Driffle handles sensitive context: calendars, messages, transcripts, browsing. We think you deserve a plain-English account of what we store, what we don’t, and the limits of where we are today. No certification badges we haven’t earned, no buzzwords. If something below doesn’t add up, tell us.

[email protected]. We respond within 1 business day and credit researchers in our changelog when fixes ship.Skim these. If they answer your question, you can stop here. Everything below is the long version.
Driffle never auto-joins meetings, auto-records, or runs in the background. You hit a button, it works. You close it, it stops.
Audio is transcribed in real time and discarded. We retain the resulting text and the notes you write, not the raw recording.
Summaries and chat are generated by models served by AWS Bedrock inside our AWS account, under terms granting the model provider no training rights. Your content is not sent to OpenAI, Anthropic, or any other model company.
We do not use your content to train AI models. Not ours, not anyone else’s. It is processed to serve you and for nothing else.
Your notes are visible only to you until you explicitly share. Workspace admins do not see private notes, only what’s shared into shared folders.
Individual notes are removed immediately. Full-account deletion clears your data within 30 days, including backups. We’ll show you the receipt.
The single most-asked question we get: “Wait, do you actually keep the audio?” No. Here’s the whole pipeline, with retention windows in the bottom corner of each card.
Notes, transcripts, and account metadata are stored in our US-region AWS Virtual Private Cloud. They are encrypted at rest using AES-256 and in transit using TLS 1.2+. Daily snapshots are retained for 30 days and encrypted with the same keys.
Access to production systems is limited to a small number of engineers, requires hardware MFA, and is logged. We use separate environments for development, staging, and production, with no customer data outside production.
Audio is captured on your device and streamed to our transcription vendor, which returns text. There is no on-device transcription mode today. If you have read otherwise anywhere, that was us describing a roadmap item as though it had shipped, and we have corrected it. The transcript and your notes are stored in our cloud so they sync across devices.
If you need a strictly on-device deployment, ask us about workspace plans. We’re working on an offline-only mode for regulated industries.
We maintain a public Vulnerability Disclosure Policy. Reports go to [email protected] with optional PGP. We aim to acknowledge within 1 business day, triage within 3 days, and patch critical issues within 7. Post-mortems for resolved vulnerabilities are published openly, because we believe you should be able to read about our mistakes.
Yes. We engage an independent third-party firm for an annual application and infrastructure pentest. The most recent test was completed in February 2026. We don’t publish the full report, but a summary letter is available under NDA.
Honest answer: no, not yet. Here’s where we are today:
We’ll update this page the moment any of that changes: not in a launch announcement, not in a footer badge, here.
Yes, on workspace plans. We support SAML 2.0 with any IdP that speaks it (Okta, Google Workspace, Azure AD, OneLogin, JumpCloud). SCIM provisioning is in beta. Workspace plans also get just-in-time deprovisioning when a user leaves your IdP.
We do not sell your data and we do not share it for advertising. Outside of people you deliberately share with, your data reaches only the vendors we need to run the product, and only the part of it each one needs:
This list is the same one published on our subprocessor registry, which we update before adding any new vendor. Email [email protected] to be told when it changes.
If you connect Google Calendar, Driffle receives read-only calendar data: event titles, times, descriptions, locations, and attendee names and email addresses. We use it to show you what meeting you are in and to prepare meeting briefs. It is shared with these parties and no others:
Google user data is not sent to Deepgram, Stripe, Resend, PostHog, or any other transcription, model, payment, or analytics provider. It is never sold, never shared with advertisers or data brokers, and never used for anyone else’s marketing. Beyond the vendors above, it is disclosed only in the situations described under other disclosures.
Driffle does not use data obtained from Google Workspace APIs, including your calendar, to develop, improve, or train generalized or non-personalized AI or ML models, our own or anyone else's. AI features that use calendar data run inside AWS Bedrock in our own AWS account, under terms that grant the model provider no training rights to your data.
Limited Use disclosure: Driffle's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke Driffle’s access at any time from your account settings or directly from your Google account permissions. Revoking deletes the stored tokens and stops all further calendar access.
People you choose. Notes are private to you by default. They become visible to someone else only when you explicitly share them, via a share link, a folder permission, or a workspace channel. Sharing a note never shares your calendar.
Legal and safety. We may disclose data where required by law or valid legal process, or where necessary to protect the rights and safety of a person. Where we are legally permitted to tell you first, we will.
Business transfers. If Driffle is acquired or merged, data may transfer to the successor, which stays bound by this policy. We would tell you before your data became subject to a different one.
Never. We do not sell your data, we do not share it with advertisers or data brokers, and we do not disclose it for anyone else's marketing.
Yes. Customer data is stored and processed in the United States, so if you are outside the US your data is transferred there. For transfers out of the EU/UK we rely on Standard Contractual Clauses, which are part of our DPA. EU data residency is on the roadmap and is not available today. If that is a hard requirement, tell us before signing up so we can be straight with you about timing.
