Privacy Policy
Last updated SAYLI, LLC
Sayli is a meeting assistant that runs on your own computer. It transcribes the calls you choose to run it on, answers questions about them, and writes briefs and action items. This policy explains what personal information we collect, how we use it, who we share it with, and the choices you have. We do not train our own models on your meetings, and we do not sell your data.
1Scope and Applicability
This policy applies to SAYLI, LLC, an Illinois limited liability company ("Sayli", "we", "us", "our"), and to the Sayli desktop and web applications, our websites, and our related services (together, the "Services").
It does not apply to third-party applications or websites, which have their own policies, and it does not apply where we process content on behalf of an organization that bought Sayli for its team. In that case the organization decides how that content is handled and it is the controller; we act as its processor under a Data Processing Addendum, and you should read the organization's own privacy notice. When you use Sayli as an individual, we are the controller. For account, billing, security and usage data, we are the controller in both cases.
By accessing or using the Services, you agree to this policy and to our Terms of Service.
2What Information Do We Collect?
| Category | What it is |
|---|---|
| Account information | Your name, email address, and the sign-in identifier from Google or Apple, or a passwordless email link. We store no passwords, because there are none. |
| Audio | The audio of calls you run Sayli on. This includes the voices of other participants. |
| Transcripts | The text of those calls, with speaker labels. |
| Briefs, notes and knowledge base | Post-call briefs, action items, bookmarks, and anything you add to your knowledge base. |
| Screen images | When you ask Sayli about what is on your screen, the app captures a single image and sends it to a vision provider to answer. We do not keep it afterwards. Sayli does not record your screen continuously. |
| Questions and answers | What you ask Sayli during and after a call, and what it replies. |
| Connected account information | If you connect your calendar, files, email or task tools, the data needed for the feature you enabled. |
| Meeting participant details | Names and email addresses of people on your calendar invitations, used to label speakers and, if you choose, to send them the brief. |
| Usage information | Which features are used and how often, plus technical data such as IP address, device and operating system, and app version. Never the content of your meetings. |
| Crash and error reports | Diagnostics when something fails. |
| Billing information | Subscription and payment records. Stripe processes the payment. We never see your full card number. |
| Support correspondence | Emails you send us, and our replies. |
Speaker separation and voice
We do not create or store a voiceprint. We do not compute or keep a mathematical model of anyone's voice, and we do not use voice characteristics to recognize a person across meetings. Sayli separates speakers within a single recording so the transcript shows who said what, then matches those labels to names using what was said in the meeting and your calendar attendee list. That matching uses text and calendar data, not voice characteristics. What we store is a number, such as 1, and any name we matched to it. Nothing is compared against another recording or another person. Speaker separation is always on; Sayli cannot produce a usable transcript of a multi-person call without it.
Redaction
Before transcript text is stored or sent to a language model, we mask card numbers, government identifiers, phone numbers, email addresses and IP addresses. This happens on our servers after the audio has been transcribed, so it does not apply to the audio itself, and our speech-to-text provider receives the audio unredacted. We would rather say that plainly than imply otherwise.
Sensitive information in meetings
Conversations sometimes touch on health, beliefs, politics, union membership or someone's private life. We do not look for it, tag it, score it, or use it to categorize anyone, and we do not build features that try to work it out. If it ends up in a transcript, it is handled the same way as the rest of that meeting: same access controls, same retention, same deletion. Sayli is not for use with protected health information, and we do not sign Business Associate Agreements.
3How Do We Use The Information We Collect?
We use the information described above to:
- transcribe your calls, answer your questions, and write briefs and action items;
- keep your meetings searchable for you and the people in your organization you share them with;
- answer a question about what is on your screen when you ask one;
- run the integrations you enabled;
- create, maintain and secure your account, and provide support;
- bill you, keep tax and accounting records, and manage our relationship with you;
- understand which features are used and how often, and find and fix faults;
- detect, prevent and investigate fraud, security incidents and other misuse of the Services; and
- comply with applicable law and enforce our Terms of Service.
We do not use your information for advertising, and we run no advertising pixels.
4Do We Share Your Personal Information?
We do not sell your personal information. We share it with the categories of service provider below. Each receives only what its job requires, is permitted to use it only to provide its service to us, and is bound by data protection terms no less protective than this policy.
| Category | What it receives | Where |
|---|---|---|
| Speech to text | Call audio, unredacted | United States |
| Language models | Transcript text after redaction, and screen images you ask about | United States |
| Search index | Transcript text after redaction, stored as embeddings | United States |
| Web search | Search queries derived from a meeting, to check facts | United States |
| Cloud hosting (Google Cloud) | All stored data, encrypted | United States, Iowa |
| Payments (Stripe) | Billing details. We never receive your full card number. | United States |
| Email delivery | Your email address and the message | United States |
| Product analytics | Feature usage events, no meeting content | European Union |
| Error monitoring | Diagnostics, scrubbed of meeting content | United States |
We do not publish the names of the companies in each category. Business customers, and anyone evaluating Sayli under a mutual non-disclosure agreement, can obtain the current list, with what each provider processes and where it runs, by writing to privacy@sayli.ai.
