Privacy Policy
Last updated: Jul 24, 2026
1. Introduction
Lungoor Notes, a venture of Surfboard India Pvt. Ltd. is operated by Surfboard India Pvt. Ltd. ("we", "us", or "our") at 8th Floor, New Viva College, Y.K Nagar, Virar West, Palghar, Maharashtra, 401303. Contact: [email protected] | Phone: +91 93730 23384
Lungoor Notes collects certain Personal Data and Usage Data to provide, maintain, and improve services. Some information is required for the platform to function properly. If you don't provide requested information where required, some services may be unavailable. See also our Terms of Service.
2. Information We Collect
2.1 Personal Data
- Email address
- First name and last name
- Organisation domain from your Google ID token (hosted domain, when Google includes it)
- Organisation display name when available from your Google profile (via the People API using your sign-in authorisation), or otherwise derived from your email domain for labelling your organisation in Lungoor Notes only
This data supports account creation, communication, authentication, and service delivery.
Sign-in via Google OAuth only - Lungoor Notes does not support password or other sign-in methods. You must sign in with Google OAuth using a work or organisation email on a non-consumer domain (not personal providers such as Gmail, Yahoo, Outlook.com, or similar free email services). Google Workspace accounts on your organisation domain are supported. After you sign in, you may connect Google Calendar using any Google account you authorise, including personal accounts.
2.2 Usage Data
- Meeting transcription records
- AI-generated summaries and derived meeting metadata
- Speech-to-Text usage count
- Platform usage metrics
Insights are generated only from user-authorised meeting data and are not used for profiling unrelated to user-requested functionality. Meeting data including transcriptions, summaries, and related insights is stored securely in our systems to provide the service.
3. Google Calendar Data We Access
Lungoor Notes currently supports Google Calendar only. Other calendar providers may be added in the future.
Lungoor Notes requests read-only access to calendar events in two situations - when you sign in with Google (initial authorisation) and when you connect an additional Google Calendar account in settings. We access only the minimum fields necessary to power meeting workflow features you explicitly request. The specific fields we read, and the sole purpose for each, are:
- Event title - to identify and display your upcoming meetings
- Start and end time - to surface the correct meeting at the right time and enable timely workflow triggers
- Attendee names and email addresses - to show meeting participants within the meeting workflow view
We do not read or store event descriptions, locations, organiser details, conferencing links, or any other calendar fields. This data is used solely to display upcoming meetings and enable meeting workflow features you request. It is not used for advertising, unrelated profiling, sale, or model training.
You may connect more than one Google account for Calendar. Each connection is separate - Lungoor Notes only reads the primary calendar for accounts you have authorised. Disconnecting one Calendar connection in Lungoor Notes does not remove access for other connected accounts.
4. Google Calendar Data Flow
The following describes where Google Calendar data goes within Lungoor Notes:
- Fetched from Google - upcoming events are read from Google when you use calendar features. We do not keep a full copy of your Google Calendar
- Stored in our systems - when you start or link a meeting session from a calendar event, we store the event title, scheduled start and end time, and participant names and email addresses in your meeting records, along with encrypted OAuth tokens and integration settings
- Used for search and AI features - meeting titles, schedule times, and participant information may be retained in our systems to enable meeting search and context retrieval for AI-powered features
- Sent to AI processing when - you use an AI-powered meeting feature such as summaries or meeting assistance. Only the calendar and meeting fields needed for that feature are included. Calendar data is not sent for unrelated purposes
- Not sent to - analytics systems, Slack, or Atlassian (Jira). These systems do not receive Google Calendar event content
Google Calendar data is never combined with analytics telemetry, advertising systems, or unrelated product features.
5. Cookies and Tracking Technologies
Lungoor Notes uses cookies and similar tracking technologies across our website and applications. Cookies help authenticate sessions and improve navigation and product quality.
- Authentication Cookies - verify user accounts and login state
- Analytics Cookies - understand usage patterns and feature interactions
6. Analytics
Lungoor Notes uses product analytics and monitoring tools. These tools receive product usage telemetry - feature interactions, session behaviour, system performance - to help us improve functionality and user experience. Analytics systems do not receive Google Calendar event content, transcription text, or any Google user data.