Most of it you can do yourself: Settings → Export produces a full copy of your data, and deleting your account removes it. For anything else (an access request, a correction, a deletion you cannot perform in-product, or a question about a specific piece of data), write to [email protected]. We acknowledge within 5 business days and respond within 30 days, or tell you why we need longer.
All customer data is stored in AWS regions in the United States (us-east-1 primary, us-west-2 for failover). EU residency is on the roadmap for late 2026 but is not available today. If EU residency is a hard requirement, please tell us before signing up so we can be straight with you about timing.
Account deletion is immediate from your perspective: notes vanish, links break, the workspace closes. Behind the scenes, your data is purged from primary storage within 24 hours and from encrypted backups within 30 days. We’ll send you a written confirmation when the backup window closes.
Yes. Settings → Export generates a ZIP containing every note as Markdown, every transcript as plain text, and a JSON manifest of metadata. Exports are produced asynchronously and emailed to you when ready, usually within minutes.
We keep your notes and transcripts for as long as your account is active. Audit logs are retained for 12 months. Anonymised, aggregated usage telemetry is kept for 24 months. Raw audio (when it briefly exists in transit during cloud transcription) is dropped within 60 seconds.
We request the narrowest scopes we can: read-only calendar (to know what meeting you’re in), profile (to know your name), and email (to identify you). We do not read your inbox and we do not write to your calendar. Tokens are encrypted at rest and revocable from your account dashboard or directly from Google / Microsoft.
For exactly who this data is shared with, the Limited Use disclosure, and how to revoke access, see who we share your Google Calendar data with.
No.Driffle does not use your content to train AI models. Not ours, not anyone else’s. Your meetings, transcripts, notes, calendar data, and everything derived from them are processed only to serve you.
Driffle does not use data obtained from Google Workspace APIs, including your calendar, to develop, improve, or train generalized or non-personalized AI or ML models, our own or anyone else's. AI features that use calendar data run inside AWS Bedrock in our own AWS account, under terms that grant the model provider no training rights to your data.
No, and the reason is structural rather than contractual: summarisation, chat, and embeddings all run on models served by AWS Bedrock inside our own AWS account. Prompts are not sent to a model company’s own API, so there is no vendor holding your content to train on. AWS does not use Bedrock inputs or outputs to train its models or share them with model providers.
Transcription is the one place content goes to an outside vendor: audio is streamed to Deepgram under a no-training agreement and returned as text. Every recipient is listed in our subprocessor registry, which we update before adding any new vendor.
On workspace plans, yes. You can point Driffle at your own OpenAI, Anthropic, or Azure OpenAI deployment and we’ll route all model calls through your tenant. We never see the prompts or responses in that mode.
Transcription: Deepgram Nova-3. Summarisation, extraction, and chat: open-weight and Amazon models served by AWS Bedrock (currently gpt-oss-120b for extraction and Amazon Nova Pro). Embeddings: Amazon Titan and Cohere embedding models, also on Bedrock.
Everything except transcription therefore runs inside our own AWS account. We change models as better ones become available; the active model for each request is recorded and the categories above are what stays true.
You can edit or delete any AI-generated note, attribution, or summary. We don’t use AI output for any consequential decision about you (no scoring, no ranking, no eligibility). If you find a consistent error pattern, please write to [email protected].
By default, only you. Notes become visible to other people only when you explicitly share them, via a share link, a folder permission, or a workspace channel. A small number of Driffle engineers can technically access production data for incident response; all such access is logged and reviewed.
No. Workspace admins see usage reports, billing, and any content explicitly shared into workspace folders. They do not see your personal folder, your private meetings, or your draft notes. We have considered “admin override” modes and chosen not to ship one.
We don’t store passwords. Authentication is done via Google, Microsoft, or your SAML IdP. Sessions are signed JWTs scoped to a single device, valid for 14 days, and revocable from Settings → Devices. Idle sessions are forced to re-auth on workspace plans per your admin’s policy.
Not yet. Some features (transcription, notes) require an account because they sync across devices. We’re exploring a local-only mode that keeps everything on-device and requires no signup. No firm date yet.
Yes. Our standard DPA covers GDPR Article 28 controller-processor terms and Standard Contractual Clauses for EU-to-US transfer. We can sign as-is or work through reasonable redlines. Request a copy from [email protected].
We offer a private-tenant deployment in AWS for workspaces of 200+ seats. Your data lives in an isolated VPC under our operational control, with a separate KMS key tree. A true self-hosted (customer-operated) build is on the roadmap but not available today.
Workspace admins can export an audit log of authentication events, share-link creation, permission changes, and export actions. Logs are available via the dashboard or as a SIEM-friendly JSON stream. Retention is 12 months by default; longer on request.
Amazon Web Services (AWS), Cloudflare, Deepgram, Stripe, Resend, Sentry, PostHog, Linear. The full registry, with what each one receives and whether Google data is among it, is in Sharing & disclosure and on the subprocessor page. Email [email protected] to subscribe to subprocessor change notifications.