We give at least 30 days notice before a new provider starts processing your content. If you are a business customer you may object in writing on reasonable data protection grounds within that period, and if we cannot resolve your objection you may end the affected part of the Services and we refund the unused fees.
Outside applications you approve can also read your meetings through Sayli's connection service. You can see and revoke every one of them in Settings. We are not responsible for what an application you approved does with what it reads.
We may also disclose information to a government or law enforcement body where we are legally required to, and only what the request actually compels. We review every request and push back on requests that are overbroad or improper. Unless we are legally prohibited, we will tell you before we disclose your data. Requests should be sent to legal@sayli.ai. Finally, we may disclose information to a buyer if the business is sold, in which case we will tell you before your data becomes subject to a different policy.
5Artificial Intelligence and Automated Processing
We do not use your meetings to train our own models, and we do not sell your data. We use aggregate, non-identifying usage information to operate and improve Sayli. That does not include the content of your meetings.
Sayli is an artificial intelligence system. Everything it produces is machine-generated, including transcripts, answers, briefs and action items, and it is marked as such. Sayli decides who said what, matches speaker labels to names, and writes action items and assigns them to people. Those are automated and they can be wrong.
We do not make decisions about you that produce a legal effect or similarly significantly affect you, and our Terms of Service prohibit customers from using Sayli's output as the sole or automated basis for decisions about hiring, promotion, discipline, termination, credit, housing, insurance, education or access to essential services. If something Sayli produced about you is wrong, write to privacy@sayli.ai and we will correct it.
6If You Were Recorded and Do Not Use Sayli
You are reading this because someone you met with used Sayli to take notes. Sayli ran on their computer and transcribed the meeting. It did not join the call, so you would not have seen it in the participant list.
What we hold. A recording of the call, a transcript of what was said including your part of it, a speaker label such as 1 with your name matched to it where we could work it out, and the parts of the brief and action items that came from what you said. If you were on the calendar invitation, we also hold your name and email address.
What happens to it. We use it to produce the transcript, the brief and the action items for that meeting. Those records are then searchable by the person who recorded the call and by other people in their organization who have access to that meeting. If they ask Sayli a question later, Sayli may retrieve parts of your meeting to answer it. If they have connected an outside application to their Sayli account, that application can read those records too. If they choose to send you the brief by email, we send it and we keep your email address and a record of the send.
What we do not do. We do not build a profile of you, we do not use your voice to identify you, we do not sell your data, and we do not train models on it.
What you can ask for. Write to privacy@sayli.ai. You can ask what we hold about you, ask us to correct it, ask us to delete it, or object to us processing it. If you object, we will stop processing your data unless we have compelling grounds not to.
Who decides, and how fast. What happens next depends on whose account the meeting is in, and we will tell you which it is. If the meeting is in an individual's account, we decide what happens to it, so we act on your request ourselves and confirm within 30 days. If the meeting is in a business account, that business decides what happens to its records; we pass your request to it within 5 business days, we help it respond, we tell you we have done so, and if it has not acted within 30 days we will act ourselves where the law requires us to.
We may be unable to delete something we are required to preserve for a legal claim or a court order. If that applies, we will tell you. If you would prefer not to be recorded, tell the person running the call.
7How Do We Use Tracking Technologies?
Our websites and the app set storage that is strictly necessary to sign you in and keep the Services working. We also use product analytics and error reporting to understand which features people use and to find faults.
Analytics and error reporting are on by default and you can switch them off at any time in Settings under Privacy. That setting governs both. Analytics events carry feature usage, never the content of your meetings. Session replay is off. We do not use advertising or cross-site tracking cookies.
Because we do not track users across third-party websites for advertising, we do not change our practices in response to Do Not Track signals.
8How Do We Secure Your Personal Information?
In summary: encryption in transit and at rest, per-organization isolation enforced in the data model, redaction of sensitive strings, private storage with short-lived signed links, short-lived access tokens with rotating refresh tokens, an audit log, scrubbed error telemetry, and rate limits on sign-in and other sensitive endpoints. We configure our error reporting to strip transcript text, questions, answers and tokens before a report leaves our systems. No scrubbing is perfect; if a report does carry a fragment, it is deleted with the report.
No system is perfectly secure, and these measures do not guarantee that your information will not be accessed, disclosed, altered or destroyed. We do not claim otherwise. To report a vulnerability, write to security@sayli.ai.
