Data we collect and sources
1) Account & authentication
- Google Sign-In data: name, email, profile image (as provided by Google).
- OAuth tokens: access and refresh tokens, granted scopes, and expiry data used to maintain only the connections you enable.
- Google requirement: Our use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy (including Limited Use).
2) In-app data you or your organisation provide
- Calls: duration, notes, optional transcript, optional recording URL, links to evaluations.
- Events & scheduling: titles, start/end time, link to related contacts.
- Contacts, companies & deals: names, emails, phones, CRM fields, lifecycle or lead state, and deal or pipeline stage.
- Files: filename/type/size/URL you upload.
- Context: organisation/user context, objection lists, candidate snippets.
- LLM content: prompts/outputs (e.g., "brain context", generated notes/summaries) tied to your usage to deliver features.
3) Connected services (only if you opt in)
- Google Calendar read-only event details, including event IDs, titles, descriptions, locations, start/end times, attendees and email addresses, RSVP status, meeting links, and colour IDs, to show schedules, prepare AI meeting briefs, and link meetings. If you separately enable and use follow-up invites, we request write access to create Google Calendar events and notify attendees.
- Google Drive read-only access to supported files you can access, including file contents and metadata. We send the OAuth credentials needed to establish the connection and the synced data to Airweave, our indexing provider, for workspace search.
- Microsoft Graph (e.g., Calendars.Read delegated) for the same scheduling/context features.
- HubSpot contact read access, plus the optional contact, company, and deal permissions you approve, to match call attendees, load CRM context, share meeting notes, and create or update CRM records when you enable those features.
Caretta does not currently request Gmail scopes and does not access Gmail messages. We do not access connected-service data beyond the permissions you grant.
4) Analytics & telemetry
We use consented website analytics and marketing tools: Visitors for website analytics, which records page views and receives the page URL, referrer, IP address, and browser user agent; Vercel Web Analytics for pageview measurement using data such as timestamp, page URL or path, referrer, browser and device information, and coarse location; and Surface for marketing and visitor identification, which records a page journey and may attempt to associate a business visitor with a company or contact and enrich a lead profile. We also use PostHog for product analytics, such as feature usage, device or browser information, and coarse location or IP data, to improve performance and user experience. We load the website measurement and marketing tools only after you accept the relevant consent category.
How we use the data
- Authenticate sessions, manage accounts, and secure the service.
- Prepare call briefings; capture/transcribe calls if enabled; generate notes/summaries; support evaluations.
- Read relevant Google/Microsoft calendar event data for scheduling and context, and create Google Calendar events only when you enable and use follow-up invites.
- Index supported files from an optional Google Drive connection so they can be found through workspace search.
- Process relevant Google-derived data through configured AI service providers only to generate requested user-facing briefings, notes, summaries, and related assistance. We do not use Google user data to train or improve generalized AI or ML models.
- Read and, when enabled, create or update HubSpot contacts, companies, deals, and associated call notes.
- Provide analytics, product improvement, and support.
- Comply with legal obligations and enforce terms.
Legal bases
- Performance of a contract (Art. 6(1)(b)) – to deliver requested features.
- Legitimate interests (Art. 6(1)(f)) – security, fraud prevention, compatible analytics.
- Consent (Art. 6(1)(a)) – cookies/analytics where required and optional features.
- Legal obligation (Art. 6(1)(c)) – record-keeping, compliance.
International transfers
If we transfer data outside the EEA/UK, we use appropriate safeguards (e.g., EU Standard Contractual Clauses) and assess local laws.
Security
We implement industry-standard technical and organisational measures, including encryption in transit and at rest, strict access controls, and role-based permissions. Our application enforces data-segregation appropriate to our environment.
Retention
We retain OAuth tokens while a connection remains enabled and as needed to refresh it. Calendar-derived records, indexed Drive data, AI inputs and outputs, and inference-observability records are retained only while needed to provide and secure the service, under applicable workspace settings and processor terms, unless law requires longer. Provider security or abuse-monitoring records may be kept for the limited periods in the applicable provider terms unless account-specific reduced-retention controls apply. The website analytics and marketing data is retained only as needed for the stated purposes, according to our provider settings and terms. Withdrawing consent prevents these scripts from loading on later page loads but does not automatically delete data already collected by a provider. Revoking access in Google stops new API access but does not automatically delete existing copies already imported, indexed, generated, or logged. You or your organisation admin may request deletion of Caretta and processor-held copies at any time by following the deletion process below.
