Privacy Policy
Last updated: August 2026
What we collect
Output collects only the information needed to provide the service:
- Email address — used to authenticate you via Google OAuth and to contact you about your account. If you join our waitlist, we also store the meeting tool and customer platform you tell us your team uses, so we can prioritise setup.
- Meeting source credentials — your Granola API key or Gong credentials, stored encrypted (AES-256-GCM), used to fetch your call notes.
- Destination OAuth tokens — your Monday.com and/or HubSpot tokens, stored encrypted, used to create tasks and write account health back on your behalf.
- Slack OAuth token — stored encrypted to send you approval DMs via your connected Slack workspace.
- Meeting metadata — meeting titles and extracted follow-up text from your call notes. We do not store full transcripts or recordings.
- Account health responses — the answers your team gives in the Slack prompt after a call: how the call went, confidence in the renewal, and any escalation flag. These are a person's subjective assessment, they are associated with a named customer account, and where HubSpot is connected they are written back to that customer's record in your CRM. Treat them as you would any internal note about a customer.
- Approval decisions — whether you approved or denied each follow-up, plus the resulting task ID in your destination.
How we use your data
Your data is used exclusively to operate Output: polling for new call notes, sending you Slack DMs for approval, and creating tasks and account health records in your connected destinations when you approve. We do not sell, share, or use your data for advertising or analytics purposes. Account health responses are never used for any purpose beyond delivering them to the destination you connected.
Customer data and your obligations
Output processes information about your customers on your behalf, including account names and your team's assessments of those accounts. You are the controller of that data; we are a processor acting on your instructions. You are responsible for ensuring you have a lawful basis for recording and storing these assessments, and for your own internal policies about who can see them. Access within Output is limited to the connected accounts in your workspace, and account health written to HubSpot inherits whatever permissions your CRM already enforces on that record.
Third-party services
- Granola — your API key is used to fetch meeting notes from Granola's API. Subject to Granola's privacy policy.
- Gong — where connected as your call source, your credentials are used to fetch call notes. Subject to Gong's privacy policy.
- HubSpot — where connected, your OAuth token is used to create tasks and write account health onto the customer record. Subject to HubSpot's privacy policy.
- Monday.com — your OAuth token is used to create tasks in your board. Subject to Monday's privacy policy.
- Slack — your workspace's bot token is used to send direct messages. Subject to Slack's privacy policy.
- Anthropic — call note content is processed by Claude (via Anthropic's API) to extract follow-ups. Per Anthropic's API terms, data sent via API is not used to train models. Subject to Anthropic's privacy policy.
- Supabase — your data is stored in a Supabase PostgreSQL database hosted in the US. Subject to Supabase's privacy policy.
- Stripe — payment processing. We never see or store your card details. Subject to Stripe's privacy policy.
Data security
All integration credentials (meeting source keys, HubSpot and Monday.com tokens, Slack token) are encrypted with AES-256-GCM before being stored. Encryption keys are stored separately from the database. All connections use TLS in transit.
Data retention
Your data is retained for as long as your account is active. Follow-up history (meeting titles, item text, approval decisions) and account health responses are retained to provide the dashboard view. You can delete all your data at any time from Settings → Delete account, or by emailing us. Deleting your Output account does not remove records already written to your own HubSpot or Monday.com workspace — those are yours, and you delete them there.
Your rights
You can request access to, correction of, or deletion of your personal data at any time. To delete your account and all associated data, use the Settings page or contact us. We will respond within 30 days.
Contact
Questions about this policy: hello@getoutput.app