7. Third-Party Service Providers
Lungoor Notes shares data with the following named processors only to deliver the service:
- Google Authentication - handles OAuth sign-in and issues access/refresh tokens. Governed by Google's own terms
- Slack API - used for the optional Slack bot integration. Operates independently and does not access or combine Google Calendar data
- Atlassian (Jira Cloud API) - used for the optional Jira integration. Does not receive Google Calendar event content
AI language-model processing, speech-to-text transcription, and product analytics may be performed by third-party processors under contractual terms that restrict use to service delivery. Those processors do not receive Google Calendar event content except as needed for an AI feature you request, as described in Section 4. Data sent for AI processing is not used for model training.
All third-party processors used by Lungoor Notes - whether named above or used without being listed by name (including AI, speech-to-text, and analytics providers) - maintain SOC 2 Type II compliance. We engage only processors that meet this standard so your data is protected under independently audited security controls. All third-party processors are contractually bound to process data only for service delivery purposes. They are not permitted to use your data for their own purposes.
Slack Bot Integration
Slack integration operates independently and does not access or combine Google user data. Our bot may request the following Slack scopes:
- Send messages in chats
- Post in public channels it can access
- Read basic user profile info
- Read user email address when available
- Read public channel list and details
- Start or send direct messages
The bot cannot read private channels unless explicitly added by a user.
Jira Integration
Jira integration is optional. It operates independently and does not access or combine Google user data or Google Calendar event content. If you connect Jira Cloud, connection details and data needed to use Jira features are stored and processed securely in Lungoor Notes. You can disconnect Jira in Lungoor Notes settings at any time.
8. Google Authentication and Calendar Access
When you sign in with Google, we request OpenID scopes - openid, email, and profile - plus read-only Google Calendar events access. Sign-in is Google OAuth only and requires a work or organisation email on a non-consumer domain.
OAuth authorisation includes offline access to support uninterrupted meeting workflows without requiring you to re-authenticate for each session. Refresh tokens obtained via offline access are:
- Encrypted at rest in our backend database
- Accessible only to the backend services that require them to fetch calendar data on your behalf
- Replaced with a new token upon each re-authentication - the previous token is discarded
- Permanently deleted from our systems after we process a verified account deletion request
9. Children's Privacy
Lungoor Notes is intended only for users aged 18 and above. We do not knowingly collect personal data from anyone under the age of 18. By creating an account, you represent that you are at least 18 years old. If we become aware that we have collected personal data from a person under 18, we will take reasonable steps to delete that information.
10. Jira Integration
When you connect Atlassian Jira, we request the following OAuth scopes to create and manage issues on your behalf:
- read:jira-work - read issues, projects, fields, and project metadata
- read:jira-user - read assignable users for a project so you can pick an assignee when creating a ticket
- write:issue:jira - create and update issues
- write:comment:jira, write:comment.property:jira - add comments to issues
- write:attachment:jira - attach files to issues
- Additional read scopes for fields, field options, issue types, and project properties - used to populate issue creation forms
Jira access tokens and refresh tokens are encrypted at rest. You can disconnect Jira at any time from Settings, which immediately revokes our stored tokens.
11. AI and Speech Processing Services
To provide AI-powered features, Lungoor Notes processes meeting transcriptions and related context through third-party AI APIs. Data sent for AI processing is not used for model training and is handled under the applicable provider data usage policies.
For transcription workflows, audio is processed by third-party speech-to-text providers. Transcription providers do not receive Google Calendar event content. Insights are generated only from user-authorised meeting data and are not used for profiling unrelated to user-requested functionality.