Your rights
You may have rights to access, rectify, erase, restrict, object, and data portability under the GDPR, and to lodge a complaint with the Autoriteit Persoonsgegevens (NL). We will respond within statutory periods.
Revocation & deletion
Revoke third-party access
- Google: revoke our access from your Google Account's third-party app settings at any time; this revokes the project's Google scopes and stops new Google API access. Google Account revocation does not by itself delete data already copied into Caretta or its processors. Disconnecting Google Drive requests deletion of its Airweave source connection and index, although processor cleanup may complete asynchronously. Because Google Calendar and Drive may share one stored Google credential, disconnecting Drive does not revoke the shared Google credential or other Google scopes. Request deletion if you want other existing Caretta and processor-held copies removed.
- Microsoft: revoke Microsoft Graph permissions from your Microsoft/Entra account settings.
- HubSpot: remove our app and its scopes in your HubSpot settings.
Request deletion
To delete in-app data, Google-derived data, and processor-held copies associated with your account or organisation (e.g., calls, transcripts, context, contacts, or files), email founders@caretta.so
Google-specific disclosures
- Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
- We use Google user data only to provide or improve prominent, user-facing Caretta features. We do not use Google user data to train or improve generalized AI or ML models.
- Relevant Google-derived data may be processed by the service providers identified in Sharing and processors. We use commercial API services for requested features and disable OpenAI Responses storage and OpenAI Agents SDK tracing in our server-side agent path; provider security or abuse-monitoring retention may still apply as described under Retention.
- We request only the minimum scopes needed and justify any sensitive/restricted scopes during verification.
Children
Our services are not directed to children and we do not knowingly process children's data.
Changes
We may update this policy from time to time. We will post the new date and, where appropriate, notify you.
Scopes & permissions
Below are the exact scopes our app requests and how we use them. We only request the minimum set of permissions required to deliver the described functionality.
openid, email, profileenable Google Sign-In and retrieve the user's basic account details (name, email, and profile image).
https://www.googleapis.com/auth/calendar.events.readonlyread Google Calendar event details, including titles, descriptions, locations, times, attendees, RSVP status, and meeting links, to display schedules and prepare meeting briefings.
https://www.googleapis.com/auth/calendar.eventsrequested incrementally only when you enable follow-up invites, so Caretta can create Google Calendar events and notify attendees when you use that feature.
https://www.googleapis.com/auth/drive.readonlyrequested incrementally only when you connect Google Drive, so Caretta can view and export supported files and metadata for workspace-search indexing. It does not permit Caretta to edit or delete Drive files.
To maintain a connection without repeated sign-in, Google OAuth is requested with the access_type=offline parameter after showing the consent screen. This asks Google for a refresh token; access_type=offline is OAuth behaviour, not an OAuth scope. Calendar write and Drive read access are requested incrementally only when you enable those features.
Microsoft
Calendars.Readread your Microsoft calendar metadata (event titles, times, attendees) to display schedules and prepare meeting briefings.
User.Readretrieve your basic Microsoft account details (name and email) to associate your user identity with your organisation's workspace.
offline_accessmaintain connection to your Microsoft account and refresh tokens without repeated sign-in.
openid, email, profilestandard authentication scopes that verify identity and provide basic user information during Microsoft login.
HubSpot
crm.objects.contacts.readrequired to find and read contact records so Caretta can match call attendees and load relevant CRM context.
crm.objects.contacts.writeoptional; create or update contact records and save meeting notes associated with selected contacts when you use those features.
crm.objects.companies.readoptional; find and read companies associated with contacts and calls.
crm.objects.companies.writeoptional; create or update company records when post-call CRM updates require it.
crm.objects.deals.readoptional; find and read deals and pipeline context related to a call.
crm.objects.deals.writeoptional; create deals or update deal stages when you enable post-call CRM updates.
Caretta connects through HubSpot OAuth. Contact read access is required; the remaining scopes are requested as optional permissions and are used only by the CRM features you enable.
Analytics
PostHog event collectiongather anonymised usage data (feature usage, device/browser type, session duration) to improve product performance and user experience.
Visitors and Vercel Web Analyticsload only after measurement consent to collect the website pageview and related technical data described above.
Surface visitor identificationloads only after marketing consent to support business-visitor identification and lead-profile enrichment.
Consent controlsallow you to withhold or withdraw measurement and marketing consent independently.