9Data Retention
| Data | Retention |
|---|---|
| Audio recordings | Kept until you delete the meeting or close your account. Your organization can set a rolling deletion window. Deleting a meeting deletes its audio immediately. |
| Transcripts, briefs, knowledge base | Kept until you delete them or close your account, or until your organization's retention window expires. |
| Screen images | Not stored. Discarded once the answer is produced. |
| Questions and answers | Kept with the meeting they belong to. |
| Usage information | 25 months. |
| Crash and error reports | 90 days. |
| Audit log | Kept for accountability. When you close your account, your identity on audit rows is replaced with a one-way hash of your email. |
| Billing records | As long as tax and accounting law requires, normally seven years. |
| Backups | Deleted data can persist in encrypted backups for up to 35 days before being overwritten. |
We may keep content for longer where we are required to preserve it for a legal claim, an investigation or a court order. We keep only what the preservation covers and delete it when the obligation ends.
10Data Transfers
Your content is stored and processed in the United States, in Google Cloud's us-central1 region in Iowa. Product analytics are processed in the European Union. We do not offer processing inside the European Union today, and we will tell you if that changes.
Our team works from North Macedonia and the United States, and accesses production systems from there when support, security or engineering work needs it. Those accesses are logged.
Where you are in the EEA, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum where the UK regime applies, to cover transfers out of your region, and we use the same Clauses with each of our own providers for any onward transfer. Ask at privacy@sayli.ai for a copy.
11Managing Your Privacy
Most of this you can do yourself, without writing to us. Delete a meeting, or your whole account, from inside the app. Export your data from Settings. Most of your data is editable in the app. Analytics and error reporting can be switched off in Settings under Privacy. Connected accounts and authorized applications can be revoked in Settings.
What deleting your account does. It removes your meetings, recordings, transcripts, briefs, knowledge base and search index entries from the live service in one operation, then closes the account. We instruct our providers to delete their copies at the same time. Three things survive. Encrypted backups can hold deleted data for up to 35 days before they are overwritten. Billing records are kept as long as tax law requires. Briefs we have already emailed to people are in their inboxes and we cannot take them back.
For anything else, including a request to review, update or delete personal information we hold about you, write to privacy@sayli.ai. We respond within 30 days and we do not charge for it. We may ask you to confirm your identity, and we will only use what you send for that purpose. You can also opt out of marketing emails using the unsubscribe link in any of them.
12Children Under 16
Sayli is not for anyone under 16 and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has used Sayli, write to privacy@sayli.ai and we will delete the account and its data.
13Region-Specific Disclosures
United States
Depending on your state, you may have the right to know what personal information we collect, to access and delete it, to correct it, to obtain a portable copy, and not to be discriminated against for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising, and we have not done so in the preceding twelve months. We do not use or disclose sensitive personal information beyond what is needed to provide the Services. To exercise a right, write to privacy@sayli.ai. An authorized agent may act for you with written proof. If we decline a request we will tell you why, and you may appeal by replying to that decision.
Illinois residents. As described in Section 2, Sayli does not create or store a voiceprint or any other biometric identifier.
Washington and Nevada residents. If a conversation happens to touch on health, that information is handled as described in Section 2.
European Economic Area, United Kingdom and Switzerland
Where the GDPR or UK GDPR applies, our legal bases for processing are:
- Performance of a contract for transcribing your calls, answering your questions, writing briefs, keeping your meetings searchable, running the integrations you enabled, and providing and securing your account;
- Legitimate interests for processing the contributions of other participants on a call in order to produce an accurate record of a conversation you were all part of, for understanding how the Services are used, for finding and fixing faults, and for preventing fraud and abuse;
- Legal obligation for keeping tax and accounting records and responding to lawful requests; and
- Consent where we ask for it, which you can withdraw at any time.
Where we rely on legitimate interests to process the words of someone else on a call, we rely on the person who recorded the call having obtained whatever consent the law requires first, which our Terms of Service require of them. We do not use those words to train any model, we do not sell them, and we do not build a profile of anyone. You can object at any time under Article 21 and we will stop unless we have compelling grounds not to.
You have the right to request access to, rectification of, or erasure of your personal data, to restrict or object to our processing of it, and to data portability. To exercise any of these, write to privacy@sayli.ai. You also have the right to lodge a complaint with your local supervisory authority at any time, and you do not have to come to us first. If you would like us to look at it first, tell us at privacy@sayli.ai; we will confirm receipt within 30 days and tell you the outcome as soon as we can.
14Changes and Contact
We will post changes to this policy here with a new date. If a change is material, we will tell you by email or in the app before it takes effect. Every previous version stays available.
| Privacy | privacy@sayli.ai |
|---|---|
| Security | security@sayli.ai |
| Legal | legal@sayli.ai |
| Copyright | dmca@sayli.ai |
| Entity | SAYLI, LLC, Naperville, Illinois, United States |