders or advertising scripts. The extension contains no tracking code.

3. Why we process it

We use the information above only to:

We process meeting audio and transcripts on the basis of your consent, which you give by starting a session and can withdraw at any time by stopping it. We do not carry out automated decision-making that produces legal or similarly significant effects about you.

4. Service providers & international transfers

We use a deliberately small number of providers, each only for the purpose listed. None of them is permitted to use your data for their own purposes.

Third parties that process data on our behalf.
Provider What it receives
Gladia Speech-to-text Live meeting audio, streamed directly from your browser, and returns text. Audio is not retained after transcription.
OpenAI Suggestion generation The recent transcript excerpt, together with your style profile, examples and meeting notes, as a single prompt. Data sent through the OpenAI API is not used to train their models.
Hosting and database Infrastructure Our servers and database run on commercial hosting infrastructure. The provider stores our data at rest on our behalf and has no independent right to use it.

We share data with no one else. We do not sell personal information, disclose it to data brokers, or use it for advertising or credit assessment. We may disclose information where we are legally required to, or where it is necessary to protect our rights or someone’s safety.

International transfers. Our providers operate in countries that may not be the one you live in, including the United States and countries in the European Union. Where your information crosses a border, we rely on the contractual data-protection commitments and transfer safeguards each provider offers, and on the encryption of all data in transit.

5. Chrome Web Store Limited Use disclosure

OnCallTalk’s use of information received through the extension adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Specifically:

6. Extension permissions

Chrome requires an extension to declare the capabilities it uses. Each of ours is listed below with the reason it is needed.

Permissions requested by the OnCallTalk extension.
Permission Why it is needed
tabCapture To capture Google Meet tab audio, only after you start a session and only for as long as it runs. It is used for nothing else.
Microphone access Granted by you through Chrome’s own prompt, so your side of the conversation is transcribed alongside everyone else’s.
offscreen Audio processing needs a document that stays alive for the whole call; Chrome shuts a background service worker down too quickly to hold a live stream.
sidePanel To show the suggestion panel beside your meeting.
storage To keep your sign-in session and preferences on your own device.
activeTab To confirm the tab you are about to capture really is a Google Meet call, so the wrong tab is never captured.
meet.google.com To read the meeting tab’s address for that same check.
oncalltalk.com To reach our API for sign-in and suggestions.

OnCallTalk transcribes what other people in your meeting say. Laws in many countries, and in several US states, require that every participant consent before a conversation is recorded or transcribed.

You are responsible for obtaining that consent and for complying with the law where you and your participants are, as well as with Google Meet’s terms and any policy of your employer or client. We strongly recommend telling participants at the start of a call that an AI assistant is transcribing it. If you are not certain the law permits it, do not start a session.

8. Retention & deletion

How long each category is kept.
Data Retention
Meeting audio Never stored. Discarded as it is transcribed.
Transcripts Never stored. Discarded at the end of each request.
Account, style profile, examples, meeting notes Kept until you delete them in the extension, or until your account is deleted.
Usage and performance records Kept while your account is open, for limit enforcement and service monitoring. Deleted with your account.
Operational logs Kept only as long as useful for diagnosing faults and investigating abuse, then discarded.

Deleting your account. Email intern01.theelitepoint@gmail.com from the address on your account and ask us to delete it. Deleting an account removes the account record and everything attached to it — style profile, examples, meetings, usage and performance records — from our database. We action deletion requests within 30 days and confirm when it is done.

9. Security

All traffic between the extension, our servers and our providers is encrypted in transit with TLS (HTTPS and WSS). Passwords are stored only as salted bcrypt hashes. Provider API keys are held on our servers and are never shipped to the extension, which is why transcription sessions are opened server-side and handed to your browser as a short-lived URL. Our database is not exposed to the public internet, and access to production systems is limited to the people who need it to operate the Service.

No system is perfectly secure and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you, and any regulator we are required to inform, without undue delay.

10. Your rights

Wherever you live, you can ask us to do any of the following, and we will not treat you differently for asking:

Most of this you can do yourself in the extension: your style profile, examples and meeting notes are all editable and deletable there. For anything else, email intern01.theelitepoint@gmail.com. We will verify that the request comes from the account holder, usually by confirming it from the account’s own email address, and respond within 30 days.

11. California residents (CCPA/CPRA)

This section applies if you live in California. In the 12 months before the date of this policy we collected the following categories of personal information, directly from you, for the business purposes described in section 3.

Categories of personal information collected.
Category What that means here
Identifiers Your email address and account identifier.
Audio and electronic information Meeting audio and its transcript, processed transiently to generate suggestions and not retained by us.
Commercial information Your plan and its monthly request limit.
Internet or network activity Request counts, latency measurements and the time you last signed in. No browsing history and no cross-site activity.
Other content you provide Your style profile, examples and meeting preparation notes.

We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding 12 months — nor do we do so now. We do not sell or share the personal information of anyone under 16. We do not use or disclose sensitive personal information for any purpose beyond providing the Service, so the right to limit its use does not arise.

You have the right to know, to delete, to correct, and to opt out of sale or sharing (which we do not do), and the right not to be discriminated against for exercising any of them. To exercise a right, email intern01.theelitepoint@gmail.com. An authorised agent may submit a request on your behalf with written proof of authority.

12. India (Digital Personal Data Protection Act, 2023)

If you are in India you are a Data Principal, and OnCallTalk is the Data Fiduciary for the personal data described in this policy. This policy, together with the consent you give by creating an account and by starting a session, is the notice required under the Act: it sets out the personal data we process, the purposes we process it for, and how to exercise your rights.

As a Data Principal you have the right to:

Withdrawing consent stops further processing but does not affect processing already carried out. Where you withdraw consent we will stop processing your personal data within a reasonable time, unless a law requires us to retain it.

Grievance redressal. Send any grievance to intern01.theelitepoint@gmail.com with “DPDP grievance” in the subject line. We will acknowledge it promptly and respond within 30 days. If our response does not satisfy you, you may complain to the Data Protection Board of India.

13. Children

The Service is intended for adults in a professional setting and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, email us and we will delete it.

14. Business & team use

If you use OnCallTalk for work, your employer’s own policies may also apply to the meetings you transcribe, and your employer may have rules about which tools are allowed on client calls. Check before you start. Accounts are individual: we do not give any employer or administrator access to another person’s account, notes or suggestions.

15. Changes to this policy

We may update this policy as the Service changes. The version number and “last updated” date at the top of this page always reflect the current version. If a change materially affects how we handle your information we will tell you in the extension or by email before it takes effect, and where the law requires it we will ask for your consent again. Continuing to use the Service after a change takes effect means you accept the updated policy.

16. Contact us

For any question about this policy, to exercise a privacy right, or to raise a grievance:

OnCallTalk
Email: intern01.theelitepoint@gmail.com

We aim to answer every privacy request within 30 days. If a request is complex and we need longer, we will tell you why before that deadline passes.