Wislab (“we”, “us”, “our”) provides a desktop meeting intelligence application and related web services at wislab.co (the “Portal”). This Privacy Policy explains what information we process when you use Wislab, including optional calendar integrations with Google Calendar and Microsoft Outlook.
1. Who this policy applies to
This policy applies to users of the Wislab desktop application, the Wislab Portal (sign-in and calendar connection), and related APIs. If you use Wislab through an organization, your employer may also have policies that apply to meeting recordings and workplace data.
2. Information we collect
2.1 Account and authentication (Portal)
When you create an account or sign in through the Portal, we may collect:
- Email address and account identifiers
- Authentication tokens (access and refresh tokens) used to keep you signed in
- Basic session and security metadata (for example, token expiry and sign-in state)
The current Portal sign-in flow uses Google or Microsoft OAuth and does not ask you to create a standalone Wislab password.
2.2 Google Calendar (read-only)
If you choose to connect Google Calendar, you authorize Wislab to access your Google account using
standard sign-in scopes (openid, email, profile) and the
Google Calendar API read-only scope
(https://www.googleapis.com/auth/calendar.readonly). We use this access to:
- Display upcoming meetings in the Wislab desktop app
- Associate recordings with the correct calendar event when you record from a meeting
- Support optional collaboration features tied to a calendar event
Calendar data we may process includes event titles, start and end times, attendee email addresses and display names, conference or join links when present, and stable event identifiers (such as iCalUID).
We do not create, modify, or delete calendar events through this integration.
2.3 Microsoft Calendar / Outlook (read-only)
If you connect Microsoft calendar, you authorize Wislab to access calendar data through Microsoft Graph with the delegated permission Calendars.Read (together with standard OpenID sign-in scopes). We use this data for the same purposes as Google Calendar above. We do not create, modify, or delete calendar events through this integration.
2.4 Calendar connection tokens
When you complete Google or Microsoft calendar authorization, OAuth tokens (including refresh tokens where provided) may be stored by the Wislab Portal for a Portal-managed calendar connection and may also be stored in protected desktop application settings for a desktop-managed connection. These tokens are used to maintain the connection and retrieve calendar events. You can disconnect a provider from Wislab desktop Settings.
2.5 Meeting recordings and AI outputs (desktop and processing server)
The current Wislab recording and summary workflow separates local meeting capture from server-side summary generation:
- On your computer: meeting audio is captured and transcribed locally; recording files, transcripts, summaries returned by the processing server, metadata, and app settings are stored locally
- On your processing server: transcript text is submitted for summary generation; summary jobs, generated outputs, and optional collaboration or consent data are stored server-side
- On the Wislab Portal: account and authentication services are provided separately from meeting summary processing
The current transcript-summary endpoint does not upload the meeting audio file. Wislab does not operate a shared multitenant service for meeting summarization in this deployment model. Your organization chooses where its processing server runs and is responsible for securing and operating it.
2.6 Optional recording consent (processing server)
When enabled by your organization, Wislab may email external meeting invitees to request recording consent. Consent status and related session data are stored on your organization’s processing server, not on a Wislab-operated meeting storage cloud.
2.7 Contact and support
If you submit a contact form or email us, we collect the information you provide (name, email, company, message) to respond to your inquiry.
Google API Services — Limited Use disclosure
Wislab’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms, this means we use Google user data only to provide or improve user-facing features that are prominent in Wislab — such as showing your upcoming meetings and linking recordings to calendar events. Specifically:
- We do not sell, rent, or transfer Google user data to third parties such as advertising platforms, data brokers, or information resellers.
- We do not use Google user data for serving ads, including retargeting or interest-based advertising.
- We do not use Google user data to determine credit-worthiness or for lending purposes.
- We do not use Google user data received through Google APIs to train, improve, or develop generalized artificial intelligence or machine learning models.
- We limit human access to Google user data to what is necessary for security, legal compliance, or with your explicit agreement (for example, when you ask us for support about a specific calendar connection).
Any transfer of Google user data is limited to providing these Wislab features, securing the Service, complying with applicable law, or with your consent. You can revoke Wislab’s access at any time in Wislab Settings or through your Google Account permissions.
3. How we use information
We use the information described above to:
- Provide and secure the Wislab application and Portal
- Authenticate you and maintain your session
- Show upcoming meetings and link recordings to calendar events
- Process meeting transcripts on the processing server you or your organization operates
- Respond to support requests and improve the product
- Comply with legal obligations
We do not sell your personal information or calendar data.
4. Where data is stored
- Portal (wislab.co): account credentials, authentication records, Portal sessions, and calendar OAuth tokens / connection state when the Portal-managed calendar flow is used
- Your desktop device: local app data, recordings, transcripts, returned summaries, desktop authentication tokens, calendar tokens when a desktop-managed connection is used, and cached meeting lists
- Your processing server: submitted transcript text, summaries, server-side job data, and optional session or consent data
5. Third-party services
We rely on the following categories of third parties:
- Google — OAuth and Google Calendar API (when you connect Google Calendar)
- Microsoft — OAuth and Microsoft Graph (when you connect Microsoft calendar)
- Hosting providers — to operate the Portal (for example, cloud hosting for wislab.co)
Each provider’s use of data is also governed by its own privacy policy and your account settings with that provider.
6. Data retention
- Portal account and calendar connection data are retained while your account is active and as needed to provide the service.
- When you disconnect Google or Microsoft calendar, we delete the associated calendar connection and tokens on the Portal.
- Recordings, transcripts, and summaries on your desktop or processing server are retained according to your organization’s policies and configuration.
7. Your choices and rights
- Disconnect calendar: Wislab desktop → Settings → disconnect Google or Microsoft
- Revoke at the provider: you can remove Wislab’s access in your Google Account permissions or Microsoft account app permissions
- Sign out: clears local Wislab session tokens on your device
- Account deletion: contact us at wisalshiekh@gmail.com to request deletion of Portal account data
Depending on where you live, you may have additional rights (access, correction, deletion, portability, objection). Contact us to exercise those rights.
8. Security
We use HTTPS for Portal traffic, hashed passwords, and industry-standard OAuth for calendar access. No method of transmission or storage is completely secure; you are responsible for securing devices and processing servers under your control.
9. Children
Wislab is not directed at children under 16, and we do not knowingly collect their personal information.
10. International transfers
Portal services may be hosted in countries other than yours. By using Wislab, you acknowledge that account and calendar connection data may be processed in those locations.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Continued use of Wislab after changes constitutes acceptance of the updated policy.
12. Contact us
Questions about this Privacy Policy or your data:
wisalshiekh@gmail.com
Wislab — wislab.co