12. Limited Use Compliance
Lungoor Notes' use of data received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. We do not:
- Use Google user data for advertising or ad targeting
- Sell Google user data to any third party
- Use Google user data to train AI or machine learning models
- Share Google user data with any party other than the named processors listed in Section 7, and only to the extent described
- Use Google user data for any purpose other than providing or improving the meeting workflow features you have requested
13. Data Retention and Deletion Requests
We retain personal data only as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. Unless a longer retention period is required by law, we retain data as follows:
- Account information (name, email, and related profile data) - retained while your account is active. After you request account deletion, there is a 30-day recovery period. After that period, we permanently delete or anonymise the data within 180 days, subject to legal requirements
- Audio recordings - audio is processed for transcription and is not retained once transcription is completed, unless you explicitly consent to retention for troubleshooting
- Meeting transcriptions, summaries, and related meeting history - retained while your account is active to provide the service, and permanently deleted after we process a verified account deletion request as described below
- Speech-to-Text usage counts and credit information - retained while your account is active for billing, fraud prevention, and account management
- Analytics data - retained as long as reasonably necessary to improve the service and troubleshoot issues
- Payment records - Lungoor Notes does not store your payment card or UPI details. Transaction records are kept for accounting, taxation, and legal obligations. Payment credentials are processed securely by our third-party payment provider
The following retention rules apply specifically to Google user data:
- Google OAuth refresh tokens are replaced on each re-authentication and permanently deleted after we process a verified account deletion request
- Calendar data in your meeting records is permanently deleted after we process a verified account deletion request
- Jira connection data is removed when you disconnect Jira and is permanently deleted after we process a verified account deletion request
- Active data derived from Google Calendar and other meeting data is removed from all active systems within 30 days after we verify your account deletion request
Lungoor Notes does not offer self-service account deletion in the app. To request deletion of your main account and all associated data, email [email protected]. We aim to send an initial response within 24-48 business hours and complete deletion within 30 days after we verify your request.
14. Security Measures
We implement industry-standard security measures to protect your data:
- Encryption - data stored on our infrastructure is encrypted at rest and protected during transmission using TLS encryption
- Access control - access to production systems is restricted to authorised personnel based on the principle of least privilege
- Monitoring - we continuously monitor application performance and operational events
- Third-party analytics - we use a third-party analytics provider for product improvement and troubleshooting. These events do not include names or email addresses and are associated only with a pseudonymous user identifier
- Compliance and certifications - we work with reputable service providers that maintain recognised security certifications such as SOC 2 Type II and ISO 27001. We expect our processors to maintain appropriate technical and organisational security measures
15. Your Rights
Subject to applicable law, you have the following rights over your personal data:
- Access - request a copy of the personal data we hold about you
- Correction - request that we correct inaccurate or incomplete data
- Deletion - request that we delete your personal data, subject to legal retention requirements
- Withdraw consent - you may withdraw your consent at any time by requesting deletion of your account, disconnecting optional integrations, updating your privacy preferences where available, or contacting us at [email protected]
If you request account deletion, your account enters a 30-day recovery period during which it can be restored. An account may be deleted and restored up to three (3) times. If you request deletion for a fourth time, or if the recovery period expires without restoration, your account and associated personal data will be permanently deleted or anonymised within 180 days, subject to any legal retention obligations.
- Review and update - you may review and update your account information at any time through your account settings. If you require assistance updating your information, you may also contact us at [email protected]
- Nomination - subject to applicable law, you may nominate another individual to exercise your privacy rights on your behalf in the event of your death or incapacity. Requests made by a nominated representative may require appropriate verification before they are processed
To exercise any of these rights, contact us at [email protected]. We may need to verify your identity before acting on a request.
16. Your Controls and How to Revoke Access
- Disconnect an additional Google Calendar account - in Lungoor Notes settings, you can disconnect Calendar integrations you added after sign-in. This removes that connection's calendar tokens and stops calendar reads for that account. It does not sign you out or delete meeting data already stored.
- Disconnect Jira - in Lungoor Notes settings, you can disconnect Jira at any time. You may also revoke access at id.atlassian.com/manage-profile/apps
- Disconnect Slack - in Lungoor Notes settings, you can disconnect your Slack workspace at any time
- Delete your main account and all connected data - email [email protected] to request deletion. After we verify the request, we delete your account and all associated data within 30 days
- Revoke Google access - visit myaccount.google.com/permissions, find Lungoor Notes, and remove access. Lungoor Notes cannot revoke sign-in Google access from inside the app - use Google Account permissions for that
- Privacy questions - contact us at [email protected] for any questions about how your data is handled
17. Grievance Officer
If you have any complaints or concerns regarding the processing of your personal data, you may contact our Grievance Officer:
Kshitija Katare
Grievance Officer
Surfboard India Pvt Ltd
Email: [email protected]
Phone: +91 93730 23384
We will acknowledge your grievance within 48 hours and aim to resolve it within 30 days of receipt.
© 2026 Lungoor Notes, a venture of Surfboard India Pvt. Ltd.
Surfboard India Pvt. Ltd.
8th Floor, New Viva College, Y.K Nagar, Virar West, Palghar, Maharashtra, 401303
Email: [email protected]
Phone: +91 93